Coldcard Wallet Hack Exposes Risks in 'Source-Available' Bitcoin Software
Coldcard Wallet Loses $100 Million in Bitcoin Due to Software Flaw
A security flaw in Coldcard, a popular hardware wallet for storing Bitcoin, led to the loss of over $100 million worth of Bitcoin (more than 1,500 BTC). The flaw remained undetected in the wallet’s publicly available code for about five years before being exploited. The incident has raised questions about the security of so-called "source-available" software, which allows users to view the code but restricts how it can be used.
The Coldcard hack highlights a key debate in the Bitcoin community: whether software handling financial assets should be fully open-source or if restricted licenses can still provide security. Open-source software allows anyone to inspect, modify, and distribute the code freely, while source-available software may limit commercial use or redistribution.
What Went Wrong with Coldcard’s Code
The flaw in Coldcard’s software was an entropy bug—a weakness in how random numbers are generated, which are critical for securing cryptographic keys. The bug was introduced during a 2021 rewrite of the wallet’s code. Despite the code being publicly viewable, the restrictions on its use may have discouraged thorough security reviews from third-party experts.
Coldcard’s firmware is released under the MIT license with an added Commons Clause, which prevents commercial use of the software. Critics argue this restriction limited the number of developers who could legally review and test the code, reducing the chances of catching the flaw earlier.
Key Differences Between Open Source and Source-Available
- Open Source: Software that meets strict criteria, including the freedom to use, modify, and distribute the code for any purpose. Examples include Bitcoin Core and the Linux kernel.
- Source-Available: Code that is publicly readable but may have restrictions on commercial use or redistribution. Coldcard’s firmware falls into this category.
- Security Impact: Open-source projects often benefit from widespread scrutiny, as anyone can review and improve the code. Source-available projects may rely more on the original developers for security checks.
How Bitcoin Core Handles Open Source
Bitcoin Core, the primary software used to run the Bitcoin network, is a fully open-source project. Its development process is public, with anyone able to review, suggest changes, or fork the code. Contributions are evaluated through a structured review system, and funding comes from nonprofit organizations rather than commercial interests.
Unlike Coldcard, Bitcoin Core’s open-source license allows anyone to use, modify, and distribute the software without restrictions. This has led to a large community of developers and security experts continuously reviewing the code, which many believe makes it more secure over time.
Why the Coldcard Hack Raises Concerns
The Coldcard incident shows that simply making code publicly viewable is not enough to ensure security. The Commons Clause in Coldcard’s license may have discouraged commercial companies from reviewing the code, leaving potential flaws undiscovered for years. In contrast, fully open-source projects like Bitcoin Core benefit from broader scrutiny, which can help catch vulnerabilities earlier.
Some developers argue that the incident demonstrates a "tragedy of the commons"—a situation where individuals act in their own short-term interest rather than contributing to the long-term security of the software. If too few people review the code, even serious flaws can go unnoticed.
AI’s Role in Future Security Reviews
After the Coldcard hack, a volunteer group called the Bitcoin Red Team used AI tools to scan hundreds of open-source Bitcoin projects. The effort uncovered thousands of potential vulnerabilities, including dozens classified as critical. The team found that open-weight AI models from China were more effective at identifying security flaws than closed-source models from U.S. companies.
However, AI also presents challenges. The flood of AI-generated code has made it harder for maintainers to review contributions, as sorting through automated suggestions can take more time than writing the code manually. Some projects have even restricted AI-generated submissions to avoid being overwhelmed.
What This Means for Bitcoin Users
The Coldcard hack serves as a reminder that not all publicly available code is equally secure. Open-source projects with unrestricted licenses tend to attract more reviewers, which can lead to faster detection and fixing of vulnerabilities. In contrast, source-available projects may rely more on the original developers for security checks, which could leave users at greater risk if flaws go unnoticed.
For Bitcoin users, the incident underscores the importance of choosing software with strong community support and transparent development processes. While no system is perfect, open-source projects like Bitcoin Core have a track record of benefiting from widespread scrutiny, which can help improve security over time.