quotingGm the Coinkite CTO authored the Coldcard vulnerability under an alias then merged it into the Coldcard repo as the CTO. ☕
nevent1q…csjr
eldorado on Nostr: It has to be extreme malice. Its hard to consider extreme incompetence for a security ...
It has to be extreme malice. Its hard to consider extreme incompetence for a security product of this kind. And then you have to factor in the fact that the code change was authored anonymously and merge by the CTO as shown by nprofile1qqsxft85q406sf4u4wz90cjwlra6wjg2hv08dkatd25822jn5r456jspr3mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmqppamhxue69uhkummnw3ezumt0d53vcuaj (nprofile…cuaj). Sounds dodgy as fuck.

