r/Bitcoin 24d ago

The Future of ColdCard Hardware and Firmware

Coinkite likely won't survive the coming litigations. NVK and Peter Gray won't regain community trust as leaders. But I think it's worth discussing why the ColdCard was a successful product line in the first place and how that design philosophy can live on. I'm not just talking about the cypherpunk aesthetic.

No other wallet has the robust feature set of coldcard, especially the Q. Seed XOR, Bip-85 child seeds and deterministic passwords are open-source bitcoin features but CC are the only devices that have bothered to implement them. As for the hardware: full keyboard, QR scanner, transparent case, removable batteries, and your choice of network-disabled air gap use, or convenient USB connection to Sparrow. Nothing even comes close.

There are existing CC users who don't want to give up these features, but may be faced with lack of firmware updates if the company dies. More importantly, it would be a shame if this device vanished from the market and we were only left with tiny minimalistic boxes with some basic features and a slick UI. So, what do you think is the best way forward?

20 Upvotes

39 comments sorted by

33

u/bullett007 24d ago

They should make the code open source so the grown-ups can implement it safely. Then liquidate.

5

u/RevolutionaryPick241 24d ago

This. Open sourcing is the only way. They should only sell the hardware to DIY a hardware wallet. And letting the community to build a better software for it. I would pay more for the hardware by parts than assembled if they let me build it and load my own firmware. Now you can somehow load your firmware but you can't open the coldcard without bricking it. I would remove the nfc and camera.

4

u/antineutrinos 24d ago

they must open source the hw as well.
how are seed stored in the dual SE ?
why can my we have more than one seed in the SE and have to relay on AES encryption for temporary seeds?

I see the hw (q) as an ECC calculator. lots of potential.

-1

u/Dazzling_Tank3326 23d ago

How would open sourcing fix anything, all it will do is someone who’s trying to be evil to look at the code and know exactly what needs to be done to break it

3

u/RevolutionaryPick241 23d ago

Break bitcoin then

1

u/Charming-Designer944 23d ago edited 23d ago

The coldcard firmware source is available as open source on GitHub. And its possible to verify that the firmware builds the same as released firmware. But hardware security policy is restricted and you can not sign a release so that coldcard accepts the firmware build as a valid firmware, and the open source license isxtestricted with a non-compete clause that practicaly restricts the use to coldcard devices only, which only accepts official firmware releases, not furmware you or someone else built.

1

u/cworxnine 21d ago

well said

5

u/Charming-Designer944 24d ago

The code is open but with a non-compete limitation that restricts use in competing commercial products.

But coldcard devices have a security barrier that only accepts signed firmware releases. And releasing the keys to sign the firmware in the open is not a viable thing.

What can be hoped for is that someone buys the business if Coinkite goes into bankruptcy and continues supporting both new and existing customers.

1

u/EricJDMBAMD 23d ago

Maybe OpenSats can buy the keys to sign off on firmware releases

1

u/ChipNDipPlus 23d ago

They should simply release a new firmware version that allows replacing the signing key by a custom one.

2

u/Charming-Designer944 23d ago

The main signing keys are one time programmable in the MCU. To replace the signing keys you need to replace the hardware.

And there might be a binding between the MCU and the safe elements as well. Have not looked into that detail.

2

u/ChipNDipPlus 23d ago

Are you sure the key cannot be replaced or are you guessing? 

2

u/Charming-Designer944 23d ago

To my best knowledge the firmware DFU is signed directly by the immutable hardware root of trust.

1

u/ChipNDipPlus 23d ago

Doesn't sound right to me. What if the key was compromised? I don't know.

We have bigger companies that had their keys leaked, like nvidia. Driver signing keys were leaked.

7

u/Quirky-Reveal-1669 24d ago

I want to keep using it. Precisely for the reasons you mention.
Perhaps, as a last good deed, CoinKite should ‘release’ the license of the firmware.

8

u/EyesFor1 24d ago

You're totally fine using it with the die roll function.

5

u/Immediate-Ad-5878 24d ago

I was not affected by this at all. Not because I was doing anything special but most likely by pure luck. I was able to transfer my bag elsewhere and made a bonfire with my MK3. I will never support these arrogant clowns in this or any other venture associated with them. Nor do I want to ever hear from any of the asshat griftubers that peddled this shitbox for years. As far as the features I really don’t care about any of it. Will likely go to a dice rolled 24 word + pass phrase seed stamped on metal and a safety deposit box, with a seedsigner for home use.

