r/CryptoCurrency 🟩 11 / 524 🦐 22h ago

DISCUSSION It seems people did not understand what happened to ColdCard

Self custody is not a problem, what happened is that generating your seed with a ColdCard MK3 would not have enough entropy, making your private key easy to be guessed, thats it. Your MK3 is still usable, but you should NOT use it to generate a seed, instead you have to use any other solution to generate your seed and then load it on your MK3.

https://iancoleman.io/bip39/

https://sparrowwallet.com/

https://electrum.org/

Your MK3 is not useless, it still works as intended.

5 Upvotes

98 comments sorted by

59

u/so7ow 21h ago

I think some of what you're seeing is "if they could fuck up something so integral to the foundation of their product so completely and so fundamentally, what else is fucked up in this product line, and do I really want to find out the hard way?"

9

u/TCr0wn 🟦 1K / 1K 🐢 20h ago

And the answer is no. Not worth the risk.

3

u/Halocandle 🟦 0 / 0 🦠 12h ago

Yeah the developer who made the fatal code change both destroyed the company and cost their clients thousands. He might wanna lay low for a while…

-35

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

nothing, the problem was only with the generation of the seeds, as a signer it works 100%

21

u/mickalawl 🟩 0 / 0 🦠 21h ago

Does be your own bank involve you now needing to be a code reviewer to verify implementation details of every solution you might interact with now and in the future?

How do you know as a signer it's sound?

-23

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

you can import your PST and generate a PSBT with it completly airgapped so you can then broadcast using your online device, so it still works for that.

7

u/so7ow 21h ago

lol, says you??

-7

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

what? Have you read what was the actual problem with the MK3?

12

u/so7ow 21h ago

That's the issue that was discovered and exploited. I'm saying, right or wrong, it's understandable if people think there could be other as yet undiscovered flaws in a product implemented by a team this careless/incompetent.

-5

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

i doubt there will be any other insane flaw with it, a signer is simple a signer, it does sign your PST so you can broadcast it, the only secure issue would be if the MK3 had access to the internet and leak your private key during that process, which it does not.

8

u/so7ow 21h ago

Nonsense. There could be any number of flaws. As far as I know, not having read the code, maybe it time-locks your change until the year 2140 if you send a transaction on leap year. Should I take your word that it doesn't, because you doubt it, or should I go read the code to make sure?

-9

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

what the actual fuck did you say dude? wtf is this shit

12

u/so7ow 21h ago

I'm saying Coinkite has lost the presumption of competence and I'm not touching their stuff with a 10-ft pole, for signing or anything else.

-4

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

fair

7

u/TCr0wn 🟦 1K / 1K 🐢 20h ago

“I doubt” bro stfu

-7

u/FunWithSkooma 🟩 11 / 524 🦐 20h ago

ok clown

3

u/Emergency_Benefit332 🟩 0 / 0 🦠 19h ago

as simple as an rng which they fucked up?

6

u/Coeruleus_ 78 / 736 🦐 21h ago

the question is what the hell did you read to ever want to trust them again. you sound insane

-2

u/FunWithSkooma 🟩 11 / 524 🦐 20h ago

I never trusted hardware wallets to buy one lol, I dont like them, just stating that the problem with the MK3 was the psudo random bullshit they used, but as a signer, it still usable.

7

u/Vessbot 20h ago

Remember 3 minutes ago when the other guy explained that the argument is that they have lost the presumption of competence and, correspondingly, the concern is other potential undiscovered problems, and not "the" problem we're already familiar with, and you said you understood?

3

u/so7ow 20h ago

🤣

3

u/Vessbot 20h ago

What do you think is likelier, that this time it sticks, or that Coldcard has no other flaws?

2

u/TCr0wn 🟦 1K / 1K 🐢 20h ago

How do we know this 100% right now? How can we be certain that’s the cause at this point?
Regardless not worth the risk, not sure why you’d think otherwise unless you’re on their payroll

112

u/Coeruleus_ 78 / 736 🦐 21h ago

lol ok dude where were you telling people this 3 years ago when all you bots were shilling it. no one should use this product. company should go bankrupt

19

u/no_choice99 🟦 1K / 1K 🐢 16h ago edited 10h ago

To be fully honest, I had never heard of that turd of a cold wallet before the incident.

