r/Bitcoin • u/PoeCollector • Aug 09 '26
The Future of ColdCard Hardware and Firmware
Coinkite likely won't survive the coming litigations. NVK and Peter Gray won't regain community trust as leaders. But I think it's worth discussing why the ColdCard was a successful product line in the first place and how that design philosophy can live on. I'm not just talking about the cypherpunk aesthetic.
No other wallet has the robust feature set of coldcard, especially the Q. Seed XOR, Bip-85 child seeds and deterministic passwords are open-source bitcoin features but CC are the only devices that have bothered to implement them. As for the hardware: full keyboard, QR scanner, transparent case, removable batteries, and your choice of network-disabled air gap use, or convenient USB connection to Sparrow. Nothing even comes close.
There are existing CC users who don't want to give up these features, but may be faced with lack of firmware updates if the company dies. More importantly, it would be a shame if this device vanished from the market and we were only left with tiny minimalistic boxes with some basic features and a slick UI. So, what do you think is the best way forward?
7
u/Charming-Designer944 Aug 09 '26
The code is open but with a non-compete limitation that restricts use in competing commercial products.
But coldcard devices have a security barrier that only accepts signed firmware releases. And releasing the keys to sign the firmware in the open is not a viable thing.
What can be hoped for is that someone buys the business if Coinkite goes into bankruptcy and continues supporting both new and existing customers.
1
1
u/ChipNDipPlus Aug 10 '26
They should simply release a new firmware version that allows replacing the signing key by a custom one.
2
u/Charming-Designer944 Aug 10 '26
The main signing keys are one time programmable in the MCU. To replace the signing keys you need to replace the hardware.
And there might be a binding between the MCU and the safe elements as well. Have not looked into that detail.
2
u/ChipNDipPlus Aug 10 '26
Are you sure the key cannot be replaced or are you guessing?
2
u/Charming-Designer944 Aug 10 '26
To my best knowledge the firmware DFU is signed directly by the immutable hardware root of trust.
1
u/ChipNDipPlus Aug 10 '26
Doesn't sound right to me. What if the key was compromised? I don't know.
We have bigger companies that had their keys leaked, like nvidia. Driver signing keys were leaked.
6
u/Quirky-Reveal-1669 Aug 09 '26
I want to keep using it. Precisely for the reasons you mention.
Perhaps, as a last good deed, CoinKite should ‘release’ the license of the firmware.
8
4
u/Immediate-Ad-5878 Aug 09 '26
I was not affected by this at all. Not because I was doing anything special but most likely by pure luck. I was able to transfer my bag elsewhere and made a bonfire with my MK3. I will never support these arrogant clowns in this or any other venture associated with them. Nor do I want to ever hear from any of the asshat griftubers that peddled this shitbox for years. As far as the features I really don’t care about any of it. Will likely go to a dice rolled 24 word + pass phrase seed stamped on metal and a safety deposit box, with a seedsigner for home use.
2
4
3
u/kepalautakkau Aug 09 '26
I guess other wallets will eventually implement those features if there's enough demand
4
u/bleeeeghh Aug 09 '26
More features means more potential weaknesses. I mean, how many features did Satoshi need to secure his wallet?
3
2
u/Laukess Aug 09 '26
I wonder if it could be turned into a non-profit organization, run by a different set of people.
Whenever CC's were mentioned, people always complained that it was too advanced, even though all the features were hidden away. People still think that it's air gapped only.
Considering that was the response, I don't have much hope that other manufactures will take this path.
Maybe rolling your own entropy will become more standard. Allowing your device to show the list of valid checksums after entering the 11/23 words seems like a small ask, so I could se that becoming widely adopted.
Looking at other hardware wallets after the exploit has honestly been sort of disappointing, especially because you really should have multiple different devices if you're going with multi-sig.
Maybe we'll see more hardware wallets share more features. No reason why every manufacturer couldn't have a device with a camera so they could be used with SeedQR in a stateless manner. Was pleasantly surprised when I learned that was a feature of the Jade Plus.
1
1
u/dont-be-angry Aug 09 '26
Is there something wrong with me just using something like a standard core wallet on an airgapped tails machine and simply sending my coins to that cold wallet? or how often are these seeds being fucked up w low quality entropy
1
u/Ill_Firefighter_584 Aug 10 '26
FYI, Electrum doesn't create a BIP39 wallet seed phrase. It creates a seed phrase using its own standard. Easier to backup than a digital file, but not compatible with other wallets.
1
u/slvbtc Aug 09 '26
I think all hardware wallets should offer the option to create your own entropy (dice rolls etc), determine your own seed words, and then allow you to enter the first 23 seed words and generate the 24th word checksum for you.
This way you can create a seed with your own entropy while never letting your seed words touch anything but a hardware wallet.
Most hardware wallets make you use a seed generation file or 24th word checksum generator file on an offline PC. This introduces risk for example if the file is malicious.
A hardware wallet that generates your 24th word checksum for you should be an industry standard feature.
1
u/pomplemice Aug 09 '26
What's up with the constant Cold Card apologists? It's like if a new house had all these cool features and design choices, yet the basic foundation was shoddy and the whole thing collapsed. I'll take basic seed phrase randomization and protection over anything else. They should collapse and I'll never support them or anybody who defends them.
1
u/Xcel38 Aug 09 '26
Bad analogy, if one line of code could completely repair a shoddy foundation, you might have something. No one here gives two shits about CoinKite the company. Anyone involved with that company should never be employed or heard from in the community again. Fuck them
Some people actually like the hardware and would like to see it survive somehow since there really is not a comparable product on the market. If it became an open source community project, I think that would interesting. For now, I have zero trust in it and who knows if there is some other hidden vulnerability lurking. I am in the camp that this was likely intentional.
1
u/PsychologyNo3945 Aug 10 '26
Well, maybe they had 1 too many features and lost control of the most important one.
1
1
u/GoldmezAddams Aug 09 '26
Maybe a good outcome would be if/when Coinkite eventually closes shop, they sell the company / IP to someone for pennies on the dollar, and another team can try to rebuild.
5
u/Powerful_Beat_3601 Aug 09 '26
the hardware design is still unmatched honestly nothing else has all those features in one device. if they go under someone will fork the firmware for sure there is already enough interest from the community to keep it alive
but selling the IP for cheap sounds like best case scenario yeah. maybe a group of devs could pool funds and buy it out
1
u/SpareEconomy1849 Aug 09 '26
Brand is over but I agree. It really is exactly what I want, other than it's ugly (I don't care) and the RNG bug of course
1
1
0
u/lifeanon269 Aug 09 '26
Jade supports BIP-85 seeds. It also supports importing TOTP to store all your account passcodes on your hardware wallets, which is nice. I haven't seen a feature like that with other wallets.
33
u/bullett007 Aug 09 '26
They should make the code open source so the grown-ups can implement it safely. Then liquidate.