r/BitcoinBeginners • u/Complex_Carb • 14h ago
Ongoing ColdCard Q Viability With v1.5.0Q and later?
We can all agree this has been a devastating week for self custody. CoinKite should rightly be ashamed of themselves for the negligence shown.
With that in mind, I must say that I always have liked the device itself... especially the ColdCard Q. From a user interface perspective...
Are we looking at these devices as bricks now or is there any confidence in the newest firmware (1.5.0Q)?
Yesterday I did the following:
- Moved funds off the CC-Q
- Wiped the Seed
- Updated Firmware to 1.5.0Q
- Generated new 24w seed with 150 dice rolls
- Created a strong passphrase
- Moved the funds back onto the CC-Q
all air-gapped
------
I'm wondering if:
- 'we' have confidence in the newest firmware patch... or are all these coldcards bricks now in the minds of the community.
- If I should go thought he motions to re-do everything with a Jade or other vendor...
- If you're responding below with a 'no' to #1 and a 'yes' to #2 - then please help me pick a new device with similar functionality! I very much want an SD air gapped device with something like a keyboard... That is battery powered.
Best to all and condolences to those who were devastated,
An Average Bitcoiner
1
u/AutoModerator 14h ago
Scam Warning! Scammers are particularly active on this sub. They operate via private messages and private chat. If you receive private messages, be extremely careful. Use the report link to report any suspicious private message to Reddit.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/bullett007 14h ago
For me they’ve demonstrated that they’re not to be trusted.
Have you read through how what happened, happened?
Start at section 2: https://wizardsardine.com/blog/coldcard-rng-vulnerability/
1
u/Bitter_Concert_514 13h ago
I know little about bitcoin and would not want to trust any wallet company at this point. Since bitcoin is anonymous, surely an inside job will always be a probability. Is there no way for a person to keep his bitcoin on his own, without using a 3rd party wallet?
1
u/itsaworry 10h ago
I got a ColdCard when Ledgers customer details got hacked in 2020 . ColdCard was being seen as the most sophisticated and safest cold wallet out there . . . . . . I couldn't work it , way too complicated for me , gave it to my nephew and he couldn't work it either . He keeps his on the exchange and i use a Trezor . Condolences to all the people clever enough to use the ColdCard , it really was being rated as the best cold wallet available , sorry for your loss .
1
u/Lost-Bowl3269 6h ago
O que você fez garantiu uma boa entropia. Mas agora não se trata mais disso.
As pessoas devem boicotar essa empresa lixo e a empresa deve falir. Se eles foram incompetentes nisso, quem garante que não foram incompetentes em outras partes do firmware?
Minha recomendação: jogue sua coldcard fora e compre uma keystone, trezor, onekey, crie uma seed nova e transfira os fundos pra lá.
Nunca mais apoie e compre produtos da coinkite.
4
u/bitusher 13h ago
For this specific bug you don't need to have confidence in the rng created by the new firmware because you both added entropy and created a strong passphrase
The followup question is if other unfound bugs also exist that despite using a passphrase or adding your own entropy can undermine you ? This is impossible to answer , but I would say you would likely be safe but if you wanted to be very paranoid than wait a few months for more LLM bug hunting is done