Coldcard exploit sparks call for independent audits: Kraken CSO
Coldcards five-year seed-generation flaw has renewed calls for independent testing of hardware wallet firmware after suspected attacks have drained nearly $90 million worth of Bitcoin from thousands of wallets. Kraken chief security officer Nick Percoco said in a post on X on Sunday that the incident should serve as a warning for the hardware wallet industry, arguing that manufacturers should not be the only parties verifying how wallet seed phrases are generated. https://t.co/cIjpnVnMDM — Nick Percoco (@c7five) August 2, 2026 He said production firmware should undergo independent testing to confirm that the approved source of randomness is the one actually used when creating wallet secrets. According to Galaxy Researchs latest blockchain analysis, suspected attackers have now swept more than 1,800 BTC from over 5,200 potential victim addresses across four observed attack waves, although the firm has stressed that those figures are on-chain estimates rather than confirmed losses. Coinkite has not verified every affected wallet, and blockchain data alone cannot determine whether a single actor carried out all of the attacks. Coldcard flaw escaped review for more than five years Coinkite disclosed on Thursday that the vulnerability dates back to March 2021, when the company migrated part of its firmware while integrating a new cryptographic library. Instead of using









