Coldcard seed-generation flaw tied to theft of nearly $90 million in Bitcoin, affecting more than 4,500 addresses
A seed-generation flaw in Coldcard hardware wallets has been linked to an ongoing theft campaign that has affected more than 4,500 addresses and resulted in the loss of nearly $90 million in Bitcoin as of Sunday, according to comments cited by Odaily from Kraken Chief Security Officer Nick Percoco. Percoco said the issue exposed a gap in independent testing for hardware wallets. Auditors verified that the intended random number generator existed, but did not confirm that the production firmware actually called that generator. He said the missing step left room for a critical failure in how wallet seeds were created. Coinkite said the software flaw had existed since March 2021. During the integration of a new cryptographic library, the wallet-creation flow was mistakenly routed to a weaker MicroPython generator. Percoco added that the hardware-wallet sector lacks end-to-end validation procedures comparable to NIST SP 800-90B and BSI AIS-31, and that current certifications and vendor-commissioned audits do not systematically require proof that production firmware uses a validated entropy source. Coldcard said it halted all device shipments after confirming the flaw on Thursday and destroyed all remaining devices at its facility that contained the affected firmware. Coinkite also told impacted users not to discard their devices and said its legal team may coordinate with law enforcement across multiple jurisdictions.








