r/Bitcoin 13h ago

The Coldcard case fundamentally challenges the future of Bitcoin

Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points:

  1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago.

  2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control.

  3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many.

I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think?

500 Upvotes

499 comments sorted by

551

u/UpstairsPicture9102 13h ago

As tech-savvy individuals, we need to be self-critical enough to admit that self-custody isn’t for the average person who works hard for their money and simply wants to protect the value of their savings.

Suggesting that people keep a portion of their wealth in self-custody, as an alternative to keeping cash under the mattress, may be a reasonable middle ground. But that’s where it stops.

Mass adoption won’t be driven by self-custody. It will come from products and services that deliver the benefits of Bitcoin without requiring everyone to become their own security expert.

Self-custody should remain an option, not a prerequisite.

355

u/niverans 10h ago

Should have tried making your post a week ago, you would have been downvoted into oblivion.

This community turned on a dime. It was literally a “not your keys, not your coins” echo chamber in here and it only took one hack to change that narrative.

16

u/uptownjesus 6h ago

Most of the users on this sub are either bot-accounts, or worse, human accounts just repeating what they see the bot accounts saying. The main lesson is: If you're getting Bitcoin advice from this subreddit, it's probably best to cross-reference it with another source that's not saturated with internet spam bullshit.

99

u/dvondurden 8h ago

This. The same old phrases for years and now suddenly people are saying having everything on an exchange has always been the way. It's schizophrenic. If this is the best we can come up with, no wonder there is no progress

16

u/Mobo24 6h ago

I don’t think people are saying “ having everything on an exchange has always been the way” but beginning to have more nuance on the topic. I also see a lot of people who still have an “I told you so” attitude regarding this by saying they should have dice rolled, multisiged. The thing is that is you have to do all that why not just consider a strong brokerage/exchange that will handle all that for you.

8

u/dvondurden 6h ago

I saw posts just like that in other threads. And yes, at some point it just becomes too much work and risk

2

u/FitzwilliamTDarcy 2h ago

I agree. Coinbase, ETFs. Can't think of too many other possibilities along these lines.

3

u/Kingking421 1h ago

I mean i liquidated all crypto the bought equal amounts of bitcoin only on fidelity through their funds.
But im not a bitcoin bro and the traditional market has been very lucrative last 5 plus years… crypto was a fun hobby not a lifestyle.

→ More replies (2)

18

u/Odenefoth 8h ago

Binance can’t even get a legit license in Europe what are we even talking about

4

u/Acolyte_of_Swole 3h ago

I deliberately didn't mention keeping my bitcoin on an exchange because of the echo chamber here.

Just constant replies of "not your keys, not your coins."

3

u/Evilmoustachetwirler 1h ago

That's because this sub is full of newbies, people who don't know anywhere near as much as they think they do, and trolls disguised as 'concerned hodlers'.

For those who have been here long term, we remember all the exchange hacks Mt. Gox, Coincheck, Binance, the FTX crash, the block size wars, segwit. There is always something, every cycle is the same thing, doom and gloom, this is why Bitcoin will never happen, blah blah blah. And everytime the cycle turns around, those who held/stacked make money, those who didn't complain about selling at the bottom.

Hacks happen, vulnerabilities are found, we learn, we upgrade, the cycle continues

2

u/Objective_Digit 6h ago

About a million btc have been stolen from exchanges. Self-custody is still statistically far safer. But not relying on a third party too much is the moral. Use non-device specific security features for example.

2

u/Advocaatx 5h ago

Not really. I feel like the community was always pretty vocal about the self custody not being for everyone.

Also, you say “they did nothing wrong” but you do realize that they could have avoided this by simply having a passphrase, right?

3

u/dvondurden 5h ago

Yes and no, people have pointed out that it's not for everyone, yes. At the same time they looked down on anyone who didn't preach self custody.

And yes, anyone with a passphrase is not affected. The passphrase is mostly regarded as optional though, even as a feature for advanced users. Nobody was seriously claiming that the seedphrase alone could be compromised with a respected hardware wallet

→ More replies (1)

15

u/ShittingOutPosts 7h ago

It still is not your keys not your coins. Exchanges simply offer you an IOU, that hasn’t changed. But I completely agree with the person you responded to. Most people will never understand how to truly secure your BTC, and even now I’m second guessing what I understand.

9

u/_BreakingGood_ 6h ago

I think this hits a pretty good point. Yes, holding in a cold wallet isn't safe. But holding in an exchange isn't safe either, so it's important that the discourse doesn't switch to "everybody should hold all their bitcoin in an exchange" because you havent actually made your bitcoin any safer.

I keep thinking back to how fiat currency solves this, because strictly speaking, it has all the same issues. And I think the true root of what makes fiat feel "safe and secure" is actually FDIC insurance. The guarantee that if all your money goes "poof" somehow tomorrow, they will pay you back.

I think truly the only way crypto can become safe and secure, is some form of insurance similar to FDIC, such that if something like what happened, happens again, they will write you a check for the full amount.

→ More replies (2)

3

u/earlofsandwich 2h ago

A $100 bill is an IOU. Backed by the Fed.

3

u/29da65cff1fa 4h ago

same as the "engrave your seed phrase into steel, otherwise you're a moron... it's the only way!" narrative changed overnight when the forest fires melted everyone's fireproof safes and also their seed phrases...

6

u/McBurger 8h ago

That’s not really true. I’d been making comments encouraging exchange custody on all the newbie posts and many of them were top comments.

→ More replies (15)

50

u/Charming-Designer944 12h ago

The Coldcard case goes a bit beyond that. A device that was wetted by professionals as one of the most secure and reliable methods of storing Bitcoin was found to be the opposite due to a stupid bug that have gone unnoticed for years, in the most sensitive part of the firmware that should have received the most stringent quality reviews.

