r/Bitcoin: whether the incident challenges the future of Bitcoin
reddit-future-of-bitcoin-debate
https://www.reddit.com/r/Bitcoin/comments/1vdds1l/the_coldcard_case_fundamentally_challenges_the/
Latest reviewed change
source content difference between and
A comment linking to a Ledger wallet thread was removed and another comment was deleted by its author.
edited: false
body:
This has nothing to do with Bitcoin. People can generate their own seed with sufficient entropy and not have to leave it to trust - if they choose. It’s just easier to assume the device is using a TRNG.
-
-comment: p1a1z9n
-parent: t1_p19vhma
-author: The25thUser
-created_utc: 1785687812
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 17
- Detected differences
- 17
- Unreviewed
- 0
- Copies held
- 18
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
A comment linking to a Ledger wallet thread was removed and another comment was deleted by its author.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
edited: false body: This has nothing to do with Bitcoin. People can generate their own seed with sufficient entropy and not have to leave it to trust - if they choose. It’s just easier to assume the device is using a TRNG. - -comment: p1a1z9n -parent: t1_p19vhma -author: The25thUser -created_utc: 1785687812 -edited: false -body: -I think it's this: https://www.reddit.com/r/ledgerwallet/s/gIdWMgCelJ comment: p1a20ry parent: t1_p19uizw comment: p1bwdnt parent: t3_1vdds1l -author: thegunky72 +author: [deleted] created_utc: 1785706146 edited: false body: -right. exactly. just like "a bank with bad security got robbed therefore all banks can't be trusted". also, cars will never replace horse and carriage +[removed] comment: p1bwfvq parent: t3_1vdds1lExtracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread lost several older comments and gained new ones continuing the exchange about Coinbase custody, centralized control and Bitcoin's value proposition, while the more-stub pointers shifted to different parents.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 110 lines
- the trade-off between full self custody/ more risk and third party custody / more trust is not a new topic, but there haven't been good advances that drive adoption. The Coldcard case sets us back substantially -comment: p18oxtw -parent: t1_p18e1as -author: the_bitcoin_kid -created_utc: 1785672638 -edited: false -body: -There isn't really a passphrase bug that could cause your coins to get stolen. - -The passphrase _adds_ security to your seed, it doesn't take it away. - comment: p18qg22 parent: t1_p189e6p author: JohnnyTreemain edited: false body: Bitkey is one - -comment: p191bju -parent: t3_1vdds1l -author: arcrad -created_utc: 1785677063 -edited: false -body: -This hack doesn't change a goddamned thing about Bitcoin. - -Y'all are sensationalists comment: p191ccu parent: t1_p18hbu5 Choose your poison. It’s still better than any fiat currency where you can only choose number 3. -comment: p1a6exs -parent: t1_p19p1g4 -author: binary_quasar -created_utc: 1785689027 -edited: false -body: ->Coinbase doesn't provide proof of reserves. It's only a matter of time before they pull an FTX or an MtGox. - -Laughably braindead take. The largest asset managers in the world, who have a fiduciary responsibility to every single person that invests with them, chose Coinbase to custody their crypto assets. - -Do you think BlackRock and their ilk would make that decision without consistent access to Coinbase's financials? Do you think they would choose a custodian lightly, knowing that even if Coinbase fucks up, BlackRock would *still have a fiduciary responsibility to their clients and would be responsible for customer deposits?* - -They did an elaborate audit of Coinbase's books before making that decision and chose Coinbase precisely because their company was financially healthy and have top-tier asset security practices. - -Furthermore, Coinbase is a publicly traded company on the NYSE, meaning their books are public as well, dumbass. - comment: p1a6l3g parent: t1_p19x63o author: gtwooh body: That goes for most everything in life though: your car, your utilities, your food, etc etc. Bitcoin provides the ability for truly sovereign money, but the implementation ultimately depends on some level of infrastructure. Unless you are a cyber security and hardware engineer expert that can build a wallet entirely on their own, you are forced to depend on some level of others. That is the flaw here, and exactly why we need better consumer protection (e.g. insurance). The average person shouldn't be expected to know what multi signature or RNG entropy is. This is solvable, but we are not there yet. -comment: p1ah949 -parent: t1_p1a6exs -author: KontoOficjalneMR -created_utc: 1785691949 -edited: false -body: -> The largest asset managers in the world - -Bernie Madoff. Lehman Brothers. AIG - comment: p1ahjja parent: t1_p196tc1 author: LPC_Rebuilder I don't think this has the potential to crack the shiny surface, I think this situation more so is showing us what the true surface looks like if you get what I'm saying lol. Someone told us the surface is super clean and shiny and we just trusted it, but the