Kraken's chief security officer Nick Percoco highlighted a critical vulnerability in Coldcard hardware wallets that has been exploited to drain nearly $90 million worth of Bitcoin from thousands of users. The security flaw, rooted in a five-year-old firmware bug, allowed attackers to predict wallet seeds due to a weak random number generator used during wallet creation.

Coinkite, the company behind Coldcard, revealed the issue originated in March 2021 when they migrated part of the firmware and unintentionally switched from a hardware-backed true random number generator to a weaker deterministic generator supplied by MicroPython. This error escaped detection because the original generator remained active elsewhere in the code, misleading reviewers.

Independent blockchain analysis by Galaxy Research estimates over 1,800 BTC stolen from more than 5,200 wallets across four waves of attacks. While these numbers are approximations and Coinkite has yet to verify each case, the scale of the breach has shaken confidence in hardware wallet security. The compromised wallets cannot be fixed via firmware updates alone, forcing users to generate new seed phrases.

In response, Nick Percoco demanded that hardware wallet manufacturers submit their production firmware to independent audits to ensure the true randomness source used in wallet seed generation is verified. He argued that relying solely on manufacturers' internal checks puts users at risk and that external validation is necessary to prevent similar incidents going unnoticed.

This incident raises pressing questions about the rigor of security audits in the crypto hardware space. It comes at a time when market players face increased scrutiny to safeguard digital assets amid rising threats. Coldcard's exploit is a stark reminder that even trusted devices can harbor hidden vulnerabilities for years.

This material is informational and does not constitute financial advice.