discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

A five-year-old bug in Coldcard's seed-generation process has exposed a weakness in how hardware wallets are independently tested, according to Kraken's chief security officer. The flaw allowed attackers to exploit weak seed phrases generated by affected devices, impactin…

By Felix Ng·Aug 3·cointelegraph.com·2 min read

Intelligence analysis by Llama

Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief
Image: cointelegraph.com

A five-year-old bug in Coldcard's seed-generation process has exposed a weakness in how hardware wallets are independently tested, according to Kraken's chief security officer. The flaw allowed attackers to exploit weak seed phrases generated by affected devices, impacting over 4,500 addresses and draining nearly $90 million in Bitcoin.

Why it matters

This story matters because it highlights a critical weakness in the testing process of hardware wallets, which could have far-reaching implications for the security of digital assets.

Imagine you have a special box that helps you keep your money safe. But what if someone could trick the box into giving them the combination to open it? That's what happened with some special boxes called Coldcard. A group of people found a way to make the boxes give them the wrong combination, and they were able to take a lot of money. This is a big problem because people trust these boxes to keep their money safe.

Analysis

A $60B Vote of Confidence

The five-year bug escaped detection because auditors verified that the intended random number generator existed, but not that it was being called. This highlights a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.

Why Cursor?

Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco. His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin.

The Road Ahead

The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called. Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.

Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said. “The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco.

Key points

  • A five-year-old bug in Coldcard's seed-generation process has exposed a weakness in how hardware wallets are independently tested.
  • The flaw allowed attackers to exploit weak seed phrases generated by affected devices, impacting over 4,500 addresses and draining nearly $90 million in Bitcoin.
  • Kraken's chief security officer is calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware.
  • The industry has no equivalent process for testing and verifying hardware wallets, unlike the payments industry and the US government.
The Upside

If the hardware wallet industry takes steps to improve testing and verification, it could lead to more secure and trustworthy products. This could give consumers more confidence in using digital assets for self-custody.

The Downside

If the industry does not take action to address the testing gap, it could lead to more vulnerabilities and attacks on hardware wallets. This could result in significant financial losses for consumers and damage to the reputation of the industry.

Originally reported at

cointelegraph.com

Discernion covers the story. Read the full piece at the source.

Tagshardware-walletscoldcardkrakensecuritytestingverification

Author

Felix Ng

Intelligence analysis by

Llama

Published

Aug 3, 2026

Source

cointelegraph.com

Share

Topics

hardware-walletscoldcardkrakensecuritytestingverification

Related

More from this desk

investing gold finance money bitcoin Breaking Push cryptocurrency USD trading CLARITY Act
Aug 24·decrypt.co

Why the Bitcoin Rally Looks Like a Vote Against the Dollar

Bitcoin gained 23.2% over seven days as gold climbed and the dollar weakened, reviving the debasement trade.

Aug 24·cointelegraph.com

Circle Gets $140 Target as Bernstein Eyes USDC Growth Cycle

Analysts at Bernstein are bullish on stablecoin issuer Circle, arguing that a new growth cycle for its USDC stablecoin could provide a significant boost for the company over the next 12 months.

UK Banks Still Blocking Bitcoin, Policy Group Tells Parliament

Aug 24·bitcoinmagazine.com

UK Banks Still Blocking Bitcoin, Policy Group Tells Parliament

A policy group has criticized British banks for applying blanket restrictions to lawful bitcoin activity. The group says that no improvements have been made over the past three years in how banks treat bitcoin activity, with roughly 40% of bank-to-exchange transfers in th…

investing finance Ethereum money banking coinbase trading Tokenized stocks Base
Aug 24·decrypt.co

Coinbase Brings Tokenized Stocks to Ethereum L2 Base

Coinbase's Ethereum layer-2 network, Base, now offers tokenized stocks for users outside the US.