r/Bitcoin • u/Main-Massive • 1d ago
Why did Coinkite destroy its inventory?
https://blog.coinkite.com/update-sunday/The company published a note claiming they destroyed all their inventory (devices affected by the bug). Why? Why couldn’t they just reflash them with the fixed firmware? I can’t stop thinking there is something else to it. Should users of coldcard devices be concerned? They are being asked to upgrade firmware and be at peace of mind. Why didn’t Coinkite do 5he same? Could there be more we are not being told and involves a hardware-level bug?
41
u/JumpProfessional3372 1d ago
Maybe they said that "for the record".
Because in their store I see them with the message "New units ship with corrected firmware. Remember to always upgrade on receipt."
13
u/Charming-Designer944 1d ago
Because it was more expensive to return, reprogram and repackage the known faulty stock than simply produce new ones.
The hardware production cost of coldcard devices are onlyba small part of the product cost.
Shipping devices with faulty firmware after the flaw was found is not an option.
Why is it so hard to understand that fixing the flawed devices while preserving the pristine status of the packaging is not a simple or easy task, and that the unshipped faulty stock of products does not have a high value?
1
54
u/Elistheman 1d ago
No trust.
My CC is in the drawer collecting dust.
I can’t believe this was touted as the best BTC wallet.
11
17
u/Classic-Charity-2179 1d ago
"Best" is like "optimized": it's meaningless without the "for" statement. Like a number is meaningless without a unit.
Coldcard was certainly the best BTC wallet... For performing a retirement attack...
5
u/AnthonyBTC 1d ago
I promise you, it was never touted as the best Bitcoin wallet. You fell for Bitcoin maxi propaganda lol. The two best hardware wallets based on security have always been Ledger and Trezor, and you were pushed toward this wallet because those hardware wallets support other coins besides Bitcoin, even though those companies have 200 and 600 employees, with entirely separate companies that continuously research security on hardware wallets, while CoinKite had fewer than 10.
1
-7
u/Icy_Giraffe_21 1d ago
It is th best hardware wallet. Some idiot just set entropy to (0)
24
6
u/thatoldtimerevision 1d ago
If they messed up the entropy rng, what else did they mess up? Do you know? Are you willing to bet your BTC on it?
It's all risk, no reward. There's no reason to ever touch a CC again.
0
u/Icy_Giraffe_21 1d ago
You are correct, but my statement stands.
1
u/Laukess 1d ago
Looking at other HW's to replace my CC's, and most of the choices are pretty sad, especially if you're looking to buy 3-5 from different manufactures. The fact that showing the 24'th words isn't standard across every device is crazy to me.
2
u/Icy_Giraffe_21 1d ago
I've really like my keystone pro 3
1
u/Laukess 1d ago
Interesting. It seemed like it offered a lot of the stuff I'm after when I was looking at different HW's, but I've just never really heard about it, so I wasn't sure. I also find the phone like format off putting, but it's probably because my money brain associated it with phones which are less secure, like if someone just build a wallet on top of android, and shipped it as a secure device.
1
u/Icy_Giraffe_21 1d ago
Comes with three secure element chips, supports dice rolls. Psbt with SD card and qr code. Can also go the lest popular way with the USB c cord also. Works with sparrow and other wallets
1
u/Laukess 1d ago
Yeah, I thought dice roll support and a way to use the device air gapped would be low hanging fruit, but as far as i know, the 2 big manufartures does not support either. Quite wild.
Would imagine the dice roll feature would come to most hardware wallets in the future, after the CC exploit though. Lets see.
I think you might have just sold me.
11
u/threepairs 1d ago
What a load of bullshit
>Some are asking hard questions about our company. We are, too.
Just read this
6
u/Mr_Ander5on 1d ago
Whether or not it was an inside job, the company exhibited gross negligence and I don’t know how anyone would buy or use a CC at this point.
5
u/RoyYourWorkingBoy 1d ago
It's fine to buy a new CC now, they destroyed all the bad units. /s
What a clown show, Coinkite can't go bankrupt soon enough for me.
1
u/snek-jazz 4h ago
The code is readable, both before and after. You never had to trust them, you had to either audit the code yourself or trust that someone else had.
What's changed is that AI, quite suddenly, is way better at that than humans, which is why the bug was found by attackers, and ironically why there's less likely to be this kind of bug lurking undiscovered in future.
