Price:

Coldcard flaw exposes $130M and kills single-key cold storage

Aug 6, 2026Summary from 10 podcasts.
  • Flawed Coldcard firmware generated weak keys, letting hackers brute-force $130M in Bitcoin.
  • Attackers used open-source AI models to scan raw code and find predictable software fallbacks.
  • The crisis forces a permanent industry shift from single-hardware wallets to multi-vendor setups.

The gold standard of Bitcoin self-custody broke overnight. A latent firmware bug in Coldcard hardware wallets rendered generated seed phrases mathematically predictable, allowing hackers to brute-force private keys and sweep more than $130 million from disciplined long-term holders.

Engineers at Block traced the vulnerability to a C-macro check in firmware introduced in March 2021. Instead of validating hardware randomness, the software silently defaulted to a predictable software fallback called Yasmarang. For affected Mk2 and Mk3 units, key creation collapsed to a maximum of 32 bits of entropy.

On What Bitcoin Did, Rob Hamilton explained that attackers didn't need physical access or malware. They simply ran GPU farms to calculate the limited range of possible keys offline. Hamilton warned that the flaw turned once-secure vaults into pre-computed targets.

"Security through obscurity died with this exploit."

- Rob Hamilton, What Bitcoin Did

The exploit highlighted an asymmetric shift in cyber warfare. While US-based models blocked security queries behind corporate guardrails, researchers and attackers used unrestricted open-source LLMs like Kimi K3 to map out the firmware defect in minutes. Offense now moves at machine speed while defense remains bottlenecked by human review.

The architectural choice behind the failure sparked immediate backlash across the developer community. On Ungovernable Misfits, Zach from Foundation pointed out that CoinKite stripped GPL-licensed code during a software rewrite to restrict competitors, replacing audited Trezor libraries with custom, unreviewed software. Disagreements over intellectual property created blind spots that persisted for years without independent peer review.

As victims scrambled to move funds, a second wave of attacks emerged in the public mempool. On Stacker News Live, technical analysts detailed how automated snipers monitored broadcast transactions, cracked the weak private keys in real time, and used Replace-By-Fee bidding wars to redirect transfers. Users were forced to bypass public nodes entirely, routing transactions directly to miners through services like Mara Slipstream.

The damage extends beyond direct theft to historical transaction privacy. Because attackers now hold master lists of vulnerable seeds, they can identify affected participants in prior CoinJoin mixing pools. Unmasking single input addresses collapses the anonymity set for all participants, retroactively de-anonymizing years of historical ledger history.

On The Jack Mallers Show, Strike CEO Jack Mallers emphasized that while the vendor failed, the underlying Bitcoin protocol cryptography remains unbreached. Mallers noted that security engineering demands failing closed rather than silently issuing compromised keys.

"A 40-bit search space requires only a trillion guesses."

- Jack Mallers, The Jack Mallers Show

Cryptographic signatures verified by security researcher James O'Beirne linked the original flawed commit to CoinKite CTO Peter Gray. On TFTC, Galaxy Research head Alex Thorn tracked automated sweeps across hundreds of script addresses, noting that passive stackers who never leaked seeds lost their life savings solely through vendor error.

The incident marks a permanent shift in self-custody architecture. Relying on a single hardware manufacturer for high-value cold storage is no longer viable. The consensus has abruptly pivoted toward multi-vendor multisig quorums, user-generated entropy like physical dice rolls, and protocol-level covenants to survive zero-day hardware failures.

Source Intelligence

- Deep dive into what was said in the episodes

Dead Canary | Bitcoin NewsAug 5

  • An anonymous whale moved 500 BTC worth $31.8 million after 12 years of inactivity, paying just 12 cents in fees. While some linked this to the Cold Card security panic, David Bennett notes the wallet predates the vulnerable firmware.
  • CoinKite's Cold Card exploit has drained an estimated $130 million in Bitcoin due to a firmware bug active since March 2021. The flaw used software fallback instead of the hardware random number generator, making wallet recovery seeds guessable.
  • David Bennett warns that panicking users are making critical errors during migration, including commingling KYC and non-KYC coins. One user lost 6 BTC after falling for a fraudulent Sparrow mobile wallet app on the Apple App Store.
  • Ledger CTO Charles Guillemet argues the exploit proves open-source code is not inherently secure, as an attacker reportedly used AI to locate the long-standing bug. Guillemet advocates for hardware-level, independently certified randomness rather than software fallbacks.
  • Juan Galt reports that over 11,000 BTC fled to custodial exchanges following the Cold Card hack. Despite this setback, Galt argues self-custody remains vital to prevent the centralized state confiscation historically seen with physical gold.
  • Boltz Exchange briefly let its warrant canary expire, only to update it four days late. David Bennett warns that a resurrected warrant canary is compromised and urges users to treat Boltz as permanently unsafe.
Also from this episode: (5)

