Thank you for the wonderful feedback both in this thread and DMs. Please find below our response. The team is currently working very hard on our BTC Multisig (NPM packages completed and in internal testing) allowing for full remote and air-gapped signing of multisigs on BTC, this is inclusive of our software wallet tooling (like Sparrow). Furthermore our EVM units are busy with internal testing (100% air-gapped like all our devices) and we are thrilled with the speed of signing and broadcasting (roughly 2 seconds). Its important to note that our BTC-only version and EVM run on different code bases and are completely separate.
Since you already saw topic I created and you didn't address what I wrote, I will repeat that I think charging so much for Cardware warranty is not cool.
Thank you for the feedback, this was designed to ensure users have access to a full replacement in the event of any issues. However your point is valid and we are busy reviewing this. Updates will be provided in future.
As far as I see it this HW has to be paired first with such widely spread software clients such as Sparrow, Electrum, Bluewallet etc. to communicate with them via PSBT, Is this correct?
The Cardware Wallet only pairs with the watch-only wallet front end (which is also open sourced). We have already built, and are actively testing our open source tooling for wallets like Sparrow etc. These tools will ensure full support of most PSBT software wallets.
Ideally we will focus on full integration, however in the interim we have the tools to ensure compatibility.
Since you only mentioned the Bitcoin-only devices as air-gapped devices, am I correct in assuming that the upcoming device that also supports EVM-compatible assets isn't fully air-gapped?
No, all of our units are 100% air-gapped with zero compromise in this regard. We believe any device housing your private key should never be exposed online. The EVM unit does however have a separate code base to ensure no overlap with our BTC-Only version and will be fully open-sourced.
You have a point, but what if the code used in Cardware turns out to be vulnerable to a new attack in a few years? What will be the best course of action for your users at that time?
While we believe this doesn’t pose a risk to any future signing (ie. The devices should always work) it does also present another transparency issue on our side. Due to the air-gapped design advanced users are unable to verify the firmware. This is why the team has made the decision to upgrade the hardware with an SD card in future for the more advanced users allowing full firmware updates and the ability to verify firmware versions. This is a simple addition on our end, but is something required to ensure full transparency and verifiability.
Based on the screenshots of the web wallet, it appears that there's a send button and I'd like to know its true function.
The front end simply calls the NPM packages, which can be found here:
https://docs.cardwarewallet.com/cardware-wallet-documentation/npm-packageAnother hardware wallet is always a good thing, especially if it's air-gapped and competitively priced. I went to see how much it actually costs, and just by selecting the euro as the currency, it shows me about EUR 120, to which at least customs and VAT costs should be added (if we take into account that shipping is already included).
We are constantly upgrading our services to include cheaper or alternative shipping options. Unfortunately, these prices are outside of our control and dictated entirely by DHL. We are currently onboarding a broad range of other providers.
It's probably going to be the same thing like with many c0dldcard devices that became unfixable and unsafe to use, even with ability for firmware to be updated.
C0ldcard is not the only manufacturer with graveyard of many defunct unsafe devices, ledger joined them in team no-open-source, and there are probably many others.
If I was in charge of Cardware I would enable offline firmware update if possible.
We agree completely, thank you for the feedback. While our entire focus is ensuring full backwards compatibility with our devices, we want to service a major request about transparency. This is why we will be releasing an SD card version in the near future allowing more advanced users to not only code their own devices, but also to verify firmware data. 100% security or nothing.
Please keep track of our socials for more information about our future releases and products:
https://linktr.ee/cardwarewallet