r/coldcard: whether COLDCARD is really open source
reddit-coldcard-open-source-question
https://www.reddit.com/r/coldcard/comments/1vf4z1b/is_coldcard_really_open_source_or_not/
Latest reviewed change
source content difference between and
The post body was deleted and now reads [removed], while the title and comments remain. The prior capture preserves the original body asking whether Coldcard's code was available for inspection.
created_utc: 1785834128
title: Is Coldcard Really Open Source or Not?
body:
-Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs?
-
-Why did no-one spot the error in Coldcard's programing?
-
-[https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt)
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 6
- Detected differences
- 6
- Unreviewed
- 0
- Copies held
- 7
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The post body was deleted and now reads [removed], while the title and comments remain. The prior capture preserves the original body asking whether Coldcard's code was available for inspection.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: -Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs? - -Why did no-one spot the error in Coldcard's programing? - -[https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) - -Was it that the code was locked up and unavailable for inspection - -or was it available to inspect but no-one bothered? +[removed] comment: p1m5tc6 parent: t3_1vf4z1bExtracted text as captured
post: 1vf4z1b author: Crypto-Moony created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: [removed] comment: p1m5tc6 parent: t3_1vf4z1b author: Level-Set5770 created_utc: 1785834583 edited: false body: According to your definition. Yes, it is. Anyone can check the code. Why did no one spot the error? Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review. comment: p1m97b1 parent: t3_1vf4z1b author: RevolutionaryPick241 created_utc: 1785836263 edited: 1785847017 body: Open source is already defined. And coldcard firmware isn't. The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery. Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)... comment: p1me5rv parent: t3_1vf4z1b author: dDtaK created_utc: 1785838592 edited: false body: It was open source in the sense that the code was available, and indeed this is what enabled the attacker to find the exploit. People who claim it wasn't true open source are referring to the licence it was shared under. This is something of a technicality, though it's possible that if it was shared under a more permissive licence then more people would have used the code and the bug would have been found by a good actor not a bad one. Obviously we will never know.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit served 1 additional comment record(s); the diff preserves their text and any edits to existing records.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
It always been don't trust. But if you are trusting and not verifying. Then don't complain that no one verified because checking buggy code is hard work and testing and the people willing to do that is because they want to build on top of it. If you can't fork it, then you have less testing. By the way, haven't you seen all the "firmware upgrade bricked my cc", "my cc doesn't boot after I..", etc? That kind of bugs are easy to fix when another company tests the firmware on different hardware. + +comment: p1tbkzb +parent: t3_1vf4z1b +author: _gianlucag_ +created_utc: 1785917100 +edited: false +body: +Being open source is totally irrelevant if you are unable to compile and flash the binary into the device. You can inspect the code on github or whatever but that's non sense if you just trust that software is really the one running on your device.Extracted text as captured
post: 1vf4z1b author: Crypto-Moony created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs? Why did no-one spot the error in Coldcard's programing? [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) Was it that the code was locked up and unavailable for inspection or was it available to inspect but no-one bothered? comment: p1m5tc6 parent: t3_1vf4z1b author: Level-Set5770 created_utc: 1785834583 edited: false body: According to your definition. Yes, it is. Anyone can check the code. Why did no one spot the error? Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review. comment: p1m97b1 parent: t3_1vf4z1b author: RevolutionaryPick241 created_utc: 1785836263 edited: 1785847017 body: Open source is already defined. And coldcard firmware isn't. The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery. Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained new participant comments.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
Just another midwit regurgitating shit takes. Since when did **"trust but verify"** become **"trust but only verify if I can fork it to start my own project"** + +comment: p1qy08f +parent: t1_p1qh56a +author: RevolutionaryPick241 +created_utc: 1785884699 +edited: false +body: +It always been don't trust. But if you are trusting and not verifying. Then don't complain that no one verified because checking buggy code is hard work and testing and the people willing to do that is because they want to build on top of it. If you can't fork it, then you have less testing. + +By the way, haven't you seen all the "firmware upgrade bricked my cc", "my cc doesn't boot after I..", etc? That kind of bugs are easy to fix when another company tests the firmware on different hardware.Extracted text as captured
post: 1vf4z1b author: Crypto-Moony created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs? Why did no-one spot the error in Coldcard's programing? [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) Was it that the code was locked up and unavailable for inspection or was it available to inspect but no-one bothered? comment: p1m5tc6 parent: t3_1vf4z1b author: Level-Set5770 created_utc: 1785834583 edited: false body: According to your definition. Yes, it is. Anyone can check the code. Why did no one spot the error? Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review. comment: p1m97b1 parent: t3_1vf4z1b author: RevolutionaryPick241 created_utc: 1785836263 edited: 1785847017 body: Open source is already defined. And coldcard firmware isn't. The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery. Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment about open-source verification.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
