The recently disclosed Coldcard hardware wallet vulnerability has sparked renewed concerns about security standards across the self-custody industry, with Kraken Chief Security Officer Nick Percoco warning that the incident exposes a critical weakness in how hardware wallets are independently tested and certified.
In a statement shared on social media, Percoco described the five-year firmware flaw as a “wake-up call” for hardware wallet manufacturers, arguing that current auditing practices often verify the presence of secure components without confirming that production firmware is actually using them correctly.
Five-Year Bug Escaped Detection
The vulnerability, disclosed by Coinkite last week, dates back to March 2021, when the company modified Coldcard’s seed-generation process while integrating a new cryptographic library.
During the migration, wallet creation was unintentionally routed through a weaker pseudo-random number generator (PRNG) instead of the device’s intended true random number generator (TRNG).
As a result, some recovery seed phrases were generated with significantly lower entropy than expected, potentially making private keys easier for attackers to reconstruct.
According to Coinkite’s internal review, the secure TRNG code remained within the firmware but was no longer responsible for generating wallet seeds, allowing the flaw to remain unnoticed for more than five years.
Audits Verified the Code But Not Its Execution
Percoco explained that the vulnerability highlights an important limitation in current hardware wallet auditing practices.
Security reviews confirmed that Coldcard’s intended random number generator existed within the codebase and operated correctly. However, auditors did not verify whether the production firmware actually called that component during seed generation.
In other words, the correct security mechanism was present, but the device was unknowingly relying on a different and weaker source of randomness.
Percoco argues that hardware wallet testing should evolve beyond static code reviews and include end-to-end verification to ensure the validated entropy source is the one actively used in production devices.
Security Standards Exist Elsewhere
The Kraken executive noted that similar verification requirements already exist across other cybersecurity industries.
He referenced internationally recognized standards including:
- NIST SP 800-90B, which defines testing and validation requirements for cryptographic random number generators.
- BSI AIS-31, Germany’s security framework for evaluating entropy sources used in cryptographic systems.
According to Percoco, these standards require comprehensive validation of randomness generation, yet no equivalent industry-wide certification currently exists for cryptocurrency hardware wallets.
He argued that digital asset self-custody should adopt security requirements comparable to those used for banking infrastructure, payment terminals, and government-approved cryptographic hardware.
Millions in Bitcoin Already Stolen
The firmware flaw has already resulted in one of the largest hardware wallet security incidents in recent years.
Blockchain analysts estimate that more than 4,500 wallet addresses have been compromised, with attackers stealing nearly $90 million worth of Bitcoin by exploiting weak recovery seed phrases generated by affected devices.
Security researchers continue to monitor additional suspicious transactions, warning that more compromised wallets may still be at risk.
Coinkite Halts Shipments
Following confirmation of the vulnerability, Coinkite announced that it has immediately suspended shipments of all affected Coldcard devices.
The company also confirmed that it has destroyed all remaining inventory containing the vulnerable firmware to prevent additional users from receiving compromised hardware.
However, existing owners have been advised not to discard affected devices, as they may become important during future recovery efforts or law enforcement investigations.
Coinkite stated that its legal team is coordinating with authorities across multiple jurisdictions as investigations continue to identify those responsible for exploiting the vulnerability.
Calls for Stronger Industry Standards
The Coldcard incident has reignited discussions about security certification within the cryptocurrency industry.
While hardware wallets remain among the safest methods for storing digital assets, experts argue that the incident demonstrates the need for more rigorous independent testing, continuous firmware verification, and standardized validation procedures across manufacturers.
As digital asset adoption continues to grow, many security professionals believe that stronger industry-wide certification frameworks will be essential to ensuring hardware wallets deliver the level of protection users expect from self-custody solutions.

