Bitcoin Mechanic on the Coldcard Scandal and NVK

(Video below) Bitcoin Mechanic has some interesting details on NVK buying up domains to fight Seedsigner adoption as he must of really determined it a threat to his company. And the history of how this bug came about from Coinkite having used Trezor’s opensource software and later getting upset that others took theirs to use in other hardware wallets, then rewriting the code under a commercially restrictive license, thus introducing this randomness code bug. If they had not tried to be so anti-competitive, they wouldn’t have just trashed their company and become a pariah in the Bitcoin space. And for me publicly, NVK was incredibly prideful, and this has become a God level humbling, which can’t sit well with the Coinkite employees having made such a huge blunder, losing people millions of dollars, some their life savings.

Consequently, the Seedsigner promoted by Bitcoin Mechanic is not a hardware wallet with secure elements to protect your secret key, as you create a QR code sheet that is your seed you have to scan in order to transact loading the seed phrase in memory unprotected via camera. You can use it air gapped, but it’s more susceptible to hacking if someone were to have ever compromised the firmware of the device (Raspberry Pi Zero) or your OS SD card. And you have to keep your seed phrase QR code sheet around to use it, loading via camera, and if anyone gets that they can steal all your funds, unless you use a good passphrase. But the passphrase is worthless if the device firmware or OS was hacked. It does have the advantage that purchasing the parts doesn’t out you for wrench attacks or alert the government you have a hardware wallet. But for me today, I wouldn’t trust it for serious holdings unless you can keep it and the QR code sheet in an extremely high quality safe and you sweep your home for camera devices before use… And an air gapped old computer used as a wallet also suffers from these same vulnerabilities.

And secure elements aren’t necessarily unhackable, but with some creative engineering you can combine multiple secure elements and the processor design so that everything needs to be hacked together to retrieve the secret key, requiring sophisticated attacks with sophisticated equipment and serious engineering expertise, also requiring physical possession. So you have to understand the design, and assess the expertise of the team working to secure and audit the code, and keep track of security research as people evaluate the hardware, update firmware and constantly make security assessments.

The Coldcard debacle is a good example that you might want to have more than one hardware wallet, so if a vulnerability you’re uncomfortable with arises, you can move your funds and not have to depend on a custodial exchange or service. And you should evaluate the hardware company and their engineering expertise, watch keynotes and posted videos, pay attention to their blog posts and the information they present. Especially security vulnerabilities and how to address them.

To make my point, I’ll include an interview of Coinkite’s NVK, and you tell me if you trust this guy and his hardware to secure a large amount of Bitcoin? And this always struck me as odd how so many influencers in the Bitcoin space promoted their products while demeaning other manufacturers, even those not paid by NVK. And compare that to the professional organization that is Trezor, who were the first to make a hardware wallet in the space to protect your secret key, as I have a wiped original 2014 Trezor Model One on my desk. And their security philosophy has always been on display. And I have a Coldcard Q as I was intrigued by the product and posted a review that highlighted one of the secure elements being hacked already, and I’ve already updated the firmware and generated a new seed on the device and will continue to use it as I didn’t lose funds, though it only has a few hundred dollars worth of Bitcoin on it for playing around.