Models (1)

  • In May, a security researcher used Claude Opus 4.8 to uncover a four-year-old Zcash vulnerability that allowed unlimited minting, causing the token's price to drop 40% in a single day.

History (1)

  • Under Executive Order 6102 in 1933, the US government confiscated $300 million in gold from citizens and banks. The state then devalued the dollar by 69% in 1934 by repricing gold to $35 per ounce.

Media (1)

  • CNBC host Jim Kramer announced he is selling his Bitcoin and Ethereum over future quantum computing risks. Investors on social media celebrated the move, citing the historically profitable strategy of trading inversely to Kramer.

Europe (1)

  • BlackRock is partnering with J.P. Morgan to bring tokenized European money market funds across sterling, euro, and dollar share classes. These tokenized shares will draw from BlackRock's Institutional Cash Series.

Regulation (1)

  • Bitwise CIO Matt Hougan claims that the Clarity Act's failure to advance past the Senate deadline will not stop crypto's progress. David Bennett suspects Hougan is trying to soften the blow of an expected negative price reaction.

ColdCard Was An Inside Job | Bitcoin NewsAug 4

  • Felix Ng reports that non-custodial swap service Boltz paused operations due to escalating, AI-assisted infrastructure probing. The service, which had a total value locked of $180,000, joined Zeus Lightning in suspending services due to rapid, machine-speed exploits.
  • Lola Leads reports over 1,000 Bitcoin worth more than $100,000,000 was drained from Coldcard devices. In 2021, developers disabled the hardware random number generator, forcing a fallback to a software library with insufficient entropy to secure wallet seeds.
  • Lola Leads details how Coldcard developer Dusty Damon discovered a silenced compiler error where the random number generator was set to zero. Security researcher Taylor Moynihan condemned CoinKite for committing code directly to the main branch without peer review.
  • James O'Byrne cryptographically proved that GitHub commits from alias switch were signed with the GPG key of CoinKite CTO Peter Gray. David Bennett asserts a 2021 CoinKite tweet joking about retirement attacks via entropy bugs points to an inside job.
  • Stephen Graves reports a surge in phishing campaigns targeting Coldcard users, with fake hardware audit sites dropping remote-access malware. Galaxy Research estimates total potential losses from the original exploit and subsequent thefts could reach $130,000,000.
Also from this episode: (3)

BTC Markets (1)

  • Matthew DeSalvo reports MicroStrategy sold $104,700,000 in Bitcoin between July 27 and August 2. David Bennett criticizes the company for failing to develop commercial products, instead liquidating assets to fund stock dividends and share buybacks.

Mining (1)

  • Robert Locken reports Texas Governor Greg Abbott ordered an audit of all AI data centers trying to connect to the state's power grid. Bernstein analysts argue this moratorium makes approved, grid-connected Bitcoin mining sites far more valuable.

Regulation (1)

  • Jesse Hamilton reports the Digital Asset Market Clarity Act faces gridlock in the Senate over ethics rules. Concurrently, a dark money group called Crypto Watchdog, led by Chapin Fay, is running television ads linking cryptocurrency to terrorism and cartels.

