What happened with COLDCARD is one of the most painful moments in the history of Bitcoin self-custody.
It did not hit the people who didn't care about trusting a third party. It hit the ones who did everything right who researched, understood, and chose sovereignty.
I really think about the affected people and it breaks my heart every single time. To hear about people losing everything. Losing money they saved for years.
This incident once again shows why we designed Specter DIY the way we did from day one:
- Hardware RNG is only one source
- Touch data and timing are continuously mixed in
- Most importantly: the user can fully control and verify the entropy themselves through coin flips, bit toggles, and transparent bit-level visibility
- No hidden fallback paths. Everything is open source and auditable
Self-custody works best when you systematically remove single points of failure. That is why I have been advocating multi-vendor multisig for years.
But this is not for everyone. This is not for people who just want to just Secure their Bitcoin. This makes the current situation so devastating.
With Specter we want to do better. Bitcoin Security is where my heart beats for. Bitcoin Security is where the heart of our Specter Association beats for. We will do everything we can to keep as many people as possible protected from incidents like that.
And we will do everything we can to make sure that we stay as transparent as possible in every single way.
Especially for advanced users we want to provide every option to be able to take the extra mile and
- To see how the coin flips affect the entropy
- To see which data enters the device.
- To see what you are actually signing
- To see which data leaves the device
- To see that the device carries the correct firmware
- To see that the correct firmware stays on the device
We know self-custody is hard.
We know not everyone will go the extra mile.
But for those who do, we will keep building the tools, the transparency and the education that make true sovereignty possible.
We will continue to fight with Specter for higher security standards of Bitcoin Self Custody. For simple bitcoiners and for advanced experts.
๐ค
Login to reply
Replies (4)
On the positive side, it was amazing to see the bitcoin security community update, research, and hard work to get to the bottom of this so fast, as it was playing out. It could have swerved in any direction until they started narrowing it down to the faulty firmware. They put aside finger pointing, and any interests to verfying and eliminating possibilities.
View quoted note โ
Hardware RNG can be disabled by software.
What does it even mean now?
I still have to trust the software and the hardware silicon.
For RNG i would not recommend any hardware anymore.
You can just roll the dice and use a strong passphrase.
Specter DIY looks cool but the STM32 board the github calls for is discontinued and out of stock or way marked up everywhere I look.
It's still manufactured. But Its currently sold out everywhere. They will have supply in February 2027 again.
I have some left at ClavaStack so you can buy still at my shop.
We are also working on supporting a new board. So that it can get build together from only off the shelf components at some time this year hopefully.