To say that Coldcard's communication during this fuckup has been lacking is an understatement. It's a mess.
So far they have done a bunch of stupid stuff including waiting too long to issue a warning, hiding from their customers, seemingly trying to pass blame on to AI and issuing vague "advisories" about AI.
Today, I saw this: in response to something Jack Mallers said in a video, Coldcard makes a rare statement about how the low entropy wasn't a "fallback" nor an intentional design decision, but rather that it "was inherited behavior from the underlying platform that became active because of a link-time error."
Perhaps their intention was otherwise, but it comes off as defensive which is not a good look for a company whose customers have recently lost $100m.
Extremely important correction.
@jackmallers there wasn’t a weak entropy fallback. I think it’s important to be precise about what actually happened.
The weak PRNG (Yasmarang) wasn’t Coinkite’s fallback—it was MicroPython’s built-in general-purpose RNG, introduced upstream in May 2018. It didn’t become part of Coldcard’s seed generation until the libNgU migration in March 2021.
Most language runtimes include a non-cryptographic RNG like this for general purposes such as shuffling, timing jitter, or other non-security-related randomness. By itself, that’s not unusual.
Coinkite’s design intent was actually the opposite of having a software fallback: seed generation was supposed to rely exclusively on the hardware TRNG and never use the software RNG. Setting MICROPY_HW_ENABLE_RNG=0 was intended to disable that software path.
The issue is that this setting didn’t have the intended effect, and the symbol instead resolved to the runtime’s default implementation. So what people are describing as a “fallback” wasn’t an intentional design decision or a shortcut in the seed-generation logic—it was inherited behavior from the underlying platform that became active because of a link-time error.
I remember that the general rule a good counsel will put on a fresh post-it on your screen every morning before you enter your office is to never argue on a third party platform, or generally, in public. Like what was said in this scene:
For some underground stuff I can see the temptation to just not run things like a business and use that as a growth driver. But if you're on your way out, a measure of professionalism will make it a lot more manageable and allows one to focus on the most orderly winding down. I'm not sure if everyone involved understands that that outcome is rather inevitable now.
It would of course be the death of MSM, Twitter and the popcorn industry in one big crisis if this were ever to be implemented by everyone of course.
Addendum: #1542002 actually shows they know, and it isn't a bad statement. Just, it should have been made in the announcement instead of vague AI statements, and not on the bird app.
I've never had to do damage control/comms crisis management on a scale like this, so I suppose my talk is cheap. But if I was the person manning their comms, I'd be going out of my way to respond to people and attempt to be helpful. I'd particularly avoid things that sound like nitpicky self defense. This seems like it will just make people angry and distracts from the main goal right now.
The worst drain exploit (1% coordinator fee) that Wasabi had was discovered internally and fixed (but not deployed quickly enough): https://github.com/WalletWasabi/WalletWasabi/pull/13191
I guess the bright side is that the damage was minimal, and the bug allowed an opportunity for coordinators to establish a history of trustworthiness (despite there being no inherent trust requirement in coordinators at the protocol level).
Do you think it a solution to copy/emulate the post-snacks solution as done for Wasabi, for Coldcard firmware if there's going to be a post-coinkite moment? (not sure if this is possible wrt the signing of the firmware, fwiw.)
What's the point? Coldcard was originally forked from Trezor, so just use their devices instead.
The point is that one generally does not solve software problems with a hardware fix (or vice versa.)
This is good.
If you're going down anyway? Only the most impactful things. Not to save you, but them. Which means do release the firmware. Do make sure people know about its existence once its there (and properly QA'd.) Do not waste time on individuals unless you have spare time, which I would doubt you'll have.
If there is any chance of being sued... legal will shut down some of that though, it's risky. Easy to make mistakes in comms that can be twisted and narrated against you in court. At least in my experience, legal will tell you to shut the fuck up, and if you need to vent, vent to them. At 10 grand an hour.
a scene from the excellent series Silo
In response to another person:
source
I am strangely fascinated by this trainwreck
https://twiiit.com/COLDCARDwallet/status/2085551118164132316
https://twiiit.com/COLDCARDwallet/status/2085541034243600805