Not Cold Enough | Bitcoin NewsAug 3

  • David Bennett states Coldcard models Mark III, Mark IV, Mark V, and Q with firmware 4.x+ were compromised by a predictable seed generation vulnerability, while firmware 3.x models appear unaffected. The flaw, active since 2021, stemmed from a software error that reduced entropy from 2^256 to approximately 2^32 bits, making wallet seeds easily guessable.
  • Bitcoin began moving from affected Coldcard addresses around July 30th, 2026, via coordinated, automated sweeps targeting large balances first (over 1.15 BTC), then smaller amounts in subsequent waves. Attackers could generate candidate seeds and compare them to the public blockchain without direct access to devices.
  • CoinKite initially dismissed public warnings, continued to sell affected products for 48 hours after the vulnerability was known, and later released a firmware update that reportedly bricked devices. David Bennett argues CoinKite's failure is inexcusable and recommends never using their products again, including OpenDimes and BlockClocks.
  • Volunteer teams, including BTC Sessions and Rob Hamilton, provided extensive support to affected users, with BTC Sessions reporting efforts protected "tens of millions of dollars." Foundation Devices also assisted Coldcard users, highlighting a community-driven "immune system" approach to crisis.
  • David Bennett advises immediately migrating funds from any CoinKite product; he suggests using centralized exchanges like Coinbase or Kraken as a temporary measure if other self-custody options are untrustworthy or unavailable. He emphasizes avoiding panic and performing test transactions.
  • David Bennett describes this incident as a "crossing the Rubicon" moment, where AI's ability to automate exploit discovery against vast code repositories means continuous, daily security audits are now essential. He suggests this creates a "security moat," raising costs for smaller projects.
  • David Bennett proposes "swarm audits" where community members pool resources (AI tokens, compute, human review) to continuously vet open-source codebases. He successfully used Grok to audit Bitbox 02 Nova's code, underscoring the potential for collective vigilance.
  • A "second layer" of sophisticated phishing attacks emerged, using truthful information about the Coldcard vulnerability, legitimate links, and urgent calls to action to trick users into revealing seed phrases or installing malicious software. David Bennett warns no legitimate manufacturer will ever ask for a seed phrase.
  • David Bennett places sole blame on CoinKite founder Rulo Novak for the "shitty code" and systemic failure, rejecting attempts to extend liability to influencers like Matt Odell or Marty Bent, who are investors in CoinKite through their firm 1031.

#780: Dissecting The Coinkite Hack with Alex ThornAug 5

  • Alex Thorn and Galaxy Research are tracking a multi-wave exploit targeting private keys generated on Coinkite Coldcard hardware wallets. Over 94 victims have contacted Galaxy Research to share drained addresses.
  • The vulnerability stems from a weak random number generator introduced in Coldcard firmware version 4.0.0 on March 17, 2021. Marty Bent urges users with affected firmware to migrate funds immediately.
  • Block Inc. engineers identified Wave 1 of the attack, which occurred over a 41-minute window on July 30th UTC. The automated attack consolidated funds into four collector addresses using a fixed fee of 30 satoshis per vByte.
  • Alex Thorn reports that the stolen coins had a median dormancy of roughly four years, indicating the victims were long-term savers. No stolen UTXOs were created before the March 2021 firmware release.
  • Wave 3 of the attack proved significantly more sophisticated than previous waves, utilizing 293 independent transactions. These funded 293 staging addresses and ultimately deposited funds into 293 P2WSH vaults.
  • Alex Thorn reports that zero multisig setups have been breached in Waves 1, 2, or 3. While threshold multisigs using multiple vulnerable Coldcards remain technically exposed, attackers have not yet targeted them.
  • One victim lost 17 Bitcoin, with 7 to 10 coins routed through Thorchain to an offshore casino called dual.com. The casino refused to freeze the funds without a police report, highlighting the need for legal hold authority rules.
  • Alex Thorn criticizes US artificial intelligence safeguards for blocking defensive cybersecurity operations. Security teams like Hugging Face have been forced to use Chinese open-source models like Qwen to bypass US frontier model safety filters.
  • Alex Thorn predicts this vulnerability will damage the viability of single-signature hardware wallets, arguing that collaborative multisig setups represent the necessary future of self-custody.
  • According to Marty Bent, collaborative custody provider Unchained Capital secures over $12 billion in Bitcoin for more than 12,000 clients.
Also from this episode: (1)

Models (1)

  • Alex Thorn highlights growing government interference in AI development, citing a midnight phone call from the United States government to Anthropic. This call halted the release of Anthropic's Mythos model.

