Alan ₿
· 1w
To be clear, the coldcard bug could have been exploited even without the use of AI, so AI is no excuse for the coinkite team’s oversight.
Still, the impetus to assess other hardware wallet vulnerab...
The Coldcard bug is clear developer negligence. They didn't write proper validation gates for their code. The hardware entropy path should have been written as a fail closed function. Instead of falling back to Python when the hardware module was not utilized, the software would have failed to generate a private key, and this issue would have been identified in early testing, instead of running in production for **FIVE FUCKING YEARS.**
Writing critical functions as fail closed, and running test suites with strict validation gates is basic SOP for building secure software. Coinkite had displayed utter incompetence and should never be trusted again.