Article may be outdated

This article is 46 days old. Some details may have changed since publication.

CoinDesk·4 min read·medium

The Coldcard hack proves reputation is not a security model

Z
Zach Herbert
The Coldcard hack proves reputation is not a security model
✦AI Summary

The article argues that Coldcard's recent security failure highlights the dangers of relying on reputation rather than verifiable open-source security. It details how a shift away from GPL licensing and a rushed code rewrite led to a critical vulnerability in the hardware wallet.

Why it matters

It underscores the importance of transparent, community-audited code in the cryptocurrency hardware industry where trust is often misplaced in company branding.

✦Dive DeeperCreate a free account to unlock

Coldcard's source code was always available for inspection. "Don't trust, verify" only works when qualified people actually look, and for five years, effectively nobody did. The timeline around the bug's introduction deserves attention. In 2020, Coldcard's firmware carried a GPL open-source license. Two days after a competitor announced a device building on that GPL code, Coinkite CEO Rodolfo Novak, known as NVK, said publicly (in a since-deleted tweet ) that he regretted choosing GPL. That November, Coldcard adopted a new license with the Commons Clause, whose own FAQ states plainly that the resulting software is no longer open source. A sweeping rewrite followed, and the March 2021 commit that stripped out the last GPL code is the same commit that broke seed generation.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycryptobusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in