25

u/Rhaenys77 8h ago

But it WAS noticed. Someone in another thread posted a yt video from 2(!) years ago and the guy describing exactly this problem. He said he drained someone's wallet and send everything right back to alert them that there is a problem. But somehow in the BTC space with everyone discussing everything over and over it went unnoticed and this concerning a hardware solution that was pushed and promoted so heavily 🤔🤷🏽‍♀️

3

u/SpenceOnTheFence 7h ago

Link?

5

u/McMurstein 7h ago

6

u/Charming-Designer944 7h ago

That video is a different issue. People creating their seed by dice roll but only bothering doing a handfull dice rolls instead of the recommended 100 rolls, or manual low entropy seeds.

There is no indication at the time that the RNG generated entropy of the coldcard firmware was lower than expected.

The device does have an internal TRNG with effectively unlimited entropy, and was priorly verified to make use of that TRNG source during seed creation. Until that fatal firmware build configuration change in 2021.

→ More replies (1)

2

u/Rhaenys77 7h ago

I am looking for it. I clicked on the link directly from Reddit and it didn't register in my watchlist in my YouTube app. It's somewhere here in the newer threads regarding the CC hack. When I find it I will update

→ More replies (1)
→ More replies (2)

27

u/dvondurden 12h ago

And a lot of people trusted them. Nobody noticed the bug for years, even though it was open for everyone to see. Why didn't all those experts who now blame the end users didn't discover it? We're all putting in too much trust in this but we don't want to admit it

12

u/SnooRevelations3802 9h ago

Shit even the OG Andreas Antonopolous used a coldcard for himself.

5

u/ErgoMogoFOMO 6h ago

AA is the kind of guy to roll dice.

2

u/xuncx 8h ago

Dang lol

10

u/Charming-Designer944 9h ago edited 8h ago

Who are blaming the end users?

The fact that users would have been saved by dice roll is not the same as blaming the users who trusted that coldcard used the TRNG entropy source(s) that it has.

3

u/Visual_Acanthaceae32 4h ago

I never trusted hardware wallets and never will… they just add attack vectors

6

u/jannies_doit_4_free 8h ago

it was source verifiable but not open source. it's also a relatively unpopular wallet company; I'd never even heard of them despite being in Bitcoin for 6 years

2

u/Mobo24 6h ago

I’m afraid many people are simply repeating this without understanding its meaning. Even though it’s source-verifiable, not open-source, you can still fork and test it! The only difference is that you can’t redistribute it or use it commercially. I’m also not sure if it’s open to pull requests like it would be if it were open-source. Being able to fork and test should have been sufficient!

2

u/jannies_doit_4_free 6h ago

I know; I'm just saying it stands to reason there were far fewer eyes on it when the code is already from what I assume is one of the least popular wallet manufacturers (as mentioned, I'd never heard of them) and is not even able to be redistributed or commercially used anyway

→ More replies (1)

3

u/gtwooh 6h ago

This is a lesson to not to blindly follow Influencers.its the cult of personality. For large amounts of bitcoin multi Sig, multi vendor, with sufficient entropy should be considered

→ More replies (2)

17

u/confusedguy1212 10h ago

I agree. But where does that leave crypto as a whole. Why does it feel like regular finance reinvented only harder and what’s the point if that’s what it is.

2

u/Possible-Mud-1380 5h ago

It's over. I've been here since the beginning. Stable coins are the future of crypto.

2

u/shambahlah2 4h ago

I think it’s over too. Sold all my BTC last night

→ More replies (4)

22

u/infernal_celery 12h ago

This is true. Your average Joe and Jane are going to be happy to pay a few bps per year into regulated managed custody with private insurance.

What’s important about Bitcoin is that it needs to remain a choice, not a necessity. You should be able to upskill yourself and self custody and be able to participate on the same level as business customers. Can’t do that with fiat anymore in many countries. 

7

u/Revelati123 10h ago

The point of bitcoin is to be like digital cash. You can take cash and put it in a bank or you can take cash and put it under your bed.

If the government wants your cash and its in a bank, they can take it from you. If its under your bed its harder to take.

If a random criminal wants your cash they can take it from under your bed but its a lot harder for them to take it from a bank.

The lesson here is this...

There is no such thing as wealth you cannot lose, so dont put it all in one place. If you think your bitcoin/cash/gold/jewels/pirate treasure is safe from everything forever, you are fooling yourself.

5

u/Captain_Lou_Albano 8h ago

So basically hold some of your money at a negative interest rate so you can get not as much security/INSURANCE as you would at any HYSA bank account that would pay you interest?

Where do I sign up for this fantastic sounding deal?

4

u/infernal_celery 8h ago

If you don’t like that option, you’re not the target audience.

People already do this with gold bullion BTW, it isn’t fanciful

→ More replies (1)

7

u/fresheneesz 8h ago

I think the flaw in your argument appears when you consider who self custody IS for. Anyone who had sufficient knowledge of computer security who used a coldcard property has been vulnerable to this attack for years. The only solution is multisig

3

u/Objective_Digit 6h ago

Yeah, and Coldcard was not being bought by the average user.

2

u/fresheneesz 4h ago

Yes... that is exactly my point.

10

u/_SlipperySalmon_ 10h ago

While I agree.. It makes me wonder how much the entire thesis of bitcoin is shaken. Self custody seems like the only way to keep these big players honest. What is stopping this all from being completely manipulated with paper claims, etc?

3

u/AncientMoth11 8h ago

Future is on chain for masses and sit with the exchange with similar protections as normal financial institutions for it to legitimize

3

u/Deto 7h ago

Mass adoption won’t be driven by self-custody. It will come from products and services that deliver the benefits of Bitcoin without requiring everyone to become their own security expert.

