Bitcoin security
Coldcard exploit sparks call for independent audits: Kraken CSO
According to reporting by LBank News based on crypto.news coverage, Kraken’s chief security officer has urged independent testing of hardware wallet seed generation following a security flaw in Coldcard devices. Suspected attacks have drained nearly $90 million in Bitcoin, with Galaxy Research tracking over 5,200 potential victim addresses, though these figures have not officially confirmed by law enforcement or device manufacturers.

Background and Industry Warnings
Recent reports published by LBank News indicate that a long-standing vulnerability within Coldcard hardware wallets has prompted severe concerns regarding the security architecture of physical cryptographic devices. Industry specialists and exchange security executives have voiced urgent demands for independent, third-party testing of wallet firmware seed generation mechanisms rather than accepting vendor assurances at face value. This development follows widespread digital disclosures regarding firmware flaws that allegedly compromised the foundational randomness required for secure private key creation.
Kraken chief security officer Nick Percoco publicly stated via social media that the incident should serve as a stark warning to all hardware wallet developers. He asserted that production firmware must undergo rigorous independent scrutiny to confirm that the designated source of cryptographic entropy is genuinely utilized during wallet secret creation. Observers noted that payment security standards and government modules mandate strict independent laboratory testing, a level of oversight that has historically been absent in the broader consumer hardware wallet sector.
Technical Analysis of the Firmware Flaw
According to disclosures outlined in publisher reports, the vulnerability originated in March 2021 when Coinkite migrated parts of its firmware while integrating a new cryptographic library. The updated code inadvertently invoked a weaker deterministic pseudo-random number generator provided by MicroPython instead of the intended hardware-backed true random number generator. Because the proper random number generator remained active for other device functions, internal code reviews failed to detect that wallet secret creation relied on a compromised fallback entropy path.
Independent technical reviews conducted by engineering teams at Block corroborated these findings, noting that the fallback path was triggered specifically during wallet initialization. Coinkite estimated that seeds generated on affected Mk2 and Mk3 units possess only about 40 bits of effective entropy, whereas later Mk4, Mk5, and Q models drop to approximately 72 bits instead of the standard 128 bits. These mathematical reductions significantly weaken the cryptographic security margin, rendering brute-force attacks far more feasible for malicious actors.
Scale of Suspected Attacks and On-Chain Tracking
Blockchain research organizations have monitored multiple coordinated attack waves targeting wallets suspected of carrying the weakened seed generation flaw. Galaxy Research analytics indicated that suspected attackers swept substantial amounts of Bitcoin across thousands of potential victim addresses over several observation periods. Researchers emphasized that these metrics represent blockchain estimations derived from address clustering and network heuristics rather than verified device inventories or law enforcement records.
The volume of suspicious transactions surged significantly during the peak observation windows, with automated sweeps extracting funds at a much higher frequency than historical baselines. Investigators noted that the stolen assets were frequently routed through newly created addresses and second-hop transactions to obscure the audit trail. While some analysts suggested that unconfirmed transactions might theoretically allow limited replacement fee actions, experts cautioned that recovery probabilities remain exceptionally low for compromised private keys.
Manufacturer Response and Remediation Steps
In response to the unfolding security crisis, Coinkite halted device shipments and destroyed inventory units containing the flawed firmware within its operational facilities. The organization released updated firmware versions across all impacted device series, including specialized patches for Mk2, Mk3, Mk4, Mk5, Q, and Edge variants. Company representatives clarified that applying the firmware update only secures future wallet creation activities and cannot retroactively repair seed phrases generated prior to the patch installation.
Consequently, users identified within the vulnerable scope have been explicitly instructed to generate entirely new seed phrases after applying the required updates. Coinkite recommended verifying destination addresses, executing minimal test transactions, and systematically migrating remaining balances only after confirming transfer success. Furthermore, the firm advised that wallets created using rigorous manual entropy methods, such as multiple independent dice rolls, remain resilient against the specific random number generator flaw.
Verification Gaps in Hardware Certification
Industry experts commenting on the Coldcard disclosures highlighted systemic shortcomings in how hardware security modules are certified and audited prior to commercial release. Current evaluation frameworks, such as Common Criteria assessments and vendor-sponsored penetration tests, generally fail to enforce end-to-end verification of the exact entropy sources invoked during production runtime. Kraken security leadership noted that existing standards lack the rigorous mathematical auditing mandated for high-assurance cryptographic systems in other regulated industries.
Reference frameworks such as NIST SP 800-90B and Germany's BSI AIS-31 outline comprehensive criteria for testing true random number generators, yet consumer hardware wallets rarely undergo this level of scrutiny. Without mandatory independent validation of production firmware code paths, manufacturers retain total authority over cryptographic implementations, leaving consumers vulnerable to undetected internal logic errors. Security advocates maintain that regulatory or community-driven auditing must evolve to mandate continuous entropy verification before devices reach the public market.
Conclusion and Ongoing Verification Status
In summary, media reports from LBank News and crypto.news indicate that Coldcard hardware wallets experienced a multi-year seed generation vulnerability stemming from a MicroPython fallback error. This flaw has sparked widespread industry calls for independent cryptographic auditing, with reported suspected attacks draining nearly $90 million in Bitcoin across more than 5,200 potential victim addresses tracked by Galaxy Research. Coinkite has released firmware updates and halted shipments, advising affected users to migrate assets to newly generated seed phrases.
Readers must note that these loss figures and attack scopes are reported-only and have not officially confirmed by law enforcement agencies, forensic accountants, or comprehensive independent device audits. Affected Coldcard owners must immediately update their device firmware, generate fresh seed phrases, and safely migrate funds while recognizing that existing on-chain estimates remain unverified by official first-party authorities.
Cexvia conclusion
Conclusion and Ongoing Verification Status
LBank News reported that a multi-year vulnerability in Coldcard hardware wallets allowed weaker random number generation during seed creation, leading to suspected ongoing attacks that have drained nearly $90 million in Bitcoin from over 5,200 potential victim addresses. Coinkite released patched firmware while emphasizing that updates cannot repair existing wallets, requiring affected users to migrate funds to newly generated seed phrases. These impact estimates and on-chain figures are reported-only and have not officially confirmed by comprehensive forensic audits.
- Risk meaning
- The incident demonstrates systemic verification gaps within hardware wallet manufacturing, highlighting that relying entirely on internal vendor code reviews is insufficient to guarantee cryptographic entropy. When core components like true random number generators are bypassed by fallback code paths, users face profound asset loss risks that firmware updates alone cannot mitigate.
- User action
- Affected users must immediately update their device firmware and generate entirely new seed phrases, followed by verifying receiving addresses, sending test transactions, and securely migrating remaining balances. Customers should also review whether their original secrets were generated using sufficient entropy such as physical dice rolls.

