Don't Trust. Verify.
The Coldcard exploit isn’t just a vendor failure. It’s a community failure.
The code was available, and everyone trusted the reputation, the marketing and the assurances—but too few of us actually verified.
With AI-assisted auditing, nearly anyone can now examine open-source software and help find bugs like this. Instead everyone vibe coded new toys.
Open source only protects us when we inspect it.
It's a harsh lesson. Our hearts go out to everyone who has lost sats.
Login to reply
Replies (4)
I thought the code was not open source?
COLDCARD’s firmware source code is publicly available and reproducibly buildable, so you can inspect it, compile it, and compare your build with the released firmware.
Walletscrutiny.com gave coldcard a pass on all 10 tests. That’s as far as I can go myself.
