On product design redlines

I wrote recently about getting Bitcoin (and Bitcoin products) into the hands of as many people as possible. I was talking through a product lens – the slow orange pill still has its place! – as there is too much at stake with tradfi players increasingly gaining market share with Bitcoin being offered alongside ‘comparable’ yet centralized alternatives.

How then should we build products that gain traction and appeal to local users, whilst staying true to first principles as Bitcoin companies?

Everyone claims purity, everyone ships compromises. And the dangerous ones are the ones we cannot see.

Take the recent Coldcard debacle as an example. 

Whilst other hardware wallet makers made visible trade-off decisions between security, privacy and usability, many Bitcoiners evangelized Coinkite (the maker of Coldcard) as a pure Bitcoin hardware wallet.

Yet, ultimately a Coinkite flaw led to the largest hardware wallet exploit in history1. Coldcard ultimately became untrustworthy in a space where nobody was paying attention; the seeds were weak from the moment of creation while everyone admired the story.

So, if trust is going to enter the equation anyway, what rules can we bend and where should we not compromise in building a ‘pure’ Bitcoin product? It’s easy to find examples where this went wrong and user trust – tenuous at the best of times – dissolved overnight, but companies that are doing it right double down on their verifiable decision-making.

One such company, Strike, has evolved from a revolutionary payment app to a serious multi-faceted Bitcoin-only company. They want users to buy, hold, spend and borrow against their stack so their redline is no rehypothecation.

When ambiguous language in their T&Cs surfaced on X, Strike’s CEO, Jack Mallers, responded within hours that the team was on it, and within days, the fuzzy language was gone2. Ownership for the mistake. Fixed immediately.

Strike has subsequently continued to pioneer institutional transparency with segregated collateral addresses that large clients can verify on-chain, a first lending proof-of-reserves and quarterly external attestations3.

Lightspark has also expanded at a rapid pace. Lightning by name and lightning by nature! In order to elevate itself above the known challenges of scaling Lightning, it compromised by establishing its own statechain-inspired Bitcoin L2 protocol, Spark. Users take some counterparty risk on a small operator set, but gain access to a simplified UX that most tradfi operators and neobanks are willing to adopt.

The key ingredient here is the non-negotiable feature that Lightspark engineered into the protocol from the outset: the user always holds a key and can exit without interacting with other parties4. Unilateral exit. No strings attached.

Lightspark has partnered with major players including Coinbase, Nubank and SoFi since inception.

Both companies are scaling globally and being crystal clear about their values, and their compromises are named and verifiable, giving users, partners and investors confidence they do what they say.

That’s the test I keep coming back to: a compromise is survivable when it’s named – so the community knows what to verify – and you as a user can walk away from it. Coldcard failed both. The flaw sat in open-source code for five years, verifiable the whole time yet verified by no one. Open source is permission to verify, not proof that anyone has.

I feel for Coinkite. I wanted their product to work so bad. But their error highlights that compromising on the value that underpins their entire selling point will eventually ruin you.

  1. A firmware flaw from a March 2021 commit routed seed generation through a weak software RNG instead of the hardware entropy source, and attackers drained roughly 1,816 BTC (~$116M+) from over 5,200 addresses. ↩︎
  2. Jack Mallers on X: x.com/jackmallers/status/1922036776631177244 ↩︎
  3. Strike’s proof-of-reserve FAQ: strike.me/en/faq/where-is-my-bitcoin-collateral-held/ ↩︎
  4. Spark’s unilateral exit announcement: lightspark.com/news/spark/unilateral-exit ↩︎

Leave a comment