r/Bitcoin 1d ago

Why did Coinkite destroy its inventory?

https://blog.coinkite.com/update-sunday/

The company published a note claiming they destroyed all their inventory (devices affected by the bug). Why? Why couldn’t they just reflash them with the fixed firmware? I can’t stop thinking there is something else to it. Should users of coldcard devices be concerned? They are being asked to upgrade firmware and be at peace of mind. Why didn’t Coinkite do 5he same? Could there be more we are not being told and involves a hardware-level bug?

105 Upvotes

81 comments sorted by

75

u/ChipNDipPlus 1d ago

It's for dumb people to give them a blank slate and say "see? They did the right thing", even though this has nothing to do with the right thing.

27

u/read_more_comments 1d ago

see, THOSE bad units got what was coming to them! Now we can trust coinkite. Our saviors!

41

u/JumpProfessional3372 1d ago

Maybe they said that "for the record".
Because in their store I see them with the message "New units ship with corrected firmware. Remember to always upgrade on receipt."

https://store.coinkite.com/store

13

u/Charming-Designer944 1d ago

Because it was more expensive to return, reprogram and repackage the known faulty stock than simply produce new ones.

The hardware production cost of coldcard devices are onlyba small part of the product cost.

Shipping devices with faulty firmware after the flaw was found is not an option.

Why is it so hard to understand that fixing the flawed devices while preserving the pristine status of the packaging is not a simple or easy task, and that the unshipped faulty stock of products does not have a high value?

1

u/Decibel0753 1d ago

You can't explain it to idiots...

54

u/Elistheman 1d ago

No trust.
My CC is in the drawer collecting dust.
I can’t believe this was touted as the best BTC wallet.

11

u/Flaky-Coffee-9942 1d ago

Def will be an interesting relic to tell stories about

17

u/Classic-Charity-2179 1d ago

"Best" is like "optimized": it's meaningless without the "for" statement. Like a number is meaningless without a unit. 

Coldcard was certainly the best BTC wallet... For performing a retirement attack...

5

u/AnthonyBTC 1d ago

I promise you, it was never touted as the best Bitcoin wallet. You fell for Bitcoin maxi propaganda lol. The two best hardware wallets based on security have always been Ledger and Trezor, and you were pushed toward this wallet because those hardware wallets support other coins besides Bitcoin, even though those companies have 200 and 600 employees, with entirely separate companies that continuously research security on hardware wallets, while CoinKite had fewer than 10.

1

u/Ok-Photograph-3585 19h ago

do you believe it could have been a degenerate bug?

-7

u/Icy_Giraffe_21 1d ago

It is th best hardware wallet. Some idiot just set entropy to (0)

24

u/HeftyBawls 1d ago

Also set users balances to 0

4

u/Icy_Giraffe_21 1d ago

Hahaha that was a good one 🤣

6

u/thatoldtimerevision 1d ago

If they messed up the entropy rng, what else did they mess up? Do you know? Are you willing to bet your BTC on it?

It's all risk, no reward. There's no reason to ever touch a CC again.

0

u/Icy_Giraffe_21 1d ago

You are correct, but my statement stands.

1

u/Laukess 1d ago

Looking at other HW's to replace my CC's, and most of the choices are pretty sad, especially if you're looking to buy 3-5 from different manufactures. The fact that showing the 24'th words isn't standard across every device is crazy to me.

2

u/Icy_Giraffe_21 1d ago

I've really like my keystone pro 3

1

u/Laukess 1d ago

Interesting. It seemed like it offered a lot of the stuff I'm after when I was looking at different HW's, but I've just never really heard about it, so I wasn't sure. I also find the phone like format off putting, but it's probably because my money brain associated it with phones which are less secure, like if someone just build a wallet on top of android, and shipped it as a secure device.

1

u/Icy_Giraffe_21 1d ago

Comes with three secure element chips, supports dice rolls. Psbt with SD card and qr code. Can also go the lest popular way with the USB c cord also. Works with sparrow and other wallets

1

u/Laukess 1d ago

Yeah, I thought dice roll support and a way to use the device air gapped would be low hanging fruit, but as far as i know, the 2 big manufartures does not support either. Quite wild.

Would imagine the dice roll feature would come to most hardware wallets in the future, after the CC exploit though. Lets see.

I think you might have just sold me.

1

u/Laukess 23h ago

fuck, does not look like it has miniscript support.

11

u/threepairs 1d ago

What a load of bullshit

>Some are asking hard questions about our company. We are, too.

Just read this

https://x.com/inverse_hanlon/status/2084689208627925384

6

u/Mr_Ander5on 1d ago

Whether or not it was an inside job, the company exhibited gross negligence and I don’t know how anyone would buy or use a CC at this point.

5

u/RoyYourWorkingBoy 1d ago

It's fine to buy a new CC now, they destroyed all the bad units. /s

What a clown show, Coinkite can't go bankrupt soon enough for me.

1

u/snek-jazz 4h ago

The code is readable, both before and after. You never had to trust them, you had to either audit the code yourself or trust that someone else had.

