The Coldcard hack proves reputation is not a security model

The article argues that Coldcard's recent security failure highlights the dangers of relying on reputation rather than verifiable open-source security. It details how a shift away from GPL licensing and a rushed code rewrite led to a critical vulnerability in the hardware wallet.
Coldcard's source code was always available for inspection. "Don't trust, verify" only works when qualified people actually look, and for five years, effectively nobody did. The timeline around the bug's introduction deserves attention. In 2020, Coldcard's firmware carried a GPL open-source license. Two days after a competitor announced a device building on that GPL code, Coinkite CEO Rodolfo Novak, known as NVK, said publicly (in a since-deleted tweet ) that he regretted choosing GPL. That November, Coldcard adopted a new license with the Commons Clause, whose own FAQ states plainly that the resulting software is no longer open source. A sweeping rewrite followed, and the March 2021 commit that stripped out the last GPL code is the same commit that broke seed generation.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in