Nobody can measure how much licensing pressure shaped the scope or speed of that rewrite, and the overhaul also pursued legitimate technical goals. The documented facts are narrower and still damning: a license change made to restrict competitors preceded a rushed replacement of battle-tested cryptographic code, and the replacement contained the flaw now draining wallets. Free and open-source software principles exist precisely to keep security from depending on any one company's choices. Those principles cannot come with a personality exception.
The Coldcard hack proves reputation is not a security model
Nobody can measure how much licensing pressure shaped the scope or speed of that rewrite, and the overhaul also pursued legitimate technical goals. The documented facts are narrower and still damning: a license change made to restrict…
Zach Herbert
Publisher CoinDesk
Aug 17, 2026 at 2:09 PM UTC · 1 Min. Lesezeit

Zach Herbert is co-founder and CEO of Foundation.
Researchers learned not to look
The deeper failure is what happened to the people who did look. In August 2020, researchers from Shift Crypto and Nunchuk disclosed a multisig verification flaw in Coldcard. Coinkite acknowledged the bug and shipped a fix, and NVK, on the Citadel Dispatch podcast simultaneously branded the disclosure "PR terrorism" and questioned whether a researcher without a CVE counted as a professional. In 2023, when the WalletScrutiny project reported problems reproducing older Coldcard builds, the response labeled the project incompetent or malicious and floated litigation. Independent follow-up later found genuine reproduction problems in older releases and concluded nobody had acted in bad faith.
Article Intelligence
Topics
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
