Coldcard's Five-Year RNG Flaw Was Hiding in Plain Code, Says Kraken's CISO 🪙
Hardware-wallet maker Coinkite disclosed on Thursday that a software flaw has existed in Coldcard devices since March 2021, when a migration to a new cryptographic library inadvertently routed wallet creation to a weaker MicroPython pseudo-random number generator in the codebase rather than Coldcard's intended true random number generator. "The bulk of randomness on the COLDCARD was coming from a PRNG that I didn't know was actually in the source code base," Coinkite said in its postmortem. "At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things." Because the intended TRNG code was present and appeared to function, code reviews confirmed its existence without verifying that production firmware was actually calling it. Coinkite said it has halted all device shipments since confirming the vulnerability on Thursday and has destroyed all remaining units at its facilities containing the affected firmware.
Kraken chief security officer Nick Percoco said in an X post on Sunday that the incident should be a "wake-up call" for hardware-wallet makers and called for independent testing to verify that the approved source of randomness is the one actually used by production firmware. "Consumers are asked to trust a manufacturer's implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing," Percoco said. He cited NIST SP 800-90B, the US government standard for designing and validating physical true random number generators, and BSI AIS-31, the German Federal Office for Information Security's equivalent standard, noting that "hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls."
Percoco added: "The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception." An ongoing attack is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses had been impacted, draining nearly $90 million in $BTC, according to figures cited by Percoco. A suspected fourth wave of the attack swept 389 $BTC, per Galaxy's Alex Thorn.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.