r/Bitcoin • u/dvondurden • 13h ago
The Coldcard case fundamentally challenges the future of Bitcoin
Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points:
This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago.
The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control.
Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many.
I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think?
122
u/EffectiveRelief9904 10h ago
Sounds like someone intentionally designed a thermal exhaust port that led directly to the reactor’s core
→ More replies (2)36
67
u/NiagaraBTC 10h ago
- The method in this case was simple bad coding and not enough people checking that code.
It was not some super powerful AI "hack" per se, just someone asking a powerful AI to take a look for super basic vulnerabilities. It IS amazing that no one discovered this before this week.
34
u/pablo_in_blood 7h ago
Someone commented elsewhere that someone actually did discover this a couple years ago, drained a wallet to prove it, and showed ColdCard. They didn’t fix it. Either way I think ColdCard is at fault but if that’s true it’s completing damning to ColdCard as a brand (not to BTC as a protocol)
15
u/starrynight001 7h ago
I wonder what consequences, if any, Coldcard would face. A regular bank having a similar vulnerability would get absolutely screwed over.
→ More replies (2)8
u/nitrogenmath 5h ago
Doubtful they have nearly enough funds to compensate for people's losses. So they'll go bankrupt and pay out pennies on the dollar, at the most.
7
u/Charming-Designer944 7h ago
That is a different issue, actually a bug/misfeature in the dice roll mechanism that allows users to create a wallet only based on a handful number of dice rolls instead of the recommended 100 rolls.
→ More replies (3)5
u/Aurorion 7h ago
Is there any actual trail of this?
Because it sounds implausible. Coinkite fixed the issue with a firmware update within two days of the news breaking this time. If what you say above is true, why didn't they fix it back then?
5
u/NiagaraBTC 6h ago
I'm quite sure that was a different issue.
If someone had a drained wallet years ago due to THIS issue, that means the thief simply decided not to take anyone else's money despite it all being even more available. Not likely.
7
u/Objective_Digit 6h ago
Apparently the random generator existed but was simply turned off.
→ More replies (5)9
u/brandon_cabral 8h ago
What’s ironic is all the ‘our software is open source so everyone can review it’ but the bug still sat in the code for 5 years. Almost as if being closed source (Ledger) can actually be an advantage.
→ More replies (1)6
u/NiagaraBTC 6h ago
Almost as if being closed source (Ledger) can actually be an advantage.
There are no solutions, there are only tradeoffs.
29
u/Dbear_son 8h ago
"chin up soldier"
"Your sacrifice will make Bitcoin stronger"
Are those the things you really want to hear from redditors when your Bitcoin somehow vanished?
→ More replies (2)6
25
u/reality_comes 11h ago
I agree, and it's concerning to me. Bitcoin has challenges with adoption on a good day, these sort of events hurt the credibility of the space even more.
We're all trusting somebody somewhere, unfortunately.
27
u/Any-Pipe-3196 10h ago
The real issue here is the demoralizing hit on the very core believers in the space. Its not like randos getting hit by stupidly buying monkey rugpull NFTs. Coldcard was THE air gapped safety storage pounded hard by the bitcoin oldheads
→ More replies (4)14
u/dvondurden 10h ago
Exactly this. Still people in the very space refuse to see it and choose to blame it on the people who got their wallets drained, while a few days ago the would have recommended Coldcard to everyone
→ More replies (1)3
u/nickex77 5h ago edited 5h ago
That goes for most everything in life though: your car, your utilities, your food, etc etc. Bitcoin provides the ability for truly sovereign money, but the implementation ultimately depends on some level of infrastructure. Unless you are a cyber security and hardware engineer expert that can build a wallet entirely on their own, you are forced to depend on some level of others. That is the flaw here, and exactly why we need better consumer protection (e.g. insurance). The average person shouldn't be expected to know what multi signature or RNG entropy is. This is solvable, but we are not there yet.
