The Coldcard hack proves reputation is not a security model
A community built on verification spent five years outsourcing its judgment to one man, writes Foundation CEO Zach Herbert.
By Zach Herbert|Edited by Cheyenne Ligon
Share this article

Attackers have now drained nearly $114 million in bitcoin from more than 709 addresses, exploiting a Coldcard firmware flaw that generated wallet seeds with a fraction of their promised randomness. The first sweep emptied roughly 500 wallets in 25 minutes. The bug entered the codebase in March 2021 and sat in public, open-source view for more than five years. Plenty of people are explaining what happened. The harder question is why nobody caught it, and the answer implicates far more than one line of code.
Coldcard’s source code was always available for inspection. “Don’t trust, verify” only works when qualified people actually look, and for five years, effectively nobody did. The timeline around the bug’s introduction deserves attention. In 2020, Coldcard’s firmware carried a GPL open-source license. Two days after a competitor announced a device building on that GPL code, Coinkite CEO Rodolfo Novak, known as NVK, said publicly (in a since-deleted tweet) that he regretted choosing GPL. That November, Coldcard adopted a new license with the Commons Clause, whose own FAQ states plainly that the resulting software is no longer open source. A sweeping rewrite followed, and the March 2021 commit that stripped out the last GPL code is the same commit that broke seed generation.
Nobody can measure how much licensing pressure shaped the scope or speed of that rewrite, and the overhaul also pursued legitimate technical goals. The documented facts are narrower and still damning: a license change made to restrict competitors preceded a rushed replacement of battle-tested cryptographic code, and the replacement contained the flaw now draining wallets. Free and open-source software principles exist precisely to keep security from depending on any one company’s choices. Those principles cannot come with a personality exception.
Zach Herbert is co-founder and CEO of Foundation.
The deeper failure is what happened to the people who did look. In August 2020, researchers from Shift Crypto and Nunchuk disclosed a multisig verification flaw in Coldcard. Coinkite acknowledged the bug and shipped a fix, and NVK, on the Citadel Dispatch podcast simultaneously branded the disclosure “PR terrorism” and questioned whether a researcher without a CVE counted as a professional. In 2023, when the WalletScrutiny project reported problems reproducing older Coldcard builds, the response labeled the project incompetent or malicious and floated litigation. Independent follow-up later found genuine reproduction problems in older releases and concluded nobody had acted in bad faith.
Every public attack on a researcher changes the math for the next one. Independent review is slow, difficult, and usually unpaid. A researcher weighing months of that work against the prospect of ridicule, blocklists, and legal threats will often spend their time elsewhere. Nobody can prove this culture caused the entropy bug to go unnoticed. What can be said with confidence is that security depends on people being willing to look, and the environment around Coldcard punished looking.
How did a community whose founding slogan is “don’t trust, verify” end up here? Psychology has names for it. The illusory truth effect makes repeated claims feel independently confirmed even when they trace to a single source. The halo effect converts status, confidence, and popular products into presumed technical authority. Year after year, the same assertions traveled through the same podcasts and feeds: critics were shills, researchers were terrorists, competitors were clones. Repetition did the work evidence should have done, and confidence became a substitute for proof.
The result is best described as epistemic capture: a community gradually outsourcing its judgment to a trusted authority until the authority itself becomes the evidence. BTC Sessions host Ben Perrin described the mechanism with unusual honesty in a recent livestream, admitting he gave the behavior a pass because he assumed the hubris came packaged with a superior ability to create and secure. Much of the industry made the same calculation. The crisis of confidence now rippling through self-custody is the bill coming due.
The first priority for the entire industry in the aftermath of the exploit is users: circulate the migration guidance and make clear that updating firmware cannot repair a seed generated on vulnerable versions. Then the industry has behind-the-scenes work to do. Old recommendation pages, show notes, and product guides carry years of claims that were repeated rather than checked, and they deserve corrections with primary sources attached. The builders and researchers who were attacked deserve the airtime to explain their work. Bitcoin media needs to become adversarial again, applying the same scrutiny to friends, sponsors, and advertisers that it applies to strangers.
Bitcoin was engineered on the assumption that experts and institutions will eventually fail, and its answer was to make trust unnecessary through verification. The community that built tools embodying that principle exempted its own loudest voices from it. The fix is the founding instruction, applied without favorites this time. Do not trust the vendor. Do not trust the vendor’s critics. Verify.
Note: The views expressed in this column are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates.
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.
Jun 30, 2026
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.
Why it matters:
Zcash’s Tachyon upgrade aims to scale shielded payments, improve quantum readiness, and test whether its funding, security, and governance can hold.


