BTC Sessions - Coldcard Aftermath: What's Next for Bitcoin Security | Jade, Passport, Trezor, SeedSigner
Episode Date: August 18, 2026Mentor Sessions Ep. 089: Bitcoin hardware wallet makers Zach Herbert, Tomas Susanka and Drew Fischer discuss the Coldcard hack, multi-sig, entropy and self-custody security.The Coldcard hack was the s...ingle biggest blow to Bitcoin self-custody yet — so four rival hardware wallet makers sat down together to figure out what it means for everyone holding their own keys. This is the conversation the industry needed.Zach Herbert (Foundation Passport), Tomas Susanka (Trezor), Drew Fischer (Blockstream Jade) and Seed from the SeedSigner team break down the fallout: what the vulnerability actually exposed, why open source alone wasn't the safety net people assumed, and the entropy/dice-roll debate that split the panel. You'll learn why multi-vendor multi-sig is emerging as the strongest defense, how entropy is really generated on these devices, and the honest trade-offs between usability and security. You'll also hear the fresh news on the Trezor fulfillment-partner data leak (disclosed August 10, 2026) and what to do if you're worried about shipping and privacy.This is a rare, candid roundtable where competitors disagree openly — and that dialog is exactly what makes it worth your time.⏱️ Timestamps:0:00 - Intro0:56 - Four wallet makers respond to Coldcard hack1:58 - Ben's question on self-custody downstream effects3:02 - Zach on short-term setback and great hardening6:19 - Tomas on AI helping attackers and defenders8:44 - Drew on custodians, ETFs and verify don't trust10:30 - SeedSigner on entropy sources and multi-sig13:11 - Usability versus security trade-off debate17:20 - Should self-custody be made harder not easier18:56 - Dice rolls versus RNG entropy disagreement22:16 - Zach on how many people actually self-custody26:14 - Priorities when choosing a hardware wallet29:01 - Security as a journey not a destination33:03 - Sponsor: Abundant Mines36:00 - Why multi-vendor multi-sig should be the goal41:25 - Source available versus fully open source explained47:34 - Open source as required but not sufficient51:11 - How to know if a wallet is actually safe56:57 - Trezor fulfillment data leak disclosed August 101:03:49 - Private device purchases and local meetups1:06:01 - Where to find each project online🔗 Links & Resources:→ SeedSigner: https://seedsigner.com→ Foundation Passport: https://foundation.xyz/→ Trezor: https://trezor.io→ Blockstream Jade: https://blockstream.com/jade🔔 Subscribe for weekly Bitcoin Podcasts🐦 Follow on X: https://x.com/BTCSessions🐦 Follow on X: https://x.com/theBTCmentor⚡Sovereign Sessions — AI, Privacy, and Bitcoin education: http://youtube.com/@SovereignSessions?sub_confirmation=1💡BOOK Private Sessions with Nathan, Ben and the BTC Mentor Team: Master self-custody, hardware, multisig, Lightning, privacy, and more. 👉 Visit btcmentor.io ⚡ POWERED by Abundant Mines: Fully managed Bitcoin mining. Learn more at https://qrco.de/bgYKPB#Bitcoin #BTC #BTCSessions #BitcoinSelfCustody #ColdCard #ColdcardHack #BitcoinHack #HardwareWallet #MultiSig #SeedSigner #Trezor #Passport #BlockstreamJade #BitcoinSecurity #NotYourKeys #ZachHerbert #TomasSusanka
Transcript
Discussion (0)
What do you anticipate might be the downstream effects for self-custody from the cold card vulnerability?
We're going to go through this great hardening, I would call it, over the next couple years of all software security.
I do think that this does set us back in the short term.
The first time I've read the news, I was like, oh man, this is going to mess up the whole self-custody industry, right?
When things calm down a little bit, I also realize trying to take the positive side that maybe now a lot of people do a lot of hardening, security at the cost of.
feasibility goes at the cost of security.
We need to make self-custody harder, not easier for people.
Personally, do want to scare Grandma a little bit.
I think Grandma can take it.
We need more people self-custody and meeting people where they are.
For better or for worse, there will be more hacks in the Bitcoin community.
Because there is value in Bitcoin, will be better for it, unfortunately.
