Bitcoin Forum
October 02, 2026, 09:32:47 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 [40]
  Print  
Author Topic: Large-scale Coldcard compromise (1596 BTC stolen so far)  (Read 13702 times)
Leon Zimmer
Jr. Member
*
Offline

Activity: 42
Merit: 60


View Profile
September 27, 2026, 07:48:20 AM
 #781


ColdCard was NOT open source. ColdCard was Source Verifiable.

What's the difference? Open source means anybody can use the code, even in their own work.

Source verifiable means anyone can read the code, but they can't use it in their own work. So, what's the incentive for experts to read it? And even for those who do read it... some bugs aren't likely to be spotted on sight. It isn't until you tinker with it that you realize something behaves unexpectedly.

ColdCard got greedy. They didn't want people using their code. Their hubris and greed led to them getting wrecked, and that would be great if ColdCard users didn't get wrecked too.

Which brings us to Coinkite’s “open” code. The last part is key. If you’d used MIT or GPL, others could fork it or provide fixes for a fee or sell competing products. With the current license anyone can read it, but they can’t make competing commercial products. That means the only people with an incentive to deeply analyze the code are researchers looking to make a reputation, who are unlikely to closely review entropy generation, or people looking to exploit it, who are likely to closely review entropy generation.

Deeply analyzing entropy generation happens if you get paid to do so, or if you’re trying to exploit it. That’s why this bug sat around for 5 years. Coinkite gets the PR of open source, with the legal protections of closed. They got the marketing benefit of both models and the security benefit of neither. Illusory security through questionable licensing.
Cricktor
Legendary
*
Offline

Activity: 1638
Merit: 4569



View Profile
September 27, 2026, 01:39:47 PM
Merited by vapourminer (4)
 #782

Who has an incentive to look closely at the code? At least those, who want to benefit from potential exploits, as happened in the recent Coldcard debacle.

Do security researchers have an incentive? It depends on minimum two prerequisites:
a) a fair bug bounty program
b) a company which is open to a constructive discourse about bugs, issues, flaws of their product

To be fair, I don't know if Coinkite has a bug bounty program in place. Dealing with reported issues, maybe also including bugs, my reception isn't really positive on how Coinkite and nvK handled it in the past (I'm certainly somewhat more negatively biased here, as I paid more attention to negative behavior than the opposite).

This likely creates an environment which isn't quite encouraging for security researchers. I mean, those commonly preinvest their time and therefore money to find something that will or rather should pay off later. If you're in that business, you don't really want to be brushed off by some arrogant dudes who think their product is superior.

Well, and voluntarily auditing the code? I doubt there are many with good enough expertise to do it for free or "for the merits". Has Coinkite ever acknowledged external contributions to improve their code? Genuine question, because I don't know and never cared to pay attention to it because the company management's behavior to date has completely repelled me.

Danish Ali
Member
**
Offline

Activity: 84
Merit: 163

★Bitvest.io★ Play Plinko or Invest!


View Profile
September 27, 2026, 04:38:13 PM
Merited by ryzaadit (1)
 #783

Who has an incentive to look closely at the code? At least those, who want to benefit from potential exploits, as happened in the recent Coldcard debacle.

This is also, I think, a good example of how just because it's reviewable doesn't mean it will be reviewed properly, as the bug was discovered by gmaxwell looking at code. Several people reached the same conclusion by disassembling the firmware. Either way, people were able to go and look at the code/firmware, but this doesn't mean that most people can/will. It takes a highly-skilled analyst to recognize what went wrong here. Openness alone is no panacea, since it took someone as good as gmaxwell to recognize a #define/#ifdef mixup.


This likely creates an environment which isn't quite encouraging for security researchers. I mean, those commonly preinvest their time and therefore money to find something that will or rather should pay off later.

And the real crux: assuming a researcher is able to find such a subtle vulnerability, and finding an RNG whitening bug is no cake-walk either, they may very well decide to exploit it, sell it or report it. Selling/exploitation will get them way more money than bug bounty will. And potentially millions.

So, unless you want to compete with black-market in offering bounties , your company’s bounty policy, however generous, will be irrelevant. Ethics and professional reputation are the only things keeping such researchers from exploiting vulnerabilities they discover.


