r/coldcard: who audited the firmware over the last five years
reddit-firmware-audit-history
https://www.reddit.com/r/coldcard/comments/1vchr6s/who_has_audited_those_firmwares_for_the_last_5/
Latest reviewed change
source content difference between and
The thread gained a reply attributing the alleged review gap to COLDCARD's source-verifiable licensing model, lack of bounties and Rodolfo Novak, which are the commenter's own assertions.
body:
I keep hearing this as a kind of excuse, but I don’t buy it. I think the fair criticism would be that Coinkite did not have bug bounties, etc. I wonder how many people actually did review the source code.
+comment: p1s2alt
+parent: t1_p1rmqd4
+author: Yodel_And_Hodl_Mode
+created_utc: 1785897735
+edited: false
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 5
- Detected differences
- 5
- Unreviewed
- 0
- Copies held
- 6
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The thread gained a reply attributing the alleged review gap to COLDCARD's source-verifiable licensing model, lack of bounties and Rodolfo Novak, which are the commenter's own assertions.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 14 lines
body: I keep hearing this as a kind of excuse, but I don’t buy it. I think the fair criticism would be that Coinkite did not have bug bounties, etc. I wonder how many people actually did review the source code. +comment: p1s2alt +parent: t1_p1rmqd4 +author: Yodel_And_Hodl_Mode +created_utc: 1785897735 +edited: false +body: +It's not an excuse. It's quite damning, actually. + +Rodolfo Novak switched the ColdCard license from open source to only being "Source Verifiable" out of hubris and greed. That decision led to fewer devs using ColdCard's code in their own work. That led to fewer errors being found. + +The lack of real bounties was an issue, but if more devs had been using the code in their own work, more devs would have been finding and reporting errors. + +This entire catastrophe is NVK's fault. + more-stub: parent t1_p1d8u3e count <live-count>Extracted text as captured
post: 1vchr6s author: seolein created_utc: 1785573088 title: WHO has audited those firmwares for the last 5 years? body: this is beyond outrage, who has done the audits for this? how can such a bug can be undetected for 5 years? how can you not constantly test your own device if everything is about security, how is it even allowed on the device to bypass the true randomness generation of the seed which is the whole point of a fucking hardware device? people need to go to jail for this - coinkite did not only fuck the lives of countless customers, they fucked every other hardware wallet company and the whole industry, there is no way I will use a wallet like this every again comment: p11pbd6 parent: t3_1vchr6s author: Mission-Disaster-447 created_utc: 1785580864 edited: false body: Yeah, they should have regularily run AI scans of their code with a swarm of agents, constantly checking for bugs. Thats what the hackers are doing too. comment: p129frr parent: t1_p11pbd6 author: Intelligent_Map_246 created_utc: 1785589016 edited: false body: Inside job 100℅. Could be them or somebody behind. This all smells fishy. comment: p12bnm1 parent: t1_p129frr author: eldude40 created_utc: 1785589784 edited: false body: I was just thinking this. Did anyone on the coinkite team lose any btc? comment: p13uv9c parent: t1_p129frr author: moviemaker2 created_utc: 1785606223 edited: false body: Not saying it's not, just that you have no way to know that, so ignorant speculation isn't helping anyone.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained a reply questioning how many people reviewed the source code and criticizing the absence of bug bounties.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Retirement plan +comment: p1rmqd4 +parent: t1_p13v4ny +author: SomeGuyInOz +created_utc: 1785892593 +edited: false +body: +I keep hearing this as a kind of excuse, but I don’t buy it. I think the fair criticism would be that Coinkite did not have bug bounties, etc. I wonder how many people actually did review the source code. + more-stub: parent t1_p1d8u3e count <live-count>Extracted text as captured
post: 1vchr6s author: seolein created_utc: 1785573088 title: WHO has audited those firmwares for the last 5 years? body: this is beyond outrage, who has done the audits for this? how can such a bug can be undetected for 5 years? how can you not constantly test your own device if everything is about security, how is it even allowed on the device to bypass the true randomness generation of the seed which is the whole point of a fucking hardware device? people need to go to jail for this - coinkite did not only fuck the lives of countless customers, they fucked every other hardware wallet company and the whole industry, there is no way I will use a wallet like this every again comment: p11pbd6 parent: t3_1vchr6s author: Mission-Disaster-447 created_utc: 1785580864 edited: false body: Yeah, they should have regularily run AI scans of their code with a swarm of agents, constantly checking for bugs. Thats what the hackers are doing too. comment: p129frr parent: t1_p11pbd6 author: Intelligent_Map_246 created_utc: 1785589016 edited: false body: Inside job 100℅. Could be them or somebody behind. This all smells fishy. comment: p12bnm1 parent: t1_p129frr author: eldude40 created_utc: 1785589784 edited: false body: I was just thinking this. Did anyone on the coinkite team lose any btc? comment: p13uv9c parent: t1_p129frr author: moviemaker2 created_utc: 1785606223 edited: false body: Not saying it's not, just that you have no way to know that, so ignorant speculation isn't helping anyone.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained new participant comments.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Retirement plan -comment: p1p6fhk -parent: t1_p1583qi -author: k_D-5kt7ZA4QGBP68ZBN -created_utc: 1785867490 -edited: false -body: -Every code executes as it was written. Congratulations you have just abolished bugs. - more-stub: parent t1_p1d8u3e count 0Extracted text as captured
