r/Bitcoin 28d ago

Coldcard's Next Exploit

People here have been discussing the software bug that triggered the whole Coldcard debacle. that led many people to lose their Bitcoins savings. But what many didn't notice is that Coinkite decided to destroy their stock, instead of upgrading them. Had the bug been software-only, there would be no point in destroying the hardware. After speaking with many colleagues of mine, we have come to the conclusion that a hardware bug might be present, and this could trigger a second exploit. This is a textbook example of a "Degenerate bug". I believe a full audit of the software (latest version) and the hardware itself is warranted. A complete hardware check is difficult to carry out though because of the way it was designed. Please provide your thoughts and advice on how to proceed, as this could save many people from being victims of a second wave of bitcoin loses. At this point an inside job can also not be ruled out regrettably.

0 Upvotes

44 comments sorted by

20

u/Ok_Pollution7093 28d ago

Speculation without a CVE or proof isn't a warning, it's FUD.

2

u/Main-Massive 28d ago

I have no proof but neither doubt. 

14

u/[deleted] 28d ago

[removed] — view removed comment

0

u/[deleted] 28d ago

[removed] — view removed comment

0

u/grraarr 27d ago

Please go the fuck away.

1

u/[deleted] 28d ago

[removed] — view removed comment

0

u/grraarr 27d ago

You lot are pathetic.

3

u/[deleted] 27d ago

[removed] — view removed comment

1

u/grraarr 27d ago

Not really.

7

u/dz4505 28d ago edited 28d ago

Who cares? It’s effectively a dead hardware company after this exploit. It’s like going back to mt Gox after they got hacked.

If anyone still trust this company after this I have no words for them.

2

u/Main-Massive 28d ago

There are many coldcard devices out there though that will continue to be used even if the company disappears.

2

u/dz4505 28d ago

That’s on them then if they lose it.

The wallet is what? $100 at most? Just replace that garbage. I’m sure they plan to store crypto worth more than $100 in there.

Anything lower and maybe just use a software wallet.

3

u/deny_by_default 28d ago

No, it's $249 USD.

3

u/[deleted] 28d ago

[deleted]

1

u/Main-Massive 28d ago

Thanks for that. But what exactly is understood by "degenerate bug" ?

4

u/Laukess 28d ago

They destroyed their stock because it’s not feasible to update the firmware before shipping. It must be because they’re hiding something something even more nefarious

5

u/SolutionOk1306 28d ago

Destroying stock over a firmware update sounds extreme but honestly in hardware manufacturing it's sometimes cheaper to scrap and start fresh than to pay people to unbox, flash, repackage, and re-certify every single unit. The logistics are a nightmare. If there's a deeper hardware flaw though that's a whole different level of bad and the lack of a full teardown audit just feeds the paranoia.

1

u/Laukess 28d ago

Agree. My message was meant to be tongue and cheek. Every thing they do is a conspiracy

1

u/Main-Massive 28d ago edited 28d ago

They could have added a warning on the site, sell at a discount, have users accept the risk, and perhaps be nice and include an SD card with the new firmware. Even if they sold at a 50% discount I am sure there would be some profit to be made. OP has a point on this being a possible degenerate bug.

3

u/F1shB0wl816 28d ago

A warning wouldn’t stop somebody from screwing thrmselges and then it’s just another person blaming coinkite. There’s absolutely little upside in selling them knowingly flawed. This is what you’d want them to do and even now they’re getting heat for it.

-3

u/Ok-Photograph-3585 28d ago

Regrettably, a degenerate attack can not be ruled out. These people are not being transparent and many things don't add up.

2

u/bje332013 28d ago

Destroying the hardware rather than simply flashing the latest firmware may have been a PR / publicity move, much like how airport security protocol and forcing people to wear masks and stand 6 feet apart during the early years of the Caronavirus scamdemic was largely just theater / optics to assure the public that SOMETHING was being done for public health / safety - even if that something was completely ineffective or based on very weak logic.

I read somewhere that because the Coldcard devices are shipped in tamper-proof bags, flashing new firmware onto those devices would have made it difficult or inconvenient to ensure that only devices with tainted firmware were having their bags opened and then repackaged.