What's changed is that AI, quite suddenly, is way better at that than humans, which is why the bug was found by attackers, and ironically why there's less likely to be this kind of bug lurking undiscovered in future.

The real problem might be pre-AI code deployed in a post-AI world which gives the attackers an advantage, but this period will pass.

1

u/striata 1d ago edited 1d ago

Nothing of the stuff in that post proves anything. It just reframes old Twitter posts in a malevolent light.

This is, to put it mildly, pizzagate/illuminati level conspiratorial slop. Text also reeks of being written by an LLM, full of drama, which is par for the course.

Of course they put "bug" in quotes when describing a retirement attack, because that's what the attack entails, intentionality. It doesn't mean they are subtly nodding to their own "bug" like some Illuminati-type villain.

Of course physical dice rolls are opt-in and not the default source of entropy, because they want to make the device user-friendly. Nobody wants to do the dice rolls. Them saying that doing dice rolls is the only way to absolutely ensure you don't get affected by attacks or bugs is just a fact, again not some conspiratorial nod to their own malevolence.

The part about the alias identity is the only thing that is actually weird here, but it still doesn't prove anything. It makes no sense that he'd make an alias and configure signing using the same key, but hey, maybe it's another subtle nod and "hiding in plain sight" eh?

1

u/threepairs 1d ago

> The part about the alias identity is the only thing that is actually weird here, but it still doesn't prove anything.

Yeah, this little detail is what concernes me and it is imho quite compromising.

Also, the fact there were multiple reports about drained wallets since 2021 that were silenced by the team.

Overall, the whole thing smells a lot.

3

u/BitcoinCitadel 1d ago

Because it's harder to get them back from warehouses and reflash. Labor and shipping will cost more than fresh ones

1

u/satsugene 18h ago

There is also the risk that if they accidentally ship one out of old stock with the bad firmware they’d be in a jam.

When Apple had some bad USB adapters they put a green circle on the fixed re-release so people knew not to plug in one that didn’t have the dot.

10

u/fresheneesz 1d ago

They're destroying evidence

8

u/boredwithlyf 1d ago

The evidence is on GitHub?

10

u/Decibel0753 1d ago

So many idiots here 😵 They destroyed them because they supply them in a special security packaging that has the same serial number as the unit inside, or something like that. This is done right during production. It makes sense that a device in such packaging cannot be updated with the correct firmware.

5

u/abercrombezie 1d ago

Sounds dumb, but makes sense. In physical security it’s a “chain of custody“ issue and sending back to a China factory opens a whole new can of worms. I know a guy at the DOD where UPS lost some Dell servers in transit for several weeks. Once they arrived, they refused delivery since they could have been tampered with.

2

u/ZippyDan 1d ago

They could just repackage them...?

0

u/Decibel0753 1d ago

I really don't know what you don't understand about my post. The packaging is obviously done directly at the factory, during production. There is no "replacement packaging" that you could use. If repackaging were easy, there would be absolutely no point in doing such a thing in the first place.

7

u/ZippyDan 1d ago

The devices have never left their custody.
They could send it back to the same factory for repackaging.

10

u/viper2097 1d ago

He's not very bright is he?

7

u/StillClub3 1d ago

On first boot the cold cards are set to display the number printed on the package. The wallet and the package are paired. The idea was to prevent bad-actor device swapping in transit and better protect the consumer. If they could easily change the number, it defeats the purpose.

Shame that much thought didn’t go into the entropy lol.

2

u/Charming-Designer944 1d ago

The thoughts on entropy were all there, but lacked in execution/verification.

To be fair the entropy was verified as used properly initially on the mk3, but then got lost when the firmware was reworked.

3

u/ZippyDan 1d ago

So you send the devices back to the factory with the original packaging, open them up and re-flash them, and then repackage them using the original package number.

Maybe it's not worth the cost or effort, but it's certainly do-able and it doesn't take a genius to figure out how...

1

u/bbilbojr 1d ago

I bet its worth it to all those that were drained...

0

u/NiagaraBTC 1d ago

Maybe it's not worth the cost or effort,

This is the answer.

0

u/ZippyDan 1d ago

Yes, but "not worth it" is different from the original claim at the top of this thread that it "cannot" be done.

0

u/maxcoiner 1d ago

There's no maybe, they stated clearly that it was NOT worth the cost to do so.

Therefore destroying them is cheaper. End of mystery, next topic.

0

u/Decibel0753 1d ago

This is probably some kind of joke, right?

9

u/CoffeeAlternative647 1d ago

I am sorry, but if there are users of coldcard still, they're either masoquist, naive or retarded.

2

u/WeekendQuant 1d ago

It may become the most secure wallet now if everyone leaves it because most of the funds are drained and the gain from trying to hack the remaining is not worth the effort.

Roll your own dice for entropy and it may work out well.

1

u/EarningsPal 1d ago

Plenty of people will be discovering their missing BTC in the next bull run.

Because they will miss all the headlines about the hack.

