mt logoMyToken
ETH Gas
Tiếng việt

The ColdCard "Hack" Should Not Be Called Theft

sưu tầmcollect
đăng lạishare
The ColdCard "Hack" Should Not Be Called Theft

We are going to take a somewhat-odd sounding position here. ColdCard was clearly exploited in some sense. But the nature of the product, and the inability due to product design to differentiate between "theft" and intentional use, leaves us thinking users should not have recourse as though their assets were stolen. We do think they are welcome to go after the team for a number of terrible decisions and defective work products. But "hack" in the conventional sense of "unauthorized access leading to asset loss which law enforcement should try to claw back" does not fit this case.

The Setup

One point of self-custody is to frustrate directives from the legal system. Possession of the keys is intended to be the sole arbiter of ownership. This is many people's main motivation to use Bitcoin. And it is on the short list of motivations for many more. ColdCard was marketed at least in part as a way to escape traditional rules. This does not, in and of itself, mean hacks cannot happen or users deserve this kind of treatment. But we think on a fuller analysis of the circumstances "hack" is the wrong word.

Of course we cannot know the intentions and desires of each and every user of ColdCard (or any other piece of software). But ColdCard's own docs make clear that escaping the possibility of government control is part of the sales pitch. And many voices in and around the self-custody space constantly preach about escaping the possibility of control. No company selling a product is going to come out and say "our use case is frustrating court orders" so we do have to read between the lines a bit. Censorship resistance is often code for this.

At the same time there needs to be a single policy for the entire class of users. All these users opted into a self-custody system with censorship resistance as a core feature. There are many ways to keep assets safe. And these users should be forced to live with the consequences of their decisions. Again: we are not saying this automatically means your assets are a free-for-all for hackers. And we need to look at the entire ColdCard situation.

If you put valuables in a safe the intent is to keep them safe. But you do not intend that whoever can open the safe owns the contents. If you intend for the keys to convey ownership then let the keys convey ownership. We should not encourage people to enact this opt-out and defer entirely to control over the keys and then to get a do-over if they trusted the wrong scheme . What was your justification for trying to use private self-custody anyway? We know for at least a reasonable fraction of people it is non-compliance with various laws.

Users that want to frustrate the legal system in this way might well deserve what they get. If you do not intend to follow court orders directing you to use your private keys to open a lock then you should not be able to go to that same court and claim someone else picked your lock and you want your money back.

If the intent is to frustrate court orders then it is too rich to expect you can go get one to recover your money. Similarly, if you intend to rely on a system where a known mathematical process controls all you have to take more responsibility for checking how the system works than when you rely on, say, the courts. Giving up one for the other must be understood in total. All the circumstances matter.

Is This About Fairness?

No. It is not about fairness. Life is not fair. This is not about fairness – it is about enforcing the bargain these users made in a way that is consistent with other sorts of bargains other users make. You wanted to opt out of the traditional legal/asset-protection system. And you should not be allowed to now cancel that move and go crawling back when you need that system's help. That would be not just unfair to everyone that participates in and supports the traditional system – it would be unfair to self-custody users who expend resources to do it properly. The cost of user negligence cannot simply be inconvenience.

There is of course a line somewhere. Hacks are still possible. But as we will cover below it sure looks like users here intended to defer to a system they did not realize was broken for years. Only when their inability to detect the problem – or maybe just their lack of interest in looking for the problem – led to disaster did they became unhappy with the system. Self-custody must impose a larger burden on users than bank- or exchange- or whatever-regulated businesses or "traditional" custody. We are not saying in every case this means a "hack" is not a hack. But sometimes it might be. Start by opening up to this possibility.

Remember that when we are talking about hacks and thefts and such there often are no good answers. The "good" answer, such as it is, is for the hack to have never occurred. But conditioned on the hack happening it is normal for all the available options to feel bad. To the extent there is a real fairness issue here: the problem is that the team did not treat their own customers and users fairly. The problem is that there are not enough assets around to satisfy everyone with their hand out. Even if assets can be clawed back that takes time and energy and resources from law enforcement. Someone has to pay for that. And law enforcement will, again by construction, do this instead of something else. Someone is going to be unhappy no matter what we do.