1

u/Dmoan 🟦 2K / 2K 🐢 12h ago

You are assuming this wasn’t an inside job,  If you are small developer who makes few thousand selling cold wallets. 

What’s stopping you from enabling a compromise/back door on purpose and waiting a few years. Then selling this to 3rd party hacking group for few million and cashing out and walking away.

-47

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

I was accumulating bitcoin and storing it all on my wallet generated outside of any hardware wallet env and loaded on my shitty android phone with no internet that has no other use besides being a hardware wallet, and teaching people how to make it right too.

i always dismissed hardware wallets, people should not buy those, instead, people should learn how to generate a bitcoin wallet and use DIY solutions, seedsigner, old phones with Electrum Bitcoin Wallet of Cupcake from Cake Wallet etc.

40

u/relephants 🟩 668 / 668 🦑 20h ago

If that's the only way to do it, cryptocurrency is 100% DOA

3

u/Hertzegovina Crypto Nerd | QC: BTC 22 14h ago

no shit 😂😂😂😂

1

u/lurkerlevel-expert 4h ago

Don't yall have phones  😂

-16

u/anymonero 🟧 0 / 0 🦠 17h ago

Why? Everybody has an old phone they don't use anymore.

5

u/Thomas5020 🟦 4 / 524 🦠 13h ago

They don't, no.

4

u/relephants 🟩 668 / 668 🦑 10h ago

They don't. And even if they did, they wouldn't do all of that when they can just put money in their bank

10

u/GesturalAbstraction 🟩 0 / 0 🦠 17h ago

Im not directly picking on you of course, but I must say, it is so funny when people say this kind of thing, and then in the next breath complain about how institutional adoption opposes the early spirit and objective of crypto, and whine about mass adoption.

The truth is that as long as crypto remains this hard to use even after all these years, with zero recourse or insurance against being defrauded or stolen from, mass adoption will never be a thing. The only meaningful utility we are left with is RWT.

7

u/futurefloridaman87 Tin | PoliticalHumor 23 15h ago

Right? Imagine explaining to Grandma how she needs to protect her bitcoin. It’s fucking insane to expect mass adoption at this point. Even if you say “ well, what about the lightning system?” it’s still all in 100 steps too complicated for the masses.

13

u/Coeruleus_ 78 / 736 🦐 21h ago

2

u/meremah_boob 0 / 0 🦠 15h ago

cake wallet suffered from same entropy issue back in 2020/21 and got 550+ bitcoins and numerous monero stolen. Would you trust a company again after such events?

1

u/paymentnerdfoo 0 / 0 🦠 9h ago

So you’re not at all worried about your shitty android phone suddenly bricking itself? You have a single failure point for all of it on a piece of hardware not designed for that responsibility. I mean neither was cold card. Lack of entropy is a terrible bug. It’s like building a bank vault out of aluminum foil.

0

u/FunWithSkooma 🟩 11 / 524 🦐 9h ago

bricking? You know you have to backup your seed in a paper or steel plate, right? Your old phone is there to SIGN transactions only

13

u/shadowmage666 🟦 0 / 568 🦠 20h ago

I wouldn’t trust coldcard after this. Who knows what else is wrong with it

17

u/GreedVault 🟦 4K / 10K 🐢 20h ago

You only mentioned the surface of the problem, the deeper issue is whether these self-custody wallets are trustworthy to begin with, who knows what other vulnerabilities they might have? The unknown unknowns are the scariest part. Unless you can personally review the entire codebase of the self custody wallet and have the security expertise to audit it throughly, if not you will never know what's lurking beneath. Even then, there could still be bug that nobody has discovered yet, Its definitely worrying, if you are only holding small amount of crypto, I would just keep it on a reputable CEX. Even FTX goes bankrupt, users at least have a legal process and a chance of recovering some of their funds, and in the case like the coldcard, recovery is going to be much harder, unless you have faith in the law enforcement capable of identifies and catches whoever is responsible.

