The folks who got burned by coldcard have something in common with the folks burned by BIP-110:
they placed too much trust in social signals and neglected to do their own independent research to form conclusions.
Login to reply
Replies (28)
Honest question: how would independent research have prevented people from the coldcard burn if they can’t read code? I mean, even the people who could understand code missed it, right?
By understanding that every piece of software and hardware is flawed and shouldn't be trusted to be a single point of failure for your life savings.
Ideally, independent research would have led someone to the conclusion that they should not be relying on a device to tell them what their seed words will be. (i.e. generate them for yourself with dice, coins, whatever you have complete control over to validate for yourself - and make sure to do the research on generating seed words from dice, coins, whatever to make sure you're doing it safely).
That said, I think it's worth answering this question from the perspective of many of those who DIDN'T get burned by coldcard just because they happened to not like its creator:
video from about 50:25 -
I know that a hardware wallet should be required and expected to provide great randomness for seeds. But how do you validate that? So, you know what I mean? Like, if there's no way to validate it, then what's the point? What is the point?
And so, this is again, if you're learning the wrong lessons, the wrong lesson would be, "Thank God I didn't trust NVK. That guy was a dickhead. You know, pat on the back. I was smart not to trust him and so I'm good."
No, that's the wrong lesson.
Or, this is, okay, you know, yeah, this is isolated to this one thing, and if you didn't get taken by this one thing, you're good.
That's not the lesson.
The lesson is, do you actually know that you're good? And how? And I'm sorry, but if you're trusting a hardware wallet, random number generator without seeing like a robust review, I think you're fooling yourself.
If there was independent research chastising ColdCard, I didn’t see it. And I was actively looking…
Give me a fucking break. All those creepy clues left by the Coldcard team??? It was an inside job and a rug pull
All 110 supporters were burned reputationally.
Unfortunately they didn't get burned economically (yet) since they had no conviction to engage in fork futures.
Listening to experts is just another form of social signals because it's social consensus to deem someone an expert.
Lived this one last week. My Knots node was running the bip110 patch — it froze on the two-block minority chain at 961633 while the real chain ran ~330 blocks ahead, and my Lightning node sat blind for two days. No feed told me. getchaintips and pinning the fork point against an explorer did. Social signals are testimony; the chain is the ledger. Ask the thing itself.
If every piece of software and hardware is vulnerable what are the odds of a 2 of 3 multisig being compromised?
Given a long enough time horizon 100%, the chance of two of them being compromised at the same time and putting you at risk is much less.
Nope. They got burnt by negligence of the company that failed to do what a closed source shabby wallet can do.
Seen.



To be frank back in my day something like this happens and you were supposed to be embarrassed, not blame anyone else. Both sides (champions and supporters) lose reputation and gain shame. But that is not the modern world anymore.
You still have to know that the hardware wallet or seed signer correctly uses the randomness provided by the dice rolls.
Absolutely: A signer provided with a seed that it has not itself generated is still required to use that seed correctly.
Unlike randomness, however, this is functionality that can be deterministically reproduced with other signers... which would suggest both a) it's reasonably easily verified by a layman; and b) any such failure to function correctly wouldn't go unnoticed for more than about 5 minutes; let alone 5 years.
Wow, I gotta say I’m a bit baffled.
Disagreements aside it is a bit harsh to wish someone gets burned whilst holding BTC. It wouldn’t inspire trust and improve adoption of BTC, similar to the Coldcard debacle.
I wouldn’t have expected such a wish from a BTC OG as yourself. Keeping the disagreements civil and and within tjhe bounds of BTC consensus should be enough.
I don’t agree and the ”experts” concept either, respectfully.
Regardless of the expertise level people make mistakes and so called expert have biases and personal interests.
Keeping one’s wits and making up one’s mind based on broader social signals and not an expert’s sole opinion surely is a sounder way to do things.
In a world where information is abundant and ”experts” gladly promote for clicks, it is imo a sounder approach to increase the broadband of information and expertise from both sides of the rift.
When I do though read you wish people got financially hurt because of a different opinion, it doesn’t help you winning points in my book
Idiotic, destructive take
Yes, trusting folks leads to destruction. This happens time and time again.
I'm not here for your points.
Bitcoin governance battles are intellectual and economic wars. No one has to participate, but if you do, know that the losers get punished one way or another.
The neat part is you can just use Bitcoin without having any involvement in protocol development debates.
It depends on how diversified a number of variables are in the multisig setup.
If Alice can rug your funds in wallet A and Bob in B, you not only need wallet A and B to be compromised but also Alice and Bob to collaborate to steal your funds out of an A/B/C multi sig.
You can’t have a functioning society without trust. Most of the problems we’re having today are due to our high-trust society breaking down after perhaps 1,000+ years.
I don’t think you can remove the need for trust. It’s not even feasible for any one person to know how to make “I, pencil”, let alone for everyone to verify how their cars or hardware wallets work.
A much lower bar is for us to be able to trust that our community leaders - most of whom are independently wealthy - wouldn’t be shilling a product for years without ponying up for some basic due diligence.
You say that but expect your curstomers to trust you.
We’re not all highly intelligent computer nerds. Sometimes we have to go with our gut
and, in such a case, both Alice and Bob will be free to go fuck themselves, thoroughly
In fact working outside of bitcoin, ignoring almost everything, stacking with self/collab-custody is zen-like
HAH! what research was it to be done about Core? 👀
View quoted note →