777: Coldcard Is Compromised with James O'BeirneJul 31

  • A critical vulnerability affects Coldcard hardware wallets, manufactured by CoinKite, produced after 2021, specifically MK2 and MK3 models with firmware between 2021 and 2023.
  • The vulnerability stems from an insufficient random number generator (RNG) used for private keys, making them deterministic and severely limiting the search space for recovery.
  • Users are secure if they initiated their Coldcard key with over 99 dice rolls or used a sufficiently complex passphrase, which is often longer than users anticipate.
  • Current Coldcard devices, including the Q model, are estimated to provide only 70 bits of security during key generation, far below the intended 256 bits.
  • Guest highlights that updating firmware alone does not fix the vulnerability; users must generate a new private key pair and migrate funds to the new address.
  • Marty Bent clarifies that MK2 and MK3 models generated after 2021 with default settings might offer as little as 30 bits of entropy, requiring urgent fund migration.
  • Marty Bent notes that AI models are becoming sophisticated enough to uncover such security vulnerabilities, with Kimmy K3 reportedly used to discover this Coldcard flaw.
  • The hosts caution that the rise of AI is accelerating the erosion of 'security by obscurity,' making all open-source code and historical versions vulnerable to automated analysis.
  • Guest expresses concern that the Coldcard incident could damage trust in self-custody among Bitcoiners and the broader public, despite best practices like multi-vendor setups.
  • Past incidents include Ledger spilling client data multiple times and BitBox having physical defects allowing key exfiltration, underscoring the inherent difficulty of hardware wallet security.
  • Guest suggests that while auditing RNGs is crucial, the ultimate fix for improved user experience and multisig-level security lies in on-chain covenant technology.
  • Multi-signature setups are safe from the Coldcard vulnerability if at least one critical signing key is generated by a non-CoinKite device unaffected by the bug.
  • Guest quotes Nick Szabo's principle that 'trusted third parties are security holes,' reinforcing the lesson that delegating security fully to a packaged product is risky.
  • Guest observed that US-based AI models censored or blocked inquiries related to the Coldcard vulnerability, making security investigations more difficult compared to less restricted models.
  • The hosts debated the ethical implications of 'white hats' using computing resources to sweep vulnerable funds from exposed Coldcards, citing challenges in attributing and returning funds.
  • As a temporary measure, individuals with affected Coldcards are advised to move their funds to a trusted exchange, performing small test transactions first to avoid errors.
  • A passphrase composed of six BIP39 words is generally not considered strong enough, as the search space for 2048 words multiplied by six is still too small for robust security.
Also from this episode: (2)

Protocol (1)

  • Marty Bent argues Bitcoin will emerge as the victor over fiat currencies in a world where central banks actively devalue their money.

Models (1)

  • Marty Bent asserts that US government intervention in 'model wars' by 'cucking' frontier AI models like Fable 5 and ChatGPT 5.6 hinders crucial security auditing for Bitcoin systems.

How Bitcoin Custody Works & Breaking Down The Coldcard IncidentAug 4

  • Mallers urges Bitcoiners using Coldcard seeds generated after March 2021 to move their funds immediately. A catastrophic firmware bug left these wallets highly vulnerable to automated theft.
  • Mallers observes that the Coldcard attackers targeted small retail holders rather than institutional whales. Most stolen balances were under one Bitcoin, representing the life savings of everyday savers.
  • Mallers explains that Bitcoin wallets do not actually store coins. Instead, the blockchain is an open ledger recording which public keys hold spending authority, which can only be exercised using corresponding private keys.
  • Mallers describes how each added bit of entropy doubles a key's security search space. A proper 256-bit key provides a space so massive that guessing a specific sequence remains mathematically infeasible.
  • The Coldcard MK3 bug occurred because the hardware random number generator was defined in the software but not actually enabled. The device silently fell back to a weak 40-bit entropy pool of only one trillion possibilities.
  • Mallers argues that the Coldcard firmware violated core security engineering principles by failing silently. A secure device must fail closed and halt operations rather than generating weak, insecure seed phrases for users.
  • Mallers recommends running Bitcoin Core on an offline laptop for ultimate security. As the most widely reviewed and audited codebase in the ecosystem, it minimizes the risks associated with proprietary hardware devices.
  • Mallers advocates for multisig setups, noting that Strike secures customer funds using geographically distributed multisig. Requiring multiple signatures ensures that compromising a single key does not lead to a total loss of funds.
  • Strike experienced massive customer inflows in the immediate aftermath of the Coldcard bug disclosure. Mallers reports that users deposited roughly $250 million in Bitcoin onto the platform within a 36-hour window.
Also from this episode: (2)

BTC Markets (1)

  • During the recording, Mallers timestamps the Bitcoin price at $63,480, with a market cap of $1.27 trillion. The network was 301 days past its October 6, 2025 all-time high of $126,160.

