Coldcard Missed Flawed Random-Number Generator for Five Years, Exposing Gaps in Hardware Wallet Security Checks
Summary
- A random-number generation flaw that went undetected for five years in Coldcard hardware wallets has exposed broader concerns over the hardware wallet industry's lack of security validation systems.
- More than 4,500 addresses lost about $90 million worth of Bitcoin, and Coinkite halted all device shipments and destroyed all inventory carrying the affected firmware.
- Percoco said independent verification is needed for approved random-number generation paths and entropy sources, and that digital-asset self-custody should not be treated as an exception.
Forecast Trend Report by Period



A random-number generation flaw that went undetected for five years in Coldcard hardware wallets has exposed broader gaps in security validation across the crypto hardware wallet industry.
Cointelegraph reported on Aug. 3 that Kraken Chief Security Officer Nick Percoco wrote on X that the episode should serve as a wake-up call for hardware wallet manufacturers. He called for independent procedures to verify that approved random-number generation paths are the ones actually executed in shipping firmware.
Consumers are entrusting manufacturers with the single most critical function in the system. Yet there is no independent process to confirm that the approved entropy path is what a device is actually running, Percoco wrote.
Coldcard maker Coinkite disclosed the flaw last Thursday. The company said the problem began in March 2021, when the wallet-generation path was mistakenly linked to a weak MicroPython pseudo-random number generator, or PRNG, already present in the codebase instead of the intended true random number generator, or TRNG, during the integration of a new cryptographic library.
In a postmortem report, Coinkite said most of Coldcard's randomness had been coming from a PRNG that it did not even realize was in the codebase. The TRNG code the company had carefully written ended up being used only for less important functions, and only by accident.
A code review confirmed that the TRNG code existed and worked. But reviewers did not check which random-number generator was actually being called, allowing the flaw to go undetected for five years. Percoco wrote that this kind of end-to-end validation is already standard elsewhere in the security industry, including at the National Institute of Standards and Technology and Germany's Federal Office for Information Security, or BSI.
The payments industry does not ship PIN-entry devices without independent lab testing, he added. The U.S. government also does not approve cryptographic modules without validating their entropy sources. Digital-asset self-custody should not be the exception.
More than 4,500 addresses have been affected in what is believed to be attacks exploiting the flaw, with about $90 million in Bitcoin stolen so far. Coinkite said it halted all device shipments after confirming the issue and destroyed all inventory loaded with the affected firmware. The company urged owners of impacted devices not to discard them, saying the hardware may be needed later in fund-recovery procedures.
Minseung Kang
minriver@bloomingbit.ioBlockchain journalist | Writer of Trade Now & Altcoin Now, must-read content for investors.