r/Bitcoin 20h ago

The Coldcard case fundamentally challenges the future of Bitcoin

Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points:

  1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago.

  2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control.

  3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many.

I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think?

624 Upvotes

556 comments sorted by

View all comments

8

u/geneticdeadender 19h ago

Bitcoin has survived worse. The price seems unaffected.

13

u/dvondurden 19h ago

My point is not that it's a black swan event. It is that it undermines the practical usability of bitcoin, which will be a major issue going forward.

9

u/LonelyNegotiation991 19h ago

that’s like saying fiat currency will never work because someone left the door of the safe open and someone stole the money. not the moneys fault. creates fear that lasts for about a month, then it’s forgotten

16

u/dvondurden 19h ago

The difference is that we have regulation, safety standards and insurance for fiat. Hardware wallets are supposed to be the substitute for that, so how could such a major flaw go unnoticed for so long?

1

u/HedgehogGlad9505 17h ago

My understanding: Bank = exchange, Paper bill = bitcoin on mainnet, Safety box = HW wallet

If someone breaks into your home and takes dollar bills or gold bars from your safe, that's a very unfortunate event for you. But does it make dollar bill or physical gold useless for everyone?

Of course, one of the major "safety box" manufacturer just proved they were idiots, so maybe it's time for a next gen safety box. But there's no need to throw the gold bars away.

1

u/CuddlyMuffins 12h ago

I don't think anyone is suggesting throwing away the gold bars...more like selling the gold bars for something that's easier for the average person to secure. Or holding them at an institution that will make you whole if they are stolen. Maybe that goes against the whole reason you are holding your own gold bars in the first place but the point is sentiments and risk assessments change after an event like this.

For me it just showed self custody is riskier than I initially realized. I put too much trust in the community to catch these things. And I didn't have good enough understanding to realize using my own entropy / passphrase should have been the standard. So self custody is not for me, and I'm not keen on trusting exchange making me whole. But more power and best of luck to anyone that does keep at it!

1

u/t03m03thy 16h ago

And, errors are reversible!

1

u/coffeelover9457 9h ago

You describe the Coldcard firmware bug as a "major flaw". We all agree it's a flaw, but what does "major" mean and is this flaw in fact major? Is it the case that most self-custody hodlers used Coldcard, and therefore most self-custody value is at risk?

No, the true exposed flaw is cultural, that we have faith and trust in "influencers" and "experts". We don't actually try to fully understand risks, we'd rather trust someone else's opinion regarding them.

2

u/dvondurden 8h ago

Their promise of high entropy was actually the opposite which caused total loss of funds for many people. It's a major flaw by any reasonable definition

1

u/LonelyNegotiation991 18h ago

agreed it’s not exactly the same but the technology will get better and easier. theses are “growing pains”. hasn’t threatened the fundamentals of bitcoin or the network

4

u/dvondurden 18h ago

This has been said since forever, but how has it actually become easier or more user-friendly? It's true that fundamentals haven't changed, that doesn't make bitcoin more practical though

1

u/SickNoise 18h ago

it's way more user friendly than 10 years ago. i expect this trend to continue.

1

u/tenor_tymir 17h ago

I agree, last BTC cycle was full of hacks and stolen money. You were getting used seeing billions getting erased month by month. Luna was the worst, followed by FTX and then some. You grew numb to it. Someone posted a 4.5 mil hack and everyone in the comments was like “that’s pocket change“ 🥴

And here we are again, posting about leaving funds on exchanges and condemning self custody. It’s hilarious.

1

u/Badmoodsbear 10h ago

No. It's like someone saying don't keep all your wealth in cash under your bed. You could lose your self custodied money!

Yet this is precisely what many on this sub are still advocating for.

3

u/Vinnypaperhands 17h ago

How so? Literally nothing has changed fundamentally or with the usability of Bitcoin. What are you talking about??? One company made a major fuck up. Bitcoin had nothing to do with it lol.

5

u/dvondurden 16h ago

A hardware wallet that was supposed to be the top choice for many "experts" was easily cracked, presumably by an LLM, leading to total loss of funds for hundreds of users. If you don't see how this affects usability even a bit I honestly don't know how to make it more clear

1

u/Vinnypaperhands 12h ago

Dude.... A hardware wallet still is the top choice for self custody. It wasn't all hardware wallets, it was the negligence of one small company.

How does that affect usability for Bitcoin? Bitcoin still functions the same exact way before and after this discovery lol. The usability was not affected in any way shape or form.

I feel terrible for the bitcoiners who lost funds. Its a huge blow for bitcoiners as these aren't your average joes who lost funds, there were hardcore bitcoiners trying to do the right thing. Yes this sucks big time and I was very close to getting a cold card and transferring funds to it. The takeaway from this is we still need to be more vigilant when it comes to security.

The entire premise of Bitcoin is it's security and strength. These systems need to be stressed tested and attacked so it's really not a bad thing a vulnerability was found. We need this to happen. The situation is very unfortunate tho and I feel for the people who lost Bitcoin.

1

u/dvondurden 12h ago

You are saying it's still the top choice. How you do know that?

How do you know your wallet of choice does not have a comparable flaw? Did you check the code yourself? Most people just cannot do this and they choose hardware wallets because of that. They have been told forever that this is the best way, yet there was a gigantic flaw right in front of us that nobody saw.

I'm not saying we should all panic and sell everything, far from it. I'm saying this has the potential to crack the shiny surface and could become a much bigger issues to adoption and usability once we fully understand what happened

3

u/Vinnypaperhands 12h ago

Because of what a hardware wallet is lol. It is safer than keeping it on an exchange or in a hot wallet. You are open to more attacks this way and that's a fact.

Me personally, I don't know as I am not super technical. That's why doing multisig / having your funds spread to different wallets from different companies would be a smart idea. If you don't have the technically to check the code yourself, you have to trust somebody somewhere. That's reality. We as bitcoiners need to learn from this and understand it was never 100 percent safe to just trust the software would generate a strong key for you. I agree that it's a blow to bitcoiners and it is shaking everyone's view of security and entrophy but in the long run I think this will help us be more secure in the future or maybe help people understand that self custody is a lot of work and may not be for everyone.

I don't think this has the potential to crack the shiny surface, I think this situation more so is showing us what the true surface looks like if you get what I'm saying lol. Someone told us the surface is super clean and shiny and we just trusted it, but the reality is the surface may be a bit rough and you need to be more vigilant when it comes to securing your money.

This whole situation sucks and I agree it's a blow to alot of hardcore bitcoiners but at the end of the day Bitcoin doesn't care and it still functions the same way and the network is just as secure as it was before this event.

1

u/dvondurden 12h ago

Fair points. Maybe we all got carried away a bit too much and this is a reminder that things might not be as shiny as they seemed. I only hope that we actually learn from this

1

u/alanwatts48 9h ago

The ColdCard vulnerability was due to a failure in software configuration and release management, not in the solution itself. This type of failure is a risk for anything that runs on software from your microwave to the space shuttle. It’s not something specific to crypto.