Coldcard seed-generation flaw tied to theft of nearly $90 million in Bitcoin, affecting more than 4,500 addresses

Coldcard seed-generation flaw tied to theft of nearly $90 million in Bitcoin, affecting more than 4,500 addresses

N
News Editor
2026-08-03 04:21:35
A seed-generation flaw in Coldcard hardware wallets has been linked to an ongoing theft campaign that has affected more than 4,500 addresses and resulted in the loss of nearly $90 million in Bitcoin as of Sunday, according to comments cited by Odaily from Kraken Chief Security Officer Nick Percoco. Percoco said the issue exposed a gap in independent testing for hardware wallets. Auditors verified that the intended random number generator existed, but did not confirm that the production firmware actually called that generator. He said the missing step left room for a critical failure in how wallet seeds were created. Coinkite said the software flaw had existed since March 2021. During the integration of a new cryptographic library, the wallet-creation flow was mistakenly routed to a weaker MicroPython generator. Percoco added that the hardware-wallet sector lacks end-to-end validation procedures comparable to NIST SP 800-90B and BSI AIS-31, and that current certifications and vendor-commissioned audits do not systematically require proof that production firmware uses a validated entropy source. Coldcard said it halted all device shipments after confirming the flaw on Thursday and destroyed all remaining devices at its facility that contained the affected firmware. Coinkite also told impacted users not to discard their devices and said its legal team may coordinate with law enforcement across multiple jurisdictions.

A seed-generation flaw in Coldcard hardware wallets has been tied to an ongoing attack that has affected more than 4,500 addresses and led to the theft of nearly $90 million in Bitcoin as of Sunday, according to Odaily, citing Kraken Chief Security Officer Nick Percoco.

Percoco said the issue had persisted for five years and exposed a gap in independent testing for hardware wallets. Auditors confirmed that the intended random number generator was present, but they did not verify whether the production firmware actually invoked that generator in practice.

Flaw dates back to March 2021

Coinkite said the software bug had existed since March 2021. According to the company, when Coldcard integrated a new cryptographic library, the wallet-creation process was mistakenly routed to a weaker MicroPython generator.

Audit standards did not verify firmware behavior

Percoco said the hardware-wallet industry lacks end-to-end validation procedures comparable to NIST SP 800-90B and BSI AIS-31. He added that existing security-element Common Criteria reviews, some CSPN certifications, and vendor-commissioned audits do not systematically require verification that production firmware calls a validated entropy source.

Shipments halted after confirmation

Coldcard said it stopped all device shipments after confirming the flaw on Thursday and destroyed all remaining devices at its facility that carried the affected firmware.

Coinkite advised users with affected devices not to throw them away. The company also said its legal team may coordinate with law enforcement agencies across multiple jurisdictions, depending on circumstances.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
560

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.