Last week’s Coldcard incident is a reminder of something the industry underrates: randomness is the foundation of self-custody. If it's weak, everything built on top of it is too.
Here’s what happened, and why Ledger devices are unaffected.
@bitcoin_clown@SeanObud111 Is it costly to guess seeds? Can you run something that guesses seeds if you have lots of compute power? (I mean without coldcard messing up?)
This Coldcard fiasco had me look into the BitBox open source code because they have a bug bounty program.
A bug bounty program is awesome. All hardware wallet developers should have one. This is one of the reasons I have always recommended BitBox on my channel.
With one-shot of GPT 5.6 Sol Ultra, I found evidence of an extremely low severity bug that has nothing to do with seed extraction, unauthorized signing, firmware compromise, or persistent bricking. No biggie.
And still, instead of being able to investigate further, the ChatGPT hall monitor stops me in my tracks.
Americans need access to frontier AI intelligence without a corporate hall monitor standing over every prompt.
I can hand a Chinese open-weight model a real firmware defect and it will inspect the code path, calculate the failure boundary, trace related handlers, and help produce a responsible report.
Meanwhile, the “safest” American model sees the word cybersecurity, slams the blast door, and offers me a pamphlet.
If American builders are forced to use lobotomized tools while open models abroad can reason freely, debug freely, and iterate locally, we are exporting AI dominance instead of leading.