Kraken Chief Security Officer Nick Percoco warned that the industry must move beyond internal audits to ensure that the hardware-backed random number generators advertised by vendors are actually the ones producing wallet keys. The Coldcard flaw, which persisted from March 2021 until its recent discovery, occurred when a firmware update inadvertently swapped a robust hardware-backed entropy source for a weaker, deterministic MicroPython generator. Although the intended security mechanism remained active for other operations, it was bypassed during the creation of new wallet secrets.
Galaxy Research data indicates that the exploitation has been significant, with more than 5,200 addresses potentially compromised and approximately 1,815 BTC moved by attackers. While Coinkite has released firmware patches to rectify the code path, these updates cannot retroactively secure existing wallets. Users are strongly advised to generate entirely new seed phrases on updated devices and migrate their balances immediately. Percoco noted that unlike the payment card industry, which mandates strict, independent laboratory testing for security modules, the hardware wallet sector currently lacks a standardized, third-party framework to validate entropy sources before products reach the consumer.

Comments (0)
No comments yet. Be the first!