BlocktoBlockto
Kraken Security Chief Says Coldcard’s Five-Year Flaw Exposes Gap in Hardware Wallet Testing
HACK

Photo: Illustrative

Kraken Security Chief Says Coldcard’s Five-Year Flaw Exposes Gap in Hardware Wallet Testing

Kraken's chief security officer Nick Percoco says the Coldcard vulnerability points to a deeper problem across the hardware wallet industry: nobody independently verifies that a device's approved randomness source is the one actually running in production. He called the incident a wake-up call for wallet makers, noting that auditors typically confirm secure code exists without checking whether it gets used.

Laurisa
By Laurisa

Junior Author · August 3, 2026

2 min
Key takeaways
Kraken's chief security officer Nick Percoco says the Coldcard vulnerability points to a deeper problem across the hardware wallet industry: nobody independently verifies that a device's approved randomness source is the one actually running in production.
He called the incident a wake-up call for wallet makers, noting that auditors typically confirm secure code exists without checking whether it gets used.
How the Flaw Slipped Through for Five Years The bug traces back to March 2021, when Coldcard switched cryptographic libraries and accidentally routed seed generation to a weaker built-in Python random number generator instead of its intended hardware-based one.

Kraken’s chief security officer Nick Percoco says the Coldcard vulnerability points to a deeper problem across the hardware wallet industry: nobody independently verifies that a device’s approved randomness source is the one actually running in production. He called the incident a wake-up call for wallet makers, noting that auditors typically confirm secure code exists without checking whether it gets used.

How the Flaw Slipped Through for Five Years

The bug traces back to March 2021, when Coldcard switched cryptographic libraries and accidentally routed seed generation to a weaker built-in Python random number generator instead of its intended hardware-based one. The maker, Coinkite, said in its postmortem that the stronger generator was still present in the code but only ran occasionally, by chance, for less critical tasks.

Industry Standards Missing for Wallet Makers

Percoco pointed to existing government-grade standards used to validate randomness in other secure systems, arguing hardware wallets lack an equivalent requirement. He compared it to payment card readers, which cannot ship without independent lab testing.

Coldcard has halted shipments, destroyed affected inventory, and is working with law enforcement, while urging affected users to keep their devices for potential fund recovery.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.