COLDCARD POSTMORTEM : WHAT'S NEXT?
Everything you should know about the Coldcard hack in plain language, no technical rabbit holes.
WHAT HAPPENED
A bug Coldcard's wallet generation technique (mainly Mk3, 2021 onward) created wallets using "weak randomness".
As a result, something that is "impossible to guess" became "easy to guess". This led to ~500 wallets hacked in under half an hour.
The scary part that bug was there for years without anyone noticing it. Note that it's a third case over the ast couple of months.
Thorchain, Zcash and not COLDCARD... In all those cases the bug was there for years.
WHAT THIS MEANS FOR YOU
• Only a portion of
@COLDCARDwallet devices are affected - but if you created your seed on a Coldcard, act as if yours is one of them.
• Important: importing your Coldcard-created seed into another wallet app does NOT help. The seed itself is weak. You need a NEW wallet created on a different device or app, then send/transfer the funds there.
• Other mainstream hardware wallets are NOT less safe because of this. This was one vendor's bug, not a flaw in hardware wallets as a concept. If you're searching for another hardware wallet we personally recommend
@Trezor due to their long standing reputation in the industry.
HOW TO CHOOSE A WALLET (our take)
• Pick wallets built on documented, open standards. For hardware, Trezor is probably the best-equipped team in the industry. Ledger is big too, but has a history of privacy breaches.
• For software wallets, we (subjectively) recommend mobile wallets. Given the wallet is built per standards , modern mobile platforms offer the best out-of-the-box security. Combine that with basic security hygiene (regular OS updates, no porn browsing etc) you will get a fairly advanced level of security.
• Look for wallets with regular public audits. For instance, we pay for those ourselves - they're expensive but we believe they are needed to ensure capable external eyes are looking at your codebase.
• Look for endorsements from technical audiences. Back in the early days, some of the more through reviews we've been through were getting listed on resources like bitcoin dot org. Enormously grateful to the teama running those resources.
• if you have a large stash in self-custody then we recommend splitting that between 2-3 wallets/brands that meet standard criteria (see above). We personally, use
@unstoppablebyhs for about 40% of our assets. despite that it's a product we build ourselves we also use
@Trezor and
@Ledger. There are other that we believe to be good mobile wallets out there. Do not keep all eggs in one basket is a good rule to follow in all aspects of life.
THE NEW REALITY
1) AI has made finding bugs dramatically easier - which is why we keep seeing flaws surface in code that sat in public view for years. Expect more of these, from everyone.
2) Open source projects are currently more exposed than closed source ones. You can't attack code that you don't see. So, AI scanning open source code puts a strain over a short term, but long term, open code that survives public scrutiny is the only thing that earns trust.
3) Finally, convincing people to self-custody just got harder. But pressure like this is what forges better security and better UX. Times like these set the new standards.
We just need to keep going!
Self custody is the only way to maintain freedom and independence long term.
⚡ Try Unstoppable Swap Bot !
@unstoppable_swap_bot
😎 Swap BTC, XMR, USDT, ZEC, USDT ...
• best rates
• clear risk scores
• no KYC (anonymous)