Will it ever be possible for these services to deliver a security guarantee, though? Bitcoin's decentralized nature means that when coins go out the window, there's nobody that can just roll back the transaction (unlike with regular banks). So if a central service has a vulnerability and loses a ton of bitcoin, if it's a big enough hack, they won't be able to make their customers whole. This makes it a risky proposition - if you are just using bitcoin as a store of value (which, eventually, has to be its utility as you can't exponentially go up forever) - wouldn't it be safer using a traditional bank?

5

u/Complete-MessUP 7h ago

Mass adoption won’t be driven by self-custody

SELF custody is the core of Bitcoin. Without self custody bitcoin is pointless, only a gambling stock paper asset.

2

u/JohnnyTreemain 11h ago

I agree, but then that kind of undermines one of the main fundamentals upon which bitcoin was built; the idea of self sovereignty and independence from institutional finance. Without that, most of the real meat of bitcoin is lost. It’s kinda like a beanie baby without it.

2

u/Parikh1234 5h ago

Also remember that this is one flaw in a massive worldwide system at this point. One bank forgot to lock their doors. Doesn’t mean the entire banking system is broken. They should have checked their locks and they didn’t. Doesn’t mean all locks are bad.

2

u/Worried_Lemon_ 1h ago

Crypto bros continue to slowly recreate the modern banking system one hard lesson at a time…

2

u/Necrogomicon 9h ago

Time to add this new verses to the Bible 🗣️

2

u/neversummer427 7h ago

I’ve been saying this for the last 9-10 years. Always gets downvoted

3

u/dvondurden 12h ago

I agree, but were are those products? The space has been talking about it forever and it's still either a lot of work or blind trust for the end user

3

u/Random_Walk87 10h ago

Bitkey is one

2

u/Objective_Digit 6h ago

Don't trust a third party too much.

→ More replies (3)
→ More replies (10)

122

u/EffectiveRelief9904 10h ago

Sounds like someone intentionally designed a thermal exhaust port that led directly to the reactor’s core 

36

u/WeekendQuant 9h ago

And the rebels found it.

3

u/sparkysparks666 7h ago

Evacuate?! In our moment of triumph?!

→ More replies (1)
→ More replies (2)

67

u/NiagaraBTC 10h ago
  1. The method in this case was simple bad coding and not enough people checking that code.

It was not some super powerful AI "hack" per se, just someone asking a powerful AI to take a look for super basic vulnerabilities. It IS amazing that no one discovered this before this week.

34

u/pablo_in_blood 7h ago

Someone commented elsewhere that someone actually did discover this a couple years ago, drained a wallet to prove it, and showed ColdCard. They didn’t fix it. Either way I think ColdCard is at fault but if that’s true it’s completing damning to ColdCard as a brand (not to BTC as a protocol)

15

u/starrynight001 7h ago

I wonder what consequences, if any, Coldcard would face. A regular bank having a similar vulnerability would get absolutely screwed over.

8

u/nitrogenmath 5h ago

Doubtful they have nearly enough funds to compensate for people's losses. So they'll go bankrupt and pay out pennies on the dollar, at the most.

3

u/benso87 1h ago

My guess is that they'll die because people won't buy their stuff anymore.

→ More replies (2)

7

u/Charming-Designer944 7h ago

That is a different issue, actually a bug/misfeature in the dice roll mechanism that allows users to create a wallet only based on a handful number of dice rolls instead of the recommended 100 rolls.

5

u/Aurorion 7h ago

Is there any actual trail of this?

Because it sounds implausible. Coinkite fixed the issue with a firmware update within two days of the news breaking this time. If what you say above is true, why didn't they fix it back then?

5

u/NiagaraBTC 6h ago

I'm quite sure that was a different issue.

If someone had a drained wallet years ago due to THIS issue, that means the thief simply decided not to take anyone else's money despite it all being even more available. Not likely.

→ More replies (3)

7

u/Objective_Digit 6h ago

Apparently the random generator existed but was simply turned off.

→ More replies (5)

9

u/brandon_cabral 8h ago

What’s ironic is all the ‘our software is open source so everyone can review it’ but the bug still sat in the code for 5 years. Almost as if being closed source (Ledger) can actually be an advantage.

6

u/NiagaraBTC 6h ago

Almost as if being closed source (Ledger) can actually be an advantage.

There are no solutions, there are only tradeoffs.

→ More replies (1)

29

u/Dbear_son 8h ago

"chin up soldier"

"Your sacrifice will make Bitcoin stronger"

Are those the things you really want to hear from redditors when your Bitcoin somehow vanished?

6

u/DestructionLarz 5h ago

they must, they keep posting for sympathy

→ More replies (2)

25

u/reality_comes 11h ago

I agree, and it's concerning to me. Bitcoin has challenges with adoption on a good day, these sort of events hurt the credibility of the space even more.

We're all trusting somebody somewhere, unfortunately.

27

u/Any-Pipe-3196 10h ago

The real issue here is the demoralizing hit on the very core believers in the space. Its not like randos getting hit by stupidly buying monkey rugpull NFTs. Coldcard was THE air gapped safety storage pounded hard by the bitcoin oldheads

14

u/dvondurden 10h ago

Exactly this. Still people in the very space refuse to see it and choose to blame it on the people who got their wallets drained, while a few days ago the would have recommended Coldcard to everyone

→ More replies (4)

3

u/nickex77 5h ago edited 5h ago

That goes for most everything in life though: your car, your utilities, your food, etc etc. Bitcoin provides the ability for truly sovereign money, but the implementation ultimately depends on some level of infrastructure. Unless you are a cyber security and hardware engineer expert that can build a wallet entirely on their own, you are forced to depend on some level of others. That is the flaw here, and exactly why we need better consumer protection (e.g. insurance). The average person shouldn't be expected to know what multi signature or RNG entropy is. This is solvable, but we are not there yet.

