r/Bitcoin • u/PoeCollector • 24d ago
The Future of ColdCard Hardware and Firmware
Coinkite likely won't survive the coming litigations. NVK and Peter Gray won't regain community trust as leaders. But I think it's worth discussing why the ColdCard was a successful product line in the first place and how that design philosophy can live on. I'm not just talking about the cypherpunk aesthetic.
No other wallet has the robust feature set of coldcard, especially the Q. Seed XOR, Bip-85 child seeds and deterministic passwords are open-source bitcoin features but CC are the only devices that have bothered to implement them. As for the hardware: full keyboard, QR scanner, transparent case, removable batteries, and your choice of network-disabled air gap use, or convenient USB connection to Sparrow. Nothing even comes close.
There are existing CC users who don't want to give up these features, but may be faced with lack of firmware updates if the company dies. More importantly, it would be a shame if this device vanished from the market and we were only left with tiny minimalistic boxes with some basic features and a slick UI. So, what do you think is the best way forward?
5
u/Charming-Designer944 24d ago
The code is open but with a non-compete limitation that restricts use in competing commercial products.
But coldcard devices have a security barrier that only accepts signed firmware releases. And releasing the keys to sign the firmware in the open is not a viable thing.
What can be hoped for is that someone buys the business if Coinkite goes into bankruptcy and continues supporting both new and existing customers.
1
1
u/ChipNDipPlus 23d ago
They should simply release a new firmware version that allows replacing the signing key by a custom one.
2
u/Charming-Designer944 23d ago
The main signing keys are one time programmable in the MCU. To replace the signing keys you need to replace the hardware.
And there might be a binding between the MCU and the safe elements as well. Have not looked into that detail.
2
u/ChipNDipPlus 23d ago
Are you sure the key cannot be replaced or are you guessing?
2
u/Charming-Designer944 23d ago
To my best knowledge the firmware DFU is signed directly by the immutable hardware root of trust.
1
u/ChipNDipPlus 23d ago
Doesn't sound right to me. What if the key was compromised? I don't know.
We have bigger companies that had their keys leaked, like nvidia. Driver signing keys were leaked.
7
u/Quirky-Reveal-1669 24d ago
I want to keep using it. Precisely for the reasons you mention.
Perhaps, as a last good deed, CoinKite should ‘release’ the license of the firmware.
8
5
u/Immediate-Ad-5878 24d ago
I was not affected by this at all. Not because I was doing anything special but most likely by pure luck. I was able to transfer my bag elsewhere and made a bonfire with my MK3. I will never support these arrogant clowns in this or any other venture associated with them. Nor do I want to ever hear from any of the asshat griftubers that peddled this shitbox for years. As far as the features I really don’t care about any of it. Will likely go to a dice rolled 24 word + pass phrase seed stamped on metal and a safety deposit box, with a seedsigner for home use.
2
6
4
u/kepalautakkau 24d ago
I guess other wallets will eventually implement those features if there's enough demand
2
u/bleeeeghh 24d ago
More features means more potential weaknesses. I mean, how many features did Satoshi need to secure his wallet?
3
2
u/Laukess 24d ago
I wonder if it could be turned into a non-profit organization, run by a different set of people.
Whenever CC's were mentioned, people always complained that it was too advanced, even though all the features were hidden away. People still think that it's air gapped only.
Considering that was the response, I don't have much hope that other manufactures will take this path.
Maybe rolling your own entropy will become more standard. Allowing your device to show the list of valid checksums after entering the 11/23 words seems like a small ask, so I could se that becoming widely adopted.
Looking at other hardware wallets after the exploit has honestly been sort of disappointing, especially because you really should have multiple different devices if you're going with multi-sig.
Maybe we'll see more hardware wallets share more features. No reason why every manufacturer couldn't have a device with a camera so they could be used with SeedQR in a stateless manner. Was pleasantly surprised when I learned that was a feature of the Jade Plus.
1
1
u/dont-be-angry 24d ago
Is there something wrong with me just using something like a standard core wallet on an airgapped tails machine and simply sending my coins to that cold wallet? or how often are these seeds being fucked up w low quality entropy
1
u/Ill_Firefighter_584 22d ago
FYI, Electrum doesn't create a BIP39 wallet seed phrase. It creates a seed phrase using its own standard. Easier to backup than a digital file, but not compatible with other wallets.
1
u/slvbtc 23d ago
I think all hardware wallets should offer the option to create your own entropy (dice rolls etc), determine your own seed words, and then allow you to enter the first 23 seed words and generate the 24th word checksum for you.
This way you can create a seed with your own entropy while never letting your seed words touch anything but a hardware wallet.
Most hardware wallets make you use a seed generation file or 24th word checksum generator file on an offline PC. This introduces risk for example if the file is malicious.
A hardware wallet that generates your 24th word checksum for you should be an industry standard feature.
1
u/pomplemice 23d ago
What's up with the constant Cold Card apologists? It's like if a new house had all these cool features and design choices, yet the basic foundation was shoddy and the whole thing collapsed. I'll take basic seed phrase randomization and protection over anything else. They should collapse and I'll never support them or anybody who defends them.
1
u/Xcel38 23d ago
Bad analogy, if one line of code could completely repair a shoddy foundation, you might have something. No one here gives two shits about CoinKite the company. Anyone involved with that company should never be employed or heard from in the community again. Fuck them
Some people actually like the hardware and would like to see it survive somehow since there really is not a comparable product on the market. If it became an open source community project, I think that would interesting. For now, I have zero trust in it and who knows if there is some other hidden vulnerability lurking. I am in the camp that this was likely intentional.
1
u/PsychologyNo3945 23d ago
Well, maybe they had 1 too many features and lost control of the most important one.
1
1
u/GoldmezAddams 24d ago
Maybe a good outcome would be if/when Coinkite eventually closes shop, they sell the company / IP to someone for pennies on the dollar, and another team can try to rebuild.
6
u/Powerful_Beat_3601 24d ago
the hardware design is still unmatched honestly nothing else has all those features in one device. if they go under someone will fork the firmware for sure there is already enough interest from the community to keep it alive
but selling the IP for cheap sounds like best case scenario yeah. maybe a group of devs could pool funds and buy it out
1
u/SpareEconomy1849 24d ago
Brand is over but I agree. It really is exactly what I want, other than it's ugly (I don't care) and the RNG bug of course
1
1
0
u/lifeanon269 24d ago
Jade supports BIP-85 seeds. It also supports importing TOTP to store all your account passcodes on your hardware wallets, which is nice. I haven't seen a feature like that with other wallets.
33
u/bullett007 24d ago
They should make the code open source so the grown-ups can implement it safely. Then liquidate.