I was thinking this same thing.
I see a lot of people here wondering what to do at this point and whether trusting Coinkite moving forward is possible. Here is my take:
Unforgivable sin #1
This bug was a integration mistake, not a complex crypto flaw. It should have been easily caught by basic build time assertions. It's a huge oversight and unforgivable for a company whose very existence is based on security.
Unforgivable sin #2
The most damning issue here is that Coinkite, a company that primary and ONLY premise is the development of a secure HARDWARE device does not test the output of that hardware at runtime. The fact that they didn't check that the output produced by the seed generator passed through standard randomness battery tests is wild! They would have instantly noticed that the outputs were coming from a deterministic PRNG if they bothered to test.
Unforgivable sin #3
At the end of the day, a hardware wallet only has one job. Generate true randomness. All coldcard wallets failed at this. Yes, you could say the bug is hard to spot, especially when doing static code analysis. The code is open source and has been subject to audits, but integration tests should have discovered this flaw before the affected firmware was ever published.
The theory that this bug was discovered by AI is also a side track and completely irrelevant. This was not a complex vulnerability.
https://np.reddit.com/r/coldcard/comments/1vcfugv/coinkite_is_done_for_here_is_why/
I was thinking this same thing.
Fuck Cold Card and the asshats being apologists right now
Also fuck the Ledger astroturfing. Coldcard being crap doesn't retroactively make Ledger not crap.
Trust no one Don’t trust. Verify Initial success or complete failure
[removed]
[removed]
Fudder will fud… ignore the noise and keep stacking
Someone who designed that shit was incompetent as fuck. Or. Or smart as fuck and rich as hell now.
As OP says - the full source code was always freely available online, wasn't it? So I wonder why nobody caught this bug until now?
"Trezor and Ledger are perfectly safe with their ultra-tested TNRG" That does not matter if it is not implemented correctly!
That´s the point: They have entire dev security departments to correctly test and implement the TRNG´s.
[removed]
not once, not twice, but thrice?
You act like this is the first time this has happened on any platform. The fact of the matter it isn't, and it'll continue to happen. Every year it's a new platform and this is all over social media. This is why etf's are becoming more popular as they're actually secure and fdic insured.
What’s the point of investing in a BTC ETF if BTC itself goes down the toilet? Am I missing something?
Roth Ira etf chill is the best way. Idgaf how many people yell about “cold storage”. Im not managing that and researching constantly how safe my keys are. People in this community will just keep moving goal posts. “Well you need self custody” “Well cold storage is best” -> “Well you need to verify how the seed is made”-> “Well you need to choose a random number” -> “Well people cant make random you have to roll dice” Like just stop. Its exhausting.
and fdic insured
no, the word you're looking for is SIPC insured
Funny thing is that it hardly did anything to the price.
Because all that matters is ETF flows and the derivatives market
I don’t disagree, but I am getting paranoid and what just happened is a huge trust issue for the whole network. People did everything right and they still got screwed. I was thinking of doing a passphrase in a couple of weeks when I’ll have some time to kill, but I just set up my alarm for early morning to do it tomorrow. Fuck this shit.
Makes me almost feel like Coinbase is a safer way to go lol
Honestly this fud and event are all pointing to something I've suspected for a while now. I think the bottom might be in
Exactly this lol I knew we would have some event between now and October, this feels like the event
There’s always a capitulation event
this event has nothing to do with price and doesn't even affect btc price.
👆 if this barely impacted movement, that says a lot about where we are
According to ai bottom is in October
It’s okay, let the FUD commence to shake the lettuce hands out. We need people like that to pump the ATH later on when they limp in anyway.
[removed]
I mean I hear all this, but the problem is that the true test is in "does it generate truly random things," and unfortunately humans can't easily tell the difference between 40bits of randomness and 128-256bits. So the review critique strikes me like, "Read this code and be super, duper, duper careful there's absolutely no mistakes." But consider a simpler task: "Read this book and be super, duper, duper careful there's no typos." But no matter how hard I stress to the reviewer(s) the importance of no typos at all, they do happen. That said, I fully align with testing true randomness as described. I don't know exactly how that works, but in a dream world, yes, they should have generated enough seed words HW-only vs. with dice rolls and been able to compare that one was only randomish while the other was truly random. I think, in theory? If it's possible to set a seed on the PRNG and get the same words every time... yeah, that's the nail in the coffin for sure on lack of testing. Otherwise, it's tough as you can only say you've probed at the limits of computing, but given someone willing to run a computer for 2yrs on the same problem... doesn't the vendor have to run with bigger computers or for longer to *really* be sure? I just don't know what that sample size is where you can start to tell the difference between outputs (absent forcing a set seed and just knowing which device is being used)? For true human root case, I still think it boils down to being rushed and motivated to get out from under the GPL license, not to do something in the name of security. They were really itching to switch to libNgU in order to block competition. I think prioritizing greed and rushing were the Achilles heel(s).
>In the hot fix Coinkite has a script that checks the generated symbol table and asserts that whether the rng_get() symbol originates from the coldcard board directory and throws an error otherwise. There are several other ways they could accomplish the same thing.