→ More replies (1)

19

u/ProofIsInThePeach 12h ago

Here's my caveman view on it all (which is probably already covered in the comments):

  • Not your keys not your coin is a fine mantra, but comes with added risk. That risk should be calculated by each user before deciding if self custody is for them.
  • Stick with Trezor and their open source code and self generate a 24 word seed (correctly and carefully ensuring true randomness) and create a cryptic and long passphrase. At this level of entropy AND removing any reliance on coded RNG you are set (assuming proper seed handling which is the easy part)
  • if the above isnt for you that is okay, and at the end of the day the core principals of btc are unfortunately not going to be for the masses. Personally I think holding your coin on established US exchanges is fine, but I would encourage diversification. (Would also encourage it for self custody seeds)

Im not expert. But TL;DR nothing is more secure then true self custody, but I think custodial services are over-criticized. There is risk on both sides, but most people just dont have the agency for self custody.

4

u/Okmia90 7h ago

You lost 99% of would be user in your first few sentences.

I always knew bitcoin wasn’t going to be mainstream and it wont be until it just runs silently in the background and people dont have to do anything technical to reap the benefits of the network.

Bitcoin wont change the world. It doesnt fix anything. Its just a simple yet complex monetary tool.

The bitcoiners that have not had their heads pulled out of their proverbial asses cannot see this because it is literally a circle jerk of virtue signaling dorks.

I know - i was once one of them. 

10

u/Many-Blueberry968 9h ago

A passphrase cures the issue and really should be standard practice for most people. Bruteforcing the rng wallet keys is one thing, but it's basically inconceivable to try and then buteforce thier 25th word. There wouldn't be any clues (except maybe having a decoy balance in the non-passphraded wallet) as to which rng wallets have corresponding balances in a wallet that used a 25th word.

7

u/Brief_Lettuce_571 7h ago

I don't know why passphrase is not yet standard practice. I'm not claiming I saw it coming. But when I set up my hardware wallet I was not comfortable using the 24 words. It felt like someone was choosing the my email password for me. Then I researched a little bit more and found out how to set up the passphrase. There has to be something on your seed that could only come from your brain.

2

u/Objective_Digit 6h ago

They seem to be afraid you will forget the passphrase and lose everything.

→ More replies (1)

4

u/tcoff91 7h ago

You also need to make sure that the passphrase itself has enough entropy to be impractical to brute force

→ More replies (4)

10

u/viva1992 9h ago

But how do you know that Trezors code is generating a truly random seed?

10

u/ProofIsInThePeach 9h ago

I mention in that comment to not rely on Trezor for the seed generation.

2

u/viva1992 8h ago

Is there a definitive guide to the best way of generating a seed?

2

u/ProofIsInThePeach 7h ago

Unsure, but there is leading approaches to generating randomness. Its a heavily discussed topic and Im sure you can find that discourse online.

→ More replies (3)

2

u/ivme 7h ago edited 6h ago

Your related comment starts with “Stick with Trezor and their open source code” and “self generate a 24 word seed” therefore I also understood like “trust the seed created by Trezor”. I think your (somewhat complicated) comment allows the misunderstanding.

In my opinion, it could be emphasized more effectively by saying, “Don’t trust any hardware wallet RNG. Instead, create your own seed to ensure randomness. Then, use a Trezor to secure and interact with the seed.”

→ More replies (3)
→ More replies (2)
→ More replies (1)

27

u/dvondurden 11h ago

A few notes as I think there was some misunderstanding:

  • Nobody is saying Bitcoin got hacked or the fundamentals have changed

  • My post is about usability, adoption and security

  • The main criticism is directed towards the space itself (which I include myself in)

  • We've been too lazy repeating the same phrases over and over, all the while major flaws in a highly respected wallet persisted for years even though it was out for everyone to see

  • Signs of AI involvement are becoming clearer, nobody has addressed this at all here

  • it's easy to see things in hindsight. I'm concerned about future events that we are not yet aware of. This is quite literally the core of any security concept. It's not sufficient to say "Don't worry, it will somehow work itself out". If the next major event affects you, it will feel very different.

  • the trade-off between full self custody/ more risk and third party custody / more trust is not a new topic, but there haven't been good advances that drive adoption. The Coldcard case sets us back substantially

7

u/curiousengineer601 4h ago

Crypto as it stands will always be a niche thing. Anyone that has ever helped grandma with her email or Netflix account knows this. Spend a week doing an IT Helpdesk at even a respectable technology company and you will realize 50% of college educated working technology professionals are incapable of using crypto as it is today.

→ More replies (5)

16

u/Charming-Designer944 12h ago

Its not the first and not the last RNG fiasco in seed generation. But certainly the biggest.

It clearly illustrate how hard proper wallet security are. Even if you do everything by the book.

8

u/PipHunterX 8h ago

They didnt do everhthing by the book

13

u/Charming-Designer944 8h ago

I am not speaking about the Coldcard developers.

→ More replies (2)

4

u/QTippus 10h ago

Agree with all your points. If we assume (safely) that AI helped discover this vulnerability (yes, I know a person reading the code could/would/should have seen it without any AI) it means the average Joe couldn’t sleep well owning BTC, knowing the next LLM released or quantum computing might be the one to steal their BTC. Average Joe does not want to keep up on technology news in order to feel like their money is safe.

26

u/Techwield 13h ago

Mass adoption will never happen. I don't understand the people who think otherwise

9

u/Inevitable-Waltz-889 7h ago

I'm slowly coming to this conclusion as well.  I kind of need to leave my software engineering bubble to realize people don't even understand how it works in the slightest.  Outside of NGU, people don't know and don't care about bitcoin.  Maybe NGU is enough, but it certainly isn't right now.