reality is the surface may be a bit rough and you need to be more vigilant when it comes to securing your money. This whole situation sucks and I agree it's a blow to alot of hardcore bitcoiners but at the end of the day Bitcoin doesn't care and it still functions the same way and the network is just as secure as it was before this event. + +comment: p1as8fe +parent: t1_p1aj3e4 +author: confusedguy1212 +created_utc: 1785694876 +edited: false +body: +Explain please. I’m interested in this take. comment: p1asd1x parent: t3_1vdds1l body: If this is true, then holy crap…… +comment: p1bb9en +parent: t1_p1as8fe +author: Possible-Mud-1380 +created_utc: 1785700120 +edited: false +body: +It's not really much different then the current system, just faster and cheaper transactions on the blockchain. Control will be mostly centralized between say a number of financial institutions, corps, and/or nation states. Look at the Unit by brics. Commodity backed stablecoin basically. + comment: p1bc4f6 parent: t3_1vdds1l author: moonkingdome Hope that helps +comment: p1bkkvq +parent: t1_p1bb9en +author: confusedguy1212 +created_utc: 1785702741 +edited: false +body: +So you’re saying the whole crypto experiment literally yielded not more than cheaper financial infrastructure for the old and tested currencies? + comment: p1blqau parent: t1_p18hbu5 author: coffeelover9457 edited: false body: That’s a great point. + +comment: p1bpoe2 +parent: t1_p1bkkvq +author: Possible-Mud-1380 +created_utc: 1785704199 +edited: false +body: +Pretty close. There will be new currency though, backed by other currencies and commodities. But your average person needs centralized institutional backing and insurance. And end of the day they are better keeping gold in safe for savings, then using a technology whose encryption protocols and safeguards could become obsolete without warning. It was a good first run. Maybe we'll get a second go at it in the future. That's my take. Could be wrong of course. comment: p1bposd parent: t3_1vdds1l body: Bitcoin has failed at everything it had hoped to achieve. -comment: p1cn25f -parent: t1_p1a6exs -author: halt_spell -created_utc: 1785714495 -edited: false -body: -> Do you think BlackRock and their ilk would make that decision without consistent access to Coinbase's financials? Do you think they would choose a custodian lightly, knowing that even if Coinbase fucks up, BlackRock would still have a fiduciary responsibility to their clients and would be responsible for customer deposits? - -It's all people at the end of the day. And yes people fuck up. - -Let me ask you a question, since you have all this confidence, when you say "consistent access" what does that look like? Perhaps a _proof of reserves_? - comment: p1cn3su parent: t1_p19xwck author: Charming-Designer944 edited: false body: I've seen several comments on this post blaming the users + +comment: p1l2qh7 +parent: t1_p1bkkvq +author: Kinslayer817 +created_utc: 1785816226 +edited: false +body: +The infrastructure isn't even cheaper than existing systems. BTC costs an insane amount of money and energy to run and the only reason people are paying that cost is that they're making tons of money off of the people using it + +All that crypto accomplished is creating a new way to scam and steal from people comment: p1l60ir parent: t3_1vdds1l more-stub: parent t1_p1b161g count <live-count> -more-stub: parent t1_p1a6exs count <live-count> +more-stub: parent t1_p19p1g4 count <live-count> more-stub: parent t1_p18x932 count <live-count> more-stub: parent t1_p19u32s count <live-count> -more-stub: parent t1_p1aj3e4 count <live-count> - more-stub: parent t1_p18djp7 count <live-count> more-stub: parent t1_p189e6p count <live-count> more-stub: parent t1_p18lzey count <live-count> +more-stub: parent t1_p18oefs count <live-count> + more-stub: parent t1_p1a23gf count <live-count> more-stub: parent t1_p19xg7j count <live-count> -more-stub: parent t1_p18oefs count <live-count> - more-stub: parent t1_p188oc0 count <live-count> more-stub: parent t1_p18cebt count <live-count> more-stub: parent t1_p18rx5l count <live-count> -more-stub: parent t1_p18oxtw count <live-count> +more-stub: parent t1_p18e1as count <live-count> more-stub: parent t1_p18ctae count <live-count>Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained a new participant reply and lost an older comment, while the live more-stub pointer shifted to a different parent.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 18 lines
edited: false body: It's the warm-up before quantum enters the room. - -comment: p1abbp5 -parent: t1_p1a8spe -author: NiagaraBTC -created_utc: 1785690358 -edited: false -body: -No, it wasn't turned off. It worked fine but wasn't being asked to participate in seed creation. I guess that's functionally the same thing. comment: p1abg2k parent: t1_p189e6p body: So has many banks 🤷🏽♂️ +comment: p2ck51g +parent: t1_p1d18sa +author: Chickenjon +created_utc: 1786138991 +edited: false +body: +Yeah I would have never thought about doing that + more-stub: parent t1_p1b161g count <live-count> more-stub: parent t1_p1a6exs count <live-count> more-stub: parent t1_p19qh4q count <live-count> -more-stub: parent t1_p1abbp5 count <live-count> +more-stub: parent t1_p1a8spe count <live-count> more-stub: parent t1_p19nkiy count <live-count>Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread added a NiagaraBTC reply saying the device's RNG was not turned off but was not asked to participate in seed creation, removed a Vipu2 comment about USD decline, and shifted several more-stub parent references.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 36 lines