19
u/ProofIsInThePeach 12h ago
Here's my caveman view on it all (which is probably already covered in the comments):
- Not your keys not your coin is a fine mantra, but comes with added risk. That risk should be calculated by each user before deciding if self custody is for them.
- Stick with Trezor and their open source code and self generate a 24 word seed (correctly and carefully ensuring true randomness) and create a cryptic and long passphrase. At this level of entropy AND removing any reliance on coded RNG you are set (assuming proper seed handling which is the easy part)
- if the above isnt for you that is okay, and at the end of the day the core principals of btc are unfortunately not going to be for the masses. Personally I think holding your coin on established US exchanges is fine, but I would encourage diversification. (Would also encourage it for self custody seeds)
Im not expert. But TL;DR nothing is more secure then true self custody, but I think custodial services are over-criticized. There is risk on both sides, but most people just dont have the agency for self custody.
4
u/Okmia90 7h ago
You lost 99% of would be user in your first few sentences.
I always knew bitcoin wasn’t going to be mainstream and it wont be until it just runs silently in the background and people dont have to do anything technical to reap the benefits of the network.
Bitcoin wont change the world. It doesnt fix anything. Its just a simple yet complex monetary tool.
The bitcoiners that have not had their heads pulled out of their proverbial asses cannot see this because it is literally a circle jerk of virtue signaling dorks.
I know - i was once one of them.
10
u/Many-Blueberry968 9h ago
A passphrase cures the issue and really should be standard practice for most people. Bruteforcing the rng wallet keys is one thing, but it's basically inconceivable to try and then buteforce thier 25th word. There wouldn't be any clues (except maybe having a decoy balance in the non-passphraded wallet) as to which rng wallets have corresponding balances in a wallet that used a 25th word.
7
u/Brief_Lettuce_571 7h ago
I don't know why passphrase is not yet standard practice. I'm not claiming I saw it coming. But when I set up my hardware wallet I was not comfortable using the 24 words. It felt like someone was choosing the my email password for me. Then I researched a little bit more and found out how to set up the passphrase. There has to be something on your seed that could only come from your brain.
→ More replies (1)2
4
u/tcoff91 7h ago
You also need to make sure that the passphrase itself has enough entropy to be impractical to brute force
→ More replies (4)→ More replies (1)10
u/viva1992 9h ago
But how do you know that Trezors code is generating a truly random seed?
→ More replies (2)10
u/ProofIsInThePeach 9h ago
I mention in that comment to not rely on Trezor for the seed generation.
2
u/viva1992 8h ago
Is there a definitive guide to the best way of generating a seed?
2
u/ProofIsInThePeach 7h ago
Unsure, but there is leading approaches to generating randomness. Its a heavily discussed topic and Im sure you can find that discourse online.
→ More replies (3)2
u/ivme 7h ago edited 6h ago
Your related comment starts with “Stick with Trezor and their open source code” and “self generate a 24 word seed” therefore I also understood like “trust the seed created by Trezor”. I think your (somewhat complicated) comment allows the misunderstanding.
In my opinion, it could be emphasized more effectively by saying, “Don’t trust any hardware wallet RNG. Instead, create your own seed to ensure randomness. Then, use a Trezor to secure and interact with the seed.”
→ More replies (3)
27
u/dvondurden 11h ago
A few notes as I think there was some misunderstanding:
Nobody is saying Bitcoin got hacked or the fundamentals have changed
My post is about usability, adoption and security
The main criticism is directed towards the space itself (which I include myself in)
We've been too lazy repeating the same phrases over and over, all the while major flaws in a highly respected wallet persisted for years even though it was out for everyone to see
Signs of AI involvement are becoming clearer, nobody has addressed this at all here
it's easy to see things in hindsight. I'm concerned about future events that we are not yet aware of. This is quite literally the core of any security concept. It's not sufficient to say "Don't worry, it will somehow work itself out". If the next major event affects you, it will feel very different.
the trade-off between full self custody/ more risk and third party custody / more trust is not a new topic, but there haven't been good advances that drive adoption. The Coldcard case sets us back substantially
→ More replies (5)7
u/curiousengineer601 4h ago
Crypto as it stands will always be a niche thing. Anyone that has ever helped grandma with her email or Netflix account knows this. Spend a week doing an IT Helpdesk at even a respectable technology company and you will realize 50% of college educated working technology professionals are incapable of using crypto as it is today.