> or was it available to inspect but no-one bothered? I'd say some people bothered for the same reason the attacker last week did, they just failed for 5 years until last week, for the reason I just gave above. + +comment: p1qh56a +parent: t1_p1m97b1 +author: Level-Set5770 +created_utc: 1785879752 +edited: false +body: +Just another midwit regurgitating shit takes. + +Since when did **"trust but verify"** become **"trust but only verify if I can fork it to start my own project"**Extracted text as captured
post: 1vf4z1b author: Crypto-Moony created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs? Why did no-one spot the error in Coldcard's programing? [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) Was it that the code was locked up and unavailable for inspection or was it available to inspect but no-one bothered? comment: p1m5tc6 parent: t3_1vf4z1b author: Level-Set5770 created_utc: 1785834583 edited: false body: According to your definition. Yes, it is. Anyone can check the code. Why did no one spot the error? Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review. comment: p1m97b1 parent: t3_1vf4z1b author: RevolutionaryPick241 created_utc: 1785836263 edited: 1785847017 body: Open source is already defined. And coldcard firmware isn't. The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery. Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
edited: false body: Ledger is not 100% open source, parts of the ledger os that interact with the Secure Element chip are closed. Trezor is closer to 100% but not 100%. You have to trust a company at some point. + +comment: p1pwdku +parent: t3_1vf4z1b +author: snek-jazz +created_utc: 1785874169 +edited: 1785874632 +body: +Some people have tried to redefine Open Source to mean FOSS (Free and Open Source Software). It's confusing and annoying. + +Yes the code is open source, but it's not FOSS. + +> Why did no-one spot the error in Coldcard's programing? + +Because it's hard for a human to find without the latest AI models. That's why it was found right after Kimi 3 became available. And it's why Calle and the others using AI to look into other projects this week with AI have said they're finding 1 critical bug per hour. + +> or was it available to inspect but no-one bothered? + +I'd say some people bothered for the same reason the attacker last week did, they just failed for 5 years until last week, for the reason I just gave above.Extracted text as captured
post: 1vf4z1b author: Crypto-Moony created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs? Why did no-one spot the error in Coldcard's programing? [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) Was it that the code was locked up and unavailable for inspection or was it available to inspect but no-one bothered? comment: p1m5tc6 parent: t3_1vf4z1b author: Level-Set5770 created_utc: 1785834583 edited: false body: According to your definition. Yes, it is. Anyone can check the code. Why did no one spot the error? Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review. comment: p1m97b1 parent: t3_1vf4z1b author: RevolutionaryPick241 created_utc: 1785836263 edited: 1785847017 body: Open source is already defined. And coldcard firmware isn't. The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery. Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: It was "source available software". Means everyone can view it, but cannot make a product using that code and start selling it, offering services, etc. + +comment: p1p3m2g +parent: t3_1vf4z1b +author: EyesFor1 +created_utc: 1785866794 +edited: false +body: +Ledger is not 100% open source, parts of the ledger os that interact with the Secure Element chip are closed. Trezor is closer to 100% but not 100%. You have to trust a company at some point.Extracted text as captured
post: 1vf4z1b author: Crypto-Moony created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs? Why did no-one spot the error in Coldcard's programing? [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) Was it that the code was locked up and unavailable for inspection or was it available to inspect but no-one bothered? comment: p1m5tc6 parent: t3_1vf4z1b author: Level-Set5770 created_utc: 1785834583 edited: false body: According to your definition. Yes, it is. Anyone can check the code. Why did no one spot the error? Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review. comment: p1m97b1 parent: t3_1vf4z1b author: RevolutionaryPick241 created_utc: 1785836263 edited: 1785847017 body: Open source is already defined. And coldcard firmware isn't. The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery. Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vf4z1b author: Crypto-Moony created_utc: 1785834128 title: Is Coldcard Really Open Source or Not? body: Is Coldcard really open-source? I'm confused. I'm getting mixed messages about this. My definition of 'Open Source' for a a hardware wallet is: Can anyone download the code for free without permission and pay a software engineer or an AI to check for bugs? Why did no-one spot the error in Coldcard's programing? [https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt](https://insider.btcpp.dev/p/when-randombytes-runs-but-doesnt) Was it that the code was locked up and unavailable for inspection or was it available to inspect but no-one bothered? comment: p1m5tc6 parent: t3_1vf4z1b author: Level-Set5770 created_utc: 1785834583 edited: false body: According to your definition. Yes, it is. Anyone can check the code. Why did no one spot the error? Because it is niche product and nobody bothered. Most of the clowns who regurgitate "trust but verify" never had the technical knowhow to actually do a proper review. comment: p1m97b1 parent: t3_1vf4z1b author: RevolutionaryPick241 created_utc: 1785836263 edited: 1785847017 body: Open source is already defined. And coldcard firmware isn't. The reason no one bothered is because it isn't open source. If you can't fork it to start your own product, you don't test it. Choosing a source available license is usually an act of misery. Edit: because it can be misunderstood: "Choosing a source available license" (instead an open source licence)...Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.