quoting
naddr1qq…gswa******** Opinion about Coldcard Mk3 (hardware) <!--HEADER END--> Coldcard and its creator, NVK, have long been polarizing figures in the Bitcoin ecosystem. Over the years, Coinkite drew criticism for repeatedly changing or tightening software licensing around Coldcard firmware and related code, frustrating some open-source advocates who felt the project was moving away from Bitcoin's traditional open-development ethos. Relations with WalletScrutiny also deteriorated, with NVK and supporters publicly criticizing WalletScrutiny's methodology and conclusions on X (formerly Twitter), particularly regarding reproducible builds and transparency. Those disputes resurfaced after the recent Coldcard security fiasco, in which a firmware flaw affecting seed generation led to large-scale Bitcoin thefts from vulnerable wallets, prompting critics to revisit earlier concerns about transparency, independent verification, and the project's adversarial stance toward external reviewers. Supporters argue Coldcard remains one of the most security-focused hardware wallets and that NVK has responded aggressively to fix issues, while detractors see the episode as evidence that independent scrutiny should be welcomed rather than attacked.
As of August 3, 2026, the best-supported public estimate is that approximately 1,367 BTC has been stolen across three waves of attacks, affecting roughly 4,585 Bitcoin addresses. At prevailing BTC prices, that is about US$89 million in losses. Galaxy Research believes the attacks are linked to the same underlying Coldcard seed-generation vulnerability disclosed at the end of July. Coindesk
The latest reporting indicates the vulnerability affected Coldcard-generated seeds, but the practical risk differed by model:
Mk2 and Mk3 (especially seeds generated with affected firmware from 2021 onward) were considered the highest risk because the entropy reduction was much more severe. news.com.au
<!--FOOTER START-->#WalletScrutiny #nostrOpinion

