I was thinking this same thing.
I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take:
Unforgivable sin #1
This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security.
Unforgivable sin #2
The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test.
Unforgivable sin #3
At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published.
The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability.
https://np.reddit.com/r/coldcard/comments/1vcfugv/coinkite_is_done_for_here_is_why/
I was thinking this same thing.
Fuck Cold Card and the asshats being apologists right now
Also fuck the Ledger astroturfing. Coldcard being crap doesn't retroactively make Ledger not crap.
Trust no one Don’t trust. Verify Initial success or complete failure
[removed]
[removed]
Fudder will fud… ignore the noise and keep stacking
Someone who designed that shit was incompetent as fuck. Or. Or smart as fuck and rich as hell now.
As OP says - the full source code was always freely available online, wasn't it? So I wonder why nobody caught this bug until now?
"Trezor and Ledger are perfectly safe with their ultra-tested TNRG" That does not matter if it is not implemented correctly!
That´s the point: They have entire dev security departments to correctly test and implement the TRNG´s.
[removed]
not once, not twice, but thrice?
You act like this is the first time this has happened on any platform. The fact of the matter it isn't, and it'll continue to happen. Every year it's a new platform and this is all over social media. This is why etf's are becoming more popular as they're actually secure and fdic insured.
What’s the point of investing in a BTC ETF if BTC itself goes down the toilet? Am I missing something?
Roth Ira etf chill is the best way. Idgaf how many people yell about “cold storage”. Im not managing that and researching constantly how safe my keys are. People in this community will just keep moving goal posts. “Well you need self custody” “Well cold storage is best” -> “Well you need to verify how the seed is made”-> “Well you need to choose a random number” -> “Well people cant make random you have to roll dice” Like just stop. Its exhausting.
Funny thing is that it hardly did anything to the price.
Because all that matters is ETF flows and the derivatives market
I don’t disagree, but I am getting paranoid and what just happened is a huge trust issue for the whole network. People did everything right and they still got screwed. I was thinking of doing a passphrase in a couple of weeks when I’ll have some time to kill, but I just set up my alarm for early morning to do it tomorrow. Fuck this shit.
Makes me almost feel like Coinbase is a safer way to go lol
Honestly this fud and event are all pointing to something I've suspected for a while now. I think the bottom might be in
Exactly this lol I knew we would have some event between now and October, this feels like the event
There’s always a capitulation event
this event has nothing to do with price and doesn't even affect btc price.
👆 if this barely impacted movement, that says a lot about where we are
It’s okay, let the FUD commence to shake the lettuce hands out. We need people like that to pump the ATH later on when they limp in anyway.
[removed]
I mean I hear all this, but the problem is that the true test is in "does it generate truly random things," and unfortunately humans can't easily tell the difference between 40bits of randomness and 128-256bits. So the review critique strikes me like, "Read this code and be super, duper, duper careful there's absolutely no mistakes." But consider a simpler task: "Read this book and be super, duper, duper careful there's no typos." But no matter how hard I stress to the reviewer(s) the importance of no typos at all, they do happen. That said, I fully align with testing true randomness as described. I don't know exactly how that works, but in a dream world, yes, they should have generated enough seed words HW-only vs. with dice rolls and been able to compare that one was only randomish while the other was truly random. I think, in theory? If it's possible to set a seed on the PRNG and get the same words every time... yeah, that's the nail in the coffin for sure on lack of testing. Otherwise, it's tough as you can only say you've probed at the limits of computing, but given someone willing to run a computer for 2yrs on the same problem... doesn't the vendor have to run with bigger computers or for longer to *really* be sure? I just don't know what that sample size is where you can start to tell the difference between outputs (absent forcing a set seed and just knowing which device is being used)? For true human root case, I still think it boils down to being rushed and motivated to get out from under the GPL license, not to do something in the name of security. They were really itching to switch to libNgU in order to block competition. I think prioritizing greed and rushing were the Achilles heel(s).
>In the hot fix Coinkite has a script that checks the generated symbol table and asserts that whether the rng_get() symbol originates from the coldcard board directory and throws an error otherwise. There are several other ways they could accomplish the same thing.
And that's also an excellent point. I saw in their technical breakdown they used the same `rng_get()` signature, just were unaware what it ultimately called. The fact they could have checked/verified (tee hee hee on the modify "verify, don't trust") is... damning for sure. Ugh.
[removed]
Some OG’s in the space have been compromised and are now attacking Bitcoin from the inside, this could potentially also be an inside attack. I wouldn’t rule it out…
Anyone who promoted then should be crucified, they never bothered to check the code. Those that did warned.
[removed]
Was the cold card RNG open source? Also RNG has always been a possible issue with any generated seed, that’s why you always use a passphrase.
Wasn’t this open source and reviewed by everyone?
I got in with Bitcoin fairly early. 2009 about maybe 2010. I was putting my coin in Coinbase. After I had ammased some amount of coin and was still collecting Coinbase went into my account and emptied it. No notification, no warning, they said they suspected fraud and I had ZERO recourse. I have tried and tried. I was done with Bitcoin that day and will never touch it again. This is not a new thing, your "money" is not safe.
This story is 100% made up.
This wallet was promoting by many influencers, another flaw in other cold storage wallets is definitely possible
Going to 50k next week or two
well next could be trezor or ledger. there is no guaranted good luck tho. i dont want self custody when AI keep getting good day by day.
The scary thing about this is its not only Coinkite that failed to find this exploit, AI that Coinkite used recently , other blackhat and whitehat crackers , us the users , and its competition like Ledger's own DonJon team that often is testing its competitors hardware wallets for ~6 years as well. This is a more systemic issue where new AI models are finding exploits that teams of security specialists overlook and there is a race to find and patch these exploits right now . Example with exploit in bitkey HW wallet just reported https://x.com/1440000bytes/status/2083507377643606068 https://x.com/milessuter/status/2083542842253656250
Tbh it is not good for your average normie to hear when it comes to normalizing Bitcoin and mass adoption. The Cold Card organization should be ashamed of themselves for this. At the same time, I’m not bothered by it personally. I know Bitcoin will be fine in the long run.
I feel for the cold card users but this could be a bottom signal, these kinds of events are usually the breaking point for alot of ppl
Can people who generated the seed by rolling dice on coldcard and use a passphrase rest easy?
Yes, also not using a passphrase is a terrible practice. Not that I’m blaming people that lost their coins, this is cold cards fuck up, but it just shows how difficult knowing and following best practices can be.