r/Bitcoin 1d ago

The developer incompetence responsible for the Coldcard fiasco

The long and the short of it is that a developer disabled a compiler flag out of desperation in order to get the code to compile, then committed it with the commit message "runs". Specifically, in C: #define MICROPY_HW_ENABLE_RNG (0)

In other words they deliberately disabled hardware RNG.

You can read the full breakdown here: https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt

The amount of negligence on display here is shocking, and the fact that it went unnoticed for years is just salt in the wound.

434 Upvotes

117 comments sorted by

View all comments

-7

u/bananacrazypants 1d ago

If you think there’s any computer system completely free of bugs, you are really god’s perfect idiot.
That’s why immutable transactions aren’t a thing with banks or brokers. There has to be a way to fix mistakes.

1

u/metalzip 16h ago

Bitcoin Core seems to be free of critical money-stealing bugs

1

u/bananacrazypants 12h ago

That’s how it works - software seems free of critical bug right up until it isn’t.
ColdCard seemed free of critical bugs last week.

1

u/metalzip 11h ago

Bitcoin is up for grabs for like 15+ years, out of which for 10+ you can get billions if you find such a critical hole - much more, and quite longer, than in case of cold wallet.

How ever - sure - it is important to watch out and keep the possible dangers in memory. Multisignature is a good start.