Price:

Coldcard flaw lets AI crack Bitcoin wallets

Aug 4, 2026Summary from 8 podcasts.
  • A firmware bug in Coldcard wallets since 2021 made seed generation predictable, exposing millions in BTC.
  • Attackers use GPUs and AI to brute-force keys; over 1,100 BTC already stolen.
  • The exploit ends trust in single-vendor hardware, forcing a shift to multisig and manual entropy.

A coding error in Coldcard firmware has shattered the foundation of Bitcoin self-custody. Since March 2021, devices have generated seeds with dangerously low entropy due to a fallback to predictable software randomness. The flaw turns what was marketed as a fortress into a target with a known combination.

The vulnerability is not theoretical. Over 1,100 BTC - worth roughly $70 million - has already been swept by attackers using GPU farms. These actors don’t need physical access. They scan the blockchain for vulnerable addresses and brute-force the private keys using precomputed lists derived from the weak entropy.

According to Rob Hamilton on What Bitcoin Did, the attack bypasses the air-gap entirely. If you clicked 'generate seed' on a Coldcard MK3, MK4, or Q without adding external entropy like dice rolls, your keys were created from a pool small enough to crack in minutes. Only users who rolled 99+ dice or used complex passphrases are likely safe.

The crisis hits the most technically diligent users. These aren’t exchange depositors - they’re Bitcoiners who followed best practices. Marty Bent on Rabbit Hole Recap called it a 'five-alarm fire.' The assumption that hardware wallets are secure by default has collapsed.

"If you didn’t manually add 100 dice rolls or a strong passphrase, your funds are effectively in an unlocked room."

- Matt Odell, Rabbit Hole Recap

That quote underscores the new reality: trust in the device itself is dead. Steve on Presidio Bitcoin Jam noted the bug wasn’t just in older models. Newer Mk4 and Q units bottleneck secure entropy into a 32-bit window - hashing down 32 bytes to four - making brute-forcing trivial. Even firmware updates can’t fix keys generated weak from birth.

AI has accelerated the exploit cycle. On What Bitcoin Did, Hamilton revealed he used China’s Kimi K3 - an uncensored LLM - to map the flaw instantly. Guarded models like GPT-4 refuse such queries, but open ones don’t. Attackers now audit code faster than human teams. As Steve pointed out, an engineer at Block reproduced the exploit in under two hours using a private LLM.

"Security through obscurity died with this exploit."

- Rob Hamilton, What Bitcoin Did

The fallout extends beyond theft. Keon on Stacker News Live explained that attackers can retroactively de-anonymize CoinJoin rounds. By identifying which participants used compromised Coldcards, they shrink the anonymity set, collapsing privacy for everyone in the mix. The exploit isn’t just stealing coins - it’s unraveling trust in privacy tools.

The path forward demands architectural change. Multisig with vendor diversity is now baseline. Casa, Unchained, and AnchorWatch offer 2-of-3 setups where keys span different manufacturers. Even then, RBF attacks threaten migrations. The SNL team recommends direct miner submission via Mara Slipstream to avoid mempool snipers.

The era of the magic bullet is over. Coldcard was the gold standard. Its failure proves no single device can be trusted. As Marty Bent said, the 'don’t trust, verify' ethos failed because verification relied on reputation, not independent math. Going forward, the only safe practice is manual entropy - dice, coins, or air-gapped randomness - never software.

Source Intelligence

- Deep dive into what was said in the episodes

SNL #235: The most important photo of my lifeAug 3

Also from this episode: (9)

Politics (1)

  • Keon met a hacker named Rob who claims responsibility for Russiagate and operates Ford Intelligence, a newsletter selling intelligence to CEOs, heads of state, and private security, pitching it as "Palantir for civilians."

