Coldcard vulnerability has affected over 4,500 addresses, with nearly $90 million in Bitcoin stolen
2026-08-03 04:21
Odaily News: Kraken Chief Security Officer Nick Percoco stated that the 5-year seed generation vulnerability in Coldcard has exposed the gap in independent testing of hardware wallets. Auditors verified that the expected random number generator exists, but did not verify that the production firmware actually calls that generator.
This vulnerability is believed to be linked to an ongoing attack. As of Sunday, over 4,500 addresses were affected, with nearly $90 million in Bitcoin stolen. Coinkite disclosed that this software vulnerability has existed since March 2021, when Coldcard, during the integration of a new cryptographic library, erroneously directed the wallet creation process to a weaker MicroPython generator.
Percoco pointed out that hardware wallets lack end-to-end verification processes similar to NIST SP 800-90B and BSI AIS-31. Existing Common Criteria certifications for security elements, some CSPN certifications, and vendor-commissioned audits do not systematically enforce verification that production firmware actually calls the verified entropy source.
Coldcard stated that it has suspended all device shipments since confirming the vulnerability on Thursday and has destroyed all remaining devices containing affected firmware at its facility. Coinkite advised affected device users not to discard their devices and stated that its legal team will coordinate with law enforcement agencies in multiple jurisdictions as appropriate.
This vulnerability is believed to be linked to an ongoing attack. As of Sunday, over 4,500 addresses were affected, with nearly $90 million in Bitcoin stolen. Coinkite disclosed that this software vulnerability has existed since March 2021, when Coldcard, during the integration of a new cryptographic library, erroneously directed the wallet creation process to a weaker MicroPython generator.
Percoco pointed out that hardware wallets lack end-to-end verification processes similar to NIST SP 800-90B and BSI AIS-31. Existing Common Criteria certifications for security elements, some CSPN certifications, and vendor-commissioned audits do not systematically enforce verification that production firmware actually calls the verified entropy source.
Coldcard stated that it has suspended all device shipments since confirming the vulnerability on Thursday and has destroyed all remaining devices containing affected firmware at its facility. Coinkite advised affected device users not to discard their devices and stated that its legal team will coordinate with law enforcement agencies in multiple jurisdictions as appropriate.
