Bullshit. I won't be gaslit. Best practice has nothing to do with failing to do the bare minimum thing the device was advertised to do. All the best practice in the world on the user end doesn't make that fact disappear. I agree the consequences are on me. I never claimed otherwise. But I stand by every statement I've made. I also don't think you can argue every manufacturer has done this. I'm not talking about every asinine attack possible. We're talking about seed generation. A mass issue at a fundamental level. Not a stolen and somehow tampered with device using high levels of skill. A simple goofy ass attack that shouldn't have happened. Big difference. Gaslighting.

Replies (1)

I get why you’re pissed, the Mk3 failure is real and Coinkite deserves criticism for it! My point wasn’t to minimize that or blame users. I’m just saying that over the years I’ve seen every hardware wallet ship bugs, and the only thing that consistently reduces the blast radius is sticking to best practices. I’m not defending Coinkite here, and I’m not defending users either. I’m just staying focused on threat models. So far we’ve got claims of lost funds but nothing proven or reproducible, and until there’s actual evidence, I’m keeping the conversation grounded in what we can verify.