The Coldcard hardware wallet contained a flaw in its random number generation that went undetected for over five years. Manufacturers Ledger, Trezor and Foundation employ distinct approaches to securing entropy generation: Ledger uses certified Secure Elements, Trezor combines multiple hardware and software entropy sources, and Foundation relies on open-source firmware with reproducible builds. The incident has prompted calls for industry-wide standards requiring independent validation of entropy sources and certification tied to specific hardware and firmware versions. Security experts recommend architectural solutions like multisig to ensure that no single vulnerability can compromise users’ funds.
Source: Read the original article

