Bitcoin security experts aren’t surprised by Coldcard’s issues
In 2019, researchers
@sedited_ &
@KasparEtter disclosed a severe bug in the Coldcard hardware wallet
They could have exploited the bug, but chose to send all the information + the fix to Rodolfo
Instead of paying them for their work, Rodolfo downlpayed the severity of the bug as “low risk” and only sent merchandise to the two researchers (mugs & Coldcards).
In the security world, Coldcard has always had a bad reputation for not offering bounties in exchange for responsible disclosures
So when teenage prodigy hacker
@saleemrash1d found a vulnerability, he disclosed it to Trezor, Ledger, BitBox, and every hardware wallet company except for Coldcard
Why? Because he knew that Coldcard doesn’t pay. So Coldcard had to learn about the vulnerability after their competitors had already patched it.
This is as a recurring theme with Coldcard:
they constantly resorted to downplaying the severity of security disclosures, paid much less money for bounties than their competitors, did a lot of dishonest marketing which emphasized that being “Bitcoin-only” makes their devices more secure (they used BIP44 too for testnet).