I agree, last BTC cycle was full of hacks and stolen money. You were getting used seeing billions getting erased month by month. Luna was the worst, followed by FTX and then some. You grew numb to it. Someone posted a 4.5 mil hack and everyone in the comments was like “that’s pocket change“ 🥴 And here we are again, posting about leaving funds on exchanges and condemning self custody. It’s hilarious. - -comment: p18s90v -parent: t1_p18d0gn -author: Vipu2 -created_utc: 1785673898 -edited: false -body: -You sound like american because if you instantly think when USD goes down there will be dooms day. - -There is a lot of other countries with other currencies in the world that would go as unnoticed as btc wallets getting drained. - -Even in the case of US going down, sure there would be pretty big collapse but things would continue and US will get replaced just like these things have happened multiple times in history. comment: p18sedz parent: t1_p1867f5 edited: false body: It's the warm-up before quantum enters the room. + +comment: p1abbp5 +parent: t1_p1a8spe +author: NiagaraBTC +created_utc: 1785690358 +edited: false +body: +No, it wasn't turned off. It worked fine but wasn't being asked to participate in seed creation. I guess that's functionally the same thing. comment: p1abg2k parent: t1_p189e6p more-stub: parent t1_p19qh4q count <live-count> -more-stub: parent t1_p1a8spe count <live-count> +more-stub: parent t1_p1abbp5 count <live-count> more-stub: parent t1_p19nkiy count <live-count> more-stub: parent t1_p18lzey count <live-count> +more-stub: parent t1_p1a23gf count <live-count> + +more-stub: parent t1_p19xg7j count <live-count> + more-stub: parent t1_p18oefs count <live-count> -more-stub: parent t1_p1a23gf count <live-count> - -more-stub: parent t1_p19xg7j count <live-count> - more-stub: parent t1_p188oc0 count <live-count> more-stub: parent t1_p18cebt count <live-count> more-stub: parent t1_p18oxtw count <live-count> +more-stub: parent t1_p18ctae count <live-count> + more-stub: parent t1_p18hbu5 count <live-count> more-stub: parent t1_p18bz0u count <live-count> -more-stub: parent t1_p18s90v count <live-count> +more-stub: parent t1_p18d0gn count <live-count> more-stub: parent t1_p186h5d count <live-count> more-stub: parent t1_p185yzn count <live-count> -more-stub: parent t1_p18ctae count <live-count> - more-stub: parent t1_p18faor count <live-count> more-stub: parent t1_p186jye count <live-count>Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two comments were deleted and two short new comments added; the collapsed-replies stub list rethreaded to match the deletions.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 36 lines
edited: false body: AI is only the beginning. You wait until we have quantum computing AI. - -comment: p18tt9g -parent: t1_p18s90v -author: dvondurden -created_utc: 1785674463 -edited: false -body: -You haven't understood both arguments. This has absolutely nothing to do with America, USD or any specific country comment: p18tz5l parent: t1_p18lzey edited: false body: It's the warm-up before quantum enters the room. - -comment: p1abbp5 -parent: t1_p1a8spe -author: NiagaraBTC -created_utc: 1785690358 -edited: false -body: -No, it wasn't turned off. It worked fine but wasn't being asked to participate in seed creation. I guess that's functionally the same thing. comment: p1abg2k parent: t1_p189e6p body: *"Your keys, not your coins"* +comment: p24qihb +parent: t1_p19uizw +author: Immediate_Factor9253 +created_utc: 1786047510 +edited: false +body: +well said, brother! + +comment: p27k0e7 +parent: t1_p1e9pcl +author: Big-Cheetah5159 +created_utc: 1786080769 +edited: false +body: +So has many banks 🤷🏽♂️ + more-stub: parent t1_p1b161g count <live-count> more-stub: parent t1_p1a6exs count <live-count> more-stub: parent t1_p19qh4q count <live-count> -more-stub: parent t1_p1abbp5 count <live-count> +more-stub: parent t1_p1a8spe count <live-count> more-stub: parent t1_p19nkiy count <live-count> more-stub: parent t1_p18bz0u count <live-count> +more-stub: parent t1_p18s90v count <live-count> + more-stub: parent t1_p186h5d count <live-count> more-stub: parent t1_p18jvb5 count <live-count>Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Three comments were deleted and two added, one arguing the incident has major implications for AI-assisted code review and citing GLM 5.2 catching the flaw.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 40 lines
