Agree. Although I don't think people should have audited ColdCard necessarily. It's the job of the company behind it, they are selling a security product. Not auditing and not having a bug bounty program is a much bigger failure than having the bug itself. Bugs happen, but a security company yoloing it is a borderline scam. I'm happy I've never used it and never recommended it (open source Trezor is a much better deal). Otherwise very good post and I agree it was not a conspiracy. Very few things are. Conspiracies are hard to coordinate, harder to keep secret and even harder to have intended effects. View quoted note →

Replies (1)

I never was so deep in this project to know about this points, because I had a bad feeling about their moral integrity. Happy to see my intuitive bullshit detector worked again. And sad so many people don’t have such detector, even they seems much less autistic.