Safety (3)

  • On July 29th, a critical vulnerability in Coldcard's firmware led to many users' Bitcoin being swept, stemming from a bug that prevented the hardware's random number generator (RNG) from being used for seed generation.
  • The Coldcard bug, present for five years, affected MK3, MK2 (with updated firmware), MK4, MK5, and Q models, enabling an attacker to steal nearly 1,000 coins, totaling $70 million, within 24 hours.
  • The attacker's actions were deemed "amateur" by experts, as they consolidated funds immediately, reused addresses, and paid high fees (80 sats per vbyte), making the attack easier to trace.

Protocol (2)

  • Bitcoin seeds typically require 128 or 256 bits of entropy; however, the vulnerable Coldcard MK3 only provided 32 bits, while MK4, MK5, and Q models had 70 bits, significantly lowering security.
  • Jason B, a jazz musician and aspiring Bitcoiner, draws parallels between Bitcoin and jazz, both lacking a central "ruler" or fixed canon, aligning with his preference for systems without needless control.

Coding (1)

  • The bug was a subtle misinterpretation of a C preprocessor macro, `ifndef`, meaning "is this symbol defined" instead of "is this symbol zero," leading to the use of low-entropy code.

Custody (2)

  • Keon anticipates hundreds of millions of dollars in further thefts, as the initial attack targeted low-hanging fruit (MK3) and subsequent attackers using AI tools like "Kimi" could exploit other vulnerable models or remaining UTXOs.
  • Coldcard users should immediately move funds to a new, securely generated seed, ideally using a hot wallet or an exchange for safety, or direct to miner transactions to avoid mempool snipers.

Not Cold Enough | Bitcoin NewsAug 3

Also from this episode: (9)

Other (9)

  • David Bennett states Coldcard models Mark III, Mark IV, Mark V, and Q with firmware 4.x+ were compromised by a predictable seed generation vulnerability, while firmware 3.x models appear unaffected. The flaw, active since 2021, stemmed from a software error that reduced entropy from 2^256 to approximately 2^32 bits, making wallet seeds easily guessable.
  • Bitcoin began moving from affected Coldcard addresses around July 30th, 2026, via coordinated, automated sweeps targeting large balances first (over 1.15 BTC), then smaller amounts in subsequent waves. Attackers could generate candidate seeds and compare them to the public blockchain without direct access to devices.
  • CoinKite initially dismissed public warnings, continued to sell affected products for 48 hours after the vulnerability was known, and later released a firmware update that reportedly bricked devices. David Bennett argues CoinKite's failure is inexcusable and recommends never using their products again, including OpenDimes and BlockClocks.
  • Volunteer teams, including BTC Sessions and Rob Hamilton, provided extensive support to affected users, with BTC Sessions reporting efforts protected "tens of millions of dollars." Foundation Devices also assisted Coldcard users, highlighting a community-driven "immune system" approach to crisis.
  • David Bennett advises immediately migrating funds from any CoinKite product; he suggests using centralized exchanges like Coinbase or Kraken as a temporary measure if other self-custody options are untrustworthy or unavailable. He emphasizes avoiding panic and performing test transactions.
  • David Bennett describes this incident as a "crossing the Rubicon" moment, where AI's ability to automate exploit discovery against vast code repositories means continuous, daily security audits are now essential. He suggests this creates a "security moat," raising costs for smaller projects.
  • David Bennett proposes "swarm audits" where community members pool resources (AI tokens, compute, human review) to continuously vet open-source codebases. He successfully used Grok to audit Bitbox 02 Nova's code, underscoring the potential for collective vigilance.
  • A "second layer" of sophisticated phishing attacks emerged, using truthful information about the Coldcard vulnerability, legitimate links, and urgent calls to action to trick users into revealing seed phrases or installing malicious software. David Bennett warns no legitimate manufacturer will ever ask for a seed phrase.
  • David Bennett places sole blame on CoinKite founder Rulo Novak for the "shitty code" and systemic failure, rejecting attempts to extend liability to influencers like Matt Odell or Marty Bent, who are investors in CoinKite through their firm 1031.