Agents (1)

  • Strike protects its systems by running an agentic AI auditing pipeline daily. Mallers explains that multiple frontier AI models, including Kimmy K3, continuously attack the codebase to identify vulnerabilities.

SNL #235: The most important photo of my lifeAug 3

  • On July 29th, a critical vulnerability in Coldcard's firmware led to many users' Bitcoin being swept, stemming from a bug that prevented the hardware's random number generator (RNG) from being used for seed generation.
  • The Coldcard bug, present for five years, affected MK3, MK2 (with updated firmware), MK4, MK5, and Q models, enabling an attacker to steal nearly 1,000 coins, totaling $70 million, within 24 hours.
  • The attacker's actions were deemed "amateur" by experts, as they consolidated funds immediately, reused addresses, and paid high fees (80 sats per vbyte), making the attack easier to trace.
  • Bitcoin seeds typically require 128 or 256 bits of entropy; however, the vulnerable Coldcard MK3 only provided 32 bits, while MK4, MK5, and Q models had 70 bits, significantly lowering security.
  • The bug was a subtle misinterpretation of a C preprocessor macro, `ifndef`, meaning "is this symbol defined" instead of "is this symbol zero," leading to the use of low-entropy code.
  • Keon anticipates hundreds of millions of dollars in further thefts, as the initial attack targeted low-hanging fruit (MK3) and subsequent attackers using AI tools like "Kimi" could exploit other vulnerable models or remaining UTXOs.
  • Coldcard users should immediately move funds to a new, securely generated seed, ideally using a hot wallet or an exchange for safety, or direct to miner transactions to avoid mempool snipers.
  • Justin Shocknet suggested that the Coldcard vulnerability could reduce the anonymity set of CoinJoin rounds for affected users, as attackers with compromised seeds could de-anonymize their transaction history.
Also from this episode: (3)

Politics (1)

  • Keon met a hacker named Rob who claims responsibility for Russiagate and operates Ford Intelligence, a newsletter selling intelligence to CEOs, heads of state, and private security, pitching it as "Palantir for civilians."

Society (1)

  • Malos10, a photographer from Venezuela, shared a photo of a pregnancy test, announcing the upcoming birth of his child, which he described as the "most important photo of my life."

Protocol (1)

  • Jason B, a jazz musician and aspiring Bitcoiner, draws parallels between Bitcoin and jazz, both lacking a central "ruler" or fixed canon, aligning with his preference for systems without needless control.

RABBIT HOLE RECAP #421: CATASTROPHIC COLDCARD BUGAug 3

  • A critical vulnerability in Coin Kite's Cold Card hardware wallets, caused by a faulty random number generator introduced in March 2021, leaves private keys generated without sufficient manual entropy vulnerable to exploitation. Matt Odell advises users to migrate funds immediately.
  • Private keys generated on Cold Card MK3, MK4, and other models after March 2021 are compromised unless users utilized more than 100 manual dice rolls or a strong passphrase. Multi-sig setups using a single Cold Card remain technically secure.
  • Matt Odell expressed deep regret for his seven-year history of endorsing Cold Card, admitting that complacency and personal trust in Coin Kite founders NVK and Peter blinded him. Odell also apologized to investors of venture fund 1031, which holds a minority stake in Coin Kite.
  • Block's Bitkey team discovered that the attacker exploited the vulnerability by pinging a centralized API provider to identify target addresses, a finding they have reported to law enforcement. A mix of malicious actors and white-hat hackers are currently sweeping vulnerable funds.
  • In response to the crisis, Rob Hamilton and a group of developers are using open-source models and OpenAI's platform to audit over 100 open-source Bitcoin projects. The initiative, initially funded out of pocket, will receive funding from Open Sats.
  • Matt Odell noted that while Coin Kite and others previously failed to find the bug using AI audits, the Frostnap team used Claude Opus seven weeks prior and highlighted insufficient entropy, though it missed the exact bug.
  • Marty Bent and Matt Odell suggest this incident marks the end of simple, single-vendor hardware wallet recommendations for high-value storage. They advocate for multi-vendor multi-signature setups and passphrase use as the new baseline for secure custody.