Has Coinkite ever acknowledged external contributions to improve their code? Genuine question, because I don't know and never cared to pay attention to it

Aside from the RNG issue itself, I think it's important to comment on the treatment of outside researchers. It doesn't take long before it becomes common knowledge in security circles if a company is going to ignore outside researchers. The next person who finds something really serious at this company might not be jumping through hoops to report it for free. At best, they'll say nothing. At worst, they'll sell it on the black market.

▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ ★ ★ ★ ★ ★ ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
● PLINKO    |7| SLOTS     (+) ROULETTE    ▼ BIT SPIN ║ BITVEST ║ PLAY or INVEST ║ ✔ Rainbot  ✔ Happy Hours  ✔ Faucet
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ ★ ★ ★ ★ ★ ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
ryzaadit
Legendary
*
Offline

Activity: 3346
Merit: 1553



View Profile WWW
September 27, 2026, 08:08:28 PM
Merited by vapourminer (1)
 #784

To be fair, I don't know if Coinkite has a bug bounty program in place. Dealing with reported issues, maybe also including bugs, my reception isn't really positive on how Coinkite and nvK handled it in the past (I'm certainly somewhat more negatively biased here, as I paid more attention to negative behavior than the opposite).

This likely creates an environment which isn't quite encouraging for security researchers. I mean, those commonly preinvest their time and therefore money to find something that will or rather should pay off later. If you're in that business, you don't really want to be brushed off by some arrogant dudes who think their product is superior.

Well, and voluntarily auditing the code? I doubt there are many with good enough expertise to do it for free or "for the merits". Has Coinkite ever acknowledged external contributions to improve their code? Genuine question, because I don't know and never cared to pay attention to it because the company management's behavior to date has completely repelled me.
No wonder you have a negative bias against CoinKite/nVk. I think other people feel the same way you do. Since we all know nVk has been known for anti-open source and has a history of sending someone cease-and-desist letters. In the past few days and weeks, they have also started to block everyone on X. I don't think that's a good reason to block everyone while they should take any word (including a negative opinion) since they already make people lose their entire life-saving.


Source: https://x.com/asanoha_gold/status/2102631552039727456/



This is someone who reported being drained from mk4 even before the tragedy, resulting being blocked from the channels.


I don't think voluntary auditors, researchers, white-hats, and bug hunters want to dealing with these behaviors. Mostly, they're just being ignored.

Wind_FURY
Legendary
*
Offline

Activity: 3794
Merit: 2226



View Profile
September 29, 2026, 11:58:11 AM
 #785

Currently only know DART. I checked both DART & Crypto Recovery Trust, and they're really new. I guess DART is taking this case as a pro bono case for the security portfolio of their service.

What are their terms for payment? Do they get a percentage of what they get from those wallets that weren't adequately secured?

Plus do those white-hat hacking services get licenses from the government for them to be allowed to operate? I believe not.

Don't you find it strange that these companies, despite having existed for some time and having no publicly verifiable cases of previous recoveries,


Plus the government probably doesn't give licenses for cyber security companies start hacking as "White-Hats".

Quote

suddenly appear directly involved in recovering the funds from the Coldcard hack?


They're probably looking for vulnerable wallets to "recover" without the owners knowing that they're being "recovered".



Quote

It's just a question I'm leaving open. Maybe I'm seeing things where they aren't there.


You have your right to question, especially if Bitcoin is involved, even it's not your Bitcoin.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
gmaxwell
Staff
Legendary
*
Offline

Activity: 4872
Merit: 11590



View Profile WWW
September 29, 2026, 07:21:35 PM
Merited by LoyceV (4), ABCbits (2), vapourminer (1), JayJuanGee (1), ryzaadit (1), stwenhao (1)
 #786

Who has an incentive to look closely at the code?
People who want to use it to secure their assets, or people working on behalf of people who do!

Unfortunately, CC has quite a few technical (and social) smells...  so they got rejected by many people *before* they looked at it close enough that they might have discovered that issue. (or even before that issue was introduced).

