@XyukonR@SimplyBitcoin Isn’t that the case with all hardware wallets? Wasn’t everyone relying on coldcard to protect their Bitcoin? If I buy a ledger, jade, or Trezor aren’t I relying on that single company’s hardware wallet with my life savings?
@zdforcier@LANDIGlobal@MTanguma open source this, open source that. Open source didn’t do shit for coldcard except for embarrass them. Ledger close sourcing the most important parts of their code and having it audited by highly skilled teams is better than exposing how everything works to the world.
The average person should rent forever and I say that as someone who builds homes for first time homebuyers a living.
Ownership is sometimes romanticized in this country to an unhealthy degree. People drain their savings, steal themselves to a 30 year mortgage and then spend every weekend doing maintenance on a depreciating structure they can't afford to leave.
Meanwhile the renter down the street has liquidity, mobility and zero exposure to a $15,000 HVAC or roof replacement.
A paid off house in a town you hate is a prison with a mailbox. I build homes because I love real estate, but I'd never tell someone to buy one just because society says they should.
Listen, there are plenty of people out there that homeownership makes sense for. Just not as many as society makes you believe.
@XMRVoid coldcards get hacked because of their poorly audited open source software. But ledger is the issue? As far as I know anyone with their BTC seed on a ledger is 100% safe. This ledger FUD is getting fucking old
How safe if your Bitcoin seed phrase?
The difference between 40 bits and 256 bits is not a small upgrade.
It is the difference between minutes and longer than the age of the universe.
@bramk@P3b7_ If you don’t want ‘crypto’ just don’t install any of those apps on your ledger. Just install the Bitcoin app. Didn’t coldcard just teach you being Bitcoin only doesn’t mean shit?
Fuck that Ledger keep the important parts of your code closed source with the appropriate teams auditing it. Being open source didn’t do shit for coldcard but get them publicly embarrased with thousands of people losing their life savings. These guys have the nerve to still complain about you being closed source is beyond me! Security first!!
@Pato77781O@wesleybrad060@Ledger@coldcard Exactly. Glad someone said it. Ledger gets a lot of hate that I think isn’t really warranted. It’s almost like it’s just cool to hate Ledger. Sorry for your loss man hope you and your fam get through this.
This does not affect Ledger wallets.
The X post (and the full thread from Max Guise / Block) describes a set of critical random-number-generation (RNG) flaws specific to Coinkite’s Coldcard hardware wallets. It has nothing to do with Ledger’s architecture, firmware, or seed-generation process.
Ledger uses a completely different design:
Seed generation occurs inside a certified Secure Element (ST or equivalent chips, typically EAL5+ or EAL6+).
Entropy comes from a hardware True Random Number Generator (TRNG) inside the Secure Element that is evaluated against standards such as AIS-31. It produces high-quality entropy (target 256-bit security for the seed material) with built-in health checks, rather than a software PRNG fallback.
There is no MicroPython runtime, no libngu/Yasmarang path, and no equivalent macro or reseed truncation bug of the type found in Coldcard’s open-source firmware.
Ledger does not share Coldcard’s codebase or board-configuration approach.