Five-Year Coldcard Security Flaw Highlights Hardware Wallet Testing Shortcomings, Says Kraken Executive

Five-Year Coldcard Security Flaw Highlights Hardware Wallet Testing Shortcomings, Says Kraken Executive

The vulnerability went unnoticed for five years because security auditors confirmed the presence of the designated random number generator, without verifying whether it was actually being utilized in practice.

According to Nick Percoco, the chief security officer at Kraken, the five-year-old vulnerability in Coldcard's seed-generation mechanism has revealed significant shortcomings in the independent testing procedures for hardware wallets.

Through a post shared on X this Sunday, Percoco characterized the situation as a necessary "wake-up call" for companies manufacturing hardware wallets, urging that independent testing must confirm the designated randomness source is actually being utilized by firmware in production environments.

"Users are expected to place their trust in how a manufacturer implements what is arguably the most crucial function within the entire system, yet there exists no independent confirmation that the designated entropy pathway is actually the one being executed," Percoco stated.

These remarks come amid a continuing series of attacks suspected to leverage compromised seed phrases that were created by Coldcard devices affected by the vulnerability. By Sunday's count, more than 4,500 addresses had been compromised, resulting in the theft of approximately $90 million worth of Bitcoin.

Coldcard RNG flaw remained undetected for five years

Coinkite made public on Thursday a software vulnerability that had been present since March 2021, the time when Coldcard modified its seed-generation methodology during the integration of a new cryptographic library.

During the migration process, wallet creation was accidentally redirected to a less secure MicroPython generator that was present in the existing codebase, instead of utilizing Coldcard's designated true random number generator (TRNG).

"The majority of randomness on the COLDCARD was being sourced from a PRNG whose presence in the actual source code base was unknown to me," Coinkite explained in its post-incident analysis. "Meanwhile, the meticulously designed TRNG code that I had written was indeed being utilized, but only coincidentally, and exclusively for functions of lesser importance."

Because the intended random number generator was present in the codebase, the security flaw managed to evade detection. Security code reviews successfully verified both the existence and proper operation of Coldcard's TRNG implementation, however no validation was performed to confirm this was the actual RNG being invoked during operation.

These types of verification checks have long been established practice throughout other sectors of the security industry, Percoco noted, citing NIST SP 800-90B, a standard established by the US government that defines requirements for the design, testing and validation of physical true random number generators used in cryptographic security applications, as well as BSI AIS-31, a comparable standard developed by Germany's Federal Office for Information Security.

"The payment card industry mandates that PIN entry devices cannot be shipped without undergoing independent laboratory testing. The United States government refuses to accept cryptographic modules that lack entropy source validation. Self-custody of digital assets should not be treated as an exception to these standards," Percoco emphasized.

As of Sunday, Coldcard announced it has suspended all device shipments following the Thursday confirmation of the security vulnerability, and has proceeded to destroy all remaining inventory at its facilities that contained the compromised firmware.

Despite this, Coinkite has recommended that users who possess affected devices should refrain from discarding them because "it may become essential if funds are recovered."

"Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible."

← Retour au blog