body: I know; I'm just saying it stands to reason there were far fewer eyes on it when the code is already from what I assume is one of the least popular wallet manufacturers (as mentioned, I'd never heard of them) and is not even able to be redistributed or commercially used anyway -comment: p1ac6ry -parent: t1_p1abbp5 -author: Objective_Digit -created_utc: 1785690589 -edited: false -body: -That's the same thing. - comment: p1acbn5 parent: t3_1vdds1l author: Constant_Apple_8748 edited: false body: Yes, of course Coldcard is to blame. I'm just stunned that nobody noticed it for so long and everyone and their cat insisted that it's one of the best devices. Isn't it weird for a space that prides itself on being outside of "the system", independent thinkers? - -comment: p1afsb3 -parent: t1_p1ac6ry -author: nickex77 -created_utc: 1785691555 -edited: false -body: -Lol it is the same comment: p1afuox parent: t1_p1a6yf9 body: Sad thing is even if you are self custody competent you may have a spouse or a family member that is not that tech savvy. Leaving them instructions in case of an emergency is like leaving them like a deer in a headlight situation. -comment: p1cu8c0 -parent: t3_1vdds1l -author: DonTheHolder -created_utc: 1785716870 -edited: false -body: -Hardware wallets are sketchy with this firmware stuff. - comment: p1cume2 parent: t1_p18rpgf author: Classic-Charity-2179 An independent trust layer sounds great. The obvious question here I have is: wouldn't I have to trust this layer then instead of the one before? I'm not a coder or cryptography expert, but in my logic we would just shift the trust over to something else. If anything goes wrong here, we're at the same issue: risk of total loss. This is the biggest risk and therefore should be the most important. The more I think about it, the more I become convinced that there is almost no way to do this without putting your trust in something (in an easy way that works for the average user, complex solutions that require a lot of knowledge and maintenance still work of course).At this point ETFs become the rational choice, where total loss is the most minimized by highest level security standards as well as regulatory and legal protection. +comment: p1zy8fr +parent: t1_p18ztl5 +author: MississippiSailor +created_utc: 1785991033 +edited: false +body: +Its lowering the bar though thats the thing. I think this has major implications for AI, people are going to want / need to have the absolute best AI to try and catch these. Even glm 5.2 was able to catch this. + +comment: p20oxjm +parent: t1_p18x932 +author: SeaTrust1844 +created_utc: 1786003518 +edited: false +body: +*"Your keys, not your coins"* + more-stub: parent t1_p1b161g count <live-count> more-stub: parent t1_p1a6exs count <live-count>Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Reddit no longer served a comment promoting an entropy service as a way the incident could have been prevented.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
body: https://www.qastlewallet.com -comment: p1p489j -parent: t3_1vdds1l -author: Moonrunner04 -created_utc: 1785866946 -edited: false -body: -Everyone needs to check out real-random. This whole thing would have been prevented if they were using them - comment: p1pi7af parent: t3_1vdds1l author: marshyr3d1andExtracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Several earlier comments were removed or replaced with deleted-account placeholders. New comments discuss passphrases, the usability of multisig and the author's view that the incident exposes a broader trust problem and makes ETFs rational for average users.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 68 lines
comment: p186jye parent: t3_1vdds1l -author: OldHamburger7923 +author: [deleted] created_utc: 1785664219 edited: false body: -I don't think it changes anything. Poor entropy for a seed is like the most basic thing never to do and they did it. Plus there are a bunch of ways to make it not be an issue, such as generating the seed yourself and passphrase. So why would anyone care, other than the ones who got stolen from? +[deleted] comment: p187031 parent: t1_p186h5d comment: p18faor parent: t1_p18dugk -author: OldHamburger7923 +author: [deleted] created_utc: 1785668500 edited: 1785668973 body: - I have skin in the game because I have a wallet with assets in it. A passphrase is sort of like a salt. No way anyone gets my wallet and no way anyone guesses my passphrase. - -Zero worries. - -Also for coldcard users to have issues, they would have had to not use a passphrase and skip the dice option. Whenever you go with lower entropy option, you take on additional risk. +[deleted] comment: p18fqcy parent: t1_p18efcc edited: false body: So fiat with extra steps. Great. - -comment: p18l9zp -parent: t1_p18jvb5 -author: klitchell -created_utc: 1785671153 -edited: false -body: -What would be bad about having a consumer protection like FDIC or SIPC that covers you in the event that the exchange is negligent and caused you to lose your coins? comment: p18lzey parent: t3_1vdds1l body: I agree it’s a big deal and changes the discourse away from “not your keys not your coins.” The problem is that the ability to hold your keys is the main thing that makes Bitcoin special. This is a big problem for wider adoption. -comment: p1azdwv -parent: t1_p1abbp5 -author: rockorangebear -created_utc: 1785696826 -edited: false -body: -That's what turned off means lmao. - comment: p1azicz parent: t1_p19bwo1 author: thewheelsturn edited: false body: Lmao true