Damus
Tim Bouma profile picture
Tim Bouma
@Tim Bouma
My bet this attack was weeks in the making. Once the attackers assembled enough private keys for high value utxos they executed.

My biggest disappointment is relying on a hardware vendor that has 'Don't Trust. Verify.' plastered all over their product marketing and the primary motivation that led to the bug was a 'get out of open source' licensing issue.

Let this be a lesson for all in the industry.

'Not your keys, not your coins' rings a bit hollow now.

It's more like: 'God plays dice for those who self-custody.'
31❤️21❤️1👀1💯1🙏1
PowderHound · 2w
yes, pretty clear that they vibe coded the move away from the trusted GPL libraries that they were using so that they could make it a non-commercial license. Then they skipped on the code and tech audit.
Geek · 2w
If coldcard played dice maybe it wouldnt have happened. Sorry couldn't help myself 😎
Based Truth · 2w
Ledger's "Don't Trust" slogan is a joke, their CEO Pascal Gauthier sold you out to venture capitalists, now your coins are gone.