Coldcard RNG flaw exposes hardware wallet testing gap

Kraken security chief Nick Percoco says a five-year vulnerability in Coldcard’s seed generation reveals a broader hardware wallet testing gap across the industry. Percoco argues that auditors may verify a “random number generator” exists, but not that the production firmware actually calls the approved entropy source. The issue traces to a change made by Coinkite (Coldcard’s manufacturer) in March 2021, when Coldcard integrated a new cryptographic library. During that migration, wallet creation was routed to a weaker MicroPython generator (a PRNG) instead of Coldcard’s intended true random number generator (TRNG). The TRNG code existed and could be reviewed, which helped the bug evade detection—yet there was no end-to-end check confirming the validated RNG path was the one truly executed. Percoco says this is missing “systematic” verification compared with standards such as NIST SP 800-90B and BSI AIS-31, which require stronger entropy source testing. He calls for independent, end-to-end validation of hardware wallet randomness. The downstream impact appears material. As of Sunday, more than 4,500 Bitcoin addresses were impacted, with nearly $90 million drained. Coldcard reportedly halted all device shipments and destroyed remaining affected firmware units. Users are advised not to dispose of devices, as they may be needed if funds are recovered. For traders, this hardware wallet testing gap highlights continuing custody risks tied to entropy/seed weaknesses—an event that can temporarily pressure sentiment around Bitcoin self-custody and prompt short-term risk-off behavior, even if broader market fundamentals remain unchanged.
Bearish
The report links a long-lived Coldcard RNG/entropy weakness to a significant real-world drain (4,500+ Bitcoin addresses; ~$90M). That combination usually triggers short-term bearish sentiment: traders may price in higher self-custody risk, watch for exchange inflows/outflows related to compromised wallets, and widen risk controls around custody/seed-generation assumptions. Similar episodes in crypto security history—when a hardware-wallet or key-generation design flaw is confirmed—often cause temporary sentiment drops in the affected asset (here, BTC) even if the underlying protocol is unchanged. In the short term, expect elevated caution around Bitcoin custody and possibly profit-taking or reduced leverage, especially among retail holders. In the long term, Kraken’s push for end-to-end entropy validation could improve testing standards, which may reduce recurrence risk; that longer-term effect is likely gradual, so near-term price impact skews bearish to neutral rather than fully neutral. Net: negative risk sentiment outweighs any immediate positive catalysts.