Your signal. Your price.

A critical vulnerability in Coin Kite's Cold Card hardware wallets, caused by a faulty random number generator introduced in March 2021, leaves private keys generated without sufficient manual entropy vulnerable to exploitation. Matt Odell advises users to migrate funds immediately.
Private keys generated on Cold Card MK3, MK4, and other models after March 2021 are compromised unless users utilized more than 100 manual dice rolls or a strong passphrase. Multi-sig setups using a single Cold Card remain technically secure.
Matt Odell expressed deep regret for his seven-year history of endorsing Cold Card, admitting that complacency and personal trust in Coin Kite founders NVK and Peter blinded him. Odell also apologized to investors of venture fund 1031, which holds a minority stake in Coin Kite.
Block's Bitkey team discovered that the attacker exploited the vulnerability by pinging a centralized API provider to identify target addresses, a finding they have reported to law enforcement. A mix of malicious actors and white-hat hackers are currently sweeping vulnerable funds.
In response to the crisis, Rob Hamilton and a group of developers are using open-source models and OpenAI's platform to audit over 100 open-source Bitcoin projects. The initiative, initially funded out of pocket, will receive funding from Open Sats.
Matt Odell noted that while Coin Kite and others previously failed to find the bug using AI audits, the Frostnap team used Claude Opus seven weeks prior and highlighted insufficient entropy, though it missed the exact bug.
Marty Bent and Matt Odell suggest this incident marks the end of simple, single-vendor hardware wallet recommendations for high-value storage. They advocate for multi-vendor multi-signature setups and passphrase use as the new baseline for secure custody.
Marty argues that Bitcoin serves as the ultimate victor and safe haven in an economic environment where central banks actively devalue their national currencies.
Marty and Matt discuss a fund manager named Leopold, dubbed "the boy wonder," who reportedly lost over $40 billion, possibly due to excessive leverage and a margin hunt by Wall Street firms.
Current Bitcoin network stats show a price of $64,760, a market cap of $1.3 trillion, and an average block time of 10 minutes and 16 seconds. The mempool currently has 86,317 transactions.
Marty clarifies that Arthur Hayes's family office, Maelstrom, funds a Bitcoin grant program run by Jonathan Beer, while Farsight Insights is Beer's separate investment management company.
BIP 110 activation is nine days away, with a monitoring dashboard (bip110.orange.surf) indicating a high likelihood of a chain split where BIP 110 nodes would form a minority chain.
Strike has launched beneficiary planning for Bitcoin inheritance, a feature addressing the need for users with significant collateral balances to designate an heir for their funds.
The Clarity Act now includes a provision safeguarding self-custody Bitcoin from abandoned property laws due to inactivity, establishing federal preemption over state laws.
Secretary Scott Bessent strongly supports the Blockchain Regulatory Clarity Act, arguing it enhances compliance for digital asset intermediaries while codifying existing Treasury policy for non-custodial developers.
Ventium, a Bitcoin accelerator based in Brazil, announced new fellowship cycles, selecting 12 developers from 322 applications for its second cohort and funding two new grantees.
NVIDIA CEO Jensen Huang, alongside Elon Musk, Microsoft, and Google, publicly supported open-weight, open-source AI models, highlighting a powerful industry alignment toward freedom in AI development.
Marty and Matt detail how OpenAI and Anthropic are reportedly "cannibalizing" customers by using their proprietary data to develop competing products, citing examples like Figma, Novo Nordisk, Microsoft, and Harvey.
Nigerian President Bola Tinubu established a Virtual Asset Council, chaired by the Central Bank, to regulate digital assets, which Marty views as an attempt to implement a surveillance and control regime.
Sparrow Wallet version 2.5.3 was released with Aera hardware wallet support, XDG directories, and PSBT verification; Marty warns users about scam mobile applications.
Buzz, a Noster-based application, leverages cryptographically signed events to build private "company brains" and enables a "multiplayer harness" for agents to interact and share compute resources within trusted environments.
India requested GitHub to ban BitChat, prompting developer Callie to enable offline self-transfer of the Android APK via Bluetooth and develop a full-fledged client for smartwatches to circumvent censorship.
An open-source ESP32 LoRa mesh relay was introduced to bridge with BitChat, allowing users to extend the application's range through low-power, continuously running devices.
Russia charged Telegram founder Pavel Durov with facilitating terrorism after he refused demands for mass surveillance and censorship, a move Durov publicly defied.
Colorado's new law, effective August 1st, mandates a restrictive process for purchasing semi-automatic firearms with detachable magazines, requiring multiple background checks, fees, classes, and an exam.
Marty highlights an alleged coordinated cyber attack on over 30 Minnesota water systems, with speculation of Iranian links, underscoring the vulnerability of critical infrastructure.
Marty advocates for unleashing open-weight AI models to audit and defend critical infrastructure, suggesting that a short-term rough patch would ultimately lead to stronger systems.