I mean look at coldcard’s blog too…
Login to reply
Replies (1)
The logic doesn’t hold. If reproducing the theft would “help attackers,” then we’re being asked to trust claims we can’t verify, which is the opposite of how Bitcoin security works. Engineers can disclose a vulnerability without publishing an exploit path, and they can demonstrate failure conditions without enabling theft.
Right now we have assertions, not evidence. “Trust but don’t verify” isn’t a security model — it’s a social request.