The Coldcard incident
The Coldcard incident got me thinking about something people rarely discuss when talking about Bitcoin security: hardware wallets are not automatically “safe” just because they are hardware. The recent incident is a good reminder that firmware, transaction signing, supply chain security and user behaviour all matter. How much attention do you actually pay to those layers?
I’ve always thought the biggest weakness is the gap between what the device protects and what the user assumes it protects. A hardware wallet can isolate keys, but it can’t stop someone from approving the wrong transaction or ignoring a suspicious signing request.