@justin_shocknet once put it perfectly in a post about the whole ecosystem: "Trezor, Ledger, Coldcard: all run on microcontrollers with closed boot ROMs. Their 'secure elements' are under NDA. Their true behavior is inaccessible. You cannot verify what code is executing. You cannot prevent what you cannot see.""The Lie of the Lock: A Meditation on the Fraud of Modern Cryptography" — Here: #1008583.
Still true...
Irony in the Coldcard case however was that the vulnerability came from the one thing you arguably could verify, and nobody did... for years... despite everyone recommending it and bleating "Don't trust, verify" just to virtue signal
Still true...
Irony in the Coldcard case however was that the vulnerability came from the one thing you arguably could verify, and nobody did... for years... despite everyone recommending it and bleating "Don't trust, verify" just to virtue signal