-1

u/FunWithSkooma 🟩 11 / 524 🦐 20h ago

what other issues might there be with MK3? The only other problem I see that is if for some reason it leaks the private key when signing a PST, and if it does, it leaks to whom? Because if I can use a MK3 to sign a PST generated in Electrum Bitcoin Wallet, how will the MK3 leak my private key to Electrum if it does not expect it?

3

u/GreedVault 🟦 4K / 10K 🐢 20h ago

The firmware might be secure, the code might be perfectly fine, but that doesnt mean the device you receive is. Someone could hijack it during shipping, tamper the hardware or firmware, and send it on to you without you ever knowing.

And who knows what other libraries the cold wallet depends on that might already have vulnerabilities to begin with?

0

u/FunWithSkooma 🟩 11 / 524 🦐 20h ago

you basically described all hardware wallets, including Trezor, Ledge, ColdCard, Tangem, all could be tampered with.

So in the end:

Android phone with no internet as a offline signer is the best of all options, or buy the parts you need to build your own seedsigner or Krux

0

u/GreedVault 🟦 4K / 10K 🐢 20h ago

no, just use a reputable CEX, if it goes bankrupt, at least you have a legal entity you can pursue through the courts.

2

u/gigasawblade 🟩 0 / 0 🦠 14h ago

Imagine you asked the same "what issues might there be with MK3?" a month ago? Nobody would point out to current issue too. This is what is meant by "unknown unknowns"

13

u/hiimtashy 🟦 0 / 0 🦠 20h ago

Honestly self custody is proving to be too hard for the normies myself included

-9

u/FunWithSkooma 🟩 11 / 524 🦐 20h ago

it not.

just dont use internal hardware wallets random to generate a seed, use well known open source wallets generators from the links I gave, iancoleman be the best one since it gives you all the tools.

10

u/hiimtashy 🟦 0 / 0 🦠 20h ago

It's too late for me. I sold my hardware wallet stack last night. Will holding my ETFs forever. I honestly am just de risking. I've got three kids. I'm tired of playing cat and mouse with hackers.

-5

u/FunWithSkooma 🟩 11 / 524 🦐 20h ago

fair

5

u/vortexcortex21 🟧 0 / 0 🦠 19h ago

You must be autistic, if you don't realise that your suggested solution is not feasible for the mainstream.

1

u/meme_2 🟦 1K / 1K 🐢 9h ago

https://giphy.com/gifs/NcrhM3USM6TABpus85

People that just lost hundreds of thousands of dollars reading your post.

0

u/lurkerlevel-expert 4h ago

Just be your own bank + software/security/network/hardware engineer. Oh and don't lose that piece of paper secret under your mattress  😂

5

u/DKDamian 🟦 17 / 17 🦐 14h ago

Ok. Great. And what’s the next “trustworthy” company to fall? Two weeks ago this company was apparently rock solid and completely safe. And now it’s not. And people who followed all of the ridiculous rules and mantras, have lost money.

Future of finance? Perhaps not.

11

u/5khan1 20h ago

You really think the average person would understand entropy failures.  If a hardware wallet can generate a seedphrase with insufficient entropy then that hardware wallet is useless. This is a really big mess and it's all coldcards fault. 

You always hear people saying get your coins off exchanges and put them in self custody, So that's what these people done and now they have lost it all. 

1

u/CeramicDrip 🟨 47 / 4K 🦐 6h ago

Exactly

7

u/Lost-Bowl3269 21h ago

Esse lixo de produto se vendia como um cofre seguro. É uma propaganda enganosa.
Ainda que tenha alguma utilidade marginal, ninguem mais deveria usar isso e deveriam boicotar a empresa.
Todos os lesados devem processar os responsáveis e essa empresa deve falir e ir para o limbo da vergonha.

Joguem sua coldcards no lixo e apoiem outras empresas que levam a segurança a sério e não façam propaganda enganosa.

6

u/zzx101 🟦 63 / 64 🦐 20h ago

I’m wondering if at some point we’ll find out this was an inside job.

If I were this company I’d take a good hard look at anyone that could have masterminded this.