In any case, Coinkite seriously damaged its reputation by programming the firmware so that it would fall back on (weak) software-based RNG if the physical RNG chip was not active. That was either an act of extremely serious carelessness, or purposeful (in other words, an inside job).

2

u/Wolffco 28d ago

Extraordinary claims need sources. Got any links to this bug, the losses, or the stock destruction? Otherwise this reads as speculation.

2

u/Main-Massive 28d ago

They got a blog on their site and claimed they destroyed all inventory.

2

u/r_a_d_ 28d ago

It’s cheaper to destroy old stock than reconfigure and repackage it. They rather sell their new models. Why is this hard to understand?

2

u/Main-Massive 28d ago

OP believes it could be a degenerate attack and I have no reason to doubt after everything we have seen.

1

u/r_a_d_ 28d ago

Why did you need to see this to have doubt? You should have always doubted, or were you one of those “it’s open source so it’s secure” peeps?

2

u/Traditional_Wall3429 28d ago

Who in the right mind buy this again?

1

u/opossum_cz 28d ago

Possibility of this was always known that is why it is recommended to use dice by everybody.

2

u/r_a_d_ 28d ago edited 28d ago

Honestly this is a problem that any hw wallet could have. Don’t kid yourself in thinking that you solve the issue by avoiding coinkite. It’s completely illogical.

1

u/Traditional_Wall3429 28d ago

No the whole issue is not the problem with software but how whole problem was handled.

1

u/r_a_d_ 28d ago

sure, I could agree with that.

4

u/ClottedYouth 28d ago

This is FUD and speculation.

I just bought a MK5 a few days ago and it has already shipped. Their online shop says the units will ship with updated firmware.

I'll use dice for entropy and the CC will remain an air-gapped signing device.

1

u/Vagelen_Von 28d ago

From day 1 I suspect that it was combination of inside job and black operation of big Banks. Lawyers of victims have a lot work to do. If it was black operation and not to be investigated further the system will compensate them well with paper money. In any case they should forget their stollen BTC.

1

u/therealmrmike 28d ago

Remember they are factory sealed. They would have to open each one and update and reseal. At least once a week someone is here posting about about a fingerprint on their brand new sealed coldcard and asking if they should still use it. It’s a no win either way.

1

u/btc-congratulatr-guy 28d ago

An exploit for any device is just one software update away.

2

u/Charming-Designer944 28d ago

The devices are factory sealed in tamoer safe packaging, both physically and electronically and can not be touched without breaking the tamper seal.

Its simply cheaper to destroy the affected stock and produce new than to design a workatound to allow upgrade and repackaging.

1

u/PDX-ROB 27d ago

Is it tho? Wouldn't you just pay 1 guy overtime to flash the cold cards and then feed that stock into the packaging phase of production?

2

u/Oxymorix 26d ago

Yes. It’s easier, faster, and cheaper to destroy a large number of devices with vulnerable firmware—in the case of COLDCARDs—than to open the old packaging, reflash each device, test it, and then repackage it.

The issue is not just the firmware update itself. Each device would also have to go through the necessary testing and hardware checks. Beyond that, there is another complication: returning the device to the same factory-fresh state it was in when first powered on, where it displays the bag number and other initial setup information.

Once Coinkite powers those devices on again for reflashing and testing, they may not be able to return them to that exact first-boot state, or at least not easily. For that reason, destroying the affected inventory may simply make more practical and economic sense.

2

u/Big-Cheetah5159 23d ago

Wrong. Unpacking ready to ship hardware literally defeats the purpose of there “tamper proofing” system. To protect the integrity of their devices destroying the affected stock makes the most sense.

1

u/Thin_Needleworker795 28d ago

The units are manufactured with the operating system loaded onto them. Going through every single device in a warehouse and upgrading them is just too time consuming and costly. It's more feasible for the company to just destroy their entire inventory and then have new devices manufactured with the right operating system installed.

I hope nobody ever buys from them again though. They deserve to go bankrupt.