CATASTROPHIC COLDCARD BUGAug 3

  • A critical vulnerability in Coldcard hardware wallets (versions 4.0.1 and later, or any model after 4.0.0) compromises private keys due to a faulty random number generator.
  • The catastrophic Coldcard bug, introduced in March 2021, compromises seeds generated on any device after that date unless sufficient dice roll entropy (over 100 rolls) or a passphrase was used.
  • Hosts advise all Coldcard users to immediately move their funds off the devices and to cease using the product entirely, regardless of previous protective measures like passphrases or multisig.
  • The hosts had previously conducted Coldcard workshops since December 2019 at Chaincode Labs with figures like Evan Kaludis and James O'Byrne, demonstrating features like dice rolls and passphrases.
  • Hosts concede to complacency, having placed too much trust in CoinKite's NVK and Peter; they now believe the concept of a "magic bullet" beginner-friendly solution for high-value self-custody is dead.
  • The bug, which existed for five years, appears to have been recently identified with assistance from AI, possibly through OpenAI's Cypher program utilized by Rob Hamilton's team for auditing Bitcoin projects.
  • The Bitcoin community has rallied to assist affected users, with Rob Hamilton (@Roboneham on X) publishing an extensive guide detailing Coldcard vulnerabilities, migration options, and recovery steps.
  • Attackers are actively brute-forcing compromised Coldcard seeds using GPUs, while authorities are investigating an attacker who reportedly pinged a centralized API provider to look up vulnerable addresses.
  • The hosts clarify the vulnerability is entirely CoinKite's responsibility, stating their firm 1031 is a minority investor (under 10%) with NVK and Peter maintaining majority ownership and control.
  • The hosts will now refrain from directly recommending specific custody solutions, instead laying out options and emphasizing multi-vendor multisig and robust passphrases as critical for long-term secure Bitcoin storage.
  • Users are strongly advised not to update Coldcard firmware, as new releases may brick devices; instead, the immediate priority should be transferring all funds off the compromised hardware.
Also from this episode: (2)

Media (2)

  • The hosts express deep regret and take accountability for recommending Coldcard for seven years, admitting their past confidence was misplaced despite consistently advocating "don't trust, verify."
  • The Coldcard vulnerability was publicly disclosed on August 3, 2023, at Bitcoin block height 960885, prompting hosts to release this podcast immediately to maximize user notification efforts.

Unpacking the Coldcard Exploit | FREEDOM TECH FRIDAY 50Aug 1

  • A Coldcard hardware wallet exploit led to approximately 600 Bitcoin, valued at about $38 million, being emptied from around 500 single-signature wallets within 30 minutes.
  • Q reports that updated estimates suggest over 1,000 Bitcoin have been stolen, emphasizing that the situation is still evolving and users who lost funds did nothing inherently wrong.
  • The exploit affects Coldcard Mark 3 devices on firmware version 4.0.1 and later, Mark 4 and 5 devices before version 5.6, and Q devices on firmware 1.5 or earlier.
  • The vulnerability stems from a core code rewrite in March 2021 that stopped using the device's hardware randomness for seed generation, instead relying on predictable software randomness.
  • Q states that the crucial factor for determining risk is the firmware version on the Coldcard when the seed was *generated*, not the current firmware version.
  • Seth advises all users to move funds from any seed generated on a Coldcard due to this issue, even if they used dice rolls or a passphrase, as the vulnerability window varies.
  • If a user generated their seed with 50-98 independent dice rolls, they achieved 128 bits of entropy, bypassing the software bug. 99 or more rolls provided 256 bits of entropy.
  • Multi-vendor multisig users, such as a 2-of-3 setup, are safe from direct fund loss because one compromised Coldcard key is insufficient to move funds, but they should rotate the key.
  • Zach explains that Foundation's Passport devices are not affected, as they combine multiple entropy sources including an open-source avalanche noise source, avoiding reliance on black-box silicon.
  • Zach attributes the bug to Coldcard's move away from free and open-source software (FOSS) in early 2021, replacing GPL code with a proprietary 'source available' library, LibNGU, which lacked community scrutiny.
  • Seth warns that privacy for non-Coldcard users could be damaged if they participated in coinjoins or payjoins with vulnerable Coldcard users, as transaction histories are now traceable.
  • For migration, Seth advises moving individual UTXOs one at a time to unique addresses and randomizing timing to preserve privacy, though sweeping all funds is simpler for security-first users.
Also from this episode: (1)