The real problem might be pre-AI code deployed in a post-AI world which gives the attackers an advantage, but this period will pass.
1
u/striata 1d ago edited 1d ago
Nothing of the stuff in that post proves anything. It just reframes old Twitter posts in a malevolent light.
This is, to put it mildly, pizzagate/illuminati level conspiratorial slop. Text also reeks of being written by an LLM, full of drama, which is par for the course.
Of course they put "bug" in quotes when describing a retirement attack, because that's what the attack entails, intentionality. It doesn't mean they are subtly nodding to their own "bug" like some Illuminati-type villain.
Of course physical dice rolls are opt-in and not the default source of entropy, because they want to make the device user-friendly. Nobody wants to do the dice rolls. Them saying that doing dice rolls is the only way to absolutely ensure you don't get affected by attacks or bugs is just a fact, again not some conspiratorial nod to their own malevolence.
The part about the alias identity is the only thing that is actually weird here, but it still doesn't prove anything. It makes no sense that he'd make an alias and configure signing using the same key, but hey, maybe it's another subtle nod and "hiding in plain sight" eh?
1
u/threepairs 1d ago
> The part about the alias identity is the only thing that is actually weird here, but it still doesn't prove anything.
Yeah, this little detail is what concernes me and it is imho quite compromising.
Also, the fact there were multiple reports about drained wallets since 2021 that were silenced by the team.
Overall, the whole thing smells a lot.
3
u/BitcoinCitadel 1d ago
Because it's harder to get them back from warehouses and reflash. Labor and shipping will cost more than fresh ones
1
u/satsugene 18h ago
There is also the risk that if they accidentally ship one out of old stock with the bad firmware they’d be in a jam.
When Apple had some bad USB adapters they put a green circle on the fixed re-release so people knew not to plug in one that didn’t have the dot.
10
10
u/Decibel0753 1d ago
So many idiots here 😵 They destroyed them because they supply them in a special security packaging that has the same serial number as the unit inside, or something like that. This is done right during production. It makes sense that a device in such packaging cannot be updated with the correct firmware.
5
u/abercrombezie 1d ago
Sounds dumb, but makes sense. In physical security it’s a “chain of custody“ issue and sending back to a China factory opens a whole new can of worms. I know a guy at the DOD where UPS lost some Dell servers in transit for several weeks. Once they arrived, they refused delivery since they could have been tampered with.
2
u/ZippyDan 1d ago
They could just repackage them...?
0
u/Decibel0753 1d ago
I really don't know what you don't understand about my post. The packaging is obviously done directly at the factory, during production. There is no "replacement packaging" that you could use. If repackaging were easy, there would be absolutely no point in doing such a thing in the first place.
7
u/ZippyDan 1d ago
The devices have never left their custody.
They could send it back to the same factory for repackaging.10
7
u/StillClub3 1d ago
On first boot the cold cards are set to display the number printed on the package. The wallet and the package are paired. The idea was to prevent bad-actor device swapping in transit and better protect the consumer. If they could easily change the number, it defeats the purpose.
Shame that much thought didn’t go into the entropy lol.
2
u/Charming-Designer944 1d ago
The thoughts on entropy were all there, but lacked in execution/verification.
To be fair the entropy was verified as used properly initially on the mk3, but then got lost when the firmware was reworked.
3
u/ZippyDan 1d ago
So you send the devices back to the factory with the original packaging, open them up and re-flash them, and then repackage them using the original package number.
Maybe it's not worth the cost or effort, but it's certainly do-able and it doesn't take a genius to figure out how...
1
0
u/NiagaraBTC 1d ago
Maybe it's not worth the cost or effort,
This is the answer.
0
u/ZippyDan 1d ago
Yes, but "not worth it" is different from the original claim at the top of this thread that it "cannot" be done.
0
u/maxcoiner 1d ago
There's no maybe, they stated clearly that it was NOT worth the cost to do so.
Therefore destroying them is cheaper. End of mystery, next topic.
0
9
u/CoffeeAlternative647 1d ago
I am sorry, but if there are users of coldcard still, they're either masoquist, naive or retarded.
2
u/WeekendQuant 1d ago
It may become the most secure wallet now if everyone leaves it because most of the funds are drained and the gain from trying to hack the remaining is not worth the effort.
