Reviews confirmed Coldcard's strong random-number generator code existed, but nothing verified it was the source actually called in production.
Percoco says consumers must trust a maker's most critical function with no independent proof the approved randomness path is the one running.
He pointed to NIST SP 800-90B and Germany's BSI AIS-31, which test and validate the entropy sources used in cryptographic systems.
Galaxy research found at least 15 separate attackers exploited the flaw, the signature of a reproducible weak-entropy problem.
Read More →