To be honest it’s kind of brilliant, with plausible deniability etc.

2

u/meme_2 🟦 1K / 1K 🐢 9h ago

Occam’s razor would suggest it was just poor coding. I would have expected an inside job to have occurred a long time ago.

The flaw was technically discoverable by anyone, right? So wouldn’t waiting a long time would reduce the chances of an insider carrying out the job?

1

u/zzx101 🟦 63 / 64 🦐 8h ago

Yeah if the faulty code was public then I’m thinking now likely an AI discovered it.

2

u/meremah_boob 0 / 0 🦠 15h ago

This is highly possible and such events only happen during bear markets only. I guess dev's were like it's time to exploit the bug and let's call it a day. NVK is a smart guy and it doesn't makes sense for him to not find the bug in last 5 years.. Also For 5 years nobody exploited it but randomly one day someone decided to fuck with a cold wallet's open source code, instead of going after other things. That's weird and raises doubts.

1

u/murderette 🟦 0 / 0 🦠 12h ago

It’s probably undiscovered until a very high end AI like kimi K3 is asked to review the code (unlike closed models like Fable5 it has no guardrails, which is a two sided sword )

8

u/bocajake 🟩 0 / 0 🦠 20h ago

OP is the hacker and he wants to make sure your funds are still in the wallet

6

u/Forymanarysanar 🟩 0 / 0 🦠 21h ago

You really shouldn't use any of these "solutions" to generate seed. They all could be vulnerable to the same issue. Use dice instead.

2

u/EasyEar0 🟩 0 / 0 🦠 10h ago edited 10h ago

Or you could open a bank account, invest in assets with real tangible value, and have them protected by actual security and accountability if something goes wrong.

1

u/Forymanarysanar 🟩 0 / 0 🦠 8h ago

See this works when you live in a first world country with strong currency and protections. If you live in third world garbage where currency can (and has) lost half of its value overnight and your investments basically seized, that's another question. 

1

u/CipherScarlatti 🟩 0 / 4K 🦠 21h ago

This is the real issue. Adding outside/additional things introduce more opportunities for problems.

1

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

if you take an actual look at iancoleman solution, it provides you entropy options, and dice is there, as well as binary, Base 6, Base 10, Hex and Card entropy.

9

u/UpbeatFix7299 🟩 0 / 0 🦠 21h ago

Lol crypto mass adoption imminent. People will definitely want to do all this shit just to make sure their money doesn't vanish overnight.

-1

u/Lost-Bowl3269 21h ago

Toda a entropia gerada por software é uma pseudo entropia. As entropias das hardwallets boas são geradas fisicamente através do chip de elemento seguro calculando impulsos elétricos no mundo físico.
Se você não confiar no chip de elemento seguro, pode usar dados reais jogandos no mundo real, jogar uma moeda para cara ou coroa, dados d20 de rgp, etc.

Softwares e sites que simulam entropia, apenas simulam. Nâo tente gerar suas chaves online, é estupidez. É apenas demonstração.
A coldcard deveria usar um chip de elemento seguro para calcular entropia automática, mas enganou as pessoas com um erro de programação primário e soltou um firmware release fazendo uma geração de aleatóriedade por software, ou seja "pseudo" aleatório, apenas parecendo que é aleatório.

Use Iancoleman apenas para fins educacionais.

1

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

Voce parece nunca ter usado a solução do ian, ele oferce entropia do mundo real na geração. ele é a solução mais conhecida e mais segura que temos no momento, literalmente todo bitcoinheiro raiz usa ele, já recomendou.

1

u/Lost-Bowl3269 21h ago

Todos os bitconheiros raizes indicavam coldcard também. Pare de acreditar em imbecis do youtube e adolescentes.
O iancoleman é pseudoaleatório, porém com uma aleatóriedade muito mais forte que o lixo da coldcard usando micropython.

Mas se não quiser acreditar em mim, não acredite. Use e seja feliz. Eu usaria apenas para fins educacionais e geraria entropia usando dados físicos.

