Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

The five-year bug escaped detection because auditors verified that the intended random number generator existed, but not that it was being called.
Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco.
In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.
“Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco.
Source: Cointelegraph →Related News
- 1 hour ago
Meta latest AI firm to see model go rogue during testing
- 4 hours ago
Mysten Labs tech chief joins Anthropic to work on AI security
- 5 hours ago
Bitcoin Red Team reports 5K findings in sweeping security audit
- 5 hours ago
Block raises 2026 outlook on strong quarter, says AI touches nearly all code
- 9 hours ago
Senator Warren questions US AI chip policy after Trump crypto investment: Report
