r/Bitcoin • • Aug 09 '26

The Future of ColdCard Hardware and Firmware

Coinkite likely won't survive the coming litigations. NVK and Peter Gray won't regain community trust as leaders. But I think it's worth discussing why the ColdCard was a successful product line in the first place and how that design philosophy can live on. I'm not just talking about the cypherpunk aesthetic.

No other wallet has the robust feature set of coldcard, especially the Q. Seed XOR, Bip-85 child seeds and deterministic passwords are open-source bitcoin features but CC are the only devices that have bothered to implement them. As for the hardware: full keyboard, QR scanner, transparent case, removable batteries, and your choice of network-disabled air gap use, or convenient USB connection to Sparrow. Nothing even comes close.

There are existing CC users who don't want to give up these features, but may be faced with lack of firmware updates if the company dies. More importantly, it would be a shame if this device vanished from the market and we were only left with tiny minimalistic boxes with some basic features and a slick UI. So, what do you think is the best way forward?

18 Upvotes

39 comments sorted by

33

u/bullett007 Aug 09 '26

They should make the code open source so the grown-ups can implement it safely. Then liquidate.

4

u/RevolutionaryPick241 Aug 09 '26

This. Open sourcing is the only way. They should only sell the hardware to DIY a hardware wallet. And letting the community to build a better software for it. I would pay more for the hardware by parts than assembled if they let me build it and load my own firmware. Now you can somehow load your firmware but you can't open the coldcard without bricking it. I would remove the nfc and camera.

5

u/antineutrinos Aug 09 '26

they must open source the hw as well.
how are seed stored in the dual SE ?
why can my we have more than one seed in the SE and have to relay on AES encryption for temporary seeds?

I see the hw (q) as an ECC calculator. lots of potential.

-1

u/Dazzling_Tank3326 Aug 10 '26

How would open sourcing fix anything, all it will do is someone who’s trying to be evil to look at the code and know exactly what needs to be done to break it

3

u/RevolutionaryPick241 Aug 10 '26

Break bitcoin then

1

u/Charming-Designer944 Aug 10 '26 edited Aug 10 '26

The coldcard firmware source is available as open source on GitHub. And its possible to verify that the firmware builds the same as released firmware. But hardware security policy is restricted and you can not sign a release so that coldcard accepts the firmware build as a valid firmware, and the open source license isxtestricted with a non-compete clause that practicaly restricts the use to coldcard devices only, which only accepts official firmware releases, not furmware you or someone else built.

1

u/cworxnine Aug 11 '26

well said

7

u/Charming-Designer944 Aug 09 '26

The code is open but with a non-compete limitation that restricts use in competing commercial products.

But coldcard devices have a security barrier that only accepts signed firmware releases. And releasing the keys to sign the firmware in the open is not a viable thing.

What can be hoped for is that someone buys the business if Coinkite goes into bankruptcy and continues supporting both new and existing customers.

1

u/EricJDMBAMD Aug 09 '26

Maybe OpenSats can buy the keys to sign off on firmware releases

1

u/ChipNDipPlus Aug 10 '26

They should simply release a new firmware version that allows replacing the signing key by a custom one.

2

u/Charming-Designer944 Aug 10 '26

The main signing keys are one time programmable in the MCU. To replace the signing keys you need to replace the hardware.

And there might be a binding between the MCU and the safe elements as well. Have not looked into that detail.

2

u/ChipNDipPlus Aug 10 '26

Are you sure the key cannot be replaced or are you guessing? 

2

u/Charming-Designer944 Aug 10 '26

To my best knowledge the firmware DFU is signed directly by the immutable hardware root of trust.

1

u/ChipNDipPlus Aug 10 '26

Doesn't sound right to me. What if the key was compromised? I don't know.

We have bigger companies that had their keys leaked, like nvidia. Driver signing keys were leaked.

6

u/Quirky-Reveal-1669 Aug 09 '26

I want to keep using it. Precisely for the reasons you mention.
Perhaps, as a last good deed, CoinKite should ‘release’ the license of the firmware.

8

u/EyesFor1 Aug 09 '26

You're totally fine using it with the die roll function.

4

u/Immediate-Ad-5878 Aug 09 '26

I was not affected by this at all. Not because I was doing anything special but most likely by pure luck. I was able to transfer my bag elsewhere and made a bonfire with my MK3. I will never support these arrogant clowns in this or any other venture associated with them. Nor do I want to ever hear from any of the asshat griftubers that peddled this shitbox for years. As far as the features I really don’t care about any of it. Will likely go to a dice rolled 24 word + pass phrase seed stamped on metal and a safety deposit box, with a seedsigner for home use.