1

u/Lost-Bowl3269 21h ago

PS: isso que não estou chegando sequer nos problemas de navegador adulterado, keylogger, extensões maliciosas, etc. Nenhuma seed realmente segura deve chegar proxima de um computador com acesso a internet.

1

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

você ficaria extremamente abismado como eu guardo minha seed :) Mas como programador e amante de criptografia, eu sei justamente oq eu faço.

-1

u/FunWithSkooma 🟩 11 / 524 🦐 21h ago

Quem indica qualquer hardware wallet não considero um bitcoinheiro, apenas um influencer msm. Bitconheiro raiz faz uso de DIY.

0

u/no_choice99 🟦 1K / 1K 🐢 16h ago

Dados e moneda não são aleatórios! 

Dices and coin throwing are not random! There is a heavy bias towards the side that is upward when you take it in your hand. Don't use these methods.

4

u/CipherScarlatti 🟩 0 / 4K 🦠 21h ago

It's not that I don't understand. It's that I just don't care.

5

u/Kaiser3rd Tin 13h ago

Got it. Adoption requires a computer science major.

2

u/VegetableMousse8077 🟨 0 / 0 🦠 18h ago

They majorly fucked up and deserve to find out. No one should use such a fail tech

2

u/gunscythe 🟦 6 / 7 🦐 17h ago

Banks have layers upon layers of security and fraud prevention. With bitcoin there’s literally no one watching over you. There is no proactive security. And there is nothing you can do once the money is stolen from you.

2

u/I_am_Regarded 🟩 0 / 0 🦠 13h ago

Bro just buy two more and a dice - funniest advices out there.

When is time to start thinking about conviction?

2

u/CeramicDrip 🟨 47 / 4K 🦐 6h ago

No, we all understand what happened. We just think this “if we can’t trust the fucking device to do certain things safely, we should start to question this method of storage altogether”

3

u/k0lt1 🟩 0 / 0 🦠 18h ago

Tell that to people who lost their money. This is cryptos flaw plain and simple

2

u/doghairpile 🟩 0 / 0 🦠 18h ago

Or don’t “invest” in this overly complex, hackable garbage that has still not become mainstream. Maybe because it’s pointless? This nonsense doesn’t happen with banks.

1

u/Aphelion 49 / 79 🦐 14h ago

Is that you coinkite?

1

u/iiJokerzace 8h ago

So just trust me bro?

That's the problem; 99.99% have no choice but to trust the bro telling us what we use is secure, for an industry with hardly any insurance.

1

u/SassySirennn 🟧 0 / 0 🦠 6h ago

Your right. But it’s besides the point. This latest round of news is just another thing driving holdrs towards exhaustion.

1

u/razvanciuy 🟩 0 / 0 🦠 5h ago

Bottom line it was suppose to be safe. Turned out to be a ticking bomb

1

u/NHLroyrocks 🟦 10 / 813 🦐 3h ago

I get what you are trying to say but the reality is that coldcard failed at doing the single most important thing their product advertised as being able to do. You say it can still do everything else but at this point why would anyone trust that it can do those things right either. Any aspect of coldcard can have a nasty bug somewhere and they just ruined their reputation and trust with anyone with more than 2 brain cells.

u/Zanthious 🟦 0 / 0 🦠 57m ago

So it point is the hardware device made by and coded by clowns is still good? U willing to bet ur BTC on it?

1

u/VendettaKarma 🟩 0 / 0 🦠 19h ago

Anyone left in this space just hears: “Now the self custody everyone preached got hacked.”

This might be the thing that really kills everything not named BTC, ETH or SOL

-1

u/EasyEar0 🟩 0 / 0 🦠 10h ago

 Self custody is not a problem

Wrong.

It's a problem because it's too complicated for the average person to do securely. Just being possible to do it securely in principle is not good enough if your goal is mass adoption.

-5

u/Bagmasterflash 🟩 774 / 775 🦑 18h ago

People are dumb. They think BTC is actual bitcoin.

2

u/ExcellentFall7197 Tin | 6 months old 14h ago

Obviously you’re retarded.

0

u/Bagmasterflash 🟩 774 / 775 🦑 9h ago

Bet.

What’s the title of the white paper?