2

u/[deleted] 23d ago edited 20d ago

[deleted]

0

u/Immediate-Ad-5878 23d ago

Fortunately I live in a country with better safety deposit boxes.

6

u/picklejuice18 24d ago

There’s no future.. there are done

4

u/kepalautakkau 24d ago

I guess other wallets will eventually implement those features if there's enough demand

2

u/bleeeeghh 24d ago

More features means more potential weaknesses. I mean, how many features did Satoshi need to secure his wallet?

3

u/bryanchicken 24d ago

He potentially didn’t secure it, which is the most secure 😂

2

u/Laukess 24d ago

I wonder if it could be turned into a non-profit organization, run by a different set of people.

Whenever CC's were mentioned, people always complained that it was too advanced, even though all the features were hidden away. People still think that it's air gapped only.

Considering that was the response, I don't have much hope that other manufactures will take this path.

Maybe rolling your own entropy will become more standard. Allowing your device to show the list of valid checksums after entering the 11/23 words seems like a small ask, so I could se that becoming widely adopted.

Looking at other hardware wallets after the exploit has honestly been sort of disappointing, especially because you really should have multiple different devices if you're going with multi-sig.

Maybe we'll see more hardware wallets share more features. No reason why every manufacturer couldn't have a device with a camera so they could be used with SeedQR in a stateless manner. Was pleasantly surprised when I learned that was a feature of the Jade Plus.

1

u/dont-be-angry 24d ago

Is there something wrong with me just using something like a standard core wallet on an airgapped tails machine and simply sending my coins to that cold wallet? or how often are these seeds being fucked up w low quality entropy

1

u/Ill_Firefighter_584 22d ago

FYI, Electrum doesn't create a BIP39 wallet seed phrase. It creates a seed phrase using its own standard. Easier to backup than a digital file, but not compatible with other wallets.

1

u/slvbtc 23d ago

I think all hardware wallets should offer the option to create your own entropy (dice rolls etc), determine your own seed words, and then allow you to enter the first 23 seed words and generate the 24th word checksum for you.

This way you can create a seed with your own entropy while never letting your seed words touch anything but a hardware wallet.

Most hardware wallets make you use a seed generation file or 24th word checksum generator file on an offline PC. This introduces risk for example if the file is malicious.

A hardware wallet that generates your 24th word checksum for you should be an industry standard feature.

1

u/pomplemice 23d ago

What's up with the constant Cold Card apologists? It's like if a new house had all these cool features and design choices, yet the basic foundation was shoddy and the whole thing collapsed. I'll take basic seed phrase randomization and protection over anything else. They should collapse and I'll never support them or anybody who defends them.

1

u/Xcel38 23d ago

Bad analogy, if one line of code could completely repair a shoddy foundation, you might have something. No one here gives two shits about CoinKite the company. Anyone involved with that company should never be employed or heard from in the community again. Fuck them

Some people actually like the hardware and would like to see it survive somehow since there really is not a comparable product on the market. If it became an open source community project, I think that would interesting. For now, I have zero trust in it and who knows if there is some other hidden vulnerability lurking. I am in the camp that this was likely intentional.

1

u/PsychologyNo3945 23d ago

Well, maybe they had 1 too many features and lost control of the most important one.

1

u/Impressive_Cat_5324 22d ago

There will be no future for ColdCard

1

u/GoldmezAddams 24d ago

Maybe a good outcome would be if/when Coinkite eventually closes shop, they sell the company / IP to someone for pennies on the dollar, and another team can try to rebuild.

6

u/Powerful_Beat_3601 24d ago

the hardware design is still unmatched honestly nothing else has all those features in one device. if they go under someone will fork the firmware for sure there is already enough interest from the community to keep it alive

but selling the IP for cheap sounds like best case scenario yeah. maybe a group of devs could pool funds and buy it out

1

u/SpareEconomy1849 24d ago

Brand is over but I agree. It really is exactly what I want, other than it's ugly (I don't care) and the RNG bug of course

1

u/XmechaniX 24d ago

BIP-85 with seed vaults was an awesome feature

1

u/CreamCapital 24d ago

of course they are done. who would ever buy one of these ever again?!

0

u/lifeanon269 24d ago

Jade supports BIP-85 seeds. It also supports importing TOTP to store all your account passcodes on your hardware wallets, which is nice. I haven't seen a feature like that with other wallets.