And that's also an excellent point. I saw in their technical breakdown they used the same `rng_get()` signature, just were unaware what it ultimately called. The fact they could have checked/verified (tee hee hee on the modify "verify, don't trust") is... damning for sure. Ugh.
[removed]
Some OG’s in the space have been compromised and are now attacking Bitcoin from the inside, this could potentially also be an inside attack. I wouldn’t rule it out…
Anyone who promoted then should be crucified, they never bothered to check the code. Those that did warned.
Who checked it an warned? Where was the canary in the coal mine? Do you know of a specific person or instance of unheeded warning?
[removed]
Was the cold card RNG open source? Also RNG has always been a possible issue with any generated seed, that’s why you always use a passphrase.
As someone who works in software, I'm inclined to agree (though I don't love the nuclear analogy lol). There is an astonishing amount of bug-ridden, exploitable code out there, and with superhuman AI now able to find and weaponize these flaws at rapidly increasing speed/decreasing cost, we're going to see *so* much more of this. Yeah, once the vulnerability is spotted it seems so obvious, but of course if it were truly trivial, it wouldn't have been sitting in an open source codebase for years.
But it wasn't Trezor was it? Don't tar everything with the same brush is the OP's point.
Wasn’t this open source and reviewed by everyone?
I got in with Bitcoin fairly early. 2009 about maybe 2010. I was putting my coin in Coinbase. After I had ammased some amount of coin and was still collecting Coinbase went into my account and emptied it. No notification, no warning, they said they suspected fraud and I had ZERO recourse. I have tried and tried. I was done with Bitcoin that day and will never touch it again. This is not a new thing, your "money" is not safe.
This story is 100% made up.
This wallet was promoting by many influencers, another flaw in other cold storage wallets is definitely possible
Going to 50k next week or two
No it isn't.
I guess so too, this shit will break down the 200 weekly ma and send us to the real bottom.
well next could be trezor or ledger. there is no guaranted good luck tho. i dont want self custody when AI keep getting good day by day.
The scary thing about this is its not only Coinkite that failed to find this exploit, AI that Coinkite used recently , other blackhat and whitehat crackers , us the users , and its competition like Ledger's own DonJon team that often is testing its competitors hardware wallets for ~6 years as well. This is a more systemic issue where new AI models are finding exploits that teams of security specialists overlook and there is a race to find and patch these exploits right now . Example with exploit in bitkey HW wallet just reported https://x.com/1440000bytes/status/2083507377643606068 https://x.com/milessuter/status/2083542842253656250
Tbh it is not good for your average normie to hear when it comes to normalizing Bitcoin and mass adoption. The Cold Card organization should be ashamed of themselves for this. At the same time, I’m not bothered by it personally. I know Bitcoin will be fine in the long run.
I feel for the cold card users but this could be a bottom signal, these kinds of events are usually the breaking point for alot of ppl
Can people who generated the seed by rolling dice on coldcard and use a passphrase rest easy?
Yes, also not using a passphrase is a terrible practice. Not that I’m blaming people that lost their coins, this is cold cards fuck up, but it just shows how difficult knowing and following best practices can be.
The fact of the matter is that ColdCard was trusted and recommended and people shouldn’t have to be security experts to feel that their funds are secure. A loss of trust event has occurred and it will take a long time for the average person to trust Bitcoin again.
The amount of money, time, and metal stamped seed words for long term storage always seemed odd to me when Bitcoin Core, Tails, and password protected wallet.dat files are very secure with little risks someone is going to not check the code to ensure no flaws. Like booting to Tails offline to open the Core, wait for it to sync and then move Bitcoin to a less secure wallet for transactions is really a no brainer and more should be doing this versus putting trust in yet another party. Bitcoin already provides all we need to be secure and there are plenty of tools and resources out there to learn how. Like 2 hours of learning and implementing which is likely the same with all these hardware wallets. Self custody with only 1 open source platform in the mix that has the most eyes on its open source code is the way to go.
The criticism of Coinkite may be justified. A RNG failure in a hardware wallet is a very serious issue, because entropy generation is one of the most critical parts of the entire system. But this is exactly why security engineering does not rely on the assumption that one component will never fail. No system is perfect. Not Coldcard, not Ledger, not Trezor, not any hardware or software. This is the reason why critical systems like banks, data centers and other high-security infrastructures use redundancy. They do not build systems assuming every component is flawless. They build systems assuming components can fail. A properly designed multisig setup is not about trusting more wallets. It is about making sure that one failure, one bug or one company mistake is not enough to destroy your entire wealth. The lesson is not “find the one perfect hardware wallet”. The lesson is “do not create a system where one company’s mistake can become your total loss.”
Don't lump Ledger into the same category as Trezor
Ledger's 'Recover' feature should not be considered trustworthy, in my opinion, and they have a poor track record of protecting customers' identities
I’m glad I have my says in a Ledger. I remember when everyone was saying go with Coldcard. I'm glad I was to lazy and cheap to get a Coldcard. Sure, Ledger can be hacked, but until that happens, I’ll keep my Ledger.
Lesson is not to trust just a single company to store your wealth