Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

Bitcoin price faces 5 macro tests this week

August 3, 2026

Bitcoin slips under $63,000 despite Iran deal hopes as Coldcard losses rattle market

August 3, 2026

Ten mystery investors are using 2,380 BTC to completely hijack a Nasdaq company and gut its leadership

August 3, 2026
Facebook X (Twitter) Instagram
Monday, August 3 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken

August 3, 2026Updated:August 3, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken
Share
Facebook Twitter LinkedIn Pinterest Email
ad



Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken

Coldcard’s five-year seed-generation flaw has uncovered a broader weak spot in how {hardware} wallets are independently examined, in keeping with Kraken chief safety officer Nick Percoco. 

In an X put up on Sunday, Percoco mentioned the incident needs to be a “wake-up name” for hardware-wallet makers, calling for impartial testing to confirm that the accredited supply of randomness is the one really utilized by manufacturing firmware. 

“Shoppers are requested to belief a producer’s implementation of the only most crucial perform within the system, with no impartial verification that the accredited entropy path is the one really executing,” mentioned Percoco. 

His feedback observe an ongoing assault that’s believed to exploit weak seed phrases generated by affected Coldcard units. As of Sunday, over 4,500 addresses have been impacted, draining almost $90 million in Bitcoin. 

Coldcard RNG flaw remained undetected for 5 years

On Thursday, Coinkite disclosed a software program flaw that has existed since March 2021, when Coldcard modified its seed-generation course of because it built-in a brand new cryptographic library. 

The migration inadvertently routed pockets creation to a weaker MicroPython generator that existed within the codebase, relatively than Coldcard’s supposed true random quantity generator (TRNG). 

“The majority of randomness on the COLDCARD was coming from a PRNG that I didn’t know was really within the supply code base,” Coinkite mentioned in its postmortem. “On the similar time the fastidiously crafted TRNG code I wrote was getting used, however simply by probability, and just for much less vital issues.”

The presence of the supposed random quantity generator allowed the vulnerability to slide via undetected. Code evaluations would verify the existence and functioning of Coldcard’s TRNG code, however there was no examine to make sure this was the RNG really being referred to as. 

Such checks are already commonplace throughout the remainder of the safety trade, mentioned Percoco, referencing NIST SP 800-90B, a US authorities commonplace specifying necessities for designing, testing and validating bodily true random quantity mills for cryptographic safety and BSI AIS-31, the same commonplace created by the German Federal Workplace for Data Safety.

“{Hardware} wallets don’t have any equal course of. We now have Frequent Standards on safe parts, some CSPN certifications, and vendor-sponsored audits. None of them systematically power end-to-end verification that the validated entropy supply is what manufacturing firmware really calls,” he mentioned. 

“The funds trade doesn’t let PIN entry units ship with out impartial lab testing. The US authorities doesn’t settle for cryptographic modules with out entropy supply validation. Digital asset self-custody shouldn’t be the exception,” mentioned Percoco. 

Associated: Suspected 4th Coldcard assault wave sweeps 389 Bitcoin: Galaxy’s Thorn

Coldcard mentioned Sunday it has halted all machine shipments since confirming the vulnerability on Thursday, and has destroyed all remaining models at its services containing the affected firmware. 

Nevertheless, Coinkite has suggested customers with affected units to not eliminate them as “it might develop into important if funds are recovered.”

“Our authorized group will coordinate as warranted with regulation enforcement throughout a number of jurisdictions to assist efforts in figuring out these accountable.” 

Associated: Coldcard exploit sparks Bitcoin flight, ‘bullish’ crypto consolidation: Hodler’s Digest, August 2



Source link

ad
Blind Coldcard exposes flaw hardware Kraken spot Testing Wallet
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

Bitcoin price faces 5 macro tests this week

August 3, 2026

Bitcoin slips under $63,000 despite Iran deal hopes as Coldcard losses rattle market

August 3, 2026

Ten mystery investors are using 2,380 BTC to completely hijack a Nasdaq company and gut its leadership

August 3, 2026

XRP Ledger v3.3.0 Release Brings Five Amendments Into Focus

August 3, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
Bitcoin price faces 5 macro tests this week
August 3, 2026
Bitcoin slips under $63,000 despite Iran deal hopes as Coldcard losses rattle market
August 3, 2026
Ten mystery investors are using 2,380 BTC to completely hijack a Nasdaq company and gut its leadership
August 3, 2026
Coldcard Flaw Exposes Hardware Wallet Testing Blind Spot: Kraken
August 3, 2026
XRP Ledger v3.3.0 Release Brings Five Amendments Into Focus
August 3, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.