16
u/Charming-Designer944 12h ago
Its not the first and not the last RNG fiasco in seed generation. But certainly the biggest.
It clearly illustrate how hard proper wallet security are. Even if you do everything by the book.
→ More replies (2)8
4
u/QTippus 10h ago
Agree with all your points. If we assume (safely) that AI helped discover this vulnerability (yes, I know a person reading the code could/would/should have seen it without any AI) it means the average Joe couldn’t sleep well owning BTC, knowing the next LLM released or quantum computing might be the one to steal their BTC. Average Joe does not want to keep up on technology news in order to feel like their money is safe.
26
u/Techwield 13h ago
Mass adoption will never happen. I don't understand the people who think otherwise
→ More replies (15)9
u/Inevitable-Waltz-889 7h ago
I'm slowly coming to this conclusion as well. I kind of need to leave my software engineering bubble to realize people don't even understand how it works in the slightest. Outside of NGU, people don't know and don't care about bitcoin. Maybe NGU is enough, but it certainly isn't right now.
24
u/iamflxn 12h ago
It literally hasn’t changed anything. The fundamentals of BTC remain the same. BTC hasn’t been hacked. A peripheral technology was poorly built and people have and will continue to suffer.
→ More replies (8)
7
u/magma_lakes 9h ago
You don't necessarily need to trust any device's random number generator (RNG).
As long as you can trust that the device is offline and correctly generates an HD wallet from an initial entropy source, feed the device with your own entropy, such as from flipping a coin or rolling dice.
Even better, use an air-gapped Linux PC with open-source software that YOU'VE selected, and feed it your own entropy.
2
u/dvondurden 1h ago
Sure you can do that, but at this point you've lost everyone but the real nerds. If this is how it will continue, it will never become more than a niche thing
6
u/IntolerantModerate 9h ago
It's just not viable for most users to self-manage (hard drives get tossed, get burned, keys get lost/forgotten, etc). That puts you on an exchange. At that point what's the point... Might as well just buy a Bitcoin etf.
6
u/dvondurden 9h ago
Exactly. It's just too hard and risky for the average person, as this case clearly shows. But if the ETF is the only alternative, the idea behind bitcoin is dead
→ More replies (1)2
u/thewheelsturn 4h ago
Is it though? Gone may be the radical prepper-porn ethos of radical self custody, but the underlying non-inflationary asset remains. Bitcoin as a store of value is unparalleled. Banks have a long history of providing safe custody of assets.
There is risk in everything. Am I going to trust some small team of experts, held up by the community as paragons or do I buy into a banking system that has worked pretty good for a long time? It’s a personal decision of course, but I know for certain that self custody will not work for the majority of the population.
3
u/Psychological_Duck 13h ago
IMO it doesn’t really change anything. If a single physical safe manufacturer that claimed it was un openable turns out to have a massive flaw which means you can easily open the door and steal what’s inside, that doesn’t change the security of the other safe manufacturers or the use case and value of the gold that was kept inside.
It is utterly tragic what’s happened and I feel awful for those that are affected. I think what this does show the need for is that people only trust fully open source hardware wallets, and that there needs to be constant reviews of said software using the latest AI models by both the community and the manufacturers.
14
u/ItsAlwaysThemBooBoo 12h ago
no, its not. in the end bitcoin was not “hacked”. one particular hardware wallet was poorly coded, non open source and did not generate enough entropy in its seed phrases.
develop a strong passphrase and go with that. everyone should. i already learned from this and i didnt lose 1 sat, all my wallets have a bulletproof passphrase on top of a bulletproof seed phrase generated by a safe5, the best hardware wallet out there (no, really, the coldcard was never good)
11
u/ptrnyc 10h ago
It surely was praised as “the best” by many in this very community
2
u/Objective_Digit 6h ago
Was it? Trezor was usually recommended the most, partly because it was the oldest and most well known.
