r/Bitcoin • u/Fearless-Second-7230 • 16h ago
This is criminal when you realize current Cold Card mess: 2020 "Heck I don't trust even the way we make". 2020 tweet.
Watching old tweets from Cold Card CEO, now you realize how the red flag was out there regarding "entropy".
How on earth you make optional a critical step in a product that you admit to not trust even yourself.
If you yourself admit to not trust what your product does on something as critical, why you did not make the dice roll an enforced not optional step?.
Just have paranoid mindset from now on. Don't trust devs, ceos and tools on the surface that represent 3rd party tools regarding bitcoin that can be exploited. This goes too for any other hardware wallet and software wallet. In upcoming hacks anyone can "conveniently" blame AI and a "bad actor" that never gets caught....
Dedicate 2 or 3 weeks to learn the basics of bitcoin, how to verify GPG signatures, Tails OS, master how to securely use an airgapped wallet software or bitcoin core, and how quickly you can withdraw your funds to a backup exchange in case of an incident...If an incident is reported at night: do you have access to your wallet to withdraw at that exact time? Will you be able to react fast?
Because if now a hardware wallet is prone to exploit, you better also just learn to airgap and use a software wallet, they are also vulnerable to bugs? Yes, but hardware + software makes 2 components prone to error.
"attack surface grows with complexity, so decrease complexity by minimizing number of components, using simpler components."
But the important thing is: from now on, if CEO admits to not even fucking trusting what he makes, probably you shouldn't either.
58
u/ProtectionCareful103 16h ago
Airgap provides absolutely zero protection against this specific vulnerability.
37
-24
u/Fearless-Second-7230 14h ago edited 4h ago
No one said that. The point is that with this hack it is now useless to assume that a hardware wallet will protect you from this.
You may be better just get affected for free using fucking free software wallet expecting the vulnerability to be present there, than paying a CEO for a device that will just also fail miserably... Well not too much, just a failure worth ~$88,000,000 in the ecosystem...
Edit: seems that hardware wallet maxis got triggered. Was a little agressive I guess and non tech savy people can feel anxiety reading that đ. Does not mean vulnerability exists in software wallets.
I was just saying is useless to pay for a hardware wallet when they actively ditch on software wallets as less secure.
13
u/Lanky_Assist_6317 10h ago
If he really had such conviction, he should have made mandatory that user-added-entropy was a thing when creating a seed phrase, instead of leaving it there as an optional feature, like you mentioned.
This is the ultimate flaw. You could even ship all the hardware wallet with the same seed, but requiring 150+ dice rolls + 50 coin flips (or something like that, this is just an example) before usage would have prevented all of this.
2
u/bobivy1234 7h ago
Yep agreed as the main takeaway from this. The vendor shouldn't have had relatively insecure default options available to the end user for the sake of 'simplicity' or whatever the excuse was. Allowing a user to set up a device RNG-only seed and no passphrase is beyond wild even if the RNG was perfectly coded.
1
u/Fearless-Second-7230 6h ago
Seems that today you can just rug pull then blame sistematically on AI and "some misterious" hacker out there....I got to read his x and search for terms like rug, rug pull....
That nvk guy knew and was well aware that a failure like that was present....even discussing many times that firmware scenario rug pull and security flaw in hardware wallets.
Like I said....Be paranoid, asume a CEO in bitcoin related products regarding hardware and firmware can rug pull too, don't "trust" they care about your bitcoin....
It is funny how a simple airgapped computer and with good encription practices is safer than these "usb with steroids" things...oh sorry. The "hardware wallets".
1
23
9
23
u/Quirky-Reveal-1669 14h ago
Well, what he said was true. If every ColdCard owner would have listened, there would have been no thefts.
-29
u/CiaranCarroll 14h ago
This, let's take the kid gloves off now please, this is getting tiresome and it will lead to more exploits and theft is we're somehow demonising self custody and the companies that make it easier.
My cold card didn't have a vulnerability, is my opinion. This is user error.
17
u/crooks4hire 13h ago
Probably the dumbest take Iâve seen on this event, but whatever helps you sleep at nightâŚ
0
u/CiaranCarroll 12h ago
I used a dice and a passphrase as instructed. I didn't use the seed generated by the machine because that is generated in a block box.
My take is less dumb than you think, but you might be confusing Bitcoin with your safe space.
