Coldcard's five-year seed generation vulnerability sparks controversy over hardware wallet verification standards
According to Nick Percoco, Kraken's chief security officer, the five-year seed generation issue with Coldcard has turned into an extensive discussion about independent verification of hardware wallets. Percoco noted in an X platform post posted on Sunday that the incident should prompt self-managed device manufacturers to implement end-to-end inspections to ensure that the sources of randomness reviewed during testing are consistent with the sources of actual production firmware execution.
The comments come amid an ongoing attack that appears to use weak mnemonics to target vulnerable Coldcard devices. As of Sunday, reports showed that more than 4500 addresses had been affected, and Bitcoin losses were estimated to be close to $90 million.
Core Points
· Kraken's Nick Percoco believes that hardware wallet certification should include verification that the entropy path approved for use is actually invoked by production firmware.
· Coldcard's random number generator-related vulnerability allegedly persisted for years after a change in the seed generation process that accidentally caused the system to over-rely on a weaker random number generator.
· Percoco cited existing standards widely used in the security and payment industries, such as NIST SP 800- 90B and BSI AIS-31, as benchmarks to follow in the field of cryptocurrency self-custody.
· Coinkite said that shipments of affected firmware versions have been stopped and that remaining inventory devices containing vulnerability code have been destroyed, while advising users not to discard certain devices.
"Alarm" for hardware wallet entropy verification
Percoco's core view revolves around trust boundaries. Hardware wallet users are required to trust the manufacturer's implementation of the random function that ultimately underpins the generation of mnemonic words. However, he pointed out that there is often a lack of independent methods to confirm whether the verified source of randomness is really the one that the device actually calls in the production environment.
"Consumers are required to trust manufacturers in their implementation of the most critical functions in the system without independent verification to ensure that the approved entropy path is the path that is actually implemented," Percoco wrote in a Sunday post.
He described the gap as an industry-wide weakness rather than an individual accidental failure, and noted that while some certifications exist for hardware components and secure elements, these certifications do not "systematically mandate" end-to-end verification of entropy sources from the production code execution level.
Percoco compares the practice in the cryptocurrency self-custody space with other industries. He mentioned the payment industry's use of independent laboratory testing of devices that collect sensitive inputs, as well as expectations at the U.S. government level for cryptographic module verification and entropy source testing.
How the Coldcard vulnerability quietly exists
According to original reports, the vulnerability can be traced to a software change disclosed by Coinkite. The company said the problems have existed since March 2021, when Coldcard modified its seed generation process while integrating a new cryptographic library.
Based on Coinkite's post-mortem analysis, this update inadvertently redirected the wallet creation process to a weaker MicroPython random number generator already in the code base. Coinkite's explanation suggests that the true random number generator code originally designed by Coldcard exists and may be running, but it has not been reliably used for the core randomness required for seed generation.
In other words, the reviewer can verify that the true random number generator code exists and works-but if there is no mechanism to ensure that the device actually calls the true random number generator when the seed is generated, the system may still produce results originating from other unexpected random number generators.
The practical consequence is that mnemonic words generated under the affected conditions may become more predictable than expected. It is widely believed in the security community that this predictability vulnerability is particularly dangerous in wallet design, because compromised mnemonics can directly lead to asset theft without having to crack the key itself.
Attack impact and user response
Continued attacks on weak mnemonics generated by affected Coldcard devices have resulted in a large amount of on-chain activity. As of Sunday, reports showed that more than 4500 addresses had been affected and Bitcoin lost nearly $90 million.
Coldcard (Coinkite) said it has stopped all equipment shipments since confirming the vulnerability on Thursday. The company also stated that it had destroyed all remaining inventory equipment in the warehouse that contained affected firmware.
At the same time, the company advised users of affected devices not to discard them immediately because "these devices may be critical if funds are recovered." The company also said its legal team will coordinate with law enforcement in multiple jurisdictions to support efforts to identify those responsible.
For affected users, this new information highlights a key operational point: Equipment disposal decisions need to be coordinated with the asset recovery process, rather than just a simple disposal or cleanup task. While this does not eliminate the security risks posed by continued exposure, it suggests that retaining evidence or available hardware can be important in responding to an incident.
Standards exist-what is missing is execution
Percoco's criticism points to a contradiction that many investors and developers may recognize: Cryptocurrency security often emphasizes reviewing code paths and cryptographic primitives, but does not always focus on end-to-end behavior in production environments-especially the specific sources of entropy used at runtime.
He cited NIST SP 800- 90B, which sets requirements for the design, testing and verification of physical true random number generators for cryptographic security, and BSI AIS-31, a similar standard from the German Federal Office for Information Security. In his view, these frameworks make it more difficult for systems to muddle by simply "passing review" because they require proof that approved random paths are indeed used for critical operations.
Whether regulators and certification bodies will apply these expectations to consumer self-managed products remains uncertain. However, the Coldcard case clearly demonstrates why this distinction is critical: Even if the correct true random number generator implementation exists in the codebase, the seed generation process can still be breached if production firmware routes randomness to a different path than the independent review assumptions.
Next, investors and users should focus on two things: how Coinkite clearly states how to identify affected devices/firmware and the best remedies to reduce future risks; and whether independent testing bodies or certification bodies will promote more stringent verification of "run-time entropy sources"-Percoco believes this should no longer be an option in the digital asset custody space.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC