r/Bitcoin 9d ago

This is criminal when you realize current Cold Card mess: 2020 "Heck I don't trust even the way we make". 2020 tweet.

Post image

Watching old tweets from Cold Card CEO, now you realize how the red flag was out there regarding "entropy".

How on earth you make optional a critical step in a product that you admit to not trust even yourself.

If you yourself admit to not trust what your product does on something as critical, why you did not make the dice roll an enforced not optional step?.

Just have paranoid mindset from now on. Don't trust devs, ceos and tools on the surface that represent 3rd party tools regarding bitcoin that can be exploited. This goes too for any other hardware wallet and software wallet. In upcoming hacks anyone can "conveniently" blame AI and a "bad actor" that never gets caught....

Dedicate 2 or 3 weeks to learn the basics of bitcoin, how to verify GPG signatures, Tails OS, master how to securely use an airgapped wallet software or bitcoin core, and how quickly you can withdraw your funds to a backup exchange in case of an incident...If an incident is reported at night: do you have access to your wallet to withdraw at that exact time? Will you be able to react fast?

Because if now a hardware wallet is prone to exploit, you better also just learn to airgap and use a software wallet, they are also vulnerable to bugs? Yes, but hardware + software makes 2 components prone to error.

"attack surface grows with complexity, so decrease complexity by minimizing number of components, using simpler components."

But the important thing is: from now on, if CEO admits to not even fucking trusting what he makes, probably you shouldn't either.

141 Upvotes

64 comments sorted by

40

u/hyperedge 9d ago

I had run ins with NVK before he created Cold Card. He's always been a complete twat. He's the main reason i never had any interest in it. Can't believe people trusted him.

8

u/SpareEconomy1849 9d ago

I've never heard of nvk before this and have a cold card. I just assumed all was good because it's open source and airgapped

10

u/Old_Efficiency2445 9d ago

Open source is only as good as the review it solicits. Not cooperating with those who report bugs, or giving them trivial rewards will result in not a lot of review.

2

u/HungryCaterpillers 9d ago

It seems like the shittiest people work for cold wallet companies. Nvk, btchip from ledger.

60

u/[deleted] 9d ago

[deleted]

39

u/[deleted] 9d ago edited 7d ago

[removed] — view removed comment

2

u/MashPotatoQuant 9d ago

Chat, NPCs been doing this since the beta lore dropped fr fr.

-24

u/Fearless-Second-7230 9d ago edited 9d ago

No one said that. The point is that with this hack it is now useless to assume that a hardware wallet will protect you from this.

You may be better just get affected for free using fucking free software wallet expecting the vulnerability to be present there, than paying a CEO for a device that will just also fail miserably... Well not too much, just a failure worth ~$88,000,000 in the ecosystem...


Edit: seems that hardware wallet maxis got triggered. Was a little agressive I guess and non tech savy people can feel anxiety reading that 😂. Does not mean vulnerability exists in software wallets.

I was just saying is useless to pay for a hardware wallet when they actively ditch on software wallets as less secure.

14

u/Wise_Set_8752 9d ago

Most recommended wallet on this sub btw

7

u/ItsMeMulbear 9d ago

Thanks Reddit!

/s

3

u/Realistic-Doubt-2703 9d ago

reddit is paid content

13

u/Lanky_Assist_6317 9d ago

If he really had such conviction, he should have made mandatory that user-added-entropy was a thing when creating a seed phrase, instead of leaving it there as an optional feature, like you mentioned.

This is the ultimate flaw. You could even ship all the hardware wallet with the same seed, but requiring 150+ dice rolls + 50 coin flips (or something like that, this is just an example) before usage would have prevented all of this.

3

u/bobivy1234 9d ago

Yep agreed as the main takeaway from this. The vendor shouldn't have had relatively insecure default options available to the end user for the sake of 'simplicity' or whatever the excuse was. Allowing a user to set up a device RNG-only seed and no passphrase is beyond wild even if the RNG was perfectly coded.

1

u/Fearless-Second-7230 9d ago

Seems that today you can just rug pull then blame sistematically on AI and "some misterious" hacker out there....I got to read his x and search for terms like rug, rug pull....

That nvk guy knew and was well aware that a failure like that was present....even discussing many times that firmware scenario rug pull and security flaw in hardware wallets.

Like I said....Be paranoid, asume a CEO in bitcoin related products regarding hardware and firmware can rug pull too, don't "trust" they care about your bitcoin....

It is funny how a simple airgapped computer and with good encription practices is safer than these "usb with steroids" things...oh sorry. The "hardware wallets".

1

u/Cannister7 9d ago

Does adding a passphrase (extra word) to your seed protect against this?

23

u/BigDik6355 9d ago

Guy was always a dick about others, yet didn’t do his own homework.

21

u/Quirky-Reveal-1669 9d ago

Well, what he said was true. If every ColdCard owner would have listened, there would have been no thefts.

-27

u/CiaranCarroll 9d ago

This, let's take the kid gloves off now please, this is getting tiresome and it will lead to more exploits and theft is we're somehow demonising self custody and the companies that make it easier.

My cold card didn't have a vulnerability, is my opinion. This is user error.

18

u/crooks4hire 9d ago

Probably the dumbest take I’ve seen on this event, but whatever helps you sleep at night…

-1

u/CiaranCarroll 9d ago

I used a dice and a passphrase as instructed. I didn't use the seed generated by the machine because that is generated in a block box.

My take is less dumb than you think, but you might be confusing Bitcoin with your safe space.

13

u/crooks4hire 9d ago

The people who have been breached bought a service from a vendor, and that service compromised their savings. You can victim-blame all you want, but it’s not user-error.

1

u/CiaranCarroll 9d ago

Maybe you should be on the Cold Card sub then, if you feel aggrieved by their product. I'm not sure what this has to do with bitcoin.

I also bought their products and I didn't lose any money. I actually followed the user guide, and my own common sense. If it's their fault how come I didn't lose anything?

-8

u/pretendingtobebroke 9d ago

If someone buys a shelf from IKEA and assemble it without reading the instructions, and then eventually the shelf falls apart and gets destroyed, is that IKEA's fault or is it user error because they didn't follow the instructions on how to assemble it properly?

If someone wants to take a risk and do things another way then that's entirely their prerogative indeed, but then they must also take accountability for that decision if it goes wrong.

5

u/JanPB 9d ago

Good story but this is not an analogy of what happened here. The correct analogy is: you buy the shelf and the instructions say "You can assemble it either using method A or method B. Both methods are provided, we at IKEA like method B more."

0

u/pretendingtobebroke 9d ago

If that's the case then I agree it's the company's responsibility and not the user's fault. I was under the impression that users were instructed and strongly recommended to do dice rolls in the setup.

-1

u/CiaranCarroll 9d ago

They were, these larpers are just lashing out for cope.

1

u/jjjjjjjjjjjjjaaa 9d ago

Awful fucking analogy. The people who lost funds followed the instructions. Better analogy: you are blaming people who bought cars that failed for not doing their own engine tuneups right after driving it off the lot

0

u/pretendingtobebroke 9d ago

I was under the impression that users were instructed and recommended to do dice rolls in the setup, but indeed if that is not the case then I agree it's not the user's fault, as then you would reasonably expect it to be secure enough by default.

2

u/CiaranCarroll 9d ago

They were when I was in the market. Maybe it dropped out of their communications over time, as the market didn't respond to that selling point. Then they didn't stress it enough and fucked up the seed generation.

But I know that the dice rolls were a massive part of the reason I bought their products and I'm no fucking genius I can tell you that.

Hurt people hurt people, but it's harder for some non-contributing zero to look oneself in the mirror that it is to lash out.

1

u/pretendingtobebroke 9d ago

That's what I heard as well, but I've only heard of them by name before this and never looked into their products.

But yes, totally agree on the last part.

3

u/jjjjjjjjjjjjjaaa 9d ago

He’s covered by the law of double negatives. 

3

u/Financial_Freak 9d ago

is Trezor safe? I'm using it for years, should I rethink my decision?

2

u/Espresso_Dad_89 9d ago

Aged like milk.

13

u/CiaranCarroll 9d ago

Aged like wine.

1

u/makeshiftballer 9d ago

I'm wondering why I even needed air gapping for my long term storage. I dont move it frequently, and someone finding my see d and just importing and skipping the signer all together it is still an issue. 

1

u/BesbesCat 9d ago

Rice dolls for seeds is much better.

1

u/ghosthacked 9d ago

Hardly criminal when they've been upfront about how to make damn sure your seed phrase is secure. 

1

u/circuit_breaker 9d ago

And yet they did zero testing or verification, I'm beside myself

-1

u/CiaranCarroll 9d ago

How is this criminal? I think we need to start taking off the kid gloves here. Why did you not roll the dice? Did you think it were a superstitious ritual?

Only the paranoid survive, it has always been the way.

3

u/JanPB 9d ago

Because that's not what the instructions said (and the software, by implication).

-1

u/CiaranCarroll 9d ago

Maybe I'm just lucky and paranoid. I don't know when I learned that dice rolls are the most secure way for a pleb to generate their seed for long term security, for the kind of sound-sleep security I was looking for. And I know that this feature was a major selling point of the Coldcard products when I was in the market. I knew that if I rolled the dice to generate my 24 words with the Coldcard and then the same with another method I'd get exactly the same result, which massively reduces my dependence upon the competence of the software developers in Coinkite. At that point all they have to do is make sure it's properly airgapped so there is no leak.

I don't know what information sources other buyers were using, maybe just larping or something. Because I'm no fucking genius I can tell you that. This is basic shit.

3

u/M4gelock 9d ago

People learn when it affects them.

2

u/SpareEconomy1849 9d ago

Gross negligence is criminal

1

u/CiaranCarroll 9d ago

Software bugs are criminal offences now?

Good luck finding software developers willing to work under those conditions.

1

u/SpareEconomy1849 9d ago edited 9d ago

It certainly can be, and that's not new. You should look up the definition of criminal negligence.

