Coldcard Bug Went Unnoticed for Half a Decade, Highlighting a Critical Miss in Wallet Audits

TL;DR:
- A flaw in Coldcard’s random number generator went undetected for five years and has already compromised nearly $90 million in Bitcoin.
- Kraken’s chief security officer noted that auditors verified the correct generator existed, but not that it was the one the firmware actually executed.
- Coinkite halted all device shipments and destroyed units with affected firmware, though it advises users not to discard compromised devices.
A vulnerability in the seed generation process of Coldcard remained active for five years without being detected by any independent audit, according to a disclosure by manufacturer Coinkite.
The flaw was introduced in March 2021 during the integration of a new cryptographic library. It redirected the wallet creation process toward a MicroPython pseudorandom generator present in the source code, instead of the true random number generator (TRNG) designed for that function. As of Sunday, more than 4,500 addresses from Coldcard had been compromised, with losses estimated at around $90 million in Bitcoin.
… Continue reading the full article at the original source below.