Education (1)

  • Q cautions against scammers and impersonators who will exploit the panic, reminding users to never give out seed words and to only use official channels for support.
What Bitcoin Did
What Bitcoin Did

Danny Knowles

EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob HamiltonJul 31

  • Rob Hamilton issued an urgent warning for Coldcard MK3, MK4, MK5, and Q users who generated wallets directly from the device without providing their own entropy or a strong passphrase, urging immediate fund recovery.
  • The critical bug, introduced in early 2021 via a firmware change, compromised the entropy generation process, making seed words created by affected Coldcard devices insecure.
  • Rob Hamilton clarifies that Coldcard MK1 and MK2 models are not impacted by this specific firmware bug, as they are older hardware and do not receive new firmware updates.
  • For impacted Coldcard users, a sufficiently strong 25th-word passphrase or providing external entropy (e.g., dice rolling) is the only protection against attackers scanning all possible Coldcard seed phrases.
  • Rob Hamilton explains that the MK3 has only 2^32 bits of entropy, which is easily brute-forced by consumer hardware, while MK4, MK5, and Q models have 45-50 bits, still vulnerable to GPU data farms.
  • The vulnerability stems from a single line of code that incorrectly skipped secure entropy generation if a function merely existed, rather than evaluating if it was true, a 'nuclear event' for hardware wallet security.
  • Initially, the attack was carried out by an amateur, evident from only targeting addresses with more than 0.15 BTC and failing to scan full addresses; now, multiple sophisticated attackers are involved.
  • Danny Knowles confirms that Trezor and Foundation devices are safe because they do not use the same compromised library as Coldcard, indicating a specific, not widespread, self-custody vulnerability.
  • Rob Hamilton recommends moving funds to trusted exchanges like River, citing its in-house custody and proof of reserves, or immediately acquiring other hardware wallets like Ledger or BitKey as emergency measures.
  • Multi-signature wallets are at risk if a majority of their signers (e.g., two of three) are compromised Coldcard devices without strong passphrases or rolled dice; Unchained, Casa, and AnchorWatch state they are not affected.
  • For at-risk multi-sig wallets with un-reused addresses, Rob Hamilton suggests using Mara Slipstream to broadcast transactions directly to a mining pool, which helps prevent replace-by-fee attacks by faster confirmation.
  • The Coldcard incident is a 'nuclear event' for Bitcoin self-custody, fundamentally undermining the trust in hardware wallets to generate sufficiently random numbers, a core tenet of Bitcoin security.
  • Rob Hamilton observed that bleeding-edge, open-source LLMs like Kimi K3, without safety guardrails, could instantly identify the Coldcard bug, signaling a new era where AI accelerates vulnerability discovery.
  • Future improvements for self-custody could include Bitcoin covenants and vault-like structures, enabling on-chain controls like address whitelisting or spending limits for enhanced security.
Also from this episode: (1)

Protocol (1)

  • Rob Hamilton estimates over 1100 BTC has been stolen already, with projections of thousands more, as well-capitalized attackers using GPU computing join the effort to exploit the vulnerability.