RABBIT HOLE RECAP #421: CATASTROPHIC COLDCARD BUGAug 3

CATASTROPHIC COLDCARD BUGAug 3

  • The bug, which existed for five years, appears to have been recently identified with assistance from AI, possibly through OpenAI's Cypher program utilized by Rob Hamilton's team for auditing Bitcoin projects.
Also from this episode: (12)

Custody (6)

  • A critical vulnerability in Coldcard hardware wallets (versions 4.0.1 and later, or any model after 4.0.0) compromises private keys due to a faulty random number generator.
  • The catastrophic Coldcard bug, introduced in March 2021, compromises seeds generated on any device after that date unless sufficient dice roll entropy (over 100 rolls) or a passphrase was used.
  • Hosts advise all Coldcard users to immediately move their funds off the devices and to cease using the product entirely, regardless of previous protective measures like passphrases or multisig.
  • The hosts had previously conducted Coldcard workshops since December 2019 at Chaincode Labs with figures like Evan Kaludis and James O'Byrne, demonstrating features like dice rolls and passphrases.
  • Hosts concede to complacency, having placed too much trust in CoinKite's NVK and Peter; they now believe the concept of a "magic bullet" beginner-friendly solution for high-value self-custody is dead.
  • The hosts will now refrain from directly recommending specific custody solutions, instead laying out options and emphasizing multi-vendor multisig and robust passphrases as critical for long-term secure Bitcoin storage.

Media (2)

  • The hosts express deep regret and take accountability for recommending Coldcard for seven years, admitting their past confidence was misplaced despite consistently advocating "don't trust, verify."
  • The Coldcard vulnerability was publicly disclosed on August 3, 2023, at Bitcoin block height 960885, prompting hosts to release this podcast immediately to maximize user notification efforts.

Safety (4)

  • The Bitcoin community has rallied to assist affected users, with Rob Hamilton (@Roboneham on X) publishing an extensive guide detailing Coldcard vulnerabilities, migration options, and recovery steps.
  • Attackers are actively brute-forcing compromised Coldcard seeds using GPUs, while authorities are investigating an attacker who reportedly pinged a centralized API provider to look up vulnerable addresses.
  • The hosts clarify the vulnerability is entirely CoinKite's responsibility, stating their firm 1031 is a minority investor (under 10%) with NVK and Peter maintaining majority ownership and control.
  • Users are strongly advised not to update Coldcard firmware, as new releases may brick devices; instead, the immediate priority should be transferring all funds off the compromised hardware.
What Bitcoin Did
What Bitcoin Did

Danny Knowles

EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob HamiltonJul 31

Also from this episode: (14)

Custody (8)

  • Rob Hamilton issued an urgent warning for Coldcard MK3, MK4, MK5, and Q users who generated wallets directly from the device without providing their own entropy or a strong passphrase, urging immediate fund recovery.
  • For impacted Coldcard users, a sufficiently strong 25th-word passphrase or providing external entropy (e.g., dice rolling) is the only protection against attackers scanning all possible Coldcard seed phrases.
  • Danny Knowles confirms that Trezor and Foundation devices are safe because they do not use the same compromised library as Coldcard, indicating a specific, not widespread, self-custody vulnerability.
  • Rob Hamilton recommends moving funds to trusted exchanges like River, citing its in-house custody and proof of reserves, or immediately acquiring other hardware wallets like Ledger or BitKey as emergency measures.
  • Multi-signature wallets are at risk if a majority of their signers (e.g., two of three) are compromised Coldcard devices without strong passphrases or rolled dice; Unchained, Casa, and AnchorWatch state they are not affected.
  • For at-risk multi-sig wallets with un-reused addresses, Rob Hamilton suggests using Mara Slipstream to broadcast transactions directly to a mining pool, which helps prevent replace-by-fee attacks by faster confirmation.
  • The Coldcard incident is a 'nuclear event' for Bitcoin self-custody, fundamentally undermining the trust in hardware wallets to generate sufficiently random numbers, a core tenet of Bitcoin security.
  • Future improvements for self-custody could include Bitcoin covenants and vault-like structures, enabling on-chain controls like address whitelisting or spending limits for enhanced security.

