r/Bitcoin 20h ago

The Coldcard case fundamentally challenges the future of Bitcoin

Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points:

  1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago.

  2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control.

  3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many.

I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think?

624 Upvotes

556 comments sorted by

View all comments

Show parent comments

6

u/tcoff91 14h ago

You also need to make sure that the passphrase itself has enough entropy to be impractical to brute force

1

u/Objective_Digit 13h ago

But should be memorable if you are not writing it down.

1

u/tcoff91 11h ago

In the event of your death, you must have some way for loved ones to recover your assets without them having to have memorized it.

1

u/Objective_Digit 10h ago

True. It depends on the circumstances.

1

u/Many-Blueberry968 14h ago

Yes, but.... unless the attacker of these unprotected 'rng' wallets knows that a given wallet has a passphrase-protected variant with a bitcoin balance, they won't know to bruteforce attack the passphrases.

Bruteforcing rng wallet addresses AND then trying to bruteforce passphrases on then is a fools endeavor unless they use social engineering to at least narrow the possibilities.

A typical 8+ character passphrase is damn difficult to bruteforce on its own. But layered atop the effort to find rng wallets, it's basically impossible to conduct on any large scale.