CoinDesk·4 min read·medium

The Coldcard hack proves reputation is not a security model

Z
Zach Herbert
The Coldcard hack proves reputation is not a security model
AI Summary

The article argues that Coldcard's recent security failure highlights the dangers of relying on reputation rather than verifiable open-source security. It details how a shift away from GPL licensing and a rushed code rewrite led to a critical vulnerability in the hardware wallet.

Coldcard's source code was always available for inspection. "Don't trust, verify" only works when qualified people actually look, and for five years, effectively nobody did. The timeline around the bug's introduction deserves attention. In 2020, Coldcard's firmware carried a GPL open-source license. Two days after a competitor announced a device building on that GPL code, Coinkite CEO Rodolfo Novak, known as NVK, said publicly (in a since-deleted tweet ) that he regretted choosing GPL. That November, Coldcard adopted a new license with the Commons Clause, whose own FAQ states plainly that the resulting software is no longer open source. A sweeping rewrite followed, and the March 2021 commit that stripped out the last GPL code is the same commit that broke seed generation.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycryptobusiness

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in