Autor Cointelegraph By Felix Ng

Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief

Coldcard’s five-year seed-generation flaw has exposed a broader weakness in how hardware wallets are independently tested, according to Kraken chief security officer Nick Percoco. In an X post on Sunday, Percoco said the incident should be a “wake-up call” for hardware-wallet makers, calling for independent testing to verify that the approved source of randomness is the one actually used by production firmware. “Consumers are asked to trust a manufacturer’s implementation of the single most critical function in the system, with no independent verification that the approved entropy path is the one actually executing,” said Percoco. His comments follow an ongoing attack that is believed to exploit weak seed phrases generated by affected Coldcard devices. As of Sunday, over 4,500 addresses have been impacted, draining nearly $90 million in Bitcoin. Coldcard RNG flaw remained undetected for five yearsOn Thursday, Coinkite disclosed a software flaw that has existed since March 2021, when Coldcard changed its seed-generation process as it integrated a new cryptographic library. The migration inadvertently routed wallet creation to a weaker MicroPython generator that existed in the codebase, rather than Coldcard’s intended true random number generator (TRNG). “The bulk of randomness on the COLDCARD was coming from a PRNG that I didn’t know was actually in the source code base,” Coinkite said in its postmortem. “At the same time the carefully crafted TRNG code I wrote was being used, but just by chance, and only for less important things.”The presence of the intended random number generator allowed the vulnerability to slip through undetected. Code reviews would confirm the existence and functioning of Coldcard’s TRNG code, but there was no check to ensure this was the RNG actually being called. Such checks are already standard across the rest of the security industry, said Percoco, referencing NIST SP 800-90B, a US government standard specifying requirements for designing, testing and validating physical true random number generators for cryptographic security and BSI AIS-31, a similar standard created by the German Federal Office for Information Security.“Hardware wallets have no equivalent process. We have Common Criteria on secure elements, some CSPN certifications, and vendor-sponsored audits. None of them systematically force end-to-end verification that the validated entropy source is what production firmware actually calls,” he said. “The payments industry does not let PIN entry devices ship without independent lab testing. The US government does not accept cryptographic modules without entropy source validation. Digital asset self-custody should not be the exception,” said Percoco. Related: Suspected 4th Coldcard attack wave sweeps 389 Bitcoin: Galaxy’s ThornColdcard said Sunday it has halted all device shipments since confirming the vulnerability on Thursday, and has destroyed all remaining units at its facilities containing the affected firmware. However, Coinkite has advised users with affected devices not to dispose of them as “it may become essential if funds are recovered.”“Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.” Related: Coldcard exploit sparks Bitcoin flight, ‘bullish’ crypto consolidation: Hodler’s Digest, August 2

Čítaj viac

Binance ‘red teams’ its own staff every month to keep hackers out

Cryptocurrency exchange Binance runs simulated phishing attacks against its own employees and can fire staff who repeatedly fail the tests, according to Binance chief security officer Jimmy Su.The fake attacks are conducted by Binance’s red team, an internal ethical hacking unit whose job is to break into systems to identify vulnerabilities.“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. “The ones that have failed it, we will do remediation training.” The measure shows the lengths crypto companies will go to prepare for social engineering attacks. Binance, the largest crypto exchange in the world, reports 323 million registered users, while DefiLlama estimates the exchange holds $137.7 billion in assets.Jimmy Su, chief security officer at Binance. Source: BinanceIn February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. In April, Drift Protocol suffered a $285 million hack, which came after a long-term social engineering campaign. Su said Binance has been running these simulated attacks for three to four years. “In the beginning, the security hygiene left a lot to be desired. But after this amount of time, the company has improved significantly.” One of the simulated attacks involves the red team posing as job recruiters, said Su. Related: Trader loses $1M after signing phishing token approval One of the more well-known attack methods in recent years has been the “Zoom meeting attack,” where hackers trick victims into installing malware disguised as an update to the video conferencing app. Many of these attacks start with a fake job opportunity, though some use project funding or a partnership proposal as the lure. In September 2025, a major Venus Protocol user lost roughly $13 million after a malicious Zoom client compromised his computer, leading him to grant an attacker control over his account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim. “The interview process is just one scenario. There are other ones. For example, it could be that we are offering some kind of free conference invite just to try to collect personal information and see how many of them will actually fall for it,” said Su.  Su said employees are incentivized to perform well on the tests because the results are reflected in their performance reviews. “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.” Repeated, severe failures could lead to their rating to “bottom out,” which could see them dismissed, he said. Magazine: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long

Čítaj viac

Získaj BONUS 8 € v Bitcoinoch

nakup bitcoin z karty

Registrácia Binance

Burza Binance

Aktuálne kurzy