You follow?  -- imagine yourself a technical expert, you're interested in CC for your own use... so you go look at it and you see it's mixing in some absolutely useless joke of a PRNG.  Then you go nope, close the window.  The fact that you see some stupid but apparently benign design feature is enough to move on.  You didn't *know* there was anything actually wrong with it, it just didn't reek of competence.  I even made a reddit post remarking on CC long back riffing on some bad smell from just their public marketing copy (specifically on the point that mixing in a security useless PRNG could mask fatal security bugs-- which is in fact a thing that happened here! ... sucks to be right).

Unfortunately you need to know there is an actual issue to seriously warn people off of it... but most of the people who might spot one don't bother going that far.

Independent outside security auditing is something people should want to see here.  Though in this specific case it might not have helped: any audits are inherently at a point in time and this was not a day-0 vulnerability, they introduced it along the way.  The rewrite they did was substantial enough that it deserved a new audit (certainly in hindsight!) but I dunno that users would have known to demand one.  I'm been the receiving end of several different third party commercial audits of Bitcoin Core and am a bit dubious of their value-- they tend to produce a lot of nitpicking and have missed more subtle but serious issues we knew existed but couldn't fix yet-- but this kind of "doesn't use the RNG" thing is exactly the sort of issue those audit firms are pretty good at finding.

Cricktor
Legendary
*
Offline

Activity: 1638
Merit: 4569



View Profile
September 29, 2026, 07:54:25 PM
 #787

...
I guess very few potential users or buyers would actually do such source code level scrutiny to not fall into the trap that Coldcard produced either by negligence/arrogance or even some sort of malice. I agree and get your point.

Unfortunately you need to know there is an actual issue to seriously warn people off of it... but most of the people who might spot one don't bother going that far.
I can imagine nobody wants to stick their head into the shit storm tornado. Sad, but unfortunately it is what it is.

I take from an audit in the past, depending how verbose it actually is, an overview of maybe design and code quality or if there are fundamental code architectural flaws. But I doubt an audit is ordered in such an open and general way because it's going to be very expensive. And yes, it's a snapshot of a state of the past. New code on top of the audit snapshot needs to be very carefully re-evaluated, not easy for people who aren't proficient in such things.


Wind_FURY
Legendary
*
Offline

Activity: 3794
Merit: 2226



View Profile
September 30, 2026, 07:15:52 AM
 #788

Who has an incentive to look closely at the code?
People who want to use it to secure their assets, or people working on behalf of people who do!

Unfortunately, CC has quite a few technical (and social) smells...  so they got rejected by many people *before* they looked at it close enough that they might have discovered that issue. (or even before that issue was introduced).

You follow?  -- imagine yourself a technical expert, you're interested in CC for your own use... so you go look at it and you see it's mixing in some absolutely useless joke of a PRNG.  Then you go nope, close the window.  The fact that you see some stupid but apparently benign design feature is enough to move on.  You didn't *know* there was anything actually wrong with it, it just didn't reek of competence.  I even made a reddit post remarking on CC long back riffing on some bad smell from just their public marketing copy (specifically on the point that mixing in a security useless PRNG could mask fatal security bugs-- which is in fact a thing that happened here! ... sucks to be right).

Unfortunately you need to know there is an actual issue to seriously warn people off of it... but most of the people who might spot one don't bother going that far.

Independent outside security auditing is something people should want to see here.  Though in this specific case it might not have helped: any audits are inherently at a point in time and this was not a day-0 vulnerability, they introduced it along the way.  The rewrite they did was substantial enough that it deserved a new audit (certainly in hindsight!) but I dunno that users would have known to demand one.  I'm been the receiving end of several different third party commercial audits of Bitcoin Core and am a bit dubious of their value-- they tend to produce a lot of nitpicking and have missed more subtle but serious issues we knew existed but couldn't fix yet-- but this kind of "doesn't use the RNG" thing is exactly the sort of issue those audit firms are pretty good at finding.


OK, now knowing about Cold Card's issue and their incompetent developers,  I will ask - Which hardware wallet, from what we see right now, would be the safest device to store our Bitcoin?

We'll take your suggestion NOT as an endorsement of a product, but as a form of guidance from a technical expert in Bitcoin development.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 [40]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!