ColdCard’s bug doesn’t have to be an inside job to be a colo...

Momo

npub1heqkxm37d5h7n8sx2gqdez5sxnu39qrylhxnnd66dxpu4e2ufyysdkkx28

hex

03f36940980af6af3bdde30a6201afa2d955e3c1f50951ab284708c007478849

nevent

nevent1qqsq8umfgzvq4a4080w7xznzqxh69k24u0ql2z234v5ywzxqqarcsjgprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgstustrdclx6tlfncr9yqxu32grf7gjspj0mnfekadxnq72u4wyjzga3amhw

Kind-1 (TextNote)

2026-08-05T15:36:59Z

ColdCard’s bug doesn’t have to be an inside job to be a colossal failure. It’s already bad enough on its own and I don’t find the claims accusing Odell of being in on it convincing.

The podcast clip that’s been circulating doesn’t incriminate Odell. He’s discussing a self-discovered vulnerability in firmware 4.0.0 (one release before the catastrophic 4.0.1), which only affected users who upgraded to that version. 4.0.1 was a patch of whatever vulnerability that existed in 4.0.0.

He’s talking about a different vulnerability that could have been exploited. Nothing in that clip suggests he knew 4.0.1 would introduce an entirely new bug.

Arguably, NVK didn’t know either. But his decision to move away from GPL-licensed code and adopt a source-available license just because he childishly hated competition is what ultimately set the stage for this catastrophe. It doesn’t make nvk any less responsible.

原始 JSON

{
  "kind": 1,
  "id": "03f36940980af6af3bdde30a6201afa2d955e3c1f50951ab284708c007478849",
  "pubkey": "be41636e3e6d2fe99e065200dc8a9034f9128064fdcd39b75a6983cae55c4909",
  "created_at": 1785944219,
  "tags": [
    [
      "client",
      "Primal iOS"
    ]
  ],
  "content": "ColdCard’s bug doesn’t have to be an inside job to be a colossal failure. It’s already bad enough on its own and I don’t find the claims accusing Odell of being in on it convincing.\n\nThe podcast clip that’s been circulating doesn’t incriminate Odell. He’s discussing a self-discovered vulnerability in firmware 4.0.0 (one release before the catastrophic 4.0.1), which only affected users who upgraded to that version. 4.0.1 was a patch of whatever vulnerability that existed in 4.0.0. \n\nHe’s talking about a different vulnerability that could have been exploited. Nothing in that clip suggests he knew 4.0.1 would introduce an entirely new bug.\n\nArguably, NVK didn’t know either. But his decision to move away from GPL-licensed code and adopt a source-available license just because he childishly hated competition is what ultimately set the stage for this catastrophe. It doesn’t make nvk any less responsible.",
  "sig": "9388c6175f4783e5f9dbdd3e1970e60ff39128810ac6b6139213990bcd41a1d7a0da9f540b83ebc6257c5501775ec5a904d415b66f470e9ef664d2f3da10dd0e"
}