A vulnerability that sat undetected in Coldcard hardware wallets for roughly five years has drained nearly $90 million in bitcoin from affected users, and Kraken's chief security officer says the episode exposes a fundamental gap in how the industry tests self-custody devices.

The flaw traces back to March 2021, when Coinkite, the company behind Coldcard, integrated a new cryptographic library into its firmware. The change inadvertently routed seed generation to a weaker MicroPython random number generator instead of the device's intended true random number generator, producing seed phrases that were far more predictable than they appeared.

a close up of a coin on a white surface
Photo by Vitaly Mazur on Unsplash

Auditors Checked the Wrong Thing

According to Kraken's Nick Percoco, the bug escaped detection for years because security auditors verified that the proper random number generator existed in the code, but never confirmed it was actually being invoked at runtime. "Digital asset self-custody should not be the exception" to independent verification of entropy sources, Percoco said, calling the incident a "wake-up call" for the hardware wallet industry.

"Independent verification that the approved entropy path is the one actually executing" is what's been missing, Percoco said.

Percoco pointed out that hardware wallets generally lack the kind of rigorous, standardized testing applied elsewhere in cryptography, referencing established frameworks like NIST SP 800-90B and BSI AIS-31 as benchmarks the industry has largely failed to adopt for consumer self-custody devices.

Scale of the Damage

Coinkite disclosed the flaw last Thursday, and by the following Sunday more than 4,500 addresses tied to affected devices had been compromised, with attackers draining close to $90 million in bitcoin using the predictable seed phrases. Coinkite has since halted all shipments of the affected units and destroyed remaining inventory.

The company has urged users who still hold vulnerable devices to keep them rather than discard them, noting they "may become essential if funds are recovered." The advice underscores how unresolved the fallout remains, with investigators and the company still working to trace where drained funds have gone.

Related: Coldcard Exploit Losses Climb to $88.6M as New Wave Drains Wallets

A Broader Industry Reckoning

The Coldcard case is likely to intensify scrutiny of how hardware wallet makers validate the randomness underpinning private key generation, an area users have long assumed was rigorously tested given its central role in securing funds. Percoco's comments suggest that assumption may not hold across the broader self-custody hardware market, not just for Coldcard.