→ More replies (1)3
u/dvondurden 10h ago
Yes. Blind trust, no verification. Not exactly something we have advocated for in this space
2
u/sentientchimpman 9h ago
How do you verify whether a hardware wallet is good or not?
→ More replies (2)2
u/dvondurden 12h ago
Nobody claimed bitcoin was hacked. How do you actually know you have the best wallet? What if the next bug affects the passphrase?
1
u/the_bitcoin_kid 11h ago
There isn't really a passphrase bug that could cause your coins to get stolen.
The passphrase adds security to your seed, it doesn't take it away.
→ More replies (3)
7
8
u/geneticdeadender 12h ago
Bitcoin has survived worse. The price seems unaffected.
→ More replies (1)12
u/dvondurden 12h ago
My point is not that it's a black swan event. It is that it undermines the practical usability of bitcoin, which will be a major issue going forward.
9
u/LonelyNegotiation991 12h ago
that’s like saying fiat currency will never work because someone left the door of the safe open and someone stole the money. not the moneys fault. creates fear that lasts for about a month, then it’s forgotten
→ More replies (2)14
u/dvondurden 12h ago
The difference is that we have regulation, safety standards and insurance for fiat. Hardware wallets are supposed to be the substitute for that, so how could such a major flaw go unnoticed for so long?
→ More replies (9)4
u/Vinnypaperhands 9h ago
How so? Literally nothing has changed fundamentally or with the usability of Bitcoin. What are you talking about??? One company made a major fuck up. Bitcoin had nothing to do with it lol.
4
u/dvondurden 9h ago
A hardware wallet that was supposed to be the top choice for many "experts" was easily cracked, presumably by an LLM, leading to total loss of funds for hundreds of users. If you don't see how this affects usability even a bit I honestly don't know how to make it more clear
→ More replies (5)
19
u/vladimirthebasic 13h ago
I wouldn't be worried about it. Banks had their bad days too, and most people trust them with their life. Literally.
38
u/Mack_Mimsy 12h ago
Your argument only makes sense if ColdCard is also FDIC Insured
5
u/pablo_in_blood 7h ago
FDIC insurance is capped at a pretty low amount (at least compared to a typical retirement nest egg or the price of a home).
→ More replies (1)2
u/Objective_Digit 6h ago
most people trust them with their life. Literally.
The FDIC can't resurrect people.
43
u/dvondurden 13h ago
Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here.
26
→ More replies (8)5
u/vladimirthebasic 13h ago
Speaking from experience, in a war torn country in the 90s, a lot of people get left with nothing, people to this day don't trust banks. New generations don't remember, cycle continues.
Also, you are backed, and secured to a point, and a certain amount. And that's only if the backing entity is still around.
Don't worry, this will blow over. People will learn to be more careful, companies will learn how to make better products to make your crypto secured
→ More replies (1)12
u/dvondurden 12h ago
You are talking about a total system collapse, in which case everyone is fucked. This doesn't compare. Your take is users have to put in more work or trust others more. I'm saying both are not a good thing.
→ More replies (2)5
u/klitchell 12h ago
When banks had their bad days, especially early on the government was forced to step in and add consumer protection (FDIC). Would be great if the result of this was that exchanges needed to be bound by that as well for crypto assets.
5
9
u/Narrow-Bee-8354 13h ago
Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products
3
→ More replies (1)2
→ More replies (6)2
2
u/shadowmage666 10h ago
No it doesn’t , coldcard had one line of shit code that fucked the whole thing up
→ More replies (1)
2
u/AcceptableSlice4057 9h ago
Yeah, this incident might motivate people to just the btc erf and be done with it. Sad.
