Coldcard Case: Why the Burden of Proof Should Not Rest Solely on the Victims

Ferrer-Bonsoms & Sanjurjo, Lawyers — FinTech, Blockchain and Crypto-Asset Law

Since the firmware flaw that has already cost Coldcard users more than 1,300 BTC came to light, much of the legal debate has focused on one obstacle: proving that Coinkite could have foreseen the defect. Some voices within the industry have been pessimistic, arguing that this type of claim will be “terribly difficult” to pursue for precisely that reason. That is an incomplete diagnosis: it assumes that the entire burden of proving foreseeability falls solely on the victim. That is not the case, and it is worth explaining why.

The Victim Has No Access to the Evidence They Would Need

To prove that Coinkite “should have known”, one would theoretically need access to the firmware source code, the version history, the internal testing and audit records, and the documentation showing when and how the flaw in the random number generator was introduced. No affected user has access to any of that. Quite simply, it is information that only Coinkite possesses.

Requiring the victim to prove something to which only the opposing party has access is what Spanish procedural doctrine refers to as a probatio diabolica (an impossible burden of proof): a burden that is practically impossible to fulfil, not because the fact does not exist, but because only one of the parties is capable of proving it.

Ease of Access to Evidence: An Established Principle, Not a Novel Theory

Article 217.7 of the Spanish Civil Procedure Act establishes a principle that Spanish courts have been applying for more than two decades: where one of the parties to the proceedings has significantly greater ease or availability to produce evidence than the other, the court must take this into account when assessing the consequences of that evidence not being produced. The Spanish Supreme Court has repeatedly applied this principle in cases involving medical negligence, financial disputes and consumer protection, precisely in situations where the defendant — the hospital, the bank or the manufacturer — controls the relevant technical documentation.

This is neither an unusual argument nor a recent innovation: it is well-established case law, and it fits the Coldcard case with remarkable precision. Coinkite is the party that knows which random number generator was used, since when, and what quality-control procedures — if any — that code underwent before being released to the market. Those affected have no way of accessing that information unless a court orders Coinkite to produce it.

It is important to be precise about the scope of this principle: it does not automatically reverse the burden of proof, but rather provides a criterion that the court must assess on a case-by-case basis. However, it substantially changes the starting point of the debate. The question is not simply, “Can the victim prove foreseeability?”, but rather, “Why has Coinkite not produced the documentation that would prove otherwise, if it possesses it?”

An Additional, More Limited Route for Recent Purchases

Those who purchased their Coldcard within the last twelve months also benefit from a more direct legal mechanism. Article 11(1) of Directive (EU) 2019/771, as implemented in Spanish consumer legislation, presumes that any lack of conformity discovered within the first year after delivery already existed at the time of purchase, placing the burden on the seller to prove otherwise.

This is a narrower route — it does not apply to users who purchased their device earlier, nor does it replace tort-based claims seeking compensation for the full value of the lost funds — but it reinforces the same underlying principle: the party that possesses the relevant information cannot rely on the silence of the party that does not.

What This Means for Those Affected

None of this guarantees the outcome of a legal claim — no responsible lawyer should promise that. However, it does undermine the idea that these cases are doomed from the outset because of evidential difficulties. There is an established legal framework, not an improvised one, that allows the courts to require Coinkite to produce the documentation that only it possesses, and to draw the appropriate conclusions if it fails to do so.

If you lost funds as a result of the Coldcard incident and would like to assess your legal position, Ferrer-Bonsoms & Sanjurjo can help you understand the options available to you.

Contact us for an assessment of your case →

Scroll to Top