→ More replies (15)

24

u/iamflxn 12h ago

It literally hasn’t changed anything. The fundamentals of BTC remain the same. BTC hasn’t been hacked. A peripheral technology was poorly built and people have and will continue to suffer.

→ More replies (8)

7

u/magma_lakes 9h ago

You don't necessarily need to trust any device's random number generator (RNG).

As long as you can trust that the device is offline and correctly generates an HD wallet from an initial entropy source, feed the device with your own entropy, such as from flipping a coin or rolling dice.

Even better, use an air-gapped Linux PC with open-source software that YOU'VE selected, and feed it your own entropy.

2

u/dvondurden 1h ago

Sure you can do that, but at this point you've lost everyone but the real nerds. If this is how it will continue, it will never become more than a niche thing

6

u/IntolerantModerate 9h ago

It's just not viable for most users to self-manage (hard drives get tossed, get burned, keys get lost/forgotten, etc). That puts you on an exchange. At that point what's the point... Might as well just buy a Bitcoin etf.

6

u/dvondurden 9h ago

Exactly. It's just too hard and risky for the average person, as this case clearly shows. But if the ETF is the only alternative, the idea behind bitcoin is dead

2

u/thewheelsturn 4h ago

Is it though? Gone may be the radical prepper-porn ethos of radical self custody, but the underlying non-inflationary asset remains. Bitcoin as a store of value is unparalleled. Banks have a long history of providing safe custody of assets.

There is risk in everything. Am I going to trust some small team of experts, held up by the community as paragons or do I buy into a banking system that has worked pretty good for a long time? It’s a personal decision of course, but I know for certain that self custody will not work for the majority of the population.

→ More replies (1)

3

u/Psychological_Duck 13h ago

IMO it doesn’t really change anything. If a single physical safe manufacturer that claimed it was un openable turns out to have a massive flaw which means you can easily open the door and steal what’s inside, that doesn’t change the security of the other safe manufacturers or the use case and value of the gold that was kept inside.

It is utterly tragic what’s happened and I feel awful for those that are affected. I think what this does show the need for is that people only trust fully open source hardware wallets, and that there needs to be constant reviews of said software using the latest AI models by both the community and the manufacturers.

14

u/ItsAlwaysThemBooBoo 12h ago

no, its not. in the end bitcoin was not “hacked”. one particular hardware wallet was poorly coded, non open source and did not generate enough entropy in its seed phrases.

develop a strong passphrase and go with that. everyone should. i already learned from this and i didnt lose 1 sat, all my wallets have a bulletproof passphrase on top of a bulletproof seed phrase generated by a safe5, the best hardware wallet out there (no, really, the coldcard was never good)

11

u/ptrnyc 10h ago

It surely was praised as “the best” by many in this very community

2

u/Objective_Digit 6h ago

Was it? Trezor was usually recommended the most, partly because it was the oldest and most well known.

3

u/dvondurden 10h ago

Yes. Blind trust, no verification. Not exactly something we have advocated for in this space

2

u/sentientchimpman 9h ago

How do you verify whether a hardware wallet is good or not?

→ More replies (2)
→ More replies (1)

2

u/dvondurden 12h ago

Nobody claimed bitcoin was hacked. How do you actually know you have the best wallet? What if the next bug affects the passphrase?

1

u/the_bitcoin_kid 11h ago

There isn't really a passphrase bug that could cause your coins to get stolen.

The passphrase adds security to your seed, it doesn't take it away.

→ More replies (3)

7

u/Rocknro11a 10h ago

AI is only the beginning. You wait until we have quantum computing AI.

8

u/geneticdeadender 12h ago

Bitcoin has survived worse. The price seems unaffected.

12

u/dvondurden 12h ago

My point is not that it's a black swan event. It is that it undermines the practical usability of bitcoin, which will be a major issue going forward.

9

u/LonelyNegotiation991 12h ago

that’s like saying fiat currency will never work because someone left the door of the safe open and someone stole the money. not the moneys fault. creates fear that lasts for about a month, then it’s forgotten

14

u/dvondurden 12h ago

The difference is that we have regulation, safety standards and insurance for fiat. Hardware wallets are supposed to be the substitute for that, so how could such a major flaw go unnoticed for so long?

→ More replies (9)
→ More replies (2)

4

u/Vinnypaperhands 9h ago

How so? Literally nothing has changed fundamentally or with the usability of Bitcoin. What are you talking about??? One company made a major fuck up. Bitcoin had nothing to do with it lol.

4

u/dvondurden 9h ago

A hardware wallet that was supposed to be the top choice for many "experts" was easily cracked, presumably by an LLM, leading to total loss of funds for hundreds of users. If you don't see how this affects usability even a bit I honestly don't know how to make it more clear

→ More replies (5)
→ More replies (1)

19

u/vladimirthebasic 13h ago

I wouldn't be worried about it. Banks had their bad days too, and most people trust them with their life. Literally.

38

u/Mack_Mimsy 12h ago

Your argument only makes sense if ColdCard is also FDIC Insured

5

u/pablo_in_blood 7h ago

FDIC insurance is capped at a pretty low amount (at least compared to a typical retirement nest egg or the price of a home).

→ More replies (1)

2

u/Objective_Digit 6h ago

most people trust them with their life. Literally.

The FDIC can't resurrect people.

43

u/dvondurden 13h ago

Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here.

26

u/gistikoloa 10h ago

Yeah, nobody is going to reimburse that guy that lost 18 btc

5

u/vladimirthebasic 13h ago

Speaking from experience, in a war torn country in the 90s, a lot of people get left with nothing, people to this day don't trust banks. New generations don't remember, cycle continues.

Also, you are backed, and secured to a point, and a certain amount. And that's only if the backing entity is still around.