have had several people advocate against passphrases and coin flips. Most on this subreddit has any clue what they are talking about though - -comment: p1b6ifx -parent: t1_p1abbp5 -author: Joghobs -created_utc: 1785698795 -edited: false -body: -I didn't quit, I'm just not playing anymore comment: p1b95iy parent: t1_p19qh4q body: maybe im an arrogant cunt but I don't really think its that hard. +comment: p1tc6du +parent: t3_1vdds1l +author: Objective-Walk6780 +created_utc: 1785917391 +edited: false +body: +Passphrase. + +You’d be surprised how many don’t know what that is. + +comment: p1tl6o1 +parent: t3_1vdds1l +author: ZookeepergameOld6699 +created_utc: 1785921790 +edited: 1785922025 +body: +Future tech only can solve dilemma between self custody or financial sovereignty and UX problem. Self custody is hard because of our natural tendency to laziness and human blind spots. Setting up a multisig wallet and obeying by best practices, easy to say but hard to do. AI even at this moment can enlighten people not to rely only a Ledger hardware but lazy people can ignore that. + +comment: p1togjg +parent: t1_p1r0r19 +author: dvondurden +created_utc: 1785923350 +edited: false +body: +Thank you for this great post. It sums up very nicely what I'm trying to say and the more I read about it, the more I come to the same conclusion: it shows a much bigger issue than just an isolated incident. It reveals that there is a fundamental flaw in our trust model. Wether it is faulty hardware, firmware or the belief that openly viewable code is automatically checked thoroughly by the whole space. +An independent trust layer sounds great. The obvious question here I have is: wouldn't I have to trust this layer then instead of the one before? I'm not a coder or cryptography expert, but in my logic we would just shift the trust over to something else. If anything goes wrong here, we're at the same issue: risk of total loss. This is the biggest risk and therefore should be the most important. +The more I think about it, the more I become convinced that there is almost no way to do this without putting your trust in something (in an easy way that works for the average user, complex solutions that require a lot of knowledge and maintenance still work of course).At this point ETFs become the rational choice, where total loss is the most minimized by highest level security standards as well as regulatory and legal protection. + more-stub: parent t1_p1b161g count <live-count> more-stub: parent t1_p1a6exs count <live-count> more-stub: parent t1_p19qh4q count <live-count> +more-stub: parent t1_p1abbp5 count <live-count> + more-stub: parent t1_p19nkiy count <live-count> more-stub: parent t1_p19ly8d count <live-count> more-stub: parent t1_p186h5d count <live-count> -more-stub: parent t1_p18l9zp count <live-count> +more-stub: parent t1_p18jvb5 count <live-count> more-stub: parent t1_p185yzn count <live-count>Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Two earlier comments about exchange protection and adoption disappeared, one new comment was added, and Reddit's remaining-comment placeholder moved to a different parent.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 32 lines
body: What would be bad about having a consumer protection like FDIC or SIPC that covers you in the event that the exchange is negligent and caused you to lose your coins? -comment: p18ls77 -parent: t1_p18l9zp -author: relatedartefacts -created_utc: 1785671367 -edited: false -body: -Decide what you want. Freedom from the system or fdic with extra steps. - - - comment: p18lzey parent: t3_1vdds1l author: reality_comes We're all trusting somebody somewhere, unfortunately. - -comment: p18nhdc -parent: t1_p18ls77 -author: klitchell -created_utc: 1785672062 -edited: false -body: -I want an answer to the question. If a new user decides to leave their coins on an exchange why would it bad if they had protection just like other assets? - - If anyone wants freedom, keep them off the exchange,nice and simple. - -If you want adoption this is what it looks like, ma and pa need to feel safe that their investment isn't going to be lost in a whim. comment: p18oefs parent: t3_1vdds1l I'd especially appreciate feedback from wallet developers, cryptographers, firmware engineers, and others with deep technical experience. If there are flaws in this reasoning—or better approaches I'd love to hear them. My goal isn't to promote a product, but to explore whether we're missing an architectural layer that could help strengthen trust across the broader Bitcoin ecosystem. +comment: p1scqz0 +parent: t1_p189e6p +author: Low_Vegetable481 +created_utc: 1785901510 +edited: false +body: +maybe im an arrogant cunt but I don't really think its that hard. + more-stub: parent t1_p1b161g count <live-count> more-stub: parent t1_p1a6exs count <live-count> more-stub: parent t1_p186h5d count <live-count> -more-stub: parent t1_p18nhdc count <live-count> +more-stub: parent t1_p18l9zp count <live-count> more-stub: parent t1_p185yzn count <live-count>Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained new participant comments.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 57 lines