The recall the root cause: a bunch of self-custody users never bothered to check if the thing they trusted was in fact trustworthy. Society as a whole has no interest in encouraging blind faith in tools people do not understand and do not check for themselves. So there is a bit of a broader social interest in disincentivizing users from allowing this to happen again. And make no mistake: the flaws that were exploited here was publicly visible for a long time. These self-custody users allowed this to happen. This is not victim blaming – it is stating the plain fact that users did not do sufficient due diligence on a product that should be all about due diligence.

Fraud

The team seems to have known about the problem for quite some time. If they were selling a product with this kind of security vulnerability and covered that up then users almost certainly can claim they were defrauded. Even if the team did not know – and, again, there is mounting evidence they did know – at some point incompetence is negligence is legal liability. ColdCard can have defrauded its users even while we do not think those users were actually hacked.

There is also evidence the team were, in general, careless and had bad security practices. To some extent this rhymes with FTX where after the blow-up everyone pled ignorance and moaned "how could we have known?" But when you go back and look at the record – whether it is SBF interviews or information emerging about ColdCard – there were obvious red flags. People just chose not to look. Or not to believe.

Does that excuse fraud? Of course not. But users here were victims of incompetence and fraud, not theft. And as we will see below, the alternative where this is considered a hack and users try to claw back assets introduces a whole other set of difficult problems.

We would also point out that the errant code was publicly visible for years. This is the core of the "it is not a hack because users did not exercise sufficient care over their self-custody solution" argument. And the company can try a defense like:

  1. Yes we made marketing statements which were inaccurate. Marketing is allowed to be a bit inaccurate. Puffery and such
  2. We had disclaimers
  3. The code with the problems was always public. So, inclusive of the disclaimers, users were supposed to check.
  4. All software has bugs. So rejecting 2+3 as a defense is a bad precedent.

We do not really think that will work given evidence the team was notified of the problem and did not proactively notify users or fix the problem. We do think the team is heavily at fault and liable here.

But in a counterfactual world where the team was never told, and has no internal communications about the bug, that theory might fly. To be clear: we do not think a jury will accept that theory. But a judge might throw out a verdict on that basis. Maybe.

Refusal to Admit the Real Problem

CoinKite, the company behind this steaming pile, put out a Technical Deep Dive that is a strange blend of bland descriptions for serious problems, unnecessary technobabble to mask how dumb these problems were, and some false statements.

The Summary section begins:

A complex and subtle series of bugs prevented the hardware RNG from contributing randomness in certain versions of the firmware. We were unaware of the bug until today.

Not only were the problems not "complex and subtle" but there is at least some evidence the team knew for a long time.

So here too we have a classic setup. Team does something dumb and amateur. This results in a large problem. And the team then puts out technobabble in a feeble attempt to cover up how dumb and incompetent their actions were.

The simplest explanation here is that the technobabble sounds and reads the way it does for the same reason the team made the mistake to begin with: their understanding of the field in which their company operates is far less than it should be. And it is far less than the team believes it is. Calling the people involved arrogant and incompetent feels more like a factual observation than an opinion.

Choosing Self-Custody Must Be Irreversible

Courts should recognize that derivations of private keys without any actual theft – hacking or stealing someone's device, physically threatening someone, etc. – do actually transfer ownership. This sounds ridiculous but is actually just a straightforward consequence of other reasonable-sounding things. The easiest way to see this is correct is to consider the alternatives.

Say you want self-custody to be recognized as legal and legitimate. Fine. So courts cannot forcibly relocate assets. And securing an order or sentence for contempt to cajole someone into doing something "voluntarily" that is really involuntary requires evidence of a crime or some misdeed not just an arbitrary desire to relocate assets. If the court cannot press the button for you then it needs solid evidence to, in the limit, send someone to jail for not pressing the button following an order.

