Loading IndicatorLoading Indicator

Coldcard Wallet Flaw Went Undetected for Five Years, Fueling Scrutiny of Hardware Wallet Security Checks

Source
Bloomingbit Newsroom

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

A flaw in random-number generation that went undetected for five years in Coldcard hardware wallets is raising broader questions about the lack of security verification standards across the crypto hardware wallet industry.

Cointelegraph reported on August 3 that Kraken Chief Security Officer Nick Percoco wrote on X that the incident should be a "wake-up call" for hardware wallet manufacturers. He called for independent verification to ensure that approved random-number generation paths are actually running in shipping firmware.

Consumers entrust manufacturers with implementing the most critical function in the system, Percoco wrote. Yet there is no independent process to confirm that the approved entropy path is the one actually being executed.

Coldcard manufacturer Coinkite disclosed the flaw last Thursday. The company said that while integrating a new cryptography library in March 2021, the wallet-generation path was mistakenly linked to a weak MicroPython pseudo-random number generator, or PRNG, embedded in the codebase, rather than the intended true random number generator, or TRNG.

In a postmortem report, Coinkite said most of Coldcard's randomness had been coming from a PRNG that it did not even know existed in the codebase. The TRNG code the company had carefully written ended up being used only for less important functions, apparently by accident.

The code review confirmed that the TRNG code existed and worked. But it did not verify which random-number generator was actually being called, allowing the flaw to remain undetected for five years. Percoco wrote that this kind of end-to-end verification is already standard in other security sectors, including those overseen by the National Institute of Standards and Technology and Germany's Federal Office for Information Security, or BSI.

He added that the payments industry does not ship PIN-entry devices without independent lab testing, and the U.S. government does not approve cryptographic modules without validating entropy sources. Digital-asset self-custody should not be treated as an exception, he wrote.

More than 4,500 addresses have been affected in attacks believed to have exploited the flaw, with about $90 million in Bitcoin stolen so far. Coinkite said it halted all device shipments after confirming the issue and destroyed all inventory loaded with the affected firmware. The company urged owners of impacted devices not to throw them away, saying they may be needed later for fund-recovery procedures.

#Hardware Wallet
Bloomingbit Newsroom

Bloomingbit Newsroom

news@bloomingbit.ioFor news reports, news@bloomingbit.io

What do you think about this news?








PiCK News






Hashtag News