It sounds like it was human error.
I don’t get it, doesn’t coinkite routinely get independent security audits? Why was this not caught?
I would imagine a sensitive project like this would have nonstop independent audits???
Humans will always make errors and new models will uncover (and introduce) new attack vectors. Isn’t this what audits are for?
I almost feel as bad for the guy who made this mistake as the people who lost their funds. Imagine wearing the burden of knowing what your one mistake resulted in …
Login to reply
Replies (5)
Audit budget was likely replaced by podcast advertisement expense.
I’m with you. I would feel bad for the guy that made this mistake also, but… There is that thing that he copied another company (Trezor’s wallet) then got made and changed his code to be locked down because Passport wallet copied his code. WAIT, you copied then got mad when someone else copied. THEN sued a guy for making a btclock that is similar to yours? isn’t this open source?
I didn’t have my funds confiscated yet, but he is on his own on this one. Some heads need to roll for this.
Feeling bad for the people that this happened to yes. 100% I’m with that. It wasn’t 1 mistake NVK made. It was many many mistakes. Went from open source to closed source so no other company could verify, then told them that it was to keep… I am just ranting here.
Maybe it was Ledger that found the mistake? NVK was first in line to go on what bitcoin did podcast with Odell and ledgers founder to get on him. Ledger has messed up, but they allow and encourage people to find holes. NVK said his code was above peer review. Now we see why.
TRUE. Big fail!