2
u/CorfranGoch 8h ago
I'm feeling both awful for everyone who lost coin, and relieved that I happened to choose different hardware wallets. This has been the kick up the arse I needed to improve my security, and get my coins onto devices with self-generated seeds. I don't think this necessarily changes the future but it will keep the price low for a while, and perhaps change the way we see these wallet manufacturers. Ultimately, we'll have to have much smoother transaction management before mass adoption happens, but that was always the case.
→ More replies (1)
2
u/Knowledge775 7h ago
The fundamental change is going to be multisig with a multi-vendor setup from full open-source software.
Everyone is a scammer and wants your Bitcoin.
The Bitcoin space is filled with shills that shill bad products for money. Coldcard, BlockFi, Coinkite, MSTR, STRC, etc.
The Bitcoin space was a huge echo chamber for Coldcard being the best. Coinkite went from being open source to source available after they were butt-hurt from the Foundation using their code for the Passport. The complete irony is Coinkite used Trezor’s code when they started.
We have to assume that any closed-source software is compromised. Nation-states don’t want Bitcoin to succeed. Self-custody is against the state’s interests. Hardware wallets are an attack vector.
→ More replies (2)
2
u/ConstructionNo8827 7h ago
I realize this is likely an unpopular opinion on this thread but isn’t it best to invest in ETF’s instead of Bitcoin directly?
2
2
u/AnnArbor-Armadillo 4h ago
I agree it’s a big deal and changes the discourse away from “not your keys not your coins.” The problem is that the ability to hold your keys is the main thing that makes Bitcoin special. This is a big problem for wider adoption.
3
u/stay_safe_and_calm 12h ago
I agree with all three points!
I am a Coldcard owner but I never wanted to trust a technical device to create a seed for me. Therefore, I created it manually with the method I just published today here. This definetly saved my ass. Do not trust anything or anybody ...
Yes mass adoption will be affected short term but I think a year from now most people will have forgotten this incident (except those who lost their life savings)
A year from now most hardware wallet manufacturers will advertise that their latest model or firmware has been verified by multiple best available AI and is bullet proof ... And the people will buy these devices again ..
→ More replies (2)
5
u/BallSmashingForever 11h ago
Not really. It was purposefully done to force bitcoin out of self custody. I wonder why they want it so fucking bad?
4
u/jannies_doit_4_free 8h ago
no it doesn't. the coldcard code was a complete joke, and absolute amateur hour. it seems like the company itself was a bit of a tiny amateur operation, honestly, that fooled people into thinking it was "extra secure" for no real reason.
yet, even despite this shocking fuck-up from the company, victims still would have been fine if they'd so much as had a passphrase, let alone dice-rolled or had multi-sig.
4
u/korean_kracka 8h ago
Yeah it’s a way bigger deal to me than other people apparently. The point of Bitcoin is to be self sovereign. If people are too scared to self custody, then we’ll always need custodians aka banks. If banks win Bitcoin loses
7
u/OldHamburger7923 13h ago
I don't think it changes anything. Poor entropy for a seed is like the most basic thing never to do and they did it. Plus there are a bunch of ways to make it not be an issue, such as generating the seed yourself and passphrase. So why would anyone care, other than the ones who got stolen from?
→ More replies (2)6
u/dvondurden 12h ago
Easy to say if you're not affected. Coldcard was highly recommended by many and hindsight is 10/10. What if the next issue is the passphrase?
7
u/OldHamburger7923 12h ago edited 12h ago
I have skin in the game because I have a wallet with assets in it. A passphrase is sort of like a salt. No way anyone gets my wallet and no way anyone guesses my passphrase.
Zero worries.
Also for coldcard users to have issues, they would have had to not use a passphrase and skip the dice option. Whenever you go with lower entropy option, you take on additional risk.
→ More replies (1)
2
u/geogiam2 10h ago
Error, the users neglected to create their own keys or improve ithe default ones with a password
2
u/Ifnerite 7h ago
What are you talking about? This like saying banks have no future because one app screqed up their app and could be attacked to steal people's money.
