Let’s forget for a moment that #COLDCARD was built on the back of open-source software, including GPLv3-licensed code developed by #Trezor. Let’s forget that @N was perfectly happy to benefit from the open-source work of others, but when Foundation built Passport using #COLDCARD’s own GPLv3-licensed code, he cried foul, and #Coinkite then moved newer #COLDCARD code away from genuine open-source licensing to basically: “You can look at it, but you can’t use it to compete with us.” Let’s forget all of that. You had one job: Generate and secure the private keys. You had one job. #IKITAO

Replies (26)

Everyone has cut QA. Too expensive. Always complain about the bugs. Always wanting to do code reviews. So negative. Not fun. Signed, unemployed QA engineer
Based Truth's avatar
Based Truth 3 weeks ago
Trezor's GPL code exploited, yet nobody sues. Tells you who really holds power: corporations, not laws.
Let’s not forget open sats. Who is involved with that 501c charity and handing out grants to potential competitors. Oh wait nvk is on the board I think
the same can be argued for EVERY hardware wallet manufacturer out there, they all have had flaws or bugs that were exploited because someone didnt use a passphrase lol but if you dont use a passphrase, secure elements, and dice rolls, you didnt follow best practices then thats on you. Dont trust.
Apiarium's avatar
Apiarium 3 weeks ago
From Zach Herbert @zherbert: Regarding the Coldcard entropy bug – many folks are explaining what happened but I wanted to take a minute to explain why it may have happened. It's a disastrous situation and our heart goes out to all the Bitcoiners affected. Here's a timeline of events: On July 28 2020: @FoundationHQ announced our first Passport hardware wallet and noted that we were building on Coldcard firmware which at the time was GPLv3 licensed (FOSS license). On July 30 2020: NVK publicly said he regretted choosing GPL because Coldcard now had a “clone” and that they would change things in future updates. https://x.com/nvk/status/1288860345864527874 On November 18 2020: Coldcard added its MIT + Commons Clause license, prohibiting commercial products substantially derived from the software. On January 8, 2021: Coldcard firmware 3.2.1 formally announced, “License changed from GPL to MIT+CC on files for which the GPL doesn’t apply.” CC is the "Commons Clause" license addendum which is "source available" instead of FOSS. On March 1, 2021: The “First pass w/ libNgU” commit removed the GPL @Trezor -derived crypto libraries and replaced them with libNgU. That same 120-file commit changed seed generation code. libNgU was licensed with a novel “Licensed for Bitcoin Only” license. On March 17, 2021: Version 4.0.0 announced that all crypto and BIP39 code had been replaced and that the “last remaining GPL code” was removed. Our best understanding right now is that the entropy bug was collateral damage from this major overhaul of the codebase. To be clear, this overhaul was not solely about licensing. Coldcard also cited technical goals including adopting Bitcoin Core’s libsecp256k1, faster AES and SHA implementations, and reproducible builds. But the timeline establishes two things: (1) Foundation’s launch was the obvious impetus for Coldcard’s licensing change, and (2) removing the remaining GPL code was an explicit goal of the subsequent v4 rewrite. We don't know by how much the licensing pressure affected the scope or timeline of the rewrite. All we can determine is that the entropy bug was introduced inside the same 120-file commit that removed the old GPL code dependencies.
Bullshit. I won't be gaslit. Best practice has nothing to do with failing to do the bare minimum thing the device was advertised to do. All the best practice in the world on the user end doesn't make that fact disappear. I agree the consequences are on me. I never claimed otherwise. But I stand by every statement I've made. I also don't think you can argue every manufacturer has done this. I'm not talking about every asinine attack possible. We're talking about seed generation. A mass issue at a fundamental level. Not a stolen and somehow tampered with device using high levels of skill. A simple goofy ass attack that shouldn't have happened. Big difference. Gaslighting.
I get why you’re pissed, the Mk3 failure is real and Coinkite deserves criticism for it! My point wasn’t to minimize that or blame users. I’m just saying that over the years I’ve seen every hardware wallet ship bugs, and the only thing that consistently reduces the blast radius is sticking to best practices. I’m not defending Coinkite here, and I’m not defending users either. I’m just staying focused on threat models. So far we’ve got claims of lost funds but nothing proven or reproducible, and until there’s actual evidence, I’m keeping the conversation grounded in what we can verify.
I hear you, if you see this as a cultural or leadership failure, that’s a totally different frame than the one I’m using. I’m looking at it strictly from a threat‑model perspective, where the Mk3 entropy failure is a serious technical issue with a clear blast radius and clear mitigations. You’re talking about the organizational mindset that allowed it to exist, which is a valid angle, just not the one I’m focused on. I’m not defending Coinkite or their culture, and I’m not defending users either, I’m just trying to separate the technical facts from the social fallout. People can make their own decisions about who they want to associate with. I’m sticking to what’s verifiable and what actually affects security.
That’s kind of the core difference in our frames. I’m sticking to “verify, then trust,” and you’re operating from “trust the narrative, then interpret the facts through it.” If you’re convinced losses definitely happened, then everything downstream looks like culture and leadership failure. I’m not taking that as a given. I’m keeping my footing in what’s been verified so far. If actual, demonstrable losses tied to the Mk3 flaw show up, that changes the picture. Until then, I’m staying in the verify-first lane.
Thanks for thinking of me. I almost got caught in this. My strong passphrase saved me 🙏. Hope all has been well. I am making sure this never happens again. Never again all eggs in one basket. I was dumb for doing this to begin with I had so much blind faith.
Also remember the block clock shit. That is when I lost all trust in NVK. Unfortunately I still thought the coldcard was safe... Should have known better.
Sorry i missed this reply. All is well but very stressful last couple days 🙏. In hindsight I cant believe I put myself in a situation to be wiped out. I will learn from this. I hope you didnt have anyone close to you go through this nightmare. I missed Nostr but seems like a bunch of people went back to X and I noticed they post more there than here already.
Default avatar
Impatiens 2 weeks ago
Yet did the user documentation specifically include the step of back loading fifty prep #whatevers ?
Default avatar
Impatiens 2 weeks ago
Could anybody weigh in on whether tweet and/or noted and or any other bullshit social media micro-chasm advice is legally official product instructions that arrive with a purchased device? View quoted note →