Looking back over my own statements about coldcard over the years and here I am in one telling a fellow Bitcoiner that coldcard is good for single sig. the very thing being exploited. While I did push multi vendor multisig often the fact that I occasionally touted coldcard as “the best” despite having no ability to audit this claim is unacceptable to me. I fell for the social proof of technical and respected friends using it and recommending it. I assumed someone was looking. Apparently no one was. I am sorry. image

Replies (41)

One thing is to say “I’d use Coldcard” and another thing is to say “Coldcard is the best one out there”, “no comparison”, etc. Nothing to apologize for PS: thank you for the coverage you’re giving to this topic
Gaftoso's avatar
Gaftoso 2 days ago
Merely recommeding was kinda OK. Saying you don't need to roll dice or use passphrase was the problem that got ppl fucked. Never fully trust something or someone especially if you don't have the hability to verify their claims.
Even with an audit you would find the hardware RNG in the code, and maybe the backup as a fallback option which all together “runs” and rolled over for 5 years. The false security people had is staggering. I saw a yt video a few years ago that warned of the dangerously low entropy the coldcard gave and it stuck with me..
I really feel sorry for the users, they did the right thing. Self-custody plus using a HW and bought from a BTC only company
Nova's avatar
Nova 2 days ago
I commend your humility and transparency.
Bitpower's avatar
Bitpower 2 days ago
This is THE lesson and THE reason self-custody from now on will be stronger. Thank you for this honest confession.
The one thing I hope you and I and all the community learns from this is that shitty attitudes are not okay. Well, that and that open source is the only way. NVK shitting on all and any competition and scrutiny is so far from the open source ethos that we all rely on. Remember, if bitcoin had been closed source or "source viewable" we would not be here.
I have no reach but I recommended coldcard to some friends for same reason as you. One took the q but we made his entropy together. I am lucky cause an other one did not want to bother to do that but he got a jade. Thinking back about it I believe I should not have recommended things I don’t want to do myself (like using entropy I am not able to control) - I guess I did it because it’s simpler and you want to onboard people.
Single sig is flawed, multi sig is key, like eating only organs for optimal security and nutrition.
Benking's avatar
Benking yesterday
@HODL , I don’t think you owe anyone an apology. You acted on the same information that a lot of smart people trusted.🧡🫂
The sad reality is that for off the shelf options, it was the best. If you followed the best practice of rolling dice. Their messaging around this was problematic, but the paranoid guide specifically says the TRNG method involves the most trust. The rest of the market is full of shit that requires their software, isn't airgapped, supports shitcoins, phones home, or some combination of the above. Simply avoiding all of that made Coldcard the obvious choice -- but that doesn't mean trust them more than you had to (or that it was a good choice -- just better). The real best option is and always has been airgapped DIY options. Glacier protocol if you wanna really do it up, or krux/seedsigner as more realistically in reach options. Or an airgapped laptop (but maybe flash clean BIOS to be sure you don't have malware right on the motherboard). And for the love of God roll the damn dice.
I recommended cc for single sig as well. I am fortunate that the people I did recommend to were able to get out in time though. I wish I knew how I could verify things myself so that I can confidently make recommendations moving forward.
you can make it up to us lol by making a vlog 🎶 and shooting some guns!
@HODL IMO the problem isn’t you or anyone else with a large following in the space. It’s the hardware manufacturers. They need to do better. It is still way too damn difficult for a newb, a pleb, or better yet a moron to properly secure their corn. You guys all think it’s easy because you’ve been in the space and have experience. Im on the ground. NO ONE understands this stuff properly and EVERYONE is scared to use it properly. It is a huge road block to Bitcoin adoption. Everyone would do stuff like dice rolls, multisig, etc. if the devices were more user friendly and instructions made absolutely idiot proof.
social proof can mask a lot of potential entropy. the vulnerability highlights that even with hardware, trust needs constant re-auditing, not just reputation. a good reminder for any system, digital or otherwise.
HODL's avatar HODL
Looking back over my own statements about coldcard over the years and here I am in one telling a fellow Bitcoiner that coldcard is good for single sig. the very thing being exploited. While I did push multi vendor multisig often the fact that I occasionally touted coldcard as “the best” despite having no ability to audit this claim is unacceptable to me. I fell for the social proof of technical and respected friends using it and recommending it. I assumed someone was looking. Apparently no one was. I am sorry. image
View quoted note →
Not sure if this is it. I watched the video and the danger he points out is not the ColdCard's onboard entropy generation, but the ability to create a wallet using dice rolls alone and people creating wallets with too low an amout of dice rolls (less than 50). His problem is that the UI doesn't prevent people from creating wallets with that few dice rolls, and that it can appear that the dice rolls are being added to onboard RNG, when that is not the case when the user selects dice only. In fact, his advice is the same as what got us into this mess: "Just trust the onboard RNG if you don't know what you're doing. Maybe add a passphrase, but even that can be dangerous because the more you complicate your setup, the more likely you will forget how to access your funds and lose all your money." From what I could tell, he had no warning in the video about the onboard RNG for creating adequate entropy whatsoever.
I'm not gonna win any popularity points for saying this, but... Anyone who was sophisticated enough to buy a ColdCard for its advanced security features, yet wasn't paranoid enough to add a passphrase - even if only a single 25th word... Well that's just kinda silly imho. Could of bought enough time to save the stash.
What for me is unacceptable is that you're punishing yourself for listetning and learn with other people. People shouldn't punish themselves for recommend things. - Are you a security expert? - Were you in the past with the skill, time and incentives of make an auditory? Is that your modus operandi everytime you recommend something? Come on, stop it. You're not the one who failed in security measures, that's the company. You were giving people what you thought was a good product and it wasn't. Period. Don't look anything more. Have you studied the Bitcoin source code line by line? No? Then you’re trusting it, not verifying it for yourself. Like me and I speak for the for 99% of people, some degree of trust is unavoidable. Break your bubble. Don't be harsh to yourself, keep building. Keep recommending stuff, keep stacking. Is this a hard one? Well, yes. Is the end of all things? No. View quoted note →
FOSHOYO 's avatar
FOSHOYO 22 hours ago
Props for owning up. This type of action only leads to increased capacity and capability within ourselves. Keep on keeping on brother 🤙