The Cold Card hack was quite possibly the single biggest blow to Bitcoin self-custody we've ever suffered.
So, in response, four of the industry's leading experts from for the industry's leading Bitcoin
hardware walls have come together to discuss what they've observed, what they've learned,
and what they plan going forward. Joining me today is Drew Fisher from Blockstream, Thomas Susanka
from Trezor, Zach Herbert from Foundation Devices, and Seed from Seed Siner.
All right gentlemen, thank you so much for sitting down with me. I hugely appreciate you guys
taking time out of your busy schedules to come have a conversation, chat. You know, it's funny,
over the past two weeks or so, the team and I have probably helped move well over a thousand people,
get off the cold card and I keep getting asked the same thing over and over again. Where do I go? What do I do
do next? What do you recommend? And funny enough, basically all four of my answers are now sitting on this
panel. We basically have my favorite, you know, multi-vender multi-sig between passport and Treasurer and Jade
and Seed Siner. And that makes me happy. So there's a lot for us to talk about today. Unfortunately,
Ben is Teribolt scheduling and couldn't be here, but there was no way he wasn't going to participate.
So I actually have the first question coming from him. So let me go ahead and play this for you guys.
Hey guys. Very sorry I couldn't be there traveling with the family. Timelines, well, funky,
but I did want to make sure that I was there with a question to kick things off for you guys.
So in light of these past couple weeks, which have been difficult and eye-opening for a lot of people,
myself included, I wanted to ask you, what are the downstream implications for self-custody?
and how is it likely to change in the next couple of years due to these events?
And furthermore, to add on an extra bit of question,
there's a mantra in Bitcoin, which is don't trust verify.
But as we've seen, many of us were just trusting and not verifying.
We thought that the code being open and auditable was enough,
but that was not the case.
So how does the average person with minimal skill actually verify and not trust?
All right. So, Zach, starting with you taking the first part of that question, everything that's happened, you've had, I'm sure, at least a little bit of time to reflect.
What do you anticipate might be the downstream effects for self-custody from the cold card vulnerability?
Yeah, I think, firstly, everyone is shaken right now, right? And I'm sure all of us experience that's,
same feeling on the hardware wallet vendor side of things, you know, that I guess it's been
almost two weeks, you know, that Thursday evening two weeks ago where we all rushed to check
our own code. But more than more than the feelings that we had, of course, all the, all the,
you know, thousands of self-custody users and Bik corners who were affected by this. So I do think that
this does set us back in the short term from a, you know, self-custody versus.
you know, custodial point of view. But I also do think, as we've seen from the response from the
Bitcoin community over the last couple of weeks, it's been enormous. It's been incredible. You know,
there's been so many folks like yourself, right, who are helping everyone migrate to new devices.
I'm sure we've all seen, you know, an increase in sales, which which does show that folks are
looking for other solutions, right? They're looking for other hardware wallets or it might be, you know,
multi-sig as well to get them off to new devices.
So I do think that we have a lot of work to do to reassure everyone,
but I also think that I'm very optimistic for the short term.
I think we're going to go through both as self-custody companies,
but then the entire industry and then outside of even the Bitcoin and crypto industry,
we're going to go through this like a great hardening,
I would call it, over the next couple years of all software,
security. And it means that we're going to be able to use AI to help us do that. And it also means that
there's going to be a little bit of a whack-a-mole situation. There's going to be other exploits.
There's going to be things that happen. We were just affected by the BTC pay stuff as well last week.
So it's going to be a little tumultuous, I think, in the short term. But I'm very optimistic that we're all
going to come out better on the other side. And then finally, just like our internal practices at the
companies, right? The way we do software development, the way that we are transparent with the
community, the way that we automate AI code review for everything, free and open source software,
engaging more actively with the community, engaging positively with security researchers.
I'm sure all of us are also currently being inundated with bug reports from not even security
research and researchers anymore, but just normal people who are running AI scans and like emailing us
and saying, you know, read this report and we're saying, you know, thank you. We've already gotten
this from 50 other people, you know, yesterday. So there's a lot of this stuff that we're all
figuring out how to navigate. But I do think that, um, the transparency, the open source,
all that kind of stuff is key. And I'm still very optimistic, um, you know, looking forward.
