With so many Spark wallets popping up, can someone ELI5 to me why we're OK with a trust model that requires that all spark operators don't collude given that from what I can see there are only 3(?) Spark operators and no clear understanding of how you'd become a Spark operator?
I'm sure I'm missing something, but if not, seems crap.
Also, not having an optional first-party companion app is a major downside. This could've been handled much faster and with less friction if there was an app flow that a) alerted to a signer having a vulnerable firmware. b) initiated a migration tx to a new seed as soon as the device firmware is updated (possibly a hop to a software key in the interim if the signer can only have one active private key).
If Bitkey can do it (ex: the enhanced privacy upgrade requiring a new key - seamless flow) every company should have a similar flow ready for this type of situation.
It should only take a couple of clicks.
A somewhat gross but nonetheless true statement:
In the grand scheme of things ~90M USD in drained ColdCard wallets is a drop in the ocean. I'd wager that ColdCard's marketshare isn't even that significant in the grand scheme of things.
What particularly sucks is that these are pretty much all from plebs who worked their assess off to stack that corn. And ironically from those who probably tried to go the extra mile to get something more "sophisticated". It's "only" 90M but the impact this loss has on those affected is immense.
I feel like the "dice roll only" advice is going to bite some noobs or people who mishandle it. There is nothing wrong with hardware RNG or the RNG sources used by any hardware signer. What happened to ColdCard is a fail-open fallback to software PRNG.
At least ask that people use methods that use dice rolls as a supplementary entropy source, not the sole one - if at all.
I see people saying this Coinkite/ColdCard incident will reduce confidence in self custody.
It shouldn't. This was an amateur flaw in a company run by a narcissist who should've never been trusted to begin with. If you ignore the red flags around their hostility towards FOSS, seedsigner (including squatting seedsigner.org btw), then I don't know what to tell you.
Maybe if nvk spent less time shitposting and more time auditing his garbage, we wouldn't be here.
If you're going to use a hardware signer, use proper hardware signers from serious companies who have their work audited... especially you know, the bits around fucking entropy and seed generation, fundamental parts of a fucking hardware signer.
And it should go without saying that "influencers" who shill this garbage should reconsider.
Sympathies to everyone affected.