Join Nostr
2026-08-17 10:17:10 UTC
in reply to

npub1j9…vuswx on Nostr: "Coldcard being open source didn't prevent keys from being stolen" fails on the ...

"Coldcard being open source didn't prevent keys from being stolen" fails on the premise. Coldcard has not been Open Source since 2020. OSI defines the term. MIT plus Commons Clause is not Open Source. Coinkite dropped GPLv3 deliberately, to stop commercial forks, and their own marketing retreated to "verifiable" after much fighting.

You know well, the March 2021 commit that purged the last GPL code replaced battle-tested Trezor crypto libraries with a novel in-house library. Seed generation changed in that same commit. Escaping FOSS obligations and introducing the flaw were the same act.

And who found it, five years later? Not Coinkite. Outsiders reading public source, quite possibly with LLM assistance. That cuts both ways and it's the part that should get Casa listening. Models are getting good at finding bugs in binaries, too. Black hats already analyze your closed source app. Publishing source doesn't hand them anything they can't increasingly get themselves. It's the white hats, who won't touch proprietary code for legal and practical reasons, that closed source locks out. Security through obscurity now selects for the adversary.