Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Nomura’s Laser Digital backs ZIGChain for onchain private credit push in UAE

4 minutes ago

Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

6 minutes ago

Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI

7 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Wednesday, August 5
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?
Cryptocurrency & Free Speech Finance

Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

News RoomBy News Room6 minutes agoNo Comments8 Mins Read0 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

Just when you thought crypto market morale couldn’t sink any lower, along comes the Coldcard entropy bug to prove you wrong.

The discovery of a flaw in one of the industry’s longest-running hardware wallets last Friday serves as a stark reminder that there is no perfectly safe place to put all your Bitcoin.

Coldcard disclosed the entropy-generation flaw affecting multiple Coldcard devices on July 31. Since then, researchers at Galaxy Digital say attackers have been able to steal more than 1,596 Bitcoin worth at least $100 million through several coordinated attacks.

Wallet manufacturers are now being forced to explain a process most users never even think about: how their wallet generates the private key to protect their Bitcoin.

Michael Tanguma, head of product at Bitcoin custody firm Onramp Bitcoin, tells Magazine:

“The whole model rests on trust that the vendor got it right […] Almost no individual can audit the hardware, the firmware and the entropy generation underneath their device.”

Coinkite, the company behind Coldcard, has released firmware fixes and told affected users to migrate their funds, but the incident has shaken Bitcoin HODLers to the core, and it raises an uncomfortable question:

If Coldcard wallets can be exploited, does that mean all hardware wallets are potentially insecure?

A bug hidden in the foundations

The Coldcard vulnerability did not exploit Bitcoin itself nor break modern cryptography, but it struck at something much more fundamental: randomness.

Every Bitcoin wallet begins by generating a seed phrase from a pool of random data, which means that randomness should be sufficiently unpredictable to make the resulting private keys effectively impossible to guess. Entropy refers to how random it is.

If that randomness is weakened for any reason, attackers can reduce the number of possible keys that could be generate and eventually find a way to reproduce them.

Related: Coldcard hack sparks biggest sub-1 BTC move since FTX: CryptoQuant

Coinkite first alerted users on July 31 that wallets created on affected firmware should be considered at risk and told customers to migrate funds to newly generated wallets. As researchers dug further into the bug over the following days, their attention quickly turned to how a flaw in such a critical part of the wallet had gone unnoticed for more than five years.

Core Lightning developer Dustin Dettmer suggested that it might have originated during firmware changes made in 2021.

He believes that code intended to interface with the hardware random number generator instead disabled it, which caused wallet creation to fall back to MicroPython’s weaker Yasmarang pseudo-random number generator.

His theory has become one of the leading explanations for how the bug may have entered production firmware, although Coinkite has not confirmed that exact sequence of events, and says that it will publish a full technical postmortem “soon.” A Coinkite spokesperson tells Magazine:

“Certain firmware versions had a fallback path in seed generation that could produce weak entropy when generated on the device firmware itself.”

Devices where users generated their own entropy through dice rolls or similar manual methods “were not affected by this specific fallback path,” the spokesperson says.

Weak random number generation (RNG) is not unprecedented, but unlike many other security flaws, it is difficult to detect.

Bitcoin security expert Jameson Lopp noted that RNG vulnerabilities have previously affected a long list of cryptocurrency wallets and libraries, ranging from Blockchain.com’s Android wallet to Trust Wallet.

Weak random number generation is not a new problem. Source: Jameson Lopp

Ledger director of product security Vincent Bouzon tells Magazine that “weak randomness passes output tests,” which means that compromised random-number generators can still produce values that appear random, making flaws difficult to identifiy.

Different wallets, different randomness assumptions

Hardware wallet manufacturers agree that secure entropy generation is non-negotiable, but they take different approaches to achieving it.

Related: Zilliqa Ledger app vulnerability lets attackers recover signer’s private keys

Ledger’s philosophy centers on dedicated security hardware. Bouzon says Ledger devices generate seeds using a true random number generator embedded in a certified Secure Element. The entropy source is certified under the AIS-31 PTG.2 standard and the Secure Element undergoes Common Criteria certification. He says:

“This Coldcard incident was a failure in one specific implementation, not a verdict on secure self-custody […] The generation of that entropy must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.”

Generating high-quality randoness is where the whole thing lives or dies. Source: Charles Guillemet

For its part, Trezor combines randomness generated inside the device with randomness supplied by the host computer, rather than depending on a single entropy source, and newer models also incorporate additional hardware sources.

The company also includes entropy checks to confirm that the device actually contributed unpredictable randomness during wallet creation. Tomáš Sušánka, Trezor’s chief technical officer, tells Magazine:

“The takeaway for the whole industry is that randomness cannot depend on a single source or a single line of code being correct.”

Foundation’s Passport wallet similarly rely on multiple entropy sources while emphasizing transparency. Chief executive Zach Herbert says Passport combines randomness generated by separate hardware components before creating a wallet.

The firmware is also published as free and open-source software with reproducible builds, so independent researchers can verify that the software running on the device matches the published code. Herbert says:

“The bug itself was specific to Coldcard […] The larger warning is that this went unnoticed for more than five years while people trusted the product with life-changing amounts of money.”