The COLDCARD Hack and Future of Self-CustodyJul 31

  • Steve estimates the Coldcard security incident has resulted in over 1,000 BTC stolen, valued between $65 million and potentially $100 million, describing it as the "worst day in Bitcoin's history" due to the impact on self-custody.
  • The bug allows attackers to regenerate private keys from on-chain transactions due to weak entropy, without physical device access or seed phrases, by brute-forcing inputs like the CPU timer cycle and unique device ID.
  • Steve advises Coldcard users in vulnerable situations to move funds immediately to temporary locations like trusted custodians or wiped, old devices; CoinKite has released new firmware for most products, but not MK3.
  • Bitcoin itself is not compromised; this is a vendor-specific issue with CoinKite's Coldcard products, underscoring Max's argument that AI poses a more immediate and significant threat to security than quantum computing.
  • Customers who properly used Coldcard's dice roll feature (e.g., 99-100 rolls) or a strong BIP39 passphrase (128-bit or more) should be safe, but Steve suggests moving funds for peace of mind.
  • Steve emphasizes custody diversification as crucial, recommending users split funds between solutions with non-intersecting risks, such as a third-party custodian and a self-custody solution, rather than relying solely on one method.
  • Max proposes that for critical software, users need transparency on which top-tier AI models are conducting 24/7 security audits, stating that "all bugs are shallow with enough tokens."
  • Project Loupe, launched by Spiral, performs AI security scans on open-source Bitcoin repositories, but models produce noise and misclassify severity, necessitating human review and active remediation by project maintainers.
  • Steve suggests that recovering stolen Bitcoin would require proving original ownership through a combination of unique device IDs, DKIM-signed email receipts from CoinKite (verified for 2023), and KYC/on-chain analysis from exchanges.
  • White hat hacking to sweep vulnerable funds to a secure system, to be returned to rightful owners, is proposed as a method to mitigate further theft, though the legality and feasibility remain uncertain.
  • Multi-signature setups remain a strong self-custody option, but require diversity across keys from different hardware/software vendors to avoid single points of failure, unlike using multiple devices from the same vendor.
  • BitKey is a multi-signature product by default, using three keys generated across different hardware and software stacks (Block server, phone, hardware device) to provide diversity, but it lacks independent verifiability for some key generation processes.
Also from this episode: (3)

Chips (2)

  • The Coldcard vulnerability affects MK2 and MK3 hardware with firmware from 2021 to the present, stemming from a compile-time bug that caused the hardware random number generator to fall back to a weak software pseudo-random generator.
  • Newer Coldcard models (MK4, MK5, Q) have 32 to 72 bits of cryptographic entropy, which is stronger but still potentially vulnerable to a financially substantial brute-force attack; reports indicate these models have also been exploited.

ETFs (1)

  • Max questions if retail users can perform in-kind BTC transfers to IBIT (BlackRock's ETF) without a taxable event, noting it's currently restricted to authorized participants with tens of millions of dollars.
Square Engineering

Square Engineering

Predictable RNG Fallback and 32-Bit Reseed in COLDCARD FirmwareJul 30

  • Block's security research identified vulnerabilities in COLDCARD firmware that could enable Bitcoin theft, stemming from an RNG integration error causing `ngu.random` to default to MicroPython's deterministic Yasmarang fallback.
  • COLDCARD Mk2/Mk3 v4.0.0-v4.1.9 firmware versions have no cryptographic entropy added to `ngu.random`, making wallet generation deterministic if the device UID, timer state, and RNG-call history are known.
  • An attacker with knowledge or sufficient constraints on device UID, timer state, and RNG-call history can reproduce the fallback stream offline, potentially recovering wallet seeds and private keys.
  • For Mk2/Mk3 v4, the maximum enumeration count under normal cold-boot with known UID but unknown SysTick is approximately 2^16.29, making the seed highly vulnerable.
  • Current devices like Mk4/Q/Mk5, even with a successful reseed, have a secure-element-derived search space limited to at most 2^32 possibilities when the fallback state and call history are known.
  • The vulnerability affects other functionalities relying on `ngu.random`, including paper-wallet private keys, seed XOR masks, cloning/USB encryption keys, Key Teleport, Web2FA, and Secure Notes passwords.
  • The regression originated from a firmware change on March 1, 2021, which migrated wallet generation to `libngu`, and appeared in released firmware v4.0.0 on March 17, 2021.
  • Block and security researchers identified the root cause on July 30, 2026, after user reports of lost funds, leading to the early publication of this advisory due to ongoing active exploitation.
Also from this episode: (3)

Coding (1)

  • The vulnerability arises because the production board configuration defines `MICROPY_HW_ENABLE_RNG` as zero, and `libngu` incorrectly checks if the macro is defined rather than enabled, binding to a deterministic software generator.

Chips (2)

  • COLDCARD Mk4/Q/Mk5 devices, using production firmware v5.0.0 onward, incorporate a limited secure-element reseed that hashes 32 bytes to retain only four, replacing just one 32-bit Yasmarang state word.
  • The Yasmarang software fallback initializes using the MCU's low 32-bit UID, SysTick counter, and RTC registers, none of which are cryptographic entropy sources, allowing for state reproduction.