edited: false body: [deleted] - -comment: p18w6w4 -parent: t1_p18nhdc -author: dvondurden -created_utc: 1785675312 -edited: false -body: -Exactly. Unless people have those options, there will be no meaningful adoption. By now there is just risk and the necessity for trust in various degrees, but no real solutions either way comment: p18w8tc parent: t1_p186h5d body: Err backed up in another location 🙄 +comment: p1r0r19 +parent: t3_1vdds1l +author: FroyoInternal8203 +created_utc: 1785885557 +edited: false +body: +I've been following the Coldcard incident closely over the past few weeks, and the more I read, the more I think this exposed something much bigger than a firmware bug—it exposed a gap in our trust model. + +For years we've repeated **"Don't trust, verify."** But in reality, every self-custody solution still depends on trusting something outside the blockchain: the hardware manufacturer, firmware developers, entropy implementation, supply chain, secure element, compiler, update process, and operational procedures. + +Bitcoin successfully proved that the transactions were valid. What it could not prove was whether the keys were generated under trusted conditions. + +Those are two different problems. + +To me, this points toward the need for an **independent trust layer** that continuously validates the environment before value moves. + +Imagine if every wallet could independently prove (without revealing the private key or seed): + +* The firmware hash matches an approved release. +* The entropy source passed required health tests. +* The device was provisioned under approved manufacturing controls. +* No known vulnerability exists for that firmware version. +* The wallet has not entered an untrusted state since initialization. +* A high-value transfer satisfies the owner's security policy (multisig, approval workflow, geofencing, etc.). + +Those proofs could be generated through cryptographic attestations and, where appropriate, zero-knowledge proofs, allowing a wallet to demonstrate trustworthiness without exposing sensitive information. + +The blockchain would continue doing what it does best—proving that a transaction occurred. The trust layer would answer a different question: + +**Should this transaction have been trusted in the first place?** + +I don't think the future of Bitcoin is choosing between self-custody and centralized custody. I think it's adding an independent verification layer that continuously measures trust instead of assuming it. + +This is actually the core idea behind a protocol/platform I've been developing called **PROOF**, which is designed as an **Independent Trust Layer**. The goal isn't to replace Bitcoin or hardware wallets, but to continuously validate firmware integrity, identity, entropy health, policy compliance, device provenance, AI-assisted operations, and transaction authorization before critical actions occur. + +In short: + +**Blockchain proves the transaction. PROOF proves the trust conditions that made the transaction possible.** + +I'm genuinely interested in whether this line of thinking resonates with others here. + +* Am I looking at the problem from the wrong angle? +* Is an independent trust layer unnecessary because multisig, passphrases, and better operational security already solve this? +* Or is this where hardware wallets and digital asset security need to evolve as AI accelerates software analysis, exploit discovery, and supply-chain attacks? + +I'd especially appreciate feedback from wallet developers, cryptographers, firmware engineers, and others with deep technical experience. If there are flaws in this reasoning—or better approaches I'd love to hear them. My goal isn't to promote a product, but to explore whether we're missing an architectural layer that could help strengthen trust across the broader Bitcoin ecosystem. + more-stub: parent t1_p1b161g count 3 more-stub: parent t1_p1a6exs count 1 more-stub: parent t1_p186h5d count 6 -more-stub: parent t1_p18nhdc count 4 +more-stub: parent t1_p18nhdc count 5 more-stub: parent t1_p185yzn count 6Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The thread no longer served an earlier comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 8 lines
edited: false body: I didn't quit, I'm just not playing anymore - -comment: p1b731i -parent: t3_1vdds1l -author: [deleted] -created_utc: 1785698954 -edited: false -body: -I think it's interesting this is happening after US government moves it's BTC to exchange and during time Clarity Act is being pushed. Just interesting.. comment: p1b95iy parent: t1_p19qh4qExtracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
An existing Reddit comment changed or its author account was deleted.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 2 lines
comment: p1b731i parent: t3_1vdds1l -author: EnvironmentalYard467 +author: [deleted] created_utc: 1785698954 edited: false body:Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
An existing Reddit comment changed or its author account was deleted.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 12 lines
