How were you on the board of Opensats this long and never suspected that Coinkite's blatant contempt for open source development wasn't a clear red flag that their products may also be affected by such a stance, that NVK's own judgement as a board member would be affected? Open source code is not secure because more people read it, it's secure because more people use it and exercise it. No one sits and reads code unless they have a worthwhile reason to do so. And with no one able to actually use Coldcard code in their own work, no one had any incentive to externally review the code. A hasty migration between cryptography libraries introduced this zero day bug 5 years ago that could have been caught if people were building on Coldcard's code. That's just in one part of the codebase. Who knows what other zero days are lurking in any Coinkite product because of their stance on so-called "cloners?" I'm glad to see NVK stepping down from Opensats board. But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him. It's crucial to continue educating users about safe practices. But I believe it's equally crucial that you educate people about how this bug really came to be, from more than a technical standpoint. So that a disaster like this can be prevented in the future.

Replies (4)

But this incident has really shaken many people's trust in the organizations NVK was a part of, and the people who most interacted with him. blah blah blah stop making shit up nvk is nvk open sats gives money to good projects they dont need your trust
james_r's avatar
james_r yesterday
what has this bug to do with opensats, really
This is not a zero day… it’s clear to me that people’s wallets have been getting drained since this bad update came out… It’s just been "covered up and disregarded" by coinkite as a company…