Loading market data...

Coldcard Hack Prompts Foundation CEO to Argue Reputation Isn't Security

Coldcard Hack Prompts Foundation CEO to Argue Reputation Isn't Security

Coldcard, a hardware wallet maker, has been hacked. The breach has drawn a pointed response from Zach Herbert, CEO of Foundation, a competing hardware wallet company, who wrote an article arguing that the community's reliance on reputation instead of verifiable security is a fundamental flaw.

A case against trusting brand names

Herbert's piece, published in the wake of the hack, contends that reputation is not a security model. He claims that for five years, the community outsourced its judgment to a single person, implying that Coldcard's trusted status was built on one individual rather than rigorous, independent verification.

Five years of outsourced judgment

The most striking claim in Herbert's article is that the community spent five years outsourcing judgment to one man. Without naming the individual, he argues that this concentration of trust created a single point of failure. The hack, in his view, exposes the risk of such an approach. He calls for a shift toward security models that do not depend on any one person's reputation or track record.

The broader debate

The incident has reignited a wider conversation about how hardware wallet companies earn and maintain user trust. While Coldcard has not yet commented on the hack, the response from a competitor highlights a growing tension in the industry between reputation-based confidence and verifiable security. Herbert's article is a direct challenge to the community's habit of elevating a single brand or figurehead above the need for ongoing, independent scrutiny.

The episode leaves an open question about whether users will start demanding more than a good name when it comes to securing their crypto. Herbert's argument makes the case for verifiable security, but it's unclear if the community will heed that call.