It's just we all have a lot of work to do. No, fair enough. Thomas, I'll, I'll
it, your reply and thoughts on downstream effects for self-custody and anything that Zach had to say there as
well. Yeah, no, I actually agree with a lot of, or with the whole thing that Zach said. So, like,
the first time I've read the news, I was like, oh, man, this is going to mess up the whole self-custody
industry, right? Like, this is going to have, like, really a long-term impact, you know, on everyone
that is doing self-custody. Then I kind of, you know, when things calm down a little bit, I also realized,
trying to take the positive side of things that maybe now exactly like a lot of people do a lot of
hardening. So there is this great Bitcoin Red Team initiative. There's finding, you know, and spending
a lot of tokens on, you know, finding bugs and exploits or whatever. And this makes me think that,
you know, maybe down the road we're going to actually come out of this stronger, you know,
our code will be actually more tested than maybe in the long term, you know, this actually, I don't want
to say it pays off because obviously, you know, there are a lot of people losing their savings,
but maybe there is some, you know, lessons learned. And with AI, it really goes both ways. You know,
it gives the attackers a hell of abilities, you know, that they can find exploits, but it also
goes the other way for the regular users. Because, you know, this saying, the saying is there
enough eyeballs, so to speak, against open source that has been here forever, right? And it's a
legitimate argument, right? Like open source or source available code is just not enough. We do need
in, we do need, you know, people to actually look at it. So now with AI, more people can look
into it, right? Because you don't need such a deep knowledge as you used to, used to need. So
it goes both ways and I'm really curious how this is going to play out. And we'll see. I'm somewhat
optimistic about this positive side of things. But yeah, I'm curious to.
see half year later.
Agreed, agreed. Drew, I want to get
your take on what the boys had to say here.
And additionally, I'll throw in the second half of that question.
In terms of the average person
not trusting and verifying, you know, it's funny.
I always, it's almost like turtles
all the way down. It's like, okay, but can you actually go through the
code? Okay, you're checking the compiler. Like, like,
it feels like at some point, at some
point you have to trust because you have the limits of your own
understanding. But this really has shaken
people's confidence. So Drew, thoughts
on self-custody and thoughts on, how does
the average person, and maybe to what extent
can they verify what they're working with?
Sure.
I agree with what Zach and Thomas were both saying.
The great hardening is upon us.
In the short term, I think we're going to see a lot.
Unfortunately, a lot of people move to the ETFs
or a custodian itself, whether that's an exchange or not.
So that will be very interesting in the short term,
in the long term, as the Bitcoin community
and the tinfoil hatters of us learn how to do their own security audits
with, you know, Kimmy and the open source ones that we can get access to.
We will learn together what that all looks like, so that is exciting in one hand and daunting
on the other.
And then for like the average Joe, we all have recommended to family members or friends that
are not, you know, crazy like us, a hardware wallet or a software wallet.
But as we learn and as the Red Team learns and, you know, as the community learns how to do these audits themselves, they're going to feel more comfortable doing those recommendations.
So, you know, Callie put out a good post earlier today about what the Red Team has learned since this whole debacle has started.
And that learning that he and the team have made is going to disseminate out to the rest of us that are not in the thick of it every day.
And unfortunately, or fortunately, we're going to.
get pretty good at this too. And so for better or for worse, there will be more hacks in the
Bitcoin community because there is value in Bitcoin and like anyone can try. So we'll be better
for it, unfortunately. Beautiful. Cid, what are your thoughts, my friend, and how this might impact
self-custody moving forward and the idea that, you know, we need to not trust and verify?
Hey, appreciate you guys asking me today. Apologies for not being on video. Just have
I'm actually building signers as we're talking here.
So a couple thoughts I have, of course, with the whole concept of, you know, don't trust verify.
Like everybody's not a coder.
Everybody's not a technologist.
Everybody, even with, you know, the aid of an AI tool is going to be able to understand what they're looking at with regard to the lower levels of the technology.
But at a higher level, there are.
things that we as Bitcoiners can do to protect ourselves.
It's kind of a unfortunate truth to say out loud, but anyone who would have rolled dice
50 or 100 times or who would have cut out, you know, 2,000 pieces of paper, which I understand
is a pain.
But anybody who would have gone through a more trustless process for creating their private
key would have been unscathed by this cold card thing.
