Replies (26)
Yeah. This is a ginormous fuck up. QA? What QA??
They can't recover from it in my mind. They failed to do the one fucking thing people paid them to do. Game over. Fucking close shop. This isn't something I'm willing to give grace on. I'll give humans grace if they deserve it, but not a company. Not for this. Done.
Everyone has cut QA. Too expensive. Always complain about the bugs. Always wanting to do code reviews. So negative. Not fun.
Signed,
unemployed QA engineer
This is rich…
NVK who sat on Seedsigner domains for years all while producing vulnerable wallets…
Oh the irony 😂
Trezor's GPL code exploited, yet nobody sues. Tells you who really holds power: corporations, not laws.
Let’s not forget open sats. Who is involved with that 501c charity and handing out grants to potential competitors. Oh wait nvk is on the board I think
the same can be argued for EVERY hardware wallet manufacturer out there, they all have had flaws or bugs that were exploited because someone didnt use a passphrase lol
but if you dont use a passphrase, secure elements, and dice rolls, you didnt follow best practices then thats on you.
Dont trust.
What does it say? Some people don't use twitter...
From Zach Herbert @zherbert:
Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened.
It's a disastrous situation and our heart goes out to all the Bitcoiners affected.
Here's a timeline of events:
On July 28 2020: @FoundationHQ
announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license).
On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates.
https://x.com/nvk/status/1288860345864527874
On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software.

GitHub
dev squashed · Coldcard/firmware@b6b9191
❄️ Firmware and simulator for Coldcard Hardware Wallet - dev squashed · Coldcard/firmware@b6b9191
On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS.
On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor
-derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license.
On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed.

COINKITE Blog
Version 4.0.0 Released (Major Internal Improvements)
All New Code, Same Great Features

GitHub
firmware/releases/ChangeLog.md at b18723dddb6d751c39978e4364b56b2414f68b47 · Coldcard/firmware
❄️ Firmware and simulator for Coldcard Hardware Wallet - Coldcard/firmware
Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase.
To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds.
But the timeline establishes two things:
(1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and
(2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite.
We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.
Bullshit. I won't be gaslit. Best practice has nothing to do with failing to do the bare minimum thing the device was advertised to do. All the best practice in the world on the user end doesn't make that fact disappear.
I agree the consequences are on me. I never claimed otherwise. But I stand by every statement I've made. I also don't think you can argue every manufacturer has done this. I'm not talking about every asinine attack possible. We're talking about seed generation. A mass issue at a fundamental level. Not a stolen and somehow tampered with device using high levels of skill. A simple goofy ass attack that shouldn't have happened. Big difference. Gaslighting.
I get why you’re pissed, the Mk3 failure is real and Coinkite deserves criticism for it! My point wasn’t to minimize that or blame users. I’m just saying that over the years I’ve seen every hardware wallet ship bugs, and the only thing that consistently reduces the blast radius is sticking to best practices.
I’m not defending Coinkite here, and I’m not defending users either. I’m just staying focused on threat models. So far we’ve got claims of lost funds but nothing proven or reproducible, and until there’s actual evidence, I’m keeping the conversation grounded in what we can verify.
This is of course all my opinion. If people want to continue associating with them, be my guest. The leadership is fucked and I think that's the root of this mess.
I hear you, if you see this as a cultural or leadership failure, that’s a totally different frame than the one I’m using. I’m looking at it strictly from a threat‑model perspective, where the Mk3 entropy failure is a serious technical issue with a clear blast radius and clear mitigations.
You’re talking about the organizational mindset that allowed it to exist, which is a valid angle, just not the one I’m focused on. I’m not defending Coinkite or their culture, and I’m not defending users either, I’m just trying to separate the technical facts from the social fallout.
People can make their own decisions about who they want to associate with. I’m sticking to what’s verifiable and what actually affects security.
I am using the frame that the losses are real. And I believe that culture and leadership led to them. To be clear. I don't think the issues are separate.
But that connection IS opinion.
That’s kind of the core difference in our frames. I’m sticking to “verify, then trust,” and you’re operating from “trust the narrative, then interpret the facts through it.” If you’re convinced losses definitely happened, then everything downstream looks like culture and leadership failure.
I’m not taking that as a given. I’m keeping my footing in what’s been verified so far. If actual, demonstrable losses tied to the Mk3 flaw show up, that changes the picture. Until then, I’m staying in the verify-first lane.
Thanks for thinking of me. I almost got caught in this. My strong passphrase saved me 🙏. Hope all has been well. I am making sure this never happens again. Never again all eggs in one basket. I was dumb for doing this to begin with I had so much blind faith.
Of course. Glad to hear that. Hope you and the family are well.
Also remember the block clock shit. That is when I lost all trust in NVK. Unfortunately I still thought the coldcard was safe... Should have known better.
Sorry i missed this reply. All is well but very stressful last couple days 🙏. In hindsight I cant believe I put myself in a situation to be wiped out. I will learn from this. I hope you didnt have anyone close to you go through this nightmare. I missed Nostr but seems like a bunch of people went back to X and I noticed they post more there than here already.
So glad I decided not to get the Coldcard after I found out what NVK did with their licensing after Foundation announced its hardware wallet. Felt bad since you were so kind as to contribute toward it. Now, I am certain it was the right decision to go with something else.
HMU on X.

X (formerly Twitter)
Ava Aum (@avaaum) on X
Spirituallly incorrect mystic. Helping people master the integrated path to true freedom
Founder @_ikitao
I'll follow back.
Yet did the user documentation specifically include the step of back loading fifty prep #whatevers ?
It isn't, like, illegal to be incompetent in this field, is it?
Could anybody weigh in on whether tweet and/or noted and or any other bullshit social media micro-chasm advice is legally official product instructions that arrive with a purchased device?
View quoted note →