Coldcard was seen as the 'luxury car' of cold storage devices among a lot of people including a lot of fairly technical people. For a reason!
Because they looked cyber-punk and they marketed their products as being more secure even though they weren't. And we know they weren't because thousands of their users are being robbed.
ColdCard devices are cheap plastic, and the design flaws are baffling. The camera for scanning QR codes isn't even pointed in the right direction. The screen on the Q is larger than their calculator-style devices, but they barely utilize the larger screen. The font is still tiny and the color is darker than it should be, making it harder to read. These are bizarre design flaws that show a lack of attention to detail. And the error in the code further proved a lack of attention to detail. That was shocking.
I wish I could convince people who claim to be serious about Bitcoin self custody to stop thinking a brand is their savior. It's bizarre. If you're going to trust a company to secure your Bitcoin, why not just buy into an ETF?
I love Bitcoin, and I love this community, but my God, all it takes to sucker people is a pic with laser eyes. Ledger literally added key-extraction to their firmware and people still trust them. That's crazy. ColdCard's shoddy code caused the biggest heist in the entire history of hardware wallets, and people are making excuses for trusting them because calculators and Blackberries look cool? Just... wow.
I'm literally begging some of you to take self custody more seriously, and I know you don't want to hear it. You want to be told you should trust ColdCard. That's crazy.
Don't trust a brand. Don't trust your Bitcoin to any code that isn't open source, and don't trust any seed you cannot back up on pen and paper unless you're only storing a few sats there (Tangem!). "Most is open source" means some isn't open source. And "Source Verifiable" means it isn't open source at all. "Seedless" means poison if anything goes wrong.
Bitcoin is open source. Your hardware wallet should be too. And at this point, I think it's time to admit that trusting somebody else's code to generate the seed phrase you'll use to secure your financial future isn't wise. There are many better ways to randomly generate the first 11 or 23 words. It's fine to let a device calculate the checksum, but you're better off randomly generating your own first 11 or 23.
I know almost nobody in this forum wants to hear this stuff. People here are brand loyal. And, y'know what? I am too. I'm brand loyal for my coffee, my beer, my phone and my toilet paper. But for securing my Bitcoin? No way. I generate my own seed, excluding the checksum, and I doublecheck that on multiple devices. I trust Bitcoin's code and hardware wallets that adhere strictly to it while being open source, and I doublecheck everything on a separate hardware wallet when setting up a wallet. Brand loyal? For Bitcoin? No way.
To anybody who thinks they should trust ColdCard, I ask this: What has the Coinkite CEO been doing for the past two weeks, as thousands of his customers were being robbed? That is not a rhetorical question.
I'm literally begging some of you to take self custody more seriously.