Trust, transparency and verification

The real divide between Ledger, Trezor and Foundation is not about the importance of randomness, but over how users can be certain that it is actually working.

Ledger argues that independent certification provides the strongest assurance. Foundation relies on open-source development, reproducible builds and welcoming external researchers, and Trezor combines open firmware with layered entropy sources to avoid relying on any single component.

Coinkite’s approach to security disclosures has also come under fire, with several Bitcoin developers criticizing the company over past responses to vulnerability reports and the absence of a traditional bug bounty program.

Related: Fears of AI-driven DeFi hack epidemic overstated for now — but not for long

Herbert argues that welcoming external researchers is itself part of building secure products, alongside open-source development and independent audits.

Nick Percoco, chief security officer at Kraken and former chief security officer at Uptake, sees the Coldcard incident as an opportunity for the industry to adopt stronger standards, no matter which design philosophy manufacturers choose.

“The Coldcard entropy failure should be a wake-up call for the entire hardware wallet industry,” he said, arguing that today’s certification schemes often validate individual components without confirming that production firmware is actually using them correctly.

The Coldcard entropy failure should be a wake-up call. Source: Nick Percoco

Percoco proposed an industry-specific assurance standard requiring independent validation of entropy sources, verification that firmware calls the intended hardware random number generator and certification tied to specific hardware and firmware versions.

But the debate goes further than technical implementation, with voices like Herbert arguing that open-source development also shapes security culture. He points to bug bounty programs and constructive engagement with independent researchers as essential parts of secure product development.

What should Bitcoiners do now?

For Coldcard users, their immediate priority is to follow Coinkite’s migration guidance if they believe their wallets were created using affected firmware.

Longer term, Bitcoiners as a whole should use this episode as a learning moment, with experts like Tanguma stressing the need to avoid design architectures in which any single failure can compromise their funds. He says:

“Today, realistically, you want multisig and independently generated entropy […] The mitigation that actually scales is architectural: setups where no single device, vendor or institution being wrong can lose the funds.”

So for now, the answer appears to be no; not all hardware wallets are insecure.

The Coldcard incident exposed a failure in one implementation, but it has also forced manufacturers to lift the veil on the process at the heart of self-custody: generating a secret that nobody else can predict.

Magazine: The 100x obsession: Fundamentals grow in importance as crypto matures

Cointelegraph publishes long-form journalism, analysis and narrative reporting produced by Cointelegraph’s in-house editorial team with subject-matter expertise. All articles are edited and reviewed by Cointelegraph editors in line with our editorial standards. Some articles contain affiliate links, from which Cointelegraph may earn a commission. These relationships do not influence which products we review or our editorial conclusions. Content published in here does not constitute financial, legal or investment advice. Readers should conduct their own research and consult qualified professionals where appropriate. Cointelegraph maintains full editorial independence.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

Nomura’s Laser Digital backs ZIGChain for onchain private credit push in UAE

4 minutes ago
Cryptocurrency & Free Speech Finance

Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI

7 minutes ago
Cryptocurrency & Free Speech Finance

Mike Novogratz’s Galaxy Digital (GLXY) heads lower after earnings

1 hour ago
Cryptocurrency & Free Speech Finance

Binance Affiliates Sue RedotPay Over User Diversion Claims

1 hour ago
Cryptocurrency & Free Speech Finance

Morning Minute: Jim Cramer Sells His Bitcoin Over Quantum Fears

1 hour ago
Cryptocurrency & Free Speech Finance

The $120 million Coldcard wallet hack lights up Bitcoin’s memory pool: Crypto Daily