We're trusting a random number generator for better or for worse, and there ended up being an issue with that.
So some of us have been talking about best practice is to collect real world entropy from the world around you.
It's cheap and it's easy to do.
That is one kind of way that you can avoid trusting during the process of doing self-custody.
Another thing I would throw out there is multi-sig.
And I know that in the past some of the Harder Wallet providers, I don't actually know which, but I've heard some of it had not been super jazz about multisig.
And I think we need to reverse our thinking about that.
Because multi-sig is how you protect yourself from these unknown unknowns that these guys have rightly pointed out that are going to come out over the next 12, 18, 24 months with all of the adversarialism of the AISO of the AISO,
is looking for vulnerabilities. If, you know, there is a vulnerability with Seed Center or with any of
these other devices we're talking about, multi-sig still is your best defense against that. So I'm
hoping that more people dig into multi-sig and it's unfortunately gotten a bad rap in terms of, you know,
being too complicated for people to understand. And I would like to see, you know, a reinvigoration
of an interest in multi-sig.
And I think Ben has been at the forefront of that,
and I love to see it.
So, yeah, those are my initial thoughts.
Beautiful, sir.
Thomas, I'll come to you,
and let me see if I can unpack a couple ideas here.
This is a lot.
This might open quite a large conversation.
With regards to multi-sig and self-custy kind of moving forward,
one of my big realizations over this event that was,
it was a bit of a hard,
it was a bit of a black pill to swallow,
but there had been a lot of people that I'd worked with,
and we had spent a number of hours together,
two years ago at the time they had really mastered their device their multi-sig everything emergency
situation comes up two years later they hadn't touched in between and they forgot everything and so
I'm really kind of playing with this idea that when we at a certain point I don't know where that
threshold is at a certain level when it's a large proportion of your net worth self-custody
it cannot be set it and forget it there has to be almost like an active participation in my mind and
turning to learn make sure you're still comfortable with the tools moving forward making sure that you're
keeping up on any updates that you would hear about any security of vulnerabilities that
unlike maybe our analog counterpart gold, or once it's stuck in the vault, there's really
not too much that you have to worry about that point in time. I think Bitcoin requires almost
like nutrition or exercise. You can't do it two years ago and still be in good shape two years later.
You have to continue with it as we go. So all of that to say, Tom, is kind of coming to you,
balancing out usability for security. I still don't necessarily have a good foothold of how I'm
thinking about it because I've seen the footguns now where people had a very secure setup,
but had no idea what they were doing.
I want to be able to onboard the entire world,
but I'm almost thinking in practical terms,
it's like, what should we be prioritizing?
How are you thinking about those two things?
That was quite the rant, so please take it any way you'd like.
No, no, no, it's a great question,
and, you know, it's something that I feel we're talking about
and thinking about at Treasurer all the way from the start.
I really like this saying that it's a bit complex,
but it goes, you know, security at the cost of usability goes at the cost of security, right?
You can have the most secure setup ever, you know, it can be so secure, but if it's hard,
you know, to actually use it, then, you know, it creates a lot of problems and it's kind
of useless if you cannot use it, right?
Sometimes, you know, I'm joking a bit that, you know, the most secure setup is if you just
like hide yourself in a cave somewhere, like, or in the desert or in a jungle, I don't
nowhere and you're calculating all this cryptography from your hat, you know, you can do the
math and then you draw it on the wall or I don't know, I'm exaggerating of course. But of course,
that is the most secure way, right? That is the, that's more secure than Treasor. I'm going to admit
that. Is it usable? It is not because first, like people cannot really do this kind of mass.
Second, it's just pain. It just doesn't work, right? So it's always this kind of never-ending balance
between the usability and the security that we're really always striving for.
And I feel that sometimes we as, you know, hardware wallet makers, sometimes we get locked
into this thinking that, you know, we need to make something 0.01% more secure, you know,
just like tiny bit.
But we actually decrease the usability for the normies, so to speak, right?
That we actually make it harder for them to use.
and then maybe they lose their coins or they do something, you know, that they didn't want to do.
So there's really a lot of the usability part is actually part of the security itself.
It's something that we need to keep an eye for and it's something that we need to design our product.
So the regular or the user simply can actually use it in a safe manner, right?
So 100% agree.
