I'm a software engineer with an MSc in Computer Science and 25+ years in the industry. Here's why Coinkite's Coldcard bug isn't an oopsy, it's disqualifying.
Coldcard's seed generation silently fell back to a non-cryptographic "random" number generator for 5 years. Not because crypto is hard, but because Coinkite violated the most basic rule of secure system design: fail closed, never open. When a security-critical path can't be verified, the system refuses to run and throws an error.
It does not quietly substitute something weaker and carry on. This code should have refused to produce a seed. Instead it produced a predictable one and continue silently. ☠️
A company that lets its most critical code path go unverified for half a decade cannot be trusted with your keys.
Throw away your Coldcards. Never buy one again.
@greentheonly Hmm.. first thought to mitigate premium but just realized it is on the software side that manages this. So yeah no reason at all to do that.