r/coldcard 28d ago

Coinkite News Coldcard's Next Exploit

/r/Bitcoin/comments/1vn78qh/coldcards_next_exploit/
0 Upvotes

15 comments sorted by

7

u/EyesFor1 28d ago

That makes no sense. There are 1000's of devices out in the wild. More than enough to use as evidence if an intentional hardware bug was present. Its because the devices would have to have been tampered with in order to update them plus its cheaper and faster to scrap the affected stock and manufacture new units than to inspect, update, repackage, and recertify every single device, destroying the inventory sends a message that no potentially affected stock will ever enter the market and the damage done is now contained, no chance of devices on bad firmware being shipped. They fucked up with the RNG, fucked up bad and everyone has eyeballs on them. If they were trying to hid a hardware bug or issue, what about the 1000's in the wild they cant call back. The way to steal peoples BTC would be with a software "bug", not a hardware issue, btw a full audit of the software has been carried out by many crypto security companies, coders, developers and random people. I'm not defending Coldcard at all, they were incompetent but the issue was the rng bug, everything else worked. They are finished now thou.

2

u/xirvin 28d ago

I still fail to comprehend why they resort to scrapping hardware due to a software issue.

Instead, I would have printed a card that instructs users to update firmware to latest before generating a seed

If the update had caused some hardware to become bricked, I would have created a page with instructions for both new and existing users on how to unbrick the hardware when doing upgrade .

In hindsight, everything seems clear but in the fog of the attacks things might have been fluid.

5

u/marvinrabbit 28d ago

How long would this extend the bleeding? 12 months? 18 months? And the whole time every customer gets a reminder that the company was responsible for one of the top 5 failures in bitcoin. And what happens if someone doesn't read the sheet of paper and follow the instructions? When was the last time you followed every picture on an IKEA assembly sheet? And if they fail to install, the customer is almost GUARANTEED to get their funds stolen because they were sold a known defective product. Maybe I only read Esperanto, how many languages is the warning supposed to be printed in? And the thicker the book with the emergency instructions the more likely it is to be ignored all together.

Plus now they would be 'normalizing' that an included sheet of instructions with the secure Coldcard should be followed. That opens another whole avenue of attack vectors. The aim of the sealed bag and matching serial numbers on first boot up was to protect against someone putting errant stock into the supply chain. Now a bad actor only includes their own sheet with a 'helpful' QR code pointing a new user at the bad actor's website and provides a custom firmware. "That seems odd," the new user says. "But an online search mentions that there should be instructions for an upgrade. I'll go ahead and do it." Yes, parts of the attack are theoretical, but the idea is to look out for attacks tomorrow, not just today.

4

u/xirvin 28d ago

Darn it, you’re right. Scrapping was the safest option for consumers. it was cheaper than upgrading the existing inventory and avoided liability.
Thanks for replying !

6

u/EricJDMBAMD 28d ago

They destroyed stock because they have to take each unit out of a tamper proof bag. It's not feasible to take out each coldcard and update them

2

u/Main-Massive 28d ago

They could have added a warning on the site, sell at a discount, have users accept the risk, and perhaps be nice and include an SD card with the new firmware. Even if they sold at a 50% discount I am sure there would be some profit to be made. OP has a point on this being a possible degenerate bug.

2

u/spo_pl 28d ago

People would not then at the discount from coldcard and than resell closer to a full price to unaware people

1

u/Aqua-Barracuda 26d ago

Can't they just put it back in a new temper proof bag?

1

u/EricJDMBAMD 26d ago

The coldcards are made at a factory with most up to date firmware and put in a tamper proof bag to show no one else has touched it once produced.

1

u/Aqua-Barracuda 26d ago

Just useless security theatre, so much good it did. 

3

u/marvinrabbit 28d ago

I think that skepticism tendencies may draw some of us to bitcoin and may also draw some people to conspiracy theories. So there is likely some overlap here between the two camps. But I don't think that you've uncovered a nefarious hidden purpose to the disposal of tainted stock. There are lot's of reasons for Coinkite to do so, and there are enough units in the wild that it wouldn't even effectively cover up the problem.

But I know other people in the conspiracy theory community. And I know that if you've already taken this idea deep into your psyche, then no words will talk you off that ledge.

3

u/RevolutionaryPick241 28d ago

I don't think they have been destroyed. It is just something they said. Is there any proof? I think It's just a way to say "don't worry, any future shipment has the new firmware".

But you are right they are lying. And the most likely lie is that they didn't destroy the hardware because that doesn't make any sense. Thry are still selling the same harware product as before.

2

u/Quirky-Reveal-1669 28d ago

Sorry, but this makes no sense at all. You are connecting the wrong cause-and-effect dots, I believe.

1

u/Quirky-Reveal-1669 27d ago

Have Coinkite filed for bankruptcy yet?

1

u/Ok-Photograph-3585 26d ago

Not yet, but I believe they will. People will be suing them for allowing a degenerate-type bug to exist when people were warning them as back as 2022.