Loading market data...
Back to Feed
CRYPTO NEWS

The Coldcard hack proves reputation is not a security model

Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$114 millionBTC

Summary

Attackers exploited a flaw in Coldcard hardware wallet firmware that generated insufficiently random wallet seeds, draining nearly $114 million in bitcoin from over 709 addresses. The bug originated in a March 2021 commit following a license change and rewrite of the firmware, and it remained publicly visible without detection for more than five years. The incident highlights broader issues beyond the code itself, including community dynamics and attitudes toward security research.

Why it matters

The exploit reveals that reputation and repeated assertions replaced actual verification in the security culture around Coldcard and the broader self-custody community. The episode calls into question trust dynamics in the industry, showing that even well-regarded products and personalities need independent scrutiny. It underlines the continuing importance of open-source principles and adversarial media coverage to maintain security in cryptocurrency infrastructure.

Key context

Coldcard’s source was open-source until 2020 under a GPL license. In late 2020, Coldcard switched to a Commons Clause license, making the firmware no longer open-source, and this coincided with a major code rewrite that introduced the flaw. Previous security researchers reporting issues were publicly discredited or threatened legally by Coldcard’s leadership, discouraging independent review. This hostile environment contributed to the flaw going unnoticed for years despite public code availability.

Key numbers and entities

Nearly $114 million in bitcoin were stolen from more than 709 wallets. The vulnerable firmware commit occurred in March 2021. Coldcard’s developer is Coinkite, led by CEO Rodolfo Novak (NVK). Security researchers mentioned include groups like Shift Crypto, Nunchuk, and WalletScrutiny. BTC Sessions’ host Ben Perrin also commented on community dynamics. No further specific figures or entities are detailed.

What remains unclear

The source does not quantify how much the licensing changes pressured the rewrite or what exact technical decisions led to the entropy flaw. It is also unclear whether the aggressive public responses to researchers were directly responsible for deterring audits that would have caught the bug. The extent of affected users beyond the known drained addresses is not detailed.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]