r/Bitcoin: the Coldcard hack does not mean hardware wallets are doomed
reddit-coldcard-not-doom-hardware-wallets
https://www.reddit.com/r/Bitcoin/comments/1vmi5bq/the_coldcards_hack_doesnt_mean_hardware_wallets/
Latest reviewed change
source content difference between and
A comment by certifr1ed was added stating they are still sticking to open source wallets.
edited: false
body:
Even if these hardware wallets are compromised, a hack is preventable if you just used a secure (i.e. sufficiently random) passphrase. These are kind of like a password being added on to the random private key (although they technically just add extra entropy). ColdCard, Trezor, and Ledger all allow you to add this extra layer of security by adding a passphrase. ColdCard and Trezor allow anyone to scrutinize their source code so you know this passphrase makes them secure.
+
+comment: p3g2lbl
+parent: t1_p3cfauy
+author: certifr1ed
+created_utc: 1786629615
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 1
- Detected differences
- 1
- Unreviewed
- 0
- Copies held
- 2
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
A comment by certifr1ed was added stating they are still sticking to open source wallets.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: Even if these hardware wallets are compromised, a hack is preventable if you just used a secure (i.e. sufficiently random) passphrase. These are kind of like a password being added on to the random private key (although they technically just add extra entropy). ColdCard, Trezor, and Ledger all allow you to add this extra layer of security by adding a passphrase. ColdCard and Trezor allow anyone to scrutinize their source code so you know this passphrase makes them secure. + +comment: p3g2lbl +parent: t1_p3cfauy +author: certifr1ed +created_utc: 1786629615 +edited: false +body: +I'm still sticking to open sourceExtracted text as captured
post: 1vmi5bq author: chainglance_cm created_utc: 1786550264 title: The Coldcard's hack doesn't mean hardware wallets are doomed body: Seeing a lot of people treat the Coldcard hack like proof hardware wallets in general aren't safe anymore. That's not really what happened. Coldcard had a bug in how their firmware generated the random numbers used to create your seed phrase, and it sat there undetected for five years. A code change in March 2021 quietly swapped out the proper hardware randomness for a broken software substitute. That made some seeds way easier to guess than they should've been, and that's how funds got drained. That's a Coldcard problem. A mistake in their code, not a flaw in the whole idea of hardware wallets as a category. However, I'm not making the argument that it can't happen to other brands too. Any company can ship a bad update. But wallets that are fully open source, like Trezor or Blockstream Jade, tend to have way more independent people checking the code over time, which makes bugs like this less likely to slip through for years. Not a guarantee, just better odds. And this is how most tech usually evolves. Some things go wrong but that's how it becomes more robust and anti-fragile. But I also understand that "that's just how tech evolves" doesn't help people who actually lost their money. Genuinely feel for everyone who lost years of savings over something totally out of their control though, that part really sucks and doesn't get fixed by any of this logic. comment: p39jxs2 parent: t3_1vmi5bq author: never_safe_for_life created_utc: 1786550674 edited: false body: Thanks ChatGPT comment: p39klwp parent: t3_1vmi5bq author: mrjune2040 created_utc: 1786550844 edited: false body: Engagement slop. comment: p39mbx2 parent: t3_1vmi5bq author: GettingFasterDude created_utc: 1786551278 edited: false body: I think a Coldcard-like hack involving another cold wallet company is much less likely now, than it was prior to July 30th. All the other companies have the benefit of a wakeup call. The have the opportunity to use the same powerful AI programs to secure their software that the hackers used to exploit Coldcard's very amateurish software bug. comment: p39n2e0Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vmi5bq author: chainglance_cm created_utc: 1786550264 title: The Coldcard's hack doesn't mean hardware wallets are doomed body: Seeing a lot of people treat the Coldcard hack like proof hardware wallets in general aren't safe anymore. That's not really what happened. Coldcard had a bug in how their firmware generated the random numbers used to create your seed phrase, and it sat there undetected for five years. A code change in March 2021 quietly swapped out the proper hardware randomness for a broken software substitute. That made some seeds way easier to guess than they should've been, and that's how funds got drained. That's a Coldcard problem. A mistake in their code, not a flaw in the whole idea of hardware wallets as a category. However, I'm not making the argument that it can't happen to other brands too. Any company can ship a bad update. But wallets that are fully open source, like Trezor or Blockstream Jade, tend to have way more independent people checking the code over time, which makes bugs like this less likely to slip through for years. Not a guarantee, just better odds. And this is how most tech usually evolves. Some things go wrong but that's how it becomes more robust and anti-fragile. But I also understand that "that's just how tech evolves" doesn't help people who actually lost their money. Genuinely feel for everyone who lost years of savings over something totally out of their control though, that part really sucks and doesn't get fixed by any of this logic. comment: p39jxs2 parent: t3_1vmi5bq author: never_safe_for_life created_utc: 1786550674 edited: false body: Thanks ChatGPT comment: p39klwp parent: t3_1vmi5bq author: mrjune2040 created_utc: 1786550844 edited: false body: Engagement slop. comment: p39mbx2 parent: t3_1vmi5bq author: GettingFasterDude created_utc: 1786551278 edited: false body: I think a Coldcard-like hack involving another cold wallet company is much less likely now, than it was prior to July 30th. All the other companies have the benefit of a wakeup call. The have the opportunity to use the same powerful AI programs to secure their software that the hackers used to exploit Coldcard's very amateurish software bug. comment: p39n2e0Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.