Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief
CoinTelegraph·

60-second summary
Coldcard's hardware wallet contains a five-year-old flaw that went undetected due to incomplete auditing. Auditors verified the presence of a random number generator but not its usage. This gap highlights the need for more comprehensive testing, particularly in the hardware wallet sector. The industry implication is a renewed focus on rigorous security protocols.
The five-year bug escaped detection because auditors verified that the intended random number generator existed, but not that it was being called.