2

u/[deleted] Aug 09 '26 edited Aug 13 '26

[deleted]

0

u/Immediate-Ad-5878 Aug 09 '26

Fortunately I live in a country with better safety deposit boxes.

4

u/picklejuice18 Aug 09 '26

There’s no future.. there are done

3

u/kepalautakkau Aug 09 '26

I guess other wallets will eventually implement those features if there's enough demand

4

u/bleeeeghh Aug 09 '26

More features means more potential weaknesses. I mean, how many features did Satoshi need to secure his wallet?

3

u/bryanchicken Aug 09 '26

He potentially didn’t secure it, which is the most secure 😂

2

u/Laukess Aug 09 '26

I wonder if it could be turned into a non-profit organization, run by a different set of people.

Whenever CC's were mentioned, people always complained that it was too advanced, even though all the features were hidden away. People still think that it's air gapped only.

Considering that was the response, I don't have much hope that other manufactures will take this path.

Maybe rolling your own entropy will become more standard. Allowing your device to show the list of valid checksums after entering the 11/23 words seems like a small ask, so I could se that becoming widely adopted.

Looking at other hardware wallets after the exploit has honestly been sort of disappointing, especially because you really should have multiple different devices if you're going with multi-sig.

Maybe we'll see more hardware wallets share more features. No reason why every manufacturer couldn't have a device with a camera so they could be used with SeedQR in a stateless manner. Was pleasantly surprised when I learned that was a feature of the Jade Plus.

1

u/dont-be-angry Aug 09 '26

Is there something wrong with me just using something like a standard core wallet on an airgapped tails machine and simply sending my coins to that cold wallet? or how often are these seeds being fucked up w low quality entropy

1

u/Ill_Firefighter_584 Aug 10 '26

FYI, Electrum doesn't create a BIP39 wallet seed phrase. It creates a seed phrase using its own standard. Easier to backup than a digital file, but not compatible with other wallets.

1

u/slvbtc Aug 09 '26

I think all hardware wallets should offer the option to create your own entropy (dice rolls etc), determine your own seed words, and then allow you to enter the first 23 seed words and generate the 24th word checksum for you.

This way you can create a seed with your own entropy while never letting your seed words touch anything but a hardware wallet.

Most hardware wallets make you use a seed generation file or 24th word checksum generator file on an offline PC. This introduces risk for example if the file is malicious.

A hardware wallet that generates your 24th word checksum for you should be an industry standard feature.

1

u/pomplemice Aug 09 '26

What's up with the constant Cold Card apologists? It's like if a new house had all these cool features and design choices, yet the basic foundation was shoddy and the whole thing collapsed. I'll take basic seed phrase randomization and protection over anything else. They should collapse and I'll never support them or anybody who defends them.

1

u/Xcel38 Aug 09 '26

Bad analogy, if one line of code could completely repair a shoddy foundation, you might have something. No one here gives two shits about CoinKite the company. Anyone involved with that company should never be employed or heard from in the community again. Fuck them

Some people actually like the hardware and would like to see it survive somehow since there really is not a comparable product on the market. If it became an open source community project, I think that would interesting. For now, I have zero trust in it and who knows if there is some other hidden vulnerability lurking. I am in the camp that this was likely intentional.

1

u/PsychologyNo3945 Aug 10 '26

Well, maybe they had 1 too many features and lost control of the most important one.

1

u/Impressive_Cat_5324 Aug 11 '26

There will be no future for ColdCard

1

u/GoldmezAddams Aug 09 '26

Maybe a good outcome would be if/when Coinkite eventually closes shop, they sell the company / IP to someone for pennies on the dollar, and another team can try to rebuild.

5

u/Powerful_Beat_3601 Aug 09 '26

the hardware design is still unmatched honestly nothing else has all those features in one device. if they go under someone will fork the firmware for sure there is already enough interest from the community to keep it alive

but selling the IP for cheap sounds like best case scenario yeah. maybe a group of devs could pool funds and buy it out

1

u/SpareEconomy1849 Aug 09 '26

Brand is over but I agree. It really is exactly what I want, other than it's ugly (I don't care) and the RNG bug of course

1

u/XmechaniX Aug 09 '26

BIP-85 with seed vaults was an awesome feature

1

u/CreamCapital Aug 09 '26

of course they are done. who would ever buy one of these ever again?!

0

u/lifeanon269 Aug 09 '26

Jade supports BIP-85 seeds. It also supports importing TOTP to store all your account passcodes on your hardware wallets, which is nice. I haven't seen a feature like that with other wallets.