Safety (3)

  • The critical bug, introduced in early 2021 via a firmware change, compromised the entropy generation process, making seed words created by affected Coldcard devices insecure.
  • Rob Hamilton clarifies that Coldcard MK1 and MK2 models are not impacted by this specific firmware bug, as they are older hardware and do not receive new firmware updates.
  • Rob Hamilton explains that the MK3 has only 2^32 bits of entropy, which is easily brute-forced by consumer hardware, while MK4, MK5, and Q models have 45-50 bits, still vulnerable to GPU data farms.

Coding (1)

  • The vulnerability stems from a single line of code that incorrectly skipped secure entropy generation if a function merely existed, rather than evaluating if it was true, a 'nuclear event' for hardware wallet security.

BTC Markets (1)

  • Initially, the attack was carried out by an amateur, evident from only targeting addresses with more than 0.15 BTC and failing to scan full addresses; now, multiple sophisticated attackers are involved.

Protocol (1)

  • Rob Hamilton estimates over 1100 BTC has been stolen already, with projections of thousands more, as well-capitalized attackers using GPU computing join the effort to exploit the vulnerability.

The COLDCARD Hack and Future of Self-CustodyJul 31

  • Bitcoin itself is not compromised; this is a vendor-specific issue with CoinKite's Coldcard products, underscoring Max's argument that AI poses a more immediate and significant threat to security than quantum computing.
Also from this episode: (13)

Custody (8)

  • Steve estimates the Coldcard security incident has resulted in over 1,000 BTC stolen, valued between $65 million and potentially $100 million, describing it as the "worst day in Bitcoin's history" due to the impact on self-custody.
  • The bug allows attackers to regenerate private keys from on-chain transactions due to weak entropy, without physical device access or seed phrases, by brute-forcing inputs like the CPU timer cycle and unique device ID.
  • Steve advises Coldcard users in vulnerable situations to move funds immediately to temporary locations like trusted custodians or wiped, old devices; CoinKite has released new firmware for most products, but not MK3.
  • Customers who properly used Coldcard's dice roll feature (e.g., 99-100 rolls) or a strong BIP39 passphrase (128-bit or more) should be safe, but Steve suggests moving funds for peace of mind.
  • Steve emphasizes custody diversification as crucial, recommending users split funds between solutions with non-intersecting risks, such as a third-party custodian and a self-custody solution, rather than relying solely on one method.
  • White hat hacking to sweep vulnerable funds to a secure system, to be returned to rightful owners, is proposed as a method to mitigate further theft, though the legality and feasibility remain uncertain.
  • Multi-signature setups remain a strong self-custody option, but require diversity across keys from different hardware/software vendors to avoid single points of failure, unlike using multiple devices from the same vendor.
  • BitKey is a multi-signature product by default, using three keys generated across different hardware and software stacks (Block server, phone, hardware device) to provide diversity, but it lacks independent verifiability for some key generation processes.

Chips (2)

  • The Coldcard vulnerability affects MK2 and MK3 hardware with firmware from 2021 to the present, stemming from a compile-time bug that caused the hardware random number generator to fall back to a weak software pseudo-random generator.
  • Newer Coldcard models (MK4, MK5, Q) have 32 to 72 bits of cryptographic entropy, which is stronger but still potentially vulnerable to a financially substantial brute-force attack; reports indicate these models have also been exploited.

Models (1)

  • Max proposes that for critical software, users need transparency on which top-tier AI models are conducting 24/7 security audits, stating that "all bugs are shallow with enough tokens."

Open Source (1)

  • Project Loupe, launched by Spiral, performs AI security scans on open-source Bitcoin repositories, but models produce noise and misclassify severity, necessitating human review and active remediation by project maintainers.

Protocol (1)

  • Steve suggests that recovering stolen Bitcoin would require proving original ownership through a combination of unique device IDs, DKIM-signed email receipts from CoinKite (verified for 2023), and KYC/on-chain analysis from exchanges.