It's very hard to set the threshold because honestly, you know, there's a lot of people,
on eggs that have the threshold somewhere else,
that they are able to accept more difficult setup.
And I completely get it and that's fine.
I like, yes, there are some more advanced setups,
but then there are a lot of people that are fine
with some simpler ones, right?
And yeah, it's so hard to advise this
because this can actually differ to different people.
I have a comment on that if I may.
Please.
So with the cold card, the easiest thing to do
was just to turn the thing on
and let it give you seed words.
A lot of the hardware wallet makers are optimizing for easy,
and I understand because it creates a smoother onboarding process.
It improves perceptions of your product,
and generally people are like, oh, that was so easy to set up.
The easiest part of setting up a cold car,
the easiest way to do it was just to accept the seed, not roll the dice.
I think we honestly do need to think about the balances like he was talking about
with usability and security.
we may have to change the culture a little bit and make things a little bit hard and force people to learn a little bit.
Was it hot old tarantula?
I'm probably butchering.
Had a great rant the other day that I retweeted.
And his conclusion was essentially, we need to make self-custody harder, not easier for people.
I know people aren't going to like to hear that.
I know it makes it harder to sell devices and whatnot.
but like when people understand what they're doing,
they have more control over the process
and they can make choices about the tradeoffs
that are appropriate for their situation.
I know we're not going to agree on everything on this call,
but it's something I've been preaching about for a while
and I felt obligated to kind of throw in there.
No, I appreciate that.
Thomas, I'd love to get your thoughts.
And I just want to outline particularly,
like I think these are important conversations to have.
We're going to have differences of opinion, right?
But I think it's through the dialogue
that we can ultimately come to some better conclusions and best practices moving forward.
So, Thomas, please.
And then Drew and Zach, I'll get your thoughts.
Yeah, yeah.
So, yeah, I disagree.
And that's totally fine.
Like, you know, we, like people have different opinions.
So it's totally fine.
So I disagree.
And I have actually disagreed on, like, before when you talk, we're talking about
dice rolls.
The fact that there was no buck in Cold Guard and the dice rolls, you know,
where actually source for de entropy.
That's, I don't want to.
to say it's a coincidence, but there could have been a different bug where the dice rolls, you know,
would have not been used. It's just, it's just some, you know, by accident or just some different
lines of code, they were actually used. But it doesn't, it doesn't mean that the secure element
that they have had that, you know, would not provide good enough entropy. The problem is that they
were not using it, right? And the fact that they have been using dynes is a completely different
topic. And I let you answer.
So that's a fair point.
If the process of combining dice rolls with output from an RNG is definitely not repeatable,
but the process of just rolling dice 100 times and seeing what seed it produces
and then going to another device that creates the seed from the same rolls using the same function is repeatable.
This is a belt and suspenders thing.
I understand everybody's not going to do it, but if you have the tinfoil hat on,
you wouldn't make absolutely sure.
um like that it is a reproducible process dice rolls and so yeah you're right dice rolls plus
rng you can't verify that so in my opinion what do i do if i'm you know really trying to make sure
that i have true and genuine entropy i want a process that's repeatable but i can verify with
another hardware stack and that process is just rolling the dice not involving the rngg totally
understand everybody's not going to do that. But I have felt our project and some of our
perspectives have been underrepresented in the Bitcoin ecosystem up to this point. So I feel compelled
to just resave the same things I've been saying for years at this point. I'll let you other guys
jump in. Yeah, just very short comment. I let you guys talk. I just wanted to do, you know,
I didn't want to say that, you know, there are not other approaches. It's totally fine.
like we should actually have like more hardcore signers and wallets and all that.
I'm up for that.
I'm just saying like I would be very careful advising this, you know,
to the generic public because I've seen reports where people were pressing number six all the time
because they thought that the dice rolling is going to happen on cold card, right?
So I'm just very careful about that not everyone is technical tech savvy as much as we might believe.
Yeah.
It's funny.
I'll jump in there and then, sorry, Zach, I'll get your take on.
And then Drew, I just wanted to quickly add, I had a lot of times actually steered people away from from dice rolls kind of for that reason is that I was always trying to bounce out the risk of loss versus the risk of theft. And I was, listen to me, I was far too concerned that they were going to fake it.
They were just going to try to randomly guess numbers