Shifting Perspectives on Security in Cryptocurrency
Pascal Gauthier, the CEO of Ledger, emphasizes that the cryptocurrency sector must shift its perspective on security. He argues that it should not simply offload more responsibilities onto users under the illusion of achieving total safety—something he maintains is unattainable.
Inherent Protection in Hardware Wallets
Gauthier believes that manufacturers of hardware wallets need to create solutions that inherently protect users, even when mistakes occur. The urgency of this message comes in light of recent troubles faced by the hardware wallet community, notably the Coldcard incident that unfolded in late July.
On July 30, Coinkite alerted users that wallets generated by certain Coldcard devices might be at risk due to an issue with how seeds were generated. By July 31, losses had already exceeded a staggering 1,000 BTC, with Gauthier advising that the compromised seeds must be considered unsafe.
Further analysis from Galaxy Research, released on August 4, revealed that over 1,596 BTC had been stolen from approximately 7,300 addresses in connection with this issue.
Limitations of User Caution
Gauthier stresses that merely exercising caution is insufficient in scenarios like these, arguing that fundamental flaws in design cannot be rectified through user discipline alone. The situation was exacerbated shortly after the Coldcard issue when Trezor, another hardware wallet provider, faced scrutiny for a data breach involving its third-party fulfillment partner.
This incident, reported on August 13 by U.Today, affected customer information of approximately 13,689 individuals across seven different nations.
The Importance of Critical Evaluation
The Ledger chief warns that if typical users are expected to grasp every potential technical pitfall, the principle of self-custody will be significantly hampered. He underscores that trust in any hardware wallet should not be blind; users should critically evaluate claims of security from manufacturers—including Ledger itself.
Continuous Improvement in Security
Ultimately, Gauthier posits that the process of securing cryptocurrency assets should be regarded as continuous, necessitating consistent testing and refinement to enhance safety measures in this evolving landscape.