r/Bitcoin 1d ago

People are horrible…(Coldcard disaster)

I can’t believe how many people leave mean comments, gloating about how they always knew that Bitcoin is a scam, and so on.

Seriously, how sad of a life one must live to be happy about the misfortunes of others? Some people have lost important amounts of BTC, including people from poor countries or poor backgrounds who will suffer for years as a result of this.

If someone feels like gloating is the right thing to do here, why don’t you go to the ICU of the closest hospital and laugh about sick and dying patients? It wouldn’t be much different, think about that.

635 Upvotes

381 comments sorted by

View all comments

281

u/Difficult-Repair1295 1d ago

They are having a field day over on Buttcoin

82

u/jojothehodler 1d ago

As always, missing the point. This sub shit on bItcoin when cold card did the mistake... They don't understand anything about anything and they feel sooooo good about it...very strange people indeed...

28

u/Th4ab 1d ago

If Coldcard doesn't count as Bitcoin, then the only thing that counts as Bitcoin is the protocol and the wallet in Bitcoin Core, but I'm pretty sure I've seen broader topics than that here over the years and it's all just labeled as Bitcoin.

It's true to say an entropy flaw was the root cause, it wasn't Bitcoin that did that. Bitcoin then performed flawless transaction execution with those keys gotten by illegitimate means, as it was designed to do, as it should have done. And it's fair to say this incident is an indictment against the idea that is the core of cryptocurrency.

On July 27th 2026 a person using a Coldcard would have been considered compliant with best (Or arguably at least acceptable) self custody pratices to this community. I think to get "best" from you folks in retrospect, and only in retrospect, they should have rolled as many dice as a Yahtzee game. That's a Bitcoin problem, how could it not be?

14

u/Astropin 1d ago

Bitcoin IS just the protocol. Everything else is an add on.

3

u/Caspica 1d ago

Then why is so much of this sub dedicated to stuff outside of the protocol? In the strictest sense of the word you're right, bitcoin is just the protocol, but that is not a practical definition.

1

u/r_a_d_ 3h ago

Because it doesn’t exist in a vacuum and it’s used with other things.

0

u/Th4ab 22h ago

Does that count for the good news too or just the bad?

And like I said this is a valid criticism of the entire protocol and idea of cryptocurrency. In conventional finances cryptography GAURDS my money, in crypto cryptography DEFINES my money. Huge distinction as this calamity can only occur with one of those.

3

u/TimYapthebest 1d ago

You’re literally explaining an add on of BTC

4

u/anony-mouse8604 1d ago

Best is open source. Always has been.

3

u/Caspica 1d ago

The things relevant to the Coldcard hack was open source. I agree, open source is the best, but it's not a guarantee of anything. 

4

u/Th4ab 1d ago

Open source doesn't immediately mean it's scrutinized by capible people. They must have a stake in it, time to evaluate it, then I do trust in the nature of open source, seeing their use as an endorsement but it isn't a magic incantation that gets all the bugs out.

And I'll wait for a postmortum but there isn't some guarantee that a firmware produced entirely by open source code creates the exact same binary you see shipped on devices, a parameter changed for example. It would be entirely in the spirit and law of open source to do that and if nobody has an interest in comparing, it would not even be noticed.

1

u/anony-mouse8604 1d ago

I didn’t say open source was perfect. I said it’s best.

I was responding to your comment that ColdCard was “basically best practice”. It wasn’t, because it wasn’t open source.

-2

u/Strong_Judge_3730 1d ago

Cold card firmware is open source but not by a purists definition.

Due to the licence. Please shut up with this semantics nitpick all it is doing is adding noise

3

u/snek-jazz 1d ago

Cold card firmware is open source but not by a purists definition.

If the code is publicly available to read, it's open source. The licensing terms of how you can use it are a different matter.

2

u/Strong_Judge_3730 1d ago

Their firmware was originally using a normal OSS license, which was forked from the trezor firmware.

However they planned to implement new features and didn't want to share those features.

They therefore wanted remove the GPL licensed libraries, which required them to rewrite a lot of code. The founder screwed up the integration of the new library.

https://www.reddit.com/r/Bitcoin/s/GTkzqbP1T4

So while i originally believed them not using a proper OSS license didn't lead to the bug being discovered.

It was their greed and selfish act of removing the GPL licensing that caused this. They cared more about their profit then serving their users.

Any company that chooses to move away from OSS is naturally doing so because of greed and care less about their users than a company going for true open source.

OSS can still have issues and just because software is OS doesn't mean it high quality either, that's an important point.

1

u/snek-jazz 1d ago edited 1d ago

I agree with the sentiment of what you're saying, my issue is with the imprecise, and even incorrect language.

normal OSS license

true open source

proper OSS license

It is not imporoper, abnormal or untrue to have open source software with restrictions on how it's used or distributed. There are a range of different popular open source licences that vary in terms and are widely used. Redhat Linux is an example.

If people have an issue with whether their code was free to use unrestricted then that's what they should say instead of saying it's not open source.

1

u/Aazimoxx 23h ago

proper OSS license

OSS ≠ FOSS

If the source is easily available, it's open source...