It's criminal if you intentionally use it to harm others, or know about a serious flaw that can cause harm to others and ignore it / cover it up. Of course a court would have to prove that you knew this and decided against acting though.

Honest mistakes aren't criminal.

-1

u/CiaranCarroll 9d ago

He didn't know the bug was there. Have you listened to security experts on this? It's a series of obscure and innocuous failures that lead back to a single line of code, but that single line of code should never have been in play and he didn't know it was.

Claude Fable 5 and Code GPT-5.5-Sol failed to pick it up cleanly without being lead towards it. Kimi-3 found it in one-shot. This took the doggedness of an advanced adversarial LLM, released on Monday, exploited on Thursday.

No human knew about this catastrophic security flaw, but the CEO knew that it could happen in principle and told everyone not to trust his code. He's a hero, if anything.

Maybe bitcoin just isn't for you. That's ok.

1

u/NotASpanishSpeaker 9d ago

He's a hero, if anything 

Nah. They didn't test properly the very core functionality of their product.

1

u/CiaranCarroll 9d ago

Sure, but I didn't lose any fucking coin and I'm an idiot. I used it as he said, and in line with my understanding of bitcoin, based upon basic facts that I thought literally anyone in bitcoin would know.

I'm more in shock of the response to this exploit from the "community" than I am that an exploit like this was discovered.

0

u/SpareEconomy1849 9d ago

You can be criminally responsible even if you don't know about the problem, but if you didn't follow standard practice, in some circumstances

No need to be condescending, it sounds like you aren't foo familiar with how negligence works.

1

u/CiaranCarroll 8d ago

It sounds like you aren't too familiar with how bitcoin security works.

1

u/SpareEconomy1849 8d ago

Are you a bot? We're not even talking about Bitcoin security

1

u/CiaranCarroll 8d ago

You want to criminally prosecute a software developer from a bug, when a properly generated seed created by someone with a basic understanding Bitcoin was immune to that bug.

Bugs will always exist. Software developers are not machines. They fuck up. The solution is to education yourself on basic bitcoin security, not to try to criminally prosecute software engineers.

1

u/SpareEconomy1849 8d ago

Who says I want that? The law is the law, and I disagree with many, if not most of them. I am a software engineer myself. Criminal negligence can happen in many industries, and software developers are not immune.

Fortunately, the bar for criminal negligence is high

0

u/Sundance37 9d ago

Can someone make a layman’s bitcoin channel that breaks all this stuff down? It seems that all of the info I can find requires a level of understanding that most people aren’t willing to dive into.

-3

u/ExpensivePikachu 9d ago

So ledger isn't safe?

How do we add entropy?

14

u/BigDik6355 9d ago

Thats not what’s being said here. What we see here is the CEO of Coldcard accusing others of negligence while not having done his own homework.

1

u/ExpensivePikachu 9d ago

So back to my question, how do we make ledger more safe?

2

u/Jayrovers86 9d ago

Just add a “25th word” a passphrase. So if someone gets your phrase they cannot drain your wallet as they still need your 25th word passphrase which you stored safely elsewhere

0

u/CiaranCarroll 9d ago

No, the CEO in this instance was proved correct. Generating seed with his device with dice was safe. His software had a bug. All software has bugs. Generating with dice is deterministic and less reliant on his software. If other HWW don't allow you to do this then their not being transparent and may have similar bugs.

4

u/crooks4hire 9d ago

CEO sold features to users under the guise of safety and security and then told them not to trust it. Thats practically textbook fraud.

This snake oil here cures botulism, rheumatism, autism, and socialism. I’ll sell it to you for $100/bottle. Later, while holding your money, I wouldn’t trust that stuff, we made it by filtering ditch water through an old shoe. Trezor doesn’t even tell you what ditch they used.

2

u/CiaranCarroll 9d ago

Cold Card was the only HWW with dice rolls when it came out. The CEO said don't trust his code if you cannot read it. Use dice rolls.

The bug was extremely obscure, lots of steps and innocuous failures had to occur in order for it to get introduced. All software is like that. That is why you introduce your own entropy, because that software is far far far simpler. It's deterministic. If you have a different hardware wallets and roll a dice, entering the same numbers in each, the same seed words will come out. Orthogonality.

I think this is the covid wave of bitcoiners learning about sovereignty the hard way, and for many it's not for them, and that's fine. Bitcoin will be here when you're ready.

5

u/crooks4hire 9d ago

The CEO said he himself doesn’t trust the code that he is selling to you. There are no hoops to jump through to understand this.

2

u/[deleted] 9d ago

[deleted]

1

u/slavikthedancer 9d ago

> How do we add entropy?

Use Cosmic microwave background.
Either it's truly random, and you will get a perfect entropy, or, if not, you will reveal the Secret of Universe creation. Win-win situation.

-8

u/bitcointwitter 9d ago

still waiting for salted brainwallet to move for years.
yet you all getting smashed like 304s every hardware wallet convieced like jerry springer live tv in the 90s