777: Coldcard Is Compromised with James O'BeirneJul 31

Also from this episode: (19)

Protocol (2)

  • Marty Bent argues Bitcoin will emerge as the victor over fiat currencies in a world where central banks actively devalue their money.
  • Guest suggests that while auditing RNGs is crucial, the ultimate fix for improved user experience and multisig-level security lies in on-chain covenant technology.

Safety (4)

  • A critical vulnerability affects Coldcard hardware wallets, manufactured by CoinKite, produced after 2021, specifically MK2 and MK3 models with firmware between 2021 and 2023.
  • The vulnerability stems from an insufficient random number generator (RNG) used for private keys, making them deterministic and severely limiting the search space for recovery.
  • Users are secure if they initiated their Coldcard key with over 99 dice rolls or used a sufficiently complex passphrase, which is often longer than users anticipate.
  • Current Coldcard devices, including the Q model, are estimated to provide only 70 bits of security during key generation, far below the intended 256 bits.

Custody (7)

  • Guest highlights that updating firmware alone does not fix the vulnerability; users must generate a new private key pair and migrate funds to the new address.
  • Marty Bent clarifies that MK2 and MK3 models generated after 2021 with default settings might offer as little as 30 bits of entropy, requiring urgent fund migration.
  • Guest expresses concern that the Coldcard incident could damage trust in self-custody among Bitcoiners and the broader public, despite best practices like multi-vendor setups.
  • Past incidents include Ledger spilling client data multiple times and BitBox having physical defects allowing key exfiltration, underscoring the inherent difficulty of hardware wallet security.
  • Multi-signature setups are safe from the Coldcard vulnerability if at least one critical signing key is generated by a non-CoinKite device unaffected by the bug.
  • As a temporary measure, individuals with affected Coldcards are advised to move their funds to a trusted exchange, performing small test transactions first to avoid errors.
  • A passphrase composed of six BIP39 words is generally not considered strong enough, as the search space for 2048 words multiplied by six is still too small for robust security.

Models (4)

  • Marty Bent notes that AI models are becoming sophisticated enough to uncover such security vulnerabilities, with Kimmy K3 reportedly used to discover this Coldcard flaw.
  • The hosts caution that the rise of AI is accelerating the erosion of 'security by obscurity,' making all open-source code and historical versions vulnerable to automated analysis.
  • Marty Bent asserts that US government intervention in 'model wars' by 'cucking' frontier AI models like Fable 5 and ChatGPT 5.6 hinders crucial security auditing for Bitcoin systems.
  • Guest observed that US-based AI models censored or blocked inquiries related to the Coldcard vulnerability, making security investigations more difficult compared to less restricted models.

Philosophy (2)

  • Guest quotes Nick Szabo's principle that 'trusted third parties are security holes,' reinforcing the lesson that delegating security fully to a packaged product is risky.
  • The hosts debated the ethical implications of 'white hats' using computing resources to sweep vulnerable funds from exposed Coldcards, citing challenges in attributing and returning funds.

#776: Yields Must Rise, Fed Must Hike with Michael HowellJul 30

  • The US economy's nominal growth, estimated between 6% and 7% (and possibly higher due to AI spending), suggests current 10-year yields are unsustainably low. Howell notes a historical gap of over 200 basis points between nominal GDP and the 10-year bond.
  • Michael Howell reports that the three-month annualized M2 money supply growth was recently near 10%, indicating future inflation issues. This expansion is attributed to robust nominal GDP growth, AI capital expenditure, and large fiscal deficits.
  • An AI system analysis by Michael Howell indicates that the two-year Treasury yield's signals for Fed policy are correct 85-90% of the time. The current spread suggests accelerating monetary tightening, tracking the 2021-2022 period.
Also from this episode: (8)

Markets (1)

  • Michael Howell observes deliberate manipulation of bond market volatility, which he terms "yield volatility control." This policy uses short-term issuance and Treasury buybacks to suppress yields, potentially by 50 basis points on the 10-year note.