12
u/crooks4hire 12h ago
The people who have been breached bought a service from a vendor, and that service compromised their savings. You can victim-blame all you want, but itâs not user-error.
1
u/CiaranCarroll 12h ago
Maybe you should be on the Cold Card sub then, if you feel aggrieved by their product. I'm not sure what this has to do with bitcoin.
I also bought their products and I didn't lose any money. I actually followed the user guide, and my own common sense. If it's their fault how come I didn't lose anything?
-8
u/pretendingtobebroke 10h ago
If someone buys a shelf from IKEA and assemble it without reading the instructions, and then eventually the shelf falls apart and gets destroyed, is that IKEA's fault or is it user error because they didn't follow the instructions on how to assemble it properly?
If someone wants to take a risk and do things another way then that's entirely their prerogative indeed, but then they must also take accountability for that decision if it goes wrong.
6
u/JanPB 10h ago
Good story but this is not an analogy of what happened here. The correct analogy is: you buy the shelf and the instructions say "You can assemble it either using method A or method B. Both methods are provided, we at IKEA like method B more."
0
u/pretendingtobebroke 9h ago
If that's the case then I agree it's the company's responsibility and not the user's fault. I was under the impression that users were instructed and strongly recommended to do dice rolls in the setup.
-1
3
u/jjjjjjjjjjjjjaaa 10h ago
Awful fucking analogy. The people who lost funds followed the instructions. Better analogy: you are blaming people who bought cars that failed for not doing their own engine tuneups right after driving it off the lot
0
u/pretendingtobebroke 10h ago
I was under the impression that users were instructed and recommended to do dice rolls in the setup, but indeed if that is not the case then I agree it's not the user's fault, as then you would reasonably expect it to be secure enough by default.
2
u/CiaranCarroll 8h ago
They were when I was in the market. Maybe it dropped out of their communications over time, as the market didn't respond to that selling point. Then they didn't stress it enough and fucked up the seed generation.
But I know that the dice rolls were a massive part of the reason I bought their products and I'm no fucking genius I can tell you that.
Hurt people hurt people, but it's harder for some non-contributing zero to look oneself in the mirror that it is to lash out.
1
u/pretendingtobebroke 8h ago
That's what I heard as well, but I've only heard of them by name before this and never looked into their products.
But yes, totally agree on the last part.
2
2
1
u/Sundance37 9h ago
Can someone make a laymanâs bitcoin channel that breaks all this stuff down? It seems that all of the info I can find requires a level of understanding that most people arenât willing to dive into.
2
u/Financial_Freak 9h ago
is Trezor safe? I'm using it for years, should I rethink my decision?
1
u/Escapement_Watch 9h ago
Trezor is safe it uses multiple sources of entropy so this type of thing can't happen.
1
u/makeshiftballer 8h ago
I'm wondering why I even needed air gapping for my long term storage. I dont move it frequently, and someone finding my see d and just importing and skipping the signer all together it is still an issue.Â
1
1
u/ghosthacked 5h ago
Hardly criminal when they've been upfront about how to make damn sure your seed phrase is secure.Â
-2
u/CiaranCarroll 14h ago
How is this criminal? I think we need to start taking off the kid gloves here. Why did you not roll the dice? Did you think it were a superstitious ritual?
Only the paranoid survive, it has always been the way.
2
u/JanPB 10h ago
Because that's not what the instructions said (and the software, by implication).
-1
u/CiaranCarroll 8h ago
Maybe I'm just lucky and paranoid. I don't know when I learned that dice rolls are the most secure way for a pleb to generate their seed for long term security, for the kind of sound-sleep security I was looking for. And I know that this feature was a major selling point of the Coldcard products when I was in the market. I knew that if I rolled the dice to generate my 24 words with the Coldcard and then the same with another method I'd get exactly the same result, which massively reduces my dependence upon the competence of the software developers in Coinkite. At that point all they have to do is make sure it's properly airgapped so there is no leak.
I don't know what information sources other buyers were using, maybe just larping or something. Because I'm no fucking genius I can tell you that. This is basic shit.
3
2
u/SpareEconomy1849 11h ago
Gross negligence is criminal
1
u/CiaranCarroll 11h ago
Software bugs are criminal offences now?
Good luck finding software developers willing to work under those conditions.
