By the way, the souce code is fully reviewable here:

https://github.com/coldcard/firmware

Software license details here:

https://github.com/coldcard/firmware?tab=License-2-ov-file

Reply to this note

Please Login to reply.

Discussion

AFAIK, it doesn't have the verifiable builds. Am I wrong?

What's the difference between verifiable builds and reproducible builds? Instructions on how to build from source and get exactly the same bytes is included in the ReadMe.

Same, maybe I used the wrong words.

So you're saying we can build from source and use that as firmware on the cold card? If so, cool, thanks for informing me, I haven't had the time and motivation to verify yet.