scary thought experiment: if coldcard had found this exploit themselves, how could they have fixed it without instantly putting all of their customers’ coins at risk? patching the firmware wouldn’t fix vulnerable seeds, and the moment they emailed customers (assuming they hadn’t purged records) or released the patched firmware this would have alerted hackers to the exploit and begun draining wallets one of the only ways to have saved vulnerable coins would have been to alert a whitehat group before any public disclosure who could preemptively seize vulnerable coins and then let people provide non-cryptographic proof of ownership, which would have been a complete mess, invited massive lawsuits, and likely an impossible task unless they had used a kyc exchange to purchase the coins (for non-kyc apparently some form of device verification might be possible but unclear)
Bit Paine ⚡️Share
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