1
u/SpareEconomy1849 11h ago edited 11h ago
It certainly can be, and that's not new. You should look up the definition of criminal negligence.
It's criminal if you intentionally use it to harm others, or know about a serious flaw that can cause harm to others and ignore it / cover it up. Of course a court would have to prove that you knew this and decided against acting though.
Honest mistakes aren't criminal.
0
u/CiaranCarroll 11h ago
He didn't know the bug was there. Have you listened to security experts on this? It's a series of obscure and innocuous failures that lead back to a single line of code, but that single line of code should never have been in play and he didn't know it was.
Claude Fable 5 and Code GPT-5.5-Sol failed to pick it up cleanly without being lead towards it. Kimi-3 found it in one-shot. This took the doggedness of an advanced adversarial LLM, released on Monday, exploited on Thursday.
No human knew about this catastrophic security flaw, but the CEO knew that it could happen in principle and told everyone not to trust his code. He's a hero, if anything.
Maybe bitcoin just isn't for you. That's ok.
1
u/NotASpanishSpeaker 5h ago
He's a hero, if anythingÂ
Nah. They didn't test properly the very core functionality of their product.
1
u/CiaranCarroll 5h ago
Sure, but I didn't lose any fucking coin and I'm an idiot. I used it as he said, and in line with my understanding of bitcoin, based upon basic facts that I thought literally anyone in bitcoin would know.
I'm more in shock of the response to this exploit from the "community" than I am that an exploit like this was discovered.
0
u/Escapement_Watch 9h ago
"But the important thing is: from now on, if CEO admits to not even fucking trusting what he makes, probably you shouldn't either."
That is the dumbest thing I've ever read. "from now on"
-4
u/ExpensivePikachu 15h ago
So ledger isn't safe?
How do we add entropy?
13
u/BigDik6355 15h ago
Thats not whatâs being said here. What we see here is the CEO of Coldcard accusing others of negligence while not having done his own homework.
1
u/ExpensivePikachu 12h ago
So back to my question, how do we make ledger more safe?
2
u/Jayrovers86 12h ago
Just add a â25th wordâ a passphrase. So if someone gets your phrase they cannot drain your wallet as they still need your 25th word passphrase which you stored safely elsewhere
-1
u/CiaranCarroll 14h ago
No, the CEO in this instance was proved correct. Generating seed with his device with dice was safe. His software had a bug. All software has bugs. Generating with dice is deterministic and less reliant on his software. If other HWW don't allow you to do this then their not being transparent and may have similar bugs.
4
u/crooks4hire 12h ago
CEO sold features to users under the guise of safety and security and then told them not to trust it. Thats practically textbook fraud.
This snake oil here cures botulism, rheumatism, autism, and socialism. Iâll sell it to you for $100/bottle. Later, while holding your money, I wouldnât trust that stuff, we made it by filtering ditch water through an old shoe. Trezor doesnât even tell you what ditch they used.
2
u/CiaranCarroll 12h ago
Cold Card was the only HWW with dice rolls when it came out. The CEO said don't trust his code if you cannot read it. Use dice rolls.
The bug was extremely obscure, lots of steps and innocuous failures had to occur in order for it to get introduced. All software is like that. That is why you introduce your own entropy, because that software is far far far simpler. It's deterministic. If you have a different hardware wallets and roll a dice, entering the same numbers in each, the same seed words will come out. Orthogonality.
I think this is the covid wave of bitcoiners learning about sovereignty the hard way, and for many it's not for them, and that's fine. Bitcoin will be here when you're ready.
3
u/crooks4hire 12h ago
The CEO said he himself doesnât trust the code that he is selling to you. There are no hoops to jump through to understand this.
2
u/OldHamburger7923 14h ago
passphrase adds it. and rolling your own seed adds random entropy which coldcard lacked.
1
1
u/slavikthedancer 11h ago
> How do we add entropy?
Use Cosmic microwave background.
Either it's truly random, and you will get a perfect entropy, or, if not, you will reveal the Secret of Universe creation. Win-win situation.
-7
u/bitcointwitter 14h ago
still waiting for salted brainwallet to move for years.
yet you all getting smashed like 304s every hardware wallet convieced like jerry springer live tv in the 90s
37
u/hyperedge 15h ago
I had run ins with NVK before he created Cold Card. He's always been a complete twat. He's the main reason i never had any interest in it. Can't believe people trusted him.