In section Cryptocurrency

Coldcard Firmware Flaw Exposes Weakness in Hardware Wallet Security

A five-year-old vulnerability in Coldcard hardware wallets has triggered a wave of attacks, resulting in the suspected theft of nearly $90 million in Bitcoin. The incident has prompted industry leaders to demand independent verification of seed generation processes, which currently rely entirely on manufacturer self-attestation.

Coldcard Firmware Flaw Exposes Weakness in Hardware Wallet Security

Kraken Chief Security Officer Nick Percoco warned that the industry must move beyond internal audits to ensure that the hardware-backed random number generators advertised by vendors are actually the ones producing wallet keys. The Coldcard flaw, which persisted from March 2021 until its recent discovery, occurred when a firmware update inadvertently swapped a robust hardware-backed entropy source for a weaker, deterministic MicroPython generator. Although the intended security mechanism remained active for other operations, it was bypassed during the creation of new wallet secrets.

Galaxy Research data indicates that the exploitation has been significant, with more than 5,200 addresses potentially compromised and approximately 1,815 BTC moved by attackers. While Coinkite has released firmware patches to rectify the code path, these updates cannot retroactively secure existing wallets. Users are strongly advised to generate entirely new seed phrases on updated devices and migrate their balances immediately. Percoco noted that unlike the payment card industry, which mandates strict, independent laboratory testing for security modules, the hardware wallet sector currently lacks a standardized, third-party framework to validate entropy sources before products reach the consumer.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!