post: 1vchr6s author: seolein created_utc: 1785573088 title: WHO has audited those firmwares for the last 5 years? body: this is beyond outrage, who has done the audits for this? how can such a bug can be undetected for 5 years? how can you not constantly test your own device if everything is about security, how is it even allowed on the device to bypass the true randomness generation of the seed which is the whole point of a fucking hardware device? people need to go to jail for this - coinkite did not only fuck the lives of countless customers, they fucked every other hardware wallet company and the whole industry, there is no way I will use a wallet like this every again comment: p11pbd6 parent: t3_1vchr6s author: Mission-Disaster-447 created_utc: 1785580864 edited: false body: Yeah, they should have regularily run AI scans of their code with a swarm of agents, constantly checking for bugs. Thats what the hackers are doing too. comment: p129frr parent: t1_p11pbd6 author: Intelligent_Map_246 created_utc: 1785589016 edited: false body: Inside job 100℅. Could be them or somebody behind. This all smells fishy. comment: p12bnm1 parent: t1_p129frr author: eldude40 created_utc: 1785589784 edited: false body: I was just thinking this. Did anyone on the coinkite team lose any btc? comment: p13uv9c parent: t1_p129frr author: moviemaker2 created_utc: 1785606223 edited: false body: Not saying it's not, just that you have no way to know that, so ignorant speculation isn't helping anyone.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 1 new comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: Retirement plan +comment: p1p6fhk +parent: t1_p1583qi +author: k_D-5kt7ZA4QGBP68ZBN +created_utc: 1785867490 +edited: false +body: +Every code executes as it was written. Congratulations you have just abolished bugs. + more-stub: parent t1_p1d8u3e count 0Extracted text as captured
post: 1vchr6s author: seolein created_utc: 1785573088 title: WHO has audited those firmwares for the last 5 years? body: this is beyond outrage, who has done the audits for this? how can such a bug can be undetected for 5 years? how can you not constantly test your own device if everything is about security, how is it even allowed on the device to bypass the true randomness generation of the seed which is the whole point of a fucking hardware device? people need to go to jail for this - coinkite did not only fuck the lives of countless customers, they fucked every other hardware wallet company and the whole industry, there is no way I will use a wallet like this every again comment: p11pbd6 parent: t3_1vchr6s author: Mission-Disaster-447 created_utc: 1785580864 edited: false body: Yeah, they should have regularily run AI scans of their code with a swarm of agents, constantly checking for bugs. Thats what the hackers are doing too. comment: p129frr parent: t1_p11pbd6 author: Intelligent_Map_246 created_utc: 1785589016 edited: false body: Inside job 100℅. Could be them or somebody behind. This all smells fishy. comment: p12bnm1 parent: t1_p129frr author: eldude40 created_utc: 1785589784 edited: false body: I was just thinking this. Did anyone on the coinkite team lose any btc? comment: p13uv9c parent: t1_p129frr author: moviemaker2 created_utc: 1785606223 edited: false body: Not saying it's not, just that you have no way to know that, so ignorant speculation isn't helping anyone.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
1 new Reddit comment was posted, including Makunouchiipp0.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: All good points. +comment: p1ms7ju +parent: t1_p19s1jn +author: Makunouchiipp0 +created_utc: 1785844191 +edited: false +body: +Retirement plan + more-stub: parent t1_p1d8u3e count 0Extracted text as captured
post: 1vchr6s author: seolein created_utc: 1785573088 title: WHO has audited those firmwares for the last 5 years? body: this is beyond outrage, who has done the audits for this? how can such a bug can be undetected for 5 years? how can you not constantly test your own device if everything is about security, how is it even allowed on the device to bypass the true randomness generation of the seed which is the whole point of a fucking hardware device? people need to go to jail for this - coinkite did not only fuck the lives of countless customers, they fucked every other hardware wallet company and the whole industry, there is no way I will use a wallet like this every again comment: p11pbd6 parent: t3_1vchr6s author: Mission-Disaster-447 created_utc: 1785580864 edited: false body: Yeah, they should have regularily run AI scans of their code with a swarm of agents, constantly checking for bugs. Thats what the hackers are doing too. comment: p129frr parent: t1_p11pbd6 author: Intelligent_Map_246 created_utc: 1785589016 edited: false body: Inside job 100℅. Could be them or somebody behind. This all smells fishy. comment: p12bnm1 parent: t1_p129frr author: eldude40 created_utc: 1785589784 edited: false body: I was just thinking this. Did anyone on the coinkite team lose any btc? comment: p13uv9c parent: t1_p129frr author: moviemaker2 created_utc: 1785606223 edited: false body: Not saying it's not, just that you have no way to know that, so ignorant speculation isn't helping anyone.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vchr6s author: seolein created_utc: 1785573088 title: WHO has audited those firmwares for the last 5 years? body: this is beyond outrage, who has done the audits for this? how can such a bug can be undetected for 5 years? how can you not constantly test your own device if everything is about security, how is it even allowed on the device to bypass the true randomness generation of the seed which is the whole point of a fucking hardware device? people need to go to jail for this - coinkite did not only fuck the lives of countless customers, they fucked every other hardware wallet company and the whole industry, there is no way I will use a wallet like this every again comment: p11pbd6 parent: t3_1vchr6s author: Mission-Disaster-447 created_utc: 1785580864 edited: false body: Yeah, they should have regularily run AI scans of their code with a swarm of agents, constantly checking for bugs. Thats what the hackers are doing too. comment: p129frr parent: t1_p11pbd6 author: Intelligent_Map_246 created_utc: 1785589016 edited: false body: Inside job 100℅. Could be them or somebody behind. This all smells fishy. comment: p12bnm1 parent: t1_p129frr author: eldude40 created_utc: 1785589784 edited: false body: I was just thinking this. Did anyone on the coinkite team lose any btc? comment: p13uv9c parent: t1_p129frr author: moviemaker2 created_utc: 1785606223 edited: false body: Not saying it's not, just that you have no way to know that, so ignorant speculation isn't helping anyone.Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.