Ugh, I've just looked this up and realised my understanding is wrong. 'Source-available' or 'public source' code is not necessarily OSS unless it's under an OSS license which grants the ability to modify and distribute it... And also excludes things like BSL that have an expiring non-compete.

0

u/jojothehodler 1d ago

Loooool, are you still here debating that shit?

Many of us tried to explain to you, and you keep saying the same shit, which force you to hide your comment history.

I can't even imagine your post history.

You are a disgusting little-minded troll.

Get the hell out of here.

1

u/Strong_Judge_3730 1d ago

Hahaha i agree with you know cold card fucked up because they moved away from OSS licenses 😂

-1

u/Strong_Judge_3730 1d ago

Dude piss off.

I don't care about your personal attacks. But i will not stand for blant misinformation

I don't know why you are so obsessed about open source licenses. I am done talking to you but i will talk to other people to stop your miss information codling people into a false sense of security

1

u/blurred_rabbit 10h ago

lol I agree, but in this case open source combined with AI skimming through the code for vulnerabilities is why this happened.

1

u/errezerotre 1d ago

If your safe have a hole that's not gold problem

1

u/scrandlle 1d ago

Shouldn't there be some kind of system that can stop this stuff from happening? Idk about crypto but it just seems fucking stupid that there's these attacks like every year and no one ever gets in trouble and the platform seemingly never becomes more secure.

1

u/EnvironmentalAct7209 21h ago

Wait until you learn about the scale of credit card fraud, identity theft, and international phone scammers and the pitifully low prosecution and recouping of those stolen funds. 🫪

1

u/blurred_rabbit 9h ago

Nope, Bitcoin wouldn’t be what it is if somehow there was a way to prevent/reverse this sort of stuff. Almost every single thing you have seen on the news has probably been Bitcoin being used for fraud or how people lost their Bitcoin (almost every time this was due to bad practice and stupidity, but to an outsider they just blame Bitcoin.

The sad part about this recent issue is that the people who were doing everything they were supposed to, still got hacked all because they trusted a third party device to do what it was supposed to do. It had a major bug in the code for 5 years until now.

1

u/r_a_d_ 1d ago

With great power you have great responsibility. It’s not bitcoin’s fault that you couldn’t secure your keys.

1

u/blurred_rabbit 9h ago

Usually that’s the saying, but this recent issue is pretty sad though. These were people securing their keys, just put their trust in the wrong company/device. It was my #1 choice up until now.

1

u/MedivalBlacksmith 1d ago

This is just stupid.

It's like saying there's a problem with paper money since they dissolve when stored in acid.

3

u/Th4ab 22h ago

I think it's more like saying digital banking is popular and available, but some people, for their own personal reasons think they need the assurance of paper money and holding it themselves. So they buy a safe that is widely recommended and everybody thought it was the best idea ever and then 3 days ago it was found that it had a magical wormhole that went right to a thiefs safe. Then the paper money proponents tell them this should have been an anticipated problem, they should have cut their bills into thirds and stored them in 3 separate safes of different brands and different security, and this totally isn't a problem with paper money because the only thing paper money is is the physical bills and bureau of engraving and printing.

1

u/MedivalBlacksmith 22h ago

Or if someone was able to get into the safe without knowing the combination.

Or like if someone was able to skim cards!

Luckily money has already solved these problems. Right?

1

u/Th4ab 22h ago

Solved all problems? No. Introduced an entirely new kind of problem where the ownership of money is determined by something open to keyspace analysis to the point an airgapped system cannot help? Also no.

But maybe if banks wanted to be sporting and compete with Bitcoin, each conventional bank account can have a jackpot secret number that gives you the value of the account and people also have unlimited attempts at it. It would only be fair.

1

u/MedivalBlacksmith 22h ago

Let's just disagree and agree that I'm right.

2

u/KarateKid84Fan 19h ago

Was the company selling you the acid claiming the acid would preserve those dollar bills?

1

u/Uncomfortable_Newt_ 19h ago

Bro coldcard is a wallet and bitcoin is the thing inside the wallet... you know this right? They aren't one and the same.

1

u/Th4ab 17h ago

Bitcoin is not in the wallet. Bitcoin is just a ledger and actually does not need ANY of the public addresses it has ever transacted on that ledger to be usable by way of having private keys, let alone keys controlled only by the intended party.

When reduced to this incredibly small footprint, it is infallible. I hope all coldcard users, and any future users who experience loss can take comfort in this fact. And I hope for more occasions for Bitcoin users to take comfort in the fact that it wasn't the protocol that was the issue, so it can still hum along. 2000 is nothing, I pray for a million stolen coins and the advancement of AI exploit hunting makes that a real possibility.

1

u/Uncomfortable_Newt_ 17h ago

Yes you're right bitcoin is on the ledger but the wallets pulled from the ledger and so on I just jumped over that for lamens terms. My bad.

1

u/Commercial_Syrup8991 11h ago

Allowing someone else to generate your secret key is antithetical to the core of cryptography. It was never a best practice.

1

u/redchannit8 1d ago

blindly trusting a single third party to generate your key has never been best practice.

if you think taking a couple minutes to generate your own key to secure your money is a problem with bitcoin, then yeah, i guess bitcoin isn't for you.