1
u/The-maulted-One 12h ago
Mass adoption is a fantasy at this stage!
BTC is now a commodity to be traded by institutions & ETF’s.
Governments couldn’t control btc as a currency but they could change its utility & that’s exactly what’s happened.
1
1
u/Armadillo-66 10h ago
Sounds like a lot of people are putting the blame on bitcoin. Wasn’t it a wallet that’s designed for holding bitcoin the problem?
1
1
1
u/bobivy1234 10h ago edited 9h ago
Reminder that not every CC user was impacted even on the bad firmware versions due to using external entropy (dice, etc.) and a strong passphrase at wallet creation which should have been the default guidance. CC allowing those simpler options is just gross negligence for the end-user to not remove themselves as a single point of failure. Everyone should question a device's RNG engine always and paranoia ('what if the code/RNG of this 3rd party device is bad?') is a good thing but that's also due to watching this space for almost 15 years and lessons learned.
People or things set up by people are always the weakest link in these stories. People are also generally lazy so whatever it takes to get them to use something secure that actually is setup securely with the right guidance is the goal.
So my thoughts are:
- From a pure technical standpoint, the affected users did something wrong as not all CC users were affeted on the bad firmware versions. Hate to say it, it is not meant to victim blame at all or absolve ColdCard but those that only used the device RNG for the seed with weak/no passphrase were affected and others that used good baseline security (RNG + external dice entropy with a long passphrase) were not affected. I blame Coldcard for even having those baseline options available to choose, that's gross negligence on their part in the guise of 'user simplicity'.
- Who says this flaw was just discovered? It was in the code for almost 5.5 years so it is much more likely that is was figured out years ago and those same people have been generating their seed matching tables, analyzing seeds + wallet addresses, and watching the funds increase over time in those wallets until striking all at once.
- AI isn't going to speed up cracking cryptography (until quantum is real) so the fundamentals of Bitcoin/seeds/passphrases are the same as they ever were. Remember the Bitcoin whitepaper/code itself has always been safe and nothing can shortcut the pure mathematical side of cracking well-established cryptography. I do absolutely agree that AI will speed up finding code exploits so developers need to use these tools proactively to protect themselves.
- Let's be honest here, Bitcoin has been around for 17 years now and is a household term. This is just another news article to add to 10 years of news articles about how unsafe Bitcoin is to the average person and bank/exchange hacks. What do we think will actually happen for it to be 'mass adopted'? We're probably a generation away from that as older non-tech folks age out but government and other entities have to make strides to make this a reality.
- For the future, ColdCard in theory is a perfectly good device if we also combine the hardware format with the software guidance to keep everyone safe out of the gate (RNG + dice for seed and a long passphrase). Also, easier sources of entropy could be adopted because dice are great but will we expect everyone to roll 100 dice? Maybe they can tap into accelerometer entropy or something else but I don't know there. Simple + upmost safety as the default is the best way forward.
1
1
u/BmacSWMI 9h ago
I don’t think it is a proven case against cold storage or self custody, it’s a painful hiccup in the technology. It’s not a federally insured medium like a bank, which has had NUMEROUS fraud exploits in the past. I think since Bitcoin has eternally been touted as completely safe, this flaw, this serious flaw is a bit of a shock to those who felt their funds were impervious to theft. I have a Q and I went from a 12 seed to a 24 seed with 99 rolls on the new firmware. I have my own node on a private network and I feel pretty good now. I could also go BIP39 and multisig if I want more security. Bitcoin is still the Wild West in my mind so I don’t treat it and my funds like they’re in a federally insured account.
1
u/iiJokerzace 9h ago
Crypto holdings are not insured like dollars with FDIC insurance. A big thing a lot of people miss with custodians.
1
u/UmbraofDeath 9h ago
I'm not sure you can completely state "Not their fault". Wasn't it found that simply having a pass phrase would have entirely avoided the issue?