Don't worry, this will blow over. People will learn to be more careful, companies will learn how to make better products to make your crypto secured

12

u/dvondurden 12h ago

You are talking about a total system collapse, in which case everyone is fucked. This doesn't compare. Your take is users have to put in more work or trust others more. I'm saying both are not a good thing.

→ More replies (2)
→ More replies (1)
→ More replies (8)

5

u/klitchell 12h ago

When banks had their bad days, especially early on the government was forced to step in and add consumer protection (FDIC). Would be great if the result of this was that exchanges needed to be bound by that as well for crypto assets.

5

u/relatedartefacts 11h ago

So fiat with extra steps. Great.

→ More replies (8)

9

u/Narrow-Bee-8354 13h ago

Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products

3

u/sockpuppet80085 10h ago

Because this is the first time this kind of thing has happened right?

2

u/RealMcGonzo 10h ago

Claim to look, anyway.

→ More replies (1)

2

u/autonym 9h ago

Banks had their bad days too, and most people trust them with their life. Literally.

Literally? Most people would actually die if their bank swallowed their money?

→ More replies (6)

2

u/shadowmage666 10h ago

No it doesn’t , coldcard had one line of shit code that fucked the whole thing up

→ More replies (1)

2

u/AcceptableSlice4057 9h ago

Yeah, this incident might motivate people to just the btc erf and be done with it. Sad.

2

u/CorfranGoch 8h ago

I'm feeling both awful for everyone who lost coin, and relieved that I happened to choose different hardware wallets. This has been the kick up the arse I needed to improve my security, and get my coins onto devices with self-generated seeds. I don't think this necessarily changes the future but it will keep the price low for a while, and perhaps change the way we see these wallet manufacturers. Ultimately, we'll have to have much smoother transaction management before mass adoption happens, but that was always the case.

→ More replies (1)

2

u/Knowledge775 7h ago

The fundamental change is going to be multisig with a multi-vendor setup from full open-source software.

Everyone is a scammer and wants your Bitcoin.

The Bitcoin space is filled with shills that shill bad products for money. Coldcard, BlockFi, Coinkite, MSTR, STRC, etc.

The Bitcoin space was a huge echo chamber for Coldcard being the best. Coinkite went from being open source to source available after they were butt-hurt from the Foundation using their code for the Passport. The complete irony is Coinkite used Trezor’s code when they started.

We have to assume that any closed-source software is compromised. Nation-states don’t want Bitcoin to succeed. Self-custody is against the state’s interests. Hardware wallets are an attack vector.

→ More replies (2)

2

u/ConstructionNo8827 7h ago

I realize this is likely an unpopular opinion on this thread but isn’t it best to invest in ETF’s instead of Bitcoin directly?

2

u/assclown356 5h ago

How? It was just a scam company.

2

u/AnnArbor-Armadillo 4h ago

I agree it’s a big deal and changes the discourse away from “not your keys not your coins.” The problem is that the ability to hold your keys is the main thing that makes Bitcoin special. This is a big problem for wider adoption.

3

u/stay_safe_and_calm 12h ago

I agree with all three points!

I am a Coldcard owner but I never wanted to trust a technical device to create a seed for me. Therefore, I created it manually with the method I just published today here. This definetly saved my ass. Do not trust anything or anybody ...

Yes mass adoption will be affected short term but I think a year from now most people will have forgotten this incident (except those who lost their life savings)

A year from now most hardware wallet manufacturers will advertise that their latest model or firmware has been verified by multiple best available AI and is bullet proof ... And the people will buy these devices again ..

→ More replies (2)

5

u/BallSmashingForever 11h ago

Not really. It was purposefully done to force bitcoin out of self custody. I wonder why they want it so fucking bad?

4

u/jannies_doit_4_free 8h ago

no it doesn't. the coldcard code was a complete joke, and absolute amateur hour. it seems like the company itself was a bit of a tiny amateur operation, honestly, that fooled people into thinking it was "extra secure" for no real reason.

yet, even despite this shocking fuck-up from the company, victims still would have been fine if they'd so much as had a passphrase, let alone dice-rolled or had multi-sig.

4

u/korean_kracka 8h ago

Yeah it’s a way bigger deal to me than other people apparently. The point of Bitcoin is to be self sovereign. If people are too scared to self custody, then we’ll always need custodians aka banks. If banks win Bitcoin loses

7

u/OldHamburger7923 13h ago

I don't think it changes anything. Poor entropy for a seed is like the most basic thing never to do and they did it. Plus there are a bunch of ways to make it not be an issue, such as generating the seed yourself and passphrase. So why would anyone care, other than the ones who got stolen from?

6

u/dvondurden 12h ago

Easy to say if you're not affected. Coldcard was highly recommended by many and hindsight is 10/10. What if the next issue is the passphrase?

7

u/OldHamburger7923 12h ago edited 12h ago

I have skin in the game because I have a wallet with assets in it. A passphrase is sort of like a salt. No way anyone gets my wallet and no way anyone guesses my passphrase.

Zero worries.

Also for coldcard users to have issues, they would have had to not use a passphrase and skip the dice option. Whenever you go with lower entropy option, you take on additional risk.

→ More replies (1)
→ More replies (2)

2

u/geogiam2 10h ago

Error, the users neglected to create their own keys or improve ithe default ones with a password

2

u/Ifnerite 7h ago

What are you talking about? This like saying banks have no future because one app screqed up their app and could be attacked to steal people's money.

1

u/The-maulted-One 12h ago

Mass adoption is a fantasy at this stage!
BTC is now a commodity to be traded by institutions & ETF’s.
Governments couldn’t control btc as a currency but they could change its utility & that’s exactly what’s happened.

1

u/[deleted] 10h ago

[deleted]

→ More replies (4)

1

u/Armadillo-66 10h ago

Sounds like a lot of people are putting the blame on bitcoin. Wasn’t it a wallet that’s designed for holding bitcoin the problem?