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

6 minutes ago

Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI

7 minutes ago

Meta Backs Off Sloppy Gambit To Nickel-And-Dime AI Glasses Customers

39 minutes ago

VDARE’s Libel Case Against N.Y. Times Thrown Out

41 minutes ago
Latest Posts

The studios of B-92 in Belgrade. Photo: EC – Audiovisual Service / Raymond Maxwell In 1989, Serbia was in a state of turbulence. The region was on the brink of the Yugoslav wars – the decade-long conflict prompted by the collapse of Yugoslavia, of which Serbia was one of six constituent republics. Slobodan Milošević, populist president of Serbia who gained power by capitalising on rising ethno-nationalist tensions, had recently come into office. Central communist control was weakening, dissent had been stifled and free media was at a premium. These were the conditions under which Veran Matić, together with several other student journalists from Belgrade University, founded the radio station B92. Matić had been involved in independent youth media since 1984, and the station was born from his desire to combine journalism with other forms of civic activism. He proposed that the founding document of the station should be the Universal Declaration of Human Rights – a principle, he told Index, that has guided him since his early life. “I grew up in a village, mostly with my grandparents. They taught me the values of honesty, justice, and many of the ethical principles rooted in religious teachings,” Matić said. “My interests have always extended beyond journalism alone.” Blending rock music with current affairs programmes and phone-ins, B92 quickly gained popularity as a rare outlet for Western news and information in Yugoslavia. However, Serbia was becoming increasingly authoritarian under Milošević; the station’s preference for truth-telling was at odds with the regime, and B92 became a prime target for suppression. Years later, Matić found out that he had been surveilled from the very beginning of his career. “The Yugoslav State Security Service had already begun monitoring and wiretapping me,” he explained. “I was aware that I was being followed, but I had no idea that my telephone conversations had been systematically intercepted for years.” Matić soon became editor-in-chief of B92. During anti-government demonstrations in Belgrade in March 1991, police stormed the newsroom and threatened staff members and foreign correspondents in the newsroom, forcing the station off the air. “Tanks had already begun appearing on the streets, and the police threatened violence against our staff,” Matić said. “We finally suspended broadcasting, but we refused to air the official state news agency’s reports. The following day we resumed broadcasting without permission because the student protests had begun.” The next time the state tried to shut B92 down, in 1996, the station was ready. Staff outmanoeuvred the authorities by transmitting their signal over the internet to the BBC in London, which relayed it by satellite back to local radio stations across Serbia for broadcast. This was one of the first examples of using the internet to circumvent censorship in broadcasting. Matić contended that the most dangerous period for B92 staff was during the NATO bombing campaign in 1999 – a large-scale air campaign to destroy Yugoslav infrastructure and to stop the repressive activities of the Milošević government. In and amongst the turbulence and warfare, Radio B92 was once again banned. But this time, Matić was arrested. “I was taken to a detention cell inside the largest police headquarters in Belgrade,” he said. “Through a tiny window I could see the night sky, waiting for the bombers to arrive. For the first time in my life, I felt completely powerless.” Matić and his colleagues were buoyed, though, by an international campaign of solidarity in support of independent media in Serbia. They responded with innovation, driven by their belief that the authorities were “not stronger than the ideas.” “We responded by installing transmitters in Romania and Bosnia and Herzegovina, as well as a clandestine transmitter in Belgrade,” Matić told Index. “We switched it on on 5 October 2000, when nearly half a million people gathered peacefully in Belgrade to bring down Slobodan Milošević’s dictatorship.” In the years that followed, Matić continued to build his career in journalism. He helped to establish the Commission for the Investigation of Murders of Journalists in 2013, and currently chairs the Permanent Working Group for the Safety of Journalists and the Association of Independent Electronic Media (ANEM). He is also head of the B92 foundation, a non-profit launched by the media house which brings together companies, foundations and civil society organisations to promote philanthropy and humanitarian aid. Even though the Milošević era is long gone, Matić continues to face adversity and censorship while reporting in Serbia. Just last month, he was attacked while filming a public gathering in front of the National Assembly, when someone forcibly took his phone despite Matić introducing himself as a journalist. Matić is keen to stress that this was not an isolated incident. “What happened that day cannot be understood simply as an incident in which I was prevented from filming,” he said. “It was the culmination of a much longer process of public targeting and the creation of an atmosphere in which violence against me has effectively been legitimised.” Veran Matić in 2011, the year he was given police protection. Photo: Portal Vlade APV / CC BY 3.0 Between 2011 and 2016 he was under 24-hour police protection, both in Serbia and while travelling abroad. More recently, current President Aleksandar Vučić publicly disparaged Matić during a TV appearance, suggesting that people convicted of crimes as a result of Matić’s investigative journalism had been wronged. At the same time, a pro-government media organisation ran what Matić described as a lengthy propaganda piece on him. “After the broadcast, the threats intensified,” he said. “I have repeatedly been verbally abused and physically confronted in public. Members of my family have also been threatened. “The most frightening aspect is not only the hostility itself, but the growing conviction that there is little institutional protection available.” Matić is not the only journalist in Serbia being targeted in this way. According to the official records of the Supreme Public Prosecutor’s Office, only 12 out of 271 recorded cases of threats and attacks against journalists over the past two and a half years have resulted in final court judgments. Independent media is vital in holding those in power to account and being part of it will never be an easy profession. Matić identified several economic, legal, and security issues facing such outlets, including the threat of SLAPPs together with smear campaigns, harassment on social media and intimidating surveillance tactics. “The consequence is that many journalists go to work every day knowing they are exposed targets,” said Matić. “It has become a struggle for personal safety, for the survival of independent journalism, and ultimately for Serbia’s democratic future.” The B92 foundation has provided support to journalists outside of Serbia in recent years, including correspondents in Ukraine and Gaza. Through his experiences, Matić understands the importance of press freedom globally – and the cost that can come with it. “In many ways, my entire professional life has unfolded under pressure, threats and various forms of state repression,” he reflected. “If we want citizens to continue knowing what is really happening in our country, we must ensure that the journalists uncovering those truths are able to continue their work safely. “That, more than anything else, is what keeps me going.” READ MORE

45 minutes ago

Mike Novogratz’s Galaxy Digital (GLXY) heads lower after earnings

1 hour ago

Binance Affiliates Sue RedotPay Over User Diversion Claims

1 hour ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Nomura’s Laser Digital backs ZIGChain for onchain private credit push in UAE

4 minutes ago

Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

6 minutes ago

Anthropic’s Claude Mythos 5 ‘Targeted Real People’ in UK Cyber Tests: AISI

7 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.