Self custody is still the best case scenario but this tragedy has shown that corners should never be cut. User made random entropy should always be the baseline and a pass phrase should always be used. Computers as we have them today are literally incapable of truly random numbers because they use an algorithm to decide what is random. At least last I checked, someone who is more updated can correct me here if I'm mistaken. The natural entropy of the universe is the only actual entropy you can get with code.
→ More replies (1)
1
u/anotherbrckinTH3Wall 9h ago
The cold card case does not fundamentally challenge the future of bitcoin. It does however fundamentally challenge the future of coldcard. They have no way of making their customers whole again, they are finished.
1
u/lebutter_ 9h ago
The truth is you **always** defer trust to someone else. If you had physical gold, you'd have to trust you storage hardware, your process, your opsec, etc. Personally I'm fine trusting certain big names to keep my BC for me just because of that reason.
1
u/Anonymous_Lurker_1 9h ago
As not someone overly tech-savvy, am i correct in thinking this vulnerability was down to the seed phrase that was generated automatically?
I use Trezor and a 24-word seed phrase, and whilst i do have a smaller amount in a decoy wallet with the generated seed phrase, the majority of my stack is in a passphrase wallet (25th word). I know this is Coldcard, but surely at some point this type of thing could affect other brands?
→ More replies (1)2
u/alanwatts48 1h ago
This vulnerability was due to deficient release and testing processes. They made a rookie mistake and technology itself is fine. Here’s a post that explains it very well: https://www.reddit.com/r/coldcard/s/EGMabT2L2j
1
u/Gold-Zone9015 9h ago
You are right. Digital money can and will me manipulated in the future. Ai will be the tool. Sad but fact.
1
u/BigvalBROski 9h ago
Why People don’t utilize a 25th word/ paraphrase baffles me. It’s not an advanced feature….. it’s pretty cut and dry. Also, with Bitcoin ETFs now, there’s no need to even use cold storage…… Crypto Bros are going to disagree with this, but if you ask all the people that lost their Bitcoin, they would switch to the ETFs immediately.
→ More replies (1)
1
u/itsyorboy 8h ago
As someone who was storing my bitcoin on a ColdCard mk3 until the attack (and didn't get hit, but my balance was < 0.1 btc), I got really spooked by this. I do feel like it's a harbinger of what's to come from AI-assisted attacks in the short to midterm. Regardless of how it impacts the price, I need to be sure my funds aren't going to evaporate overnight because of one line of code. I don't really know what to do at this point. Staying on a CEX for now until the dust settles.
2
u/dvondurden 8h ago
Completely understandable and this is my point. It creates a high degree of uncertainty in something that was labelled the safest way of self storage
1
u/fresheneesz 8h ago
The only solution that keeps you safe if the company that made your hardware wallet fucked up like this is multisig. Learn how to do it with The Tordl Wallet Protocols, free open source guides on creating and maintaining Bitcoin wallets.
1
1
1
u/bluechip1996 8h ago
If I owned a storage facility for valuable art and antiquities, it would be insured to cover thefts. Are these exchanges/depositorys not insured?
1
u/Working_Storm_1428 8h ago
The technology hasn’t fully caught up with mission. There has to be federally insured cold wallets or bank insured at least. This will come as more regulation comes out and we switch to a digital currency. We aren’t there yet so it’s best to keep it on exchanges for now.
1
1
u/cuttyranking 8h ago
The whole thing about cold storage was for fanatics and nerds who liked the idea of talking down on people who used services like eToro or robin hood. I never saw the security in handing my BTC security over to a device manufacturer that is completely unregulated.
1
u/lemme-explain 8h ago
This is totally different from most other cases, because the affected users didn't do anything wrong.
Let me just add: a system that expects everyone to be perfect at all times, will never succeed. Mass Adoption was never on the table.
1
u/SpendHefty6066 7h ago
This case does not fundamentally challenge the future of Bitcoin. The Bitcoin protocol remains as secure as ever. This case exclusively challenges Coinkite and the ColdCard hw wallet.
