Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken
Kraken’s chief security officer said the Coldcard vulnerability exposes a broader weakness in hardware wallet testing.
YayaNews contributes financial news and market context through the YayaNews editorial workflow.

Kraken’s chief security officer said the Coldcard vulnerability exposes a broader weakness in hardware wallet testing.
Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken
DOGE
$0.07000
0.20%
TRX
$0.3262
0.60%
LINK
$8.27
1.05%
ZEC
$477.14
0.45%
ADA
$0.1860
1.28%
XRP
$1.07
0.81%
ETH
$1,861.91
0.91%
BTC
$62,976.65
0.86%
XMR
$362.82
0.50%
BNB
$583.92
0.14%
XLM
$0.1718
1.99%
SOL
$73.04
0.42%
HYPE
$52.61
0.14%
Written by
Felix Ng
staff editor
Reviewed by
Yohan Yun
staff editor
Written by
Felix Ng
staff editor
Reviewed by
Yohan Yun
staff editor
Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief
Latest News
Published
Aug 3, 2026
The five-year bug escaped detection because auditors verified that the intended random number generator existed, but not that it was being called.
Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco.
In an X post on Sunday, Percoco
said
the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.
“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco.
His comments follow an ongoing attack that is believed to
exploit weak seed phrases
generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted,
draining nearly $90 million in Bitcoin
.
Coldcard RNG flaw remained undetected for five years
On Thursday, Coinkite disclosed a software flaw that has existed since March 2021, when Coldcard changed its seed-generation process as it integrated a new cryptographic library.
The migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codebase, rather than Coldcard’s intended true random number generator (TRNG).
“The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” Coinkite said in its postmortem. “At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.”
The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called.
Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.
“Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said.
“The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco.
Related:
Suspected 4th Coldcard attack wave sweeps 389 Bitcoin: Galaxy’s Thorn
Coldcard said Sunday it has
halted
all device shipments since confirming the vulnerability on Thursday, and has destroyed all remaining units at its facilities
containing the affected firmware
.
However, Coinkite has
advised
users with affected devices not to dispose of them as “it may become essential if funds are recovered.”
“Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.”
Related:
Coldcard exploit sparks Bitcoin flight, ‘bullish’ crypto consolidation: Hodler’s Digest, August 2
Subscribe to daily byte-sized crypto news from Cointelegraph
Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s
Editorial Policy
and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
Hardware Wallet
Hacks
Kraken
Scams & Cybercrime
More on the subject
Apple faces lawsuit over alleged $1.8M Bitcoin wallet app losses
Jul 28, 2026
Helen Partz
News Brief
Brazilian police bust cocaine traffickers in crypto-linked transnational probe
Jul 27, 2026
Adrian Zmudzinski
News Brief
Robinhood CEO’s X account hacked in apparent memecoin scam
Jul 23, 2026
Sam Bourgi
News Brief
Apple faces lawsuit over alleged $1.8M Bitcoin wallet app losses
Jul 28, 2026
Helen Partz
News Brief
Brazilian police bust cocaine traffickers in crypto-linked transnational probe
Jul 27, 2026
Adrian Zmudzinski
News Brief
Robinhood CEO’s X account hacked in apparent memecoin scam
Jul 23, 2026
Sam Bourgi
News Brief
Original YayaNews editorial coverage, published for informational purposes.
This article is sourced from CoinTelegraph. It is for informational purposes only and does not constitute investment advice.
Topics & Symbols
Continue Reading
Related Reading
Binance Launches TradFi Perpetual Contracts: A New Milestone in Crypto-Traditional Finance Convergence
On July 29, 2026, Binance Futures introduced multiple USDⓈ-margined TradFi perpetual contracts, bridging crypto and traditional markets. This article analyzes their impact, risks, and industry significance.

Coldcard Likely 4th Attack Wave Sweeps Nearly 389 BTC: Galaxy
Galaxy’s Alex Thorn has warned of a suspected fourth Coldcard attack wave impacting 388.93 BTC from 462 addresses.

Bitcoin Spot ETFs See Over $1B Inflows in Three Days, Signaling Institutional Accumulation
Bitcoin spot ETFs recorded over $1 billion in net inflows over three days, signaling accelerated institutional accumulation. This article analyzes fund flows, institutional allocation logic, and the impact on short-term price support and market sentiment, while looking ahead to key variables.

Coldcard Exploit Sparks Bitcoin Flight, ‘Bullish’ Crypto Consolidation: Hodler’s Digest,
The “sickening” Coldcard exploit sparks a flight to safety among small Bitcoin hodlers. The Clarity Act stalls with just five days left on the clock. Hodler’s Digest, July 2.