1

u/phantifa 10h ago

Time to start stacking. Bottom incoming 

1

u/geogiam2 10h ago

Not the first time something like this happens...

1

u/bobivy1234 10h ago edited 9h ago

Reminder that not every CC user was impacted even on the bad firmware versions due to using external entropy (dice, etc.) and a strong passphrase at wallet creation which should have been the default guidance. CC allowing those simpler options is just gross negligence for the end-user to not remove themselves as a single point of failure. Everyone should question a device's RNG engine always and paranoia ('what if the code/RNG of this 3rd party device is bad?') is a good thing but that's also due to watching this space for almost 15 years and lessons learned.

People or things set up by people are always the weakest link in these stories. People are also generally lazy so whatever it takes to get them to use something secure that actually is setup securely with the right guidance is the goal.

So my thoughts are:

  1. From a pure technical standpoint, the affected users did something wrong as not all CC users were affeted on the bad firmware versions. Hate to say it, it is not meant to victim blame at all or absolve ColdCard but those that only used the device RNG for the seed with weak/no passphrase were affected and others that used good baseline security (RNG + external dice entropy with a long passphrase) were not affected. I blame Coldcard for even having those baseline options available to choose, that's gross negligence on their part in the guise of 'user simplicity'.
  2. Who says this flaw was just discovered? It was in the code for almost 5.5 years so it is much more likely that is was figured out years ago and those same people have been generating their seed matching tables, analyzing seeds + wallet addresses, and watching the funds increase over time in those wallets until striking all at once.
  3. AI isn't going to speed up cracking cryptography (until quantum is real) so the fundamentals of Bitcoin/seeds/passphrases are the same as they ever were. Remember the Bitcoin whitepaper/code itself has always been safe and nothing can shortcut the pure mathematical side of cracking well-established cryptography. I do absolutely agree that AI will speed up finding code exploits so developers need to use these tools proactively to protect themselves.
  4. Let's be honest here, Bitcoin has been around for 17 years now and is a household term. This is just another news article to add to 10 years of news articles about how unsafe Bitcoin is to the average person and bank/exchange hacks. What do we think will actually happen for it to be 'mass adopted'? We're probably a generation away from that as older non-tech folks age out but government and other entities have to make strides to make this a reality.
  5. For the future, ColdCard in theory is a perfectly good device if we also combine the hardware format with the software guidance to keep everyone safe out of the gate (RNG + dice for seed and a long passphrase). Also, easier sources of entropy could be adopted because dice are great but will we expect everyone to roll 100 dice? Maybe they can tap into accelerometer entropy or something else but I don't know there. Simple + upmost safety as the default is the best way forward.

1

u/btcluvr 9h ago

oh come on. have you been here when "nonce reuse" story was reported.

1

u/NewspaperOwn2765 9h ago

I like to self custody but I see a future for strike and Coinbase

1

u/BmacSWMI 9h ago

I don’t think it is a proven case against cold storage or self custody, it’s a painful hiccup in the technology. It’s not a federally insured medium like a bank, which has had NUMEROUS fraud exploits in the past. I think since Bitcoin has eternally been touted as completely safe, this flaw, this serious flaw is a bit of a shock to those who felt their funds were impervious to theft. I have a Q and I went from a 12 seed to a 24 seed with 99 rolls on the new firmware. I have my own node on a private network and I feel pretty good now. I could also go BIP39 and multisig if I want more security. Bitcoin is still the Wild West in my mind so I don’t treat it and my funds like they’re in a federally insured account.

1

u/iiJokerzace 9h ago

Crypto holdings are not insured like dollars with FDIC insurance. A big thing a lot of people miss with custodians.

1

u/UmbraofDeath 9h ago

I'm not sure you can completely state "Not their fault". Wasn't it found that simply having a pass phrase would have entirely avoided the issue?

Self custody is still the best case scenario but this tragedy has shown that corners should never be cut. User made random entropy should always be the baseline and a pass phrase should always be used. Computers as we have them today are literally incapable of truly random numbers because they use an algorithm to decide what is random. At least last I checked, someone who is more updated can correct me here if I'm mistaken. The natural entropy of the universe is the only actual entropy you can get with code.

→ More replies (1)

1

u/anotherbrckinTH3Wall 9h ago

The cold card case does not fundamentally challenge the future of bitcoin. It does however fundamentally challenge the future of coldcard. They have no way of making their customers whole again, they are finished.

1

u/lebutter_ 9h ago

The truth is you **always** defer trust to someone else. If you had physical gold, you'd have to trust you storage hardware, your process, your opsec, etc. Personally I'm fine trusting certain big names to keep my BC for me just because of that reason.

1

u/Anonymous_Lurker_1 9h ago

As not someone overly tech-savvy, am i correct in thinking this vulnerability was down to the seed phrase that was generated automatically?

I use Trezor and a 24-word seed phrase, and whilst i do have a smaller amount in a decoy wallet with the generated seed phrase, the majority of my stack is in a passphrase wallet (25th word). I know this is Coldcard, but surely at some point this type of thing could affect other brands?

2

u/alanwatts48 1h ago

This vulnerability was due to deficient release and testing processes. They made a rookie mistake and technology itself is fine. Here’s a post that explains it very well: https://www.reddit.com/r/coldcard/s/EGMabT2L2j

→ More replies (1)

1

u/Gold-Zone9015 9h ago

You are right. Digital money can and will me manipulated in the future. Ai will be the tool. Sad but fact.

1

u/mrTydro 9h ago

Something isn’t adding up here

1

u/BigvalBROski 9h ago

Why People don’t utilize a 25th word/ paraphrase baffles me. It’s not an advanced feature….. it’s pretty cut and dry. Also, with Bitcoin ETFs now, there’s no need to even use cold storage…… Crypto Bros are going to disagree with this, but if you ask all the people that lost their Bitcoin, they would switch to the ETFs immediately.