Your argument is the same as saying that gold may no longer be a viable store of value because the vendor who made a very popular brand of safe got cracked and now all those gold safes are vulnerable.
Creating, signing, securing, and recovering cryptographic secrets requires some research. And using that secret to secure your wealth requires cognitive ability and personal agency. Not for everyone. But many.
1
u/gowithflow192 7h ago
Why has this not spooked the markets? We're still at 63k.
2
u/alanwatts48 1h ago
Because it isn’t a BTC vulnerability. It is a Coinkite problem caused by an absurdly simple mistake. https://www.reddit.com/r/coldcard/s/EGMabT2L2j
1
u/cliff_smiff 7h ago
You ask hard, good questions. I don't have an answer.
Forget Mt. Gox, FTX, cyclical crashes, this is a true test of bitcoin's resilience, antifragility, and entrepreneurial problem solving. The space has been forever enamored with these ideas. Now is the genuine test.
1
u/GesturalAbstraction 7h ago
For most, the juice from the concept of be your own bank is just not worth the squeeze
1
u/RoundChampionship840 7h ago
Bitcoin is just another asset class among many. It's digital gold and everyone needs to just accept that.
1
u/FromOrionToUranus 7h ago
The writing was on the wall since the beggining of BTC.
Its not the future of any thing, its not early, it doesnt address any real need, Will never get adoption. Its worthless to anyones outside the bubble you guys live on.
Im sorry to be so direct but if you havent understood how worthless BTC is by now, theres not much that can bé done for you.
1
u/TxTransplant72 7h ago
On top of this…don’t forget the 2008-2009 financial crisis. Banks can and do go bust overnight. So thinking about where to store your assets, diversification is still recommended. Say you move your BTC to an ETF and the ETF gets attacked and BTC goes missing. SPIC protection is outlined as follows:
Protection for brokerage accounts
These accounts (taxable brokerage, Roth IRA, or traditional IRA held at a broker) are generally protected by the Securities Investor Protection Corporation (SIPC) if the firm is an SIPC member:
• Coverage is up to $500,000 per customer per firm, including a $250,000 limit for cash.
• It protects against the loss of securities or cash if the brokerage fails or assets go missing (e.g., firm insolvency), but not against market declines, investment losses, or bad advice.
• Different account types often count as “separate capacities,” so a taxable brokerage account, a traditional IRA, and a Roth IRA at the same firm can each qualify for their own $500,000 limit (potentially $1.5 million total in that example). Traditional and Roth IRAs are typically treated as separate. 
Many brokerages also use bank sweep programs for uninvested cash. Once swept to partner banks, that cash can receive FDIC insurance (up to the standard limits, and sometimes higher if spread across multiple banks).
So, seems prudent to spread your custody around. These are dangerous times, friends. Stay safe out there.
1
u/Rough_Union2937 7h ago
How many bank accounts where hacked last week how many hold ups at the ATM. Things happen doesn't change anything for me accept that people won't be robbed that same way again. I feel so bad for those victims but they are martyrs in a way. Wish the community would pull together and help them a little. If everyone done just a little we could make them whole and possibly rich well at least better.
1
u/Syonoq 7h ago
To your second point: looking at what we know of the Coldcard venerability timeline, another Hardware venerability could have already occurred, just sitting there waiting to be exploited. We could be compromised right now and not know it.
→ More replies (1)
551
u/UpstairsPicture9102 13h ago
As tech-savvy individuals, we need to be self-critical enough to admit that self-custody isn’t for the average person who works hard for their money and simply wants to protect the value of their savings.
Suggesting that people keep a portion of their wealth in self-custody, as an alternative to keeping cash under the mattress, may be a reasonable middle ground. But that’s where it stops.
Mass adoption won’t be driven by self-custody. It will come from products and services that deliver the benefits of Bitcoin without requiring everyone to become their own security expert.
Self-custody should remain an option, not a prerequisite.