source avatar₿odhiSATtva

Share

Regarding the ColdCard exploit... From what I can gather, the bug is understood. The fix is targeted and has build-time guards against recurrence, the code is open for community audit, and the disclosure & hotfix process was relatively transparent. Other devices have had their own serious issues (physical extraction paths, supply-chain concerns, closed-source elements, past recovery controversies, etc.). No single-vendor HWW is immune to process or implementation failures. Generating your own entropy with dice & using multisig reduces reliance on any one manufacturer’s RNG path. The problem was a subtle but ultimately straightforward build/config error that had catastrophic consequences because it hit the entropy foundation and persisted for years before anyone noticed. The update correctly restores proper hardware RNG use for new seeds. Post-fix Coldcard Q entropy *should* be on par with other solid hardware wallets. Ledger is not categorically superior; the bigger lasting impact is eroded trust in Coinkite’s prior review processes. Permanent shunning is an emotional but understandable response for some; a more calibrated rational approach for most is to treat any single device as untrusted for sole custody of large amounts, verify the fixed firmware (or use dice), and prefer multisig.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.