Macro (4)

  • Michael Howell notes the global liquidity cycle's growth rate slowed around Q3 last year, diverting money from financial markets into the real economy. This typically leads to flattening yield curves, a normal cycle in robust economic conditions.
  • Michael Howell argues the world is in a "capital wars" regime, where governments actively boost national competitiveness, driving higher nominal GDP growth by 200 basis points. This shift diverts liquidity from financial assets to the real economy.
  • Michael Howell states that the US government's current debt funding model involves 80% of gross issuance under two years duration, a practice he compares to Latin American economies. Other nations are adopting similar short-term funding strategies.
  • Michael Howell indicates that an R-squared value above 32% links crypto basket variation to global liquidity changes, a powerful correlation in financial markets. Global liquidity accounts for about 45% of crypto's total price variation.

Fed (1)

  • Michael Howell explains that during the 2021-2022 monetary tightening, the S&P 500 fell 25% and crypto assets fell 75%. He suggests risk assets like stocks have yet to discount the current projected tightening.

Inflation (1)

  • Michael Howell asserts that governments will resort to printing money due to an inability to cut spending, reform welfare, or increase taxes without an exodus of talent (e.g., UK lost 600,000 millionaires since 2021).

BTC Markets (1)

  • Michael Howell's analysis shows cryptocurrencies (Bitcoin, Ethereum, Solana basket) have an 8x sensitivity to global liquidity, significantly higher than gold/silver's 2x sensitivity. A small crypto allocation, perhaps 5% of a portfolio, offers strong monetary inflation protection.
Square Engineering

Square Engineering

Predictable RNG Fallback and 32-Bit Reseed in COLDCARD FirmwareJul 30

Also from this episode: (11)

Custody (4)

  • Block's security research identified vulnerabilities in COLDCARD firmware that could enable Bitcoin theft, stemming from an RNG integration error causing `ngu.random` to default to MicroPython's deterministic Yasmarang fallback.
  • COLDCARD Mk2/Mk3 v4.0.0-v4.1.9 firmware versions have no cryptographic entropy added to `ngu.random`, making wallet generation deterministic if the device UID, timer state, and RNG-call history are known.
  • For Mk2/Mk3 v4, the maximum enumeration count under normal cold-boot with known UID but unknown SysTick is approximately 2^16.29, making the seed highly vulnerable.
  • Current devices like Mk4/Q/Mk5, even with a successful reseed, have a secure-element-derived search space limited to at most 2^32 possibilities when the fallback state and call history are known.

Coding (2)

  • The vulnerability arises because the production board configuration defines `MICROPY_HW_ENABLE_RNG` as zero, and `libngu` incorrectly checks if the macro is defined rather than enabled, binding to a deterministic software generator.
  • The regression originated from a firmware change on March 1, 2021, which migrated wallet generation to `libngu`, and appeared in released firmware v4.0.0 on March 17, 2021.

Chips (2)

  • COLDCARD Mk4/Q/Mk5 devices, using production firmware v5.0.0 onward, incorporate a limited secure-element reseed that hashes 32 bytes to retain only four, replacing just one 32-bit Yasmarang state word.
  • The Yasmarang software fallback initializes using the MCU's low 32-bit UID, SysTick counter, and RTC registers, none of which are cryptographic entropy sources, allowing for state reproduction.

Privacy (2)

  • An attacker with knowledge or sufficient constraints on device UID, timer state, and RNG-call history can reproduce the fallback stream offline, potentially recovering wallet seeds and private keys.
  • The vulnerability affects other functionalities relying on `ngu.random`, including paper-wallet private keys, seed XOR masks, cloning/USB encryption keys, Key Teleport, Web2FA, and Secure Notes passwords.

Safety (1)

  • Block and security researchers identified the root cause on July 30, 2026, after user reports of lost funds, leading to the early publication of this advisory due to ongoing active exploitation.