‹ BackNewsColdCard

ColdCard

Bitcoin
2026-08-20 20:49:28

Coldcard breach reignites debate over open source, source-available software in Bitcoin

A new analysis from Bitcoin Magazine argues that the Coldcard hardware wallet incident exposed a core misconception in Bitcoin software: publicly readable code is not the same thing as open-source software. The article says users lost more than $100 million in bitcoin, over 1,500 BTC, after a critical entropy flaw in Coldcard firmware went unnoticed for roughly five years. That flaw, it argues, showed how software safety depends less on source visibility alone and more on who has the legal and economic incentive to review code closely. The piece draws a sharp distinction between Free and Open Source Software standards and “source-available” licensing. It notes that Coldcard firmware was released under MIT terms plus the Commons Clause, which removes the right to sell the software commercially. Because of that restriction, the article says the software does not meet the Open Source Initiative standard. It contrasts that model with Bitcoin Core, whose MIT-licensed code, public review process, contributor structure, nonprofit funding base, and long-running public discussions are presented as a large-scale example of open-source development working as intended. The article also says AI is changing the security equation on both sides. It cites the volunteer Bitcoin Red Team, backed by OpenSats, which used frontier AI models to scan hundreds of Bitcoin repositories and reported thousands of findings, including dozens rated critical or high severity. At the same time, it argues that AI-generated code is adding strain to maintainers and weakening the old security advantage once associated with closed-source software.

1160
Coldcard breach reignites debate over open source, source-available software in Bitcoin
Coldcard releases new firmware to tighten security and asks affected users to regenerate seed phrases and move funds
Coldcard rolls out new firmware after mnemonic generation security review
Specter flags Coldcard claim as 73 BTC moved through mixers and into phishing Tornado Cash interface
Specter says claimed Coldcard hack victim story conflicts with on-chain data
BitBox tells users to update after finding severe firmware vulnerabilities
Metaplanet
2026-08-19 13:54:06

Metaplanet Plans 2,100 BTC Injection Into Super League as SEC Unveils Proposed Crypto Asset Offering Framework

WuBlockchain’s daily roundup highlighted a set of major crypto developments spanning corporate treasury expansion, U.S. securities regulation, bitcoin market research, wallet security, and institutional positioning. At the center of the update, Japan-listed bitcoin treasury firm Metaplanet said it reached a definitive agreement with Nasdaq-listed Super League Enterprise to inject 2,100 BTC, valued at about $132.1 million, plus $2.5 million in cash through its U.S. subsidiary. In return, Metaplanet would receive common stock, preferred stock, and warrants, bringing the initial investment to about $134.6 million. After closing, Super League is expected to rename itself Superplanet, Inc., change its ticker to SUPA, and serve as Metaplanet’s U.S. bitcoin treasury platform, with Metaplanet holding about 95.7% of its common shares. The roundup also noted that the U.S. Securities and Exchange Commission has proposed “Regulation Crypto Assets,” a new offering framework for certain crypto-related investment contracts that includes two Securities Act registration exemptions and a conditional safe harbor. Separately, BlackRock and VanEck published fresh assessments of bitcoin’s drawdown and accumulation signals, investigators said the FBI may have identified a suspect in the Coldcard wallet exploit, and CryptoSlate reported that institutional bitcoin ETF holdings rose in the second quarter despite a decline in BTC’s price.

1270
Metaplanet Plans 2,100 BTC Injection Into Super League as SEC Unveils Proposed Crypto Asset Offering Framework