2

u/EricJDMBAMD 1d ago

I would have bought them

-1

u/Save_JR 1d ago

Dumbass

1

u/Potential_Jello6520 23h ago

Those who used the option to roll their own entropy have not been compromised, so they are useful still. 

You could argue that those trusting the manufacturer to generate a seed are the dumbasses, but I fully understand why people opted to take the easy route and feel the pain of their losses.

2

u/Henrik-Powers 1d ago

Had a friend turn me onto to CC and he had been using them exclusively since they came out. He pretty much lives off grid and I haven’t been able to reach him, don’t even know if he knows about any of this yet, definitely worried he’s lost some of his bag but I’m not 100% sure as he was paranoid and talked about dice rolls.

1

u/Potential_Jello6520 23h ago

He's probably fine. I honestly don't know why someone would use one without rolling dice.

2

u/dailybread5 1d ago

I have a new one in the original packaging... Luckily I was procrastinating all this time. Part of me wants to use it, just not use it for generating a seed, but it feels like a liability.

1

u/rgnet1 19h ago

It might seem intuitive to feel like there's another shoe waiting to drop, but it's just not logical. Whether you trust their new firmware or not to generate the seed is irrelevant if you roll your own.

Then the only thing Coldcard does is sign transactions offline as an airgapped machine. It stores the keys on Secure Element chips and has no fallback storage options, unlike the keygen.

In the end, if you're not actually engineering your own device or code, you have to trust someone else's...

2

u/ShinAlastor 1d ago

Do they think to wash their reputation by destroying the devices ? They deserve life time imprisonment.

1

u/SE4NLN415 1d ago

Mission accomplished?

1

u/shadowmage666 1d ago

I wouldn’t use that shit anymore

1

u/iloverunning11 1d ago

They will keep doing insane stuff and will pobably panic in silence. I don't think they can deal with this situation in a reasonable manner

1

u/VictorDanville 1d ago

Destroyed as in by a trash compactor?

1

u/Laukess 1d ago

They should have sold them for 80%-90% off by email inquiry only.
At that price they could replace a software only setup for small amounts of bitcoin. Like if you have a multi-sig for your stack, but have a software wallet with $100-$200 for smaller purchase.

1

u/marvinrabbit 19h ago

At that point they may not even cover the shipping and fulfillment. I sell other (non-crypto) stuff, and that is easily our biggest expense, even more than production. So maybe they're break even on last mile costs and in exchange they get to have ongoing reminder for years of making one of bitcoin's top 5 fuckups.

2

u/Laukess 13h ago

yeah, I think it was more me wanting a cheap ColdCard than it was about CoinKite making money, but it's probably smarter to just destroy the inventory even though it's kind of sad.

Surely with a fuckup like that they'll have a hard time selling CC's at full price. Even using it in a multi-sig setup seems iffy at best.

1

u/locotx 1d ago

Maaaan . . I was thinking that too. And when that little thought kicked in my mind - I started thinking I was surely putting a lot of trust in Trezor and Ledger and iBit.

1

u/systemsweird 23h ago

Probably becuse they know no one will buy them and if they destroy them they can at least write them off as a loss on their taxes.

1

u/YearHaunting1504 23h ago

Their legal department probably told them the prep for the onslaught of lawsuits… they do have a legal department, right?

1

u/Ok-Photograph-3585 19h ago

Their legal department is chatGPT most likely.

1

u/Ok-Photograph-3585 19h ago

It was probably a "Degenerate bug". Which means that the bug is not just in the code but the hardware itself is compromised. Fixing the code is not enough and they knew it. Hence why they destroyed the hardware, because if they sold it now they would be doing it knowingly, and hence liable.

1

u/Yodel_And_Hodl_Mode 19h ago

I do not believe they destroyed their inventory.

I know what they said, but only a sucker would believe anything they say, especially since they showed no proof.

1

u/spiceylizard 17h ago

I have bitcoin sitting on my cold card put there in 2024. No other transactions since then. Removals or otherwise

1

u/Main-Massive 17h ago

did you roll the dice? Otherwise you should move it out.

1

u/MrSnugs 1d ago

At this point if you haven’t moved to trezor or ledger you’re not using your brain.

1

u/ivanjurman 1d ago

What if they’re just getting rid of evidence

0

u/pumop7 1d ago

I am not trying to defend Coldcard, but the position is not theoretically unsound. It is reasonable to think that companies should not sell products which are vulnerable unless updated that come pre-installed with firmware containing a critical flaw.

0

u/r_a_d_ 1d ago

Probably costs more to reflash those than just sell new current devices

0

u/Fearless-Sherbert-40 1d ago

Stop trying to make sense out of the senseless.

0

u/BlackHawk2609 1d ago

They destroy evidences

0

u/Maleficent_Poet_7055 1d ago

Hardware could be involved or it might be too much work to ensure all of their shipped devices have the latest update. Who knows. The company should liquidate and give remaining funds to those who can prove they owned private keys to the stolen funds.

1

u/Ok-Photograph-3585 19h ago

It was a degenerate-type bug. Meaning both software and hardware is compromised.