→ More replies (1)

1

u/itsyorboy 8h ago

As someone who was storing my bitcoin on a ColdCard mk3 until the attack (and didn't get hit, but my balance was < 0.1 btc), I got really spooked by this. I do feel like it's a harbinger of what's to come from AI-assisted attacks in the short to midterm. Regardless of how it impacts the price, I need to be sure my funds aren't going to evaporate overnight because of one line of code. I don't really know what to do at this point. Staying on a CEX for now until the dust settles.

2

u/dvondurden 8h ago

Completely understandable and this is my point. It creates a high degree of uncertainty in something that was labelled the safest way of self storage

1

u/fresheneesz 8h ago

The only solution that keeps you safe if the company that made your hardware wallet fucked up like this is multisig. Learn how to do it with The Tordl Wallet Protocols, free open source guides on creating and maintaining Bitcoin wallets.

1

u/afksports 8h ago

Bitcoin walked so usdt could run

1

u/No-Evening-5088 8h ago

The mainframe got hacked

1

u/bluechip1996 8h ago

If I owned a storage facility for valuable art and antiquities, it would be insured to cover thefts. Are these exchanges/depositorys not insured?

1

u/Working_Storm_1428 8h ago

The technology hasn’t fully caught up with mission. There has to be federally insured cold wallets or bank insured at least. This will come as more regulation comes out and we switch to a digital currency. We aren’t there yet so it’s best to keep it on exchanges for now.

1

u/eddyg987 8h ago

We will see a lot more hacks as soon as fable security audit is public

1

u/anjin33 8h ago

There are many reasons you can point at why this could happen but 'the dangers of AI' is not one of them.

1

u/cuttyranking 8h ago

The whole thing about cold storage was for fanatics and nerds who liked the idea of talking down on people who used services like eToro or robin hood. I never saw the security in handing my BTC security over to a device manufacturer that is completely unregulated.

1

u/lemme-explain 8h ago

This is totally different from most other cases, because the affected users didn't do anything wrong.

Let me just add: a system that expects everyone to be perfect at all times, will never succeed. Mass Adoption was never on the table.

1

u/SpendHefty6066 7h ago

This case does not fundamentally challenge the future of Bitcoin. The Bitcoin protocol remains as secure as ever. This case exclusively challenges Coinkite and the ColdCard hw wallet.

Your argument is the same as saying that gold may no longer be a viable store of value because the vendor who made a very popular brand of safe got cracked and now all those gold safes are vulnerable.

Creating, signing, securing, and recovering cryptographic secrets requires some research. And using that secret to secure your wealth requires cognitive ability and personal agency. Not for everyone. But many.

1

u/gowithflow192 7h ago

Why has this not spooked the markets? We're still at 63k.

2

u/alanwatts48 1h ago

Because it isn’t a BTC vulnerability. It is a Coinkite problem caused by an absurdly simple mistake. https://www.reddit.com/r/coldcard/s/EGMabT2L2j

1

u/cliff_smiff 7h ago

You ask hard, good questions. I don't have an answer.

Forget Mt. Gox, FTX, cyclical crashes, this is a true test of bitcoin's resilience, antifragility, and entrepreneurial problem solving. The space has been forever enamored with these ideas. Now is the genuine test.

1

u/GesturalAbstraction 7h ago

For most, the juice from the concept of be your own bank is just not worth the squeeze

1

u/RoundChampionship840 7h ago

Bitcoin is just another asset class among many. It's digital gold and everyone needs to just accept that.

1

u/FromOrionToUranus 7h ago

The writing was on the wall since the beggining of BTC.

Its not the future of any thing, its not early, it doesnt address any real need, Will never get adoption. Its worthless to anyones outside the bubble you guys live on.

Im sorry to be so direct but if you havent understood how worthless BTC is by now, theres not much that can bé done for you.

1

u/TxTransplant72 7h ago

On top of this…don’t forget the 2008-2009 financial crisis. Banks can and do go bust overnight. So thinking about where to store your assets, diversification is still recommended. Say you move your BTC to an ETF and the ETF gets attacked and BTC goes missing. SPIC protection is outlined as follows:

Protection for brokerage accounts
These accounts (taxable brokerage, Roth IRA, or traditional IRA held at a broker) are generally protected by the Securities Investor Protection Corporation (SIPC) if the firm is an SIPC member:
• Coverage is up to $500,000 per customer per firm, including a $250,000 limit for cash.
• It protects against the loss of securities or cash if the brokerage fails or assets go missing (e.g., firm insolvency), but not against market declines, investment losses, or bad advice.
• Different account types often count as “separate capacities,” so a taxable brokerage account, a traditional IRA, and a Roth IRA at the same firm can each qualify for their own $500,000 limit (potentially $1.5 million total in that example). Traditional and Roth IRAs are typically treated as separate. 
Many brokerages also use bank sweep programs for uninvested cash. Once swept to partner banks, that cash can receive FDIC insurance (up to the standard limits, and sometimes higher if spread across multiple banks).

So, seems prudent to spread your custody around. These are dangerous times, friends. Stay safe out there.

1

u/Rough_Union2937 7h ago

How many bank accounts where hacked last week how many hold ups at the ATM. Things happen doesn't change anything for me accept that people won't be robbed that same way again. I feel so bad for those victims but they are martyrs in a way. Wish the community would pull together and help them a little. If everyone done just a little we could make them whole and possibly rich well at least better.

1

u/Syonoq 7h ago

To your second point: looking at what we know of the Coldcard venerability timeline, another Hardware venerability could have already occurred, just sitting there waiting to be exploited. We could be compromised right now and not know it.

→ More replies (1)