We're all trusting somebody somewhere, unfortunately. - -comment: p18mgt8 -parent: t3_1vdds1l -author: AnarchyCheesemonger -created_utc: 1785671649 -edited: false -body: -Well written fud, bro comment: p18nhdc parent: t1_p18ls77 more-stub: parent t1_p186jye count 2 -more-stub: parent t1_p18mgt8 count 2 - -more-stub: parent t3_1vdds1l count 59 +more-stub: parent t3_1vdds1l count 62Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread changed through new comments, removals, or edits.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 35 lines
- the trade-off between full self custody/ more risk and third party custody / more trust is not a new topic, but there haven't been good advances that drive adoption. The Coldcard case sets us back substantially -comment: p18om9k -parent: t1_p18mgt8 -author: dvondurden -created_utc: 1785672514 -edited: false -body: -Thank you, trying my best here to pour some oil into the fire - comment: p18oxtw parent: t1_p18e1as author: the_bitcoin_kid user interface, sturdiness, open source code, aesthetics, independent and internal audits, resistance to attacks, abilities to use multiple numbers of seed phrases, theres plenty. no idea why cold cards were considered the best, i never even considered them. it was always trezor. - -comment: p19pzle -parent: t1_p18mgt8 -author: cliff_smiff -created_utc: 1785684505 -edited: false -body: -I'm gonna take this chance to say that FUD is a braindead term reflective of a braindead mentality. Fear? Uncertainty? Doubt? Yes these are real factors in life. Dismissing doubt is the absolute height of arrogance. comment: p19pzrr parent: t1_p19nlwt body: Everyone needs to check out real-random. This whole thing would have been prevented if they were using them +comment: p1pi7af +parent: t3_1vdds1l +author: marshyr3d1and +created_utc: 1785870453 +edited: false +body: +Why the fuck can't we all just use stainless plates in multiple locations? +Trust NO ONE! + +comment: p1piit3 +parent: t1_p1b1vie +author: marshyr3d1and +created_utc: 1785870535 +edited: false +body: +Err backed up in another location 🙄 + more-stub: parent t1_p1b161g count 3 more-stub: parent t1_p1a6exs count 1 more-stub: parent t1_p186jye count 2 +more-stub: parent t1_p18mgt8 count 2 + more-stub: parent t3_1vdds1l count 59Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
An existing Reddit comment changed or its author account was deleted.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 16 lines
body: Everyone needs to check out real-random. This whole thing would have been prevented if they were using them -comment: p1p5twz -parent: t3_1vdds1l -author: clueless707 -created_utc: 1785867342 -edited: false -body: -I don’t think this breaks Bitcoin, but it does break the very comfortable way people talk about self-custody. - -A hardware wallet doesn’t remove trust. You’re still trusting the firmware, the build process, the random number generation and whatever security review happened before you bought it. Most people have no realistic way to check any of that themselves. - -The AI part is still unclear. Coinkite thinks AI may have helped someone find the bug because the code was public, but they don’t know that. They also said they ran an AI review themselves and it missed the bug. Organisations like Prem AI have opened K3 access for researchers auditing public code: [https://x.com/premai\_io/status/2084552134444662986](https://x.com/premai_io/status/2084552134444662986) - -For most people, custody will probably end up being a mix. Some will self-custody. Some will use multisig or assisted custody. Plenty will choose an ETF or regulated custodian. - -Bitcoin still gives people the option to hold their own money. We probably need to stop pretending that option is automatically simple or safe. - more-stub: parent t1_p1b161g count 3 more-stub: parent t1_p1a6exs count 1Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The Reddit thread gained 2 new comments while 2 existing comments no longer appeared.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 46 lines
body: Sounds like someone intentionally designed a thermal exhaust port that led directly to the reactor’s core -comment: p18rw92 -parent: t3_1vdds1l -author: philippony -created_utc: 1785673767 -edited: false -body: -I am not affected as I create the 24 word seed phase in my brain. So that I select the words from the 2048 list. It is better than any other ways. - comment: p18rx5l parent: t1_p18b2cz author: ptrnyc edited: false body: AI is only the beginning. You wait until we have quantum computing AI. - -comment: p18tlp9 -parent: t3_1vdds1l -author: [deleted] -created_utc: 1785674388 -edited: false -body: -[removed] comment: p18tt9g parent: t1_p18s90v body: https://www.qastlewallet.com +comment: p1p489j +parent: t3_1vdds1l +author: Moonrunner04 +created_utc: 1785866946 +edited: false +body: +Everyone needs to check out real-random. This whole thing would have been prevented if they were using them + +comment: p1p5twz +parent: t3_1vdds1l +author: clueless707 +created_utc: 1785867342 +edited: false +body: +I don’t think this breaks Bitcoin, but it does break the very comfortable way people talk about self-custody. + +A hardware wallet doesn’t remove trust. You’re still trusting the firmware, the build process, the random number generation and whatever security review happened before you