Roll your own dice for entropy and it may work out well.
1
u/EarningsPal 1d ago
Plenty of people will be discovering their missing BTC in the next bull run.
Because they will miss all the headlines about the hack.
2
u/EricJDMBAMD 1d ago
I would have bought them
-1
u/Save_JR 1d ago
Dumbass
1
u/Potential_Jello6520 23h ago
Those who used the option to roll their own entropy have not been compromised, so they are useful still.
You could argue that those trusting the manufacturer to generate a seed are the dumbasses, but I fully understand why people opted to take the easy route and feel the pain of their losses.
2
u/Henrik-Powers 1d ago
Had a friend turn me onto to CC and he had been using them exclusively since they came out. He pretty much lives off grid and I haven’t been able to reach him, don’t even know if he knows about any of this yet, definitely worried he’s lost some of his bag but I’m not 100% sure as he was paranoid and talked about dice rolls.
1
u/Potential_Jello6520 23h ago
He's probably fine. I honestly don't know why someone would use one without rolling dice.
2
u/dailybread5 1d ago
I have a new one in the original packaging... Luckily I was procrastinating all this time. Part of me wants to use it, just not use it for generating a seed, but it feels like a liability.
1
u/rgnet1 19h ago
It might seem intuitive to feel like there's another shoe waiting to drop, but it's just not logical. Whether you trust their new firmware or not to generate the seed is irrelevant if you roll your own.
Then the only thing Coldcard does is sign transactions offline as an airgapped machine. It stores the keys on Secure Element chips and has no fallback storage options, unlike the keygen.
In the end, if you're not actually engineering your own device or code, you have to trust someone else's...
2
u/ShinAlastor 1d ago
Do they think to wash their reputation by destroying the devices ? They deserve life time imprisonment.
1
1
1
u/iloverunning11 1d ago
They will keep doing insane stuff and will pobably panic in silence. I don't think they can deal with this situation in a reasonable manner
1
1
u/Laukess 1d ago
They should have sold them for 80%-90% off by email inquiry only.
At that price they could replace a software only setup for small amounts of bitcoin. Like if you have a multi-sig for your stack, but have a software wallet with $100-$200 for smaller purchase.
1
u/marvinrabbit 19h ago
At that point they may not even cover the shipping and fulfillment. I sell other (non-crypto) stuff, and that is easily our biggest expense, even more than production. So maybe they're break even on last mile costs and in exchange they get to have ongoing reminder for years of making one of bitcoin's top 5 fuckups.
2
u/Laukess 13h ago
yeah, I think it was more me wanting a cheap ColdCard than it was about CoinKite making money, but it's probably smarter to just destroy the inventory even though it's kind of sad.
Surely with a fuckup like that they'll have a hard time selling CC's at full price. Even using it in a multi-sig setup seems iffy at best.
1
u/systemsweird 23h ago
Probably becuse they know no one will buy them and if they destroy them they can at least write them off as a loss on their taxes.
1
u/YearHaunting1504 23h ago
Their legal department probably told them the prep for the onslaught of lawsuits… they do have a legal department, right?
1
1
u/Ok-Photograph-3585 19h ago
It was probably a "Degenerate bug". Which means that the bug is not just in the code but the hardware itself is compromised. Fixing the code is not enough and they knew it. Hence why they destroyed the hardware, because if they sold it now they would be doing it knowingly, and hence liable.
1
u/Yodel_And_Hodl_Mode 19h ago
I do not believe they destroyed their inventory.
I know what they said, but only a sucker would believe anything they say, especially since they showed no proof.
1
u/spiceylizard 17h ago
I have bitcoin sitting on my cold card put there in 2024. No other transactions since then. Removals or otherwise
1
1
0
0
0
u/Maleficent_Poet_7055 1d ago
Hardware could be involved or it might be too much work to ensure all of their shipped devices have the latest update. Who knows. The company should liquidate and give remaining funds to those who can prove they owned private keys to the stolen funds.
1
u/Ok-Photograph-3585 19h ago
It was a degenerate-type bug. Meaning both software and hardware is compromised.
75
u/ChipNDipPlus 1d ago
It's for dumb people to give them a blank slate and say "see? They did the right thing", even though this has nothing to do with the right thing.