Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

The Coldcard hack proves reputation is not a security model

A community built on verification spent five years outsourcing its judgment to one man, writes Foundation CEO Zach Herbert.

The Coldcard hack proves reputation is not a security model

A Coldcard firmware flaw enabled attackers to steal nearly $114 million from over 709 bitcoin addresses by generating wallet seeds with reduced randomness. The flaw, introduced in March 2021, went unchecked for more than five years, despite the source code being publicly available. The issue stems from a license change in November 2020 that shifted to a non-open-source model, prompting a rushed rewrite of the codebase.

This rewrite coincided with the introduction of the vulnerability. Researchers had previously disclosed a multisig verification flaw in August 2020, but their efforts were met with skepticism, branding and potential legal threats. The culture of attacking researchers has created an environment where independent review is discouraged, undermining security.

The industry must prioritize user migration guidance and address outdated claims in its documentation. Bitcoin media should reassert adversarial scrutiny, applying the same scrutiny to allies as it does to outsiders. Ultimately, the community must return to verifying claims independently, as the founding principle of "don't trust, verify" was intended to ensure security through decentralized validation.

Written by urgent.news from CoinDesk's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at coindesk.com →

More in Tech

More from Monday 17 August →