▼ Bear
Impact
98 · High

The "reputation security model" exposed by the Coldcard hacking incident

BTC
CoinDesk · Aug 17, 04:12 PMView original ↗
Attackers exploited a flaw in the Coldcard firmware's entropy generation to steal approximately $114 million worth of Bitcoin from over 709 addresses. The first wave of the attack emptied nearly 500 wallets in just 25 minutes. The core of the flaw lies in the fact that sufficient randomness was not ensured when generating wallet seeds. The problematic code was introduced in a commit in March 2021 and remained exposed in the open-source repository for over five years. Jack Herbert, co-founder and CEO of Foundation, argues that this incident is more than just a simple technical error. He points to the changes in Coldcard's licensing history. In 2020, when a competitor announced that it was developing a device based on GPL code, Coinkite CEO Rodolfo Novak (NVK) tweeted (and later deleted) that he regretted choosing the GPL. Later that same year, in November, Coldcard adopted a new license that included the Commons Clause, and the official FAQ for that license explicitly states that "the resulting product is no longer open source." A major code rewrite followed, and the commit that finally removed the GPL code in March 2021 is the same commit that broke the seed generation functionality. Herbert acknowledged that he could not precisely measure the extent to which licensing pressures influenced the scope or speed of the rewriting, but he emphasized that it is clear that "validated encryption code was hastily replaced after a licensing change intended to restrict competition, and that replacement contained flaws." The principles of free and open-source software exist to ensure that security does not depend on the choices of a specific company. A culture of hostility towards security researchers is also cited as a key factor. In August 2020, when Shift Crypto and Nunchuk researchers publicly disclosed a multi-signature validation flaw in Coldcard, NVK labeled this disclosure as "PR terrorism" on the Citadel Dispatch podcast. Similarly, when the WalletScrutiny project reported issues with reproducing older builds in 2023, NVK dismissed it as incompetence or malice and even mentioned the possibility of legal action. Subsequent independent investigations later confirmed that there were actual reproduction issues with the older builds and concluded that the researchers had no malicious intent. These attacks on researchers altered the risk assessment for anyone considering reporting vulnerabilities, ultimately reducing the likelihood that someone would come forward to report bugs. Hubert calls this phenomenon "epistemic capture." The same arguments, repeated through the same podcasts and feeds, began to feel like independently verified facts, and the community gradually outsourced its judgment to a single authority. Ben Perrin, the host of BTC Sessions, recently admitted during a livestream that "we tolerated that arrogance because we assumed it came along with exceptional product creation abilities.". Herbert emphasizes that the immediate priority should be to distribute migration instructions for affected users, and it is crucial to clearly state that seeds generated from vulnerable versions cannot be recovered through firmware updates. Furthermore, he urges that inaccurate recommended content from the past needs to be corrected, and that researchers who were targeted should be given the opportunity to speak. He concludes his message with the words: "Verify, do not trust the vendor, nor the vendor's critics, but verify.".
This is an AI summary. Read the full article at the source.
Comments 0
Log in to write a comment
Loading…