bought it. Most people have no realistic way to check any of that themselves. + +The AI part is still unclear. Coinkite thinks AI may have helped someone find the bug because the code was public, but they don’t know that. They also said they ran an AI review themselves and it missed the bug. Organisations like Prem AI have opened K3 access for researchers auditing public code: [https://x.com/premai\_io/status/2084552134444662986](https://x.com/premai_io/status/2084552134444662986) + +For most people, custody will probably end up being a mix. Some will self-custody. Some will use multisig or assisted custody. Plenty will choose an ETF or regulated custodian. + +Bitcoin still gives people the option to hold their own money. We probably need to stop pretending that option is automatically simple or safe. + more-stub: parent t1_p1b161g count 3 more-stub: parent t1_p1a6exs count 1 more-stub: parent t1_p186jye count 2 -more-stub: parent t1_p18rw92 count 2 - -more-stub: parent t1_p18tlp9 count 1 - -more-stub: parent t3_1vdds1l count 54 +more-stub: parent t3_1vdds1l count 59Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
The captured reply tree gained a collapsed more-stub indicating one additional reply under an existing comment.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 10 lines
edited: false body: No it doesn’t , coldcard had one line of shit code that fucked the whole thing up - -comment: p18uww5 -parent: t1_p18tlp9 -author: dvondurden -created_utc: 1785674859 -edited: false -body: -It's reflecting the space. A highly regarded and recommended product by many had faulty code for years for everyone to see, yet nobody noticed. Do we really lack self awareness so badly? I'm including myself in this comment: p18w5ya parent: t3_1vdds1l more-stub: parent t1_p18rw92 count 2 +more-stub: parent t1_p18tlp9 count 1 + more-stub: parent t3_1vdds1l count 54Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vdds1l author: dvondurden created_utc: 1785663699 title: The Coldcard case fundamentally challenges the future of Bitcoin body: Like many of us, I have followed the news of the Coldcard disaster. It has left me stunned and I feel terrible for everyone who has lost their hard earned BTC. After thinking about it consistently since it happened, I believe this case is challenging the concept of Bitcoin in its core and I'm curious how others look at it. Let's have an honest discussion about what it means for the future of the space. Here are my main points: 1. This is totally different from most other cases, because the affected users didn't do anything wrong. It was a complete fuck up on Coldcard's side. For years we told ourselves self storage is the only way, never leave it on the exchanges, not your keys not your coins, don't trust verify etc. But in the end you have to trust something or someone, in this case the people behind CC. Now everyone says Ledger or Tresor is safe just because they were not the ones affected. How do you actually know this? You would have said the same thing about CC a few days ago. 2. The danger of AI is absolutely real and will only increase. Without knowing the method in this case, it's likely that some form of AI was involved. The code for CC was not open source, but still viewable by everyone. It's mind-blowing that it took several years for the flaw to be discovered and exploited. Don't expect this to take so long next time. I'm not an expert in coding or cryptography, most users aren't. So in the end you just have to trust the code. Sure, it can be tested with AI too. But do I really want to expose all my holdings to this battle just hoping that it will be fine in the end? It feels way too risky and out of your control. 3. Mass adoption is absolutely not going to happen this way. I'm a nerd and enjoy the technical side of it, but even I feel overwhelmed by this. The average person is much less interested and willing to put in the work. For years we've been saying good solutions for self storage, payments and so on will be found. I don't see it. It seems to become more complicated than less. So what's the alternative here? Keeping it on the exchange, buying an ETF? It doesn't solve the trust issue and contradicts pretty much everything Bitcoin stands for. Just another asset class among many. I still love the idea behind Bitcoin and believe in the concept. But I struggle to find good and honest answers to these points without just repeating the same old mantras we've been telling ourselves. What do you think? comment: p185yzn parent: t3_1vdds1l author: [deleted] created_utc: 1785663917 edited: false body: [removed] comment: p1867f5 parent: t1_p185yzn author: Narrow-Bee-8354 created_utc: 1785664038 edited: false body: Yeah, to add to this, this incident is going to make other wallet manufacturers to look seriously into their own products comment: p186h5d parent: t1_p185yzn author: dvondurden created_utc: 1785664178 edited: false body: Completely different case. If a major bank goes down, it's backed by safety regulations and the state. Nobody cares if your btc wallet gets drained. "Don't worry about it" is not good enough here. comment: p186jyeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.