What incentive did Coldcard have to intentionally create the vulnerability? I do not see one. So was it an unintentional error which no one found in open source code for ~5 years? I feel horrible for all involved. Because, at the end of the day, the only people we have to blame are ourselves. We each choose the trust that we extend. And, we are also the only ones that can forgive ourselves and move forward.

Replies (1)