Now say you send someone assets to make a purchase or as part of a swap or other financial transaction. What stops you from claiming that transfer was theft? The entire thing is supposed to be based on control over private keys. Your outgoing transfer was signed with the keys so it is legitimate. The receiver controls assets with their keys so ownership is legitimate. The bar to upset this situation needs to be evidence of a hack or break-in or theft or something. Merely claiming "hey I did not transfer this" cannot be enough. Why? Because then you have chaos. Self-custody will not be legitimate and usable if you can run to court without direct evidence of a crime. Not a theoretical way someone could have exploited something to take your money. Direct evidence. Or it is chaos.

If these transfers are considered theft and people try to claw back how is that going to get adjudicated? How many people will claim to claw back payments they actually did make? The whole thing is supposed to be based on keys = control = ownership. If we upset that balance then every transaction can and will get litigated. Anyone paying out of a ColdCard (of the relevant versions) can claim they were a victim and there really is no way to tell.

Scam-Adjacent

There are already scams out there where criminals falsely claim to have been defrauded and report people to the police to get their tokens frozen and clawed back. Variants of this problem exist today.

Our position is merely that a claim assets were "stolen" from self-custody should require direct evidence of an independent hack or intrusion or similar crime. Bad random numbers do not give that kind of trail. User's private data was never touched. A bunch of simultaneous transfers the users claim were involuntary sure is suggestive of a problem. And the ColdCard team surely did things wrong. But theft? How can we differentiate between the "hacker" and someone that just wants to reverse a legitimate payment?

From a digital forensics perspective there is nothing that differentiates a legit ColdCard payment from one borne of this incident. If we cannot tell one from the other we cannot treat them differently. The nature of the flaw in ColdCard is that there are no logs. This is a feature of self-custody. Maybe it is a feature users do not now want but it has been there all along.

Further, any trail that tries to prove there was a hack needs to also show the assets came from some kind of legitimate place. Self-custody itself is not proof anything wrong happened – but the process needs to be thorough enough that users running unlicensed money changers and the like cannot use the police to recover assets which were themselves proceeds of crime. Trying to claw back flows out of systems where "hacks" are technically indistinguishable from legitimate transfers can clearly introduce some big issues.

If you try to report the theft of a large quantity of cash from your house the police are reasonably going to ask where it came from even though holding cash is perfectly legal . This is no different.

If someone had logs proving their computer was hacked. Or video footage of someone breaking into a safe: yes sure those are hacks. Those are theft. But we must distinguish this case from those if self-custody is to retain any meaning over the medium- to long-term. Otherwise it will either be a court-approved license to crime or always and everywhere suspect. Neither of those is compatible with self-custody being legitimate, accepted and legal.

Our core thesis here is really very simple: To live outside the law you must be honest . If you want to lean on self-custody in a way that consciously, knowingly, frustrates court orders and capital controls and the like then you need to take responsibility for verifying the code which manages your custody. Users relying on intentionally ungovernable systems should not be able to go to law enforcement and ask for help later. Because if they can the entire system will unravel in short order.

On a related note: if you trust your assets to an platform that lacks the required licenses, and your assets are lost in a spear phishing attack: yes we think that is a hack and yes law enforcement should be responsive. But we do not think those efforts deserve much priority in much the same way a drug dealer can absolutely report a crime if they are held up at gunpoint but we do not really expect them to report it or the police to spend a lot of time on the matter.

If you want to operate further from oversight you should expect to have fewer people to call when something goes wrong. Impacted users can (and almost surely will) sue the ColdCard team. Fair enough. They also are unlikely to get much money back. That, too, is both a bug and a feature of self-custody.


➢ Stay ahead of the curve. Join Blockhead on Telegram today for all the latest in crypto.
+ Follow Blockhead on Google News
Licensed to Shill: Ethereum’s Staking Yield Cut Won’t Fix What’s Actually BrokenThe panel, featuring Blockhead’s Tim Han, discusses why cutting ETH’s risk-free rate from roughly 3% to 1.2% cannot fix a token that still has nowhere useful to go.
Tuyên bố từ chối trách nhiệm: Bản quyền của bài viết này thuộc về tác giả gốc và không đại diện cho MyToken(www.mytokencap.com)Ý kiến ​​và vị trí; vui lòng liên hệ với chúng tôi nếu bạn có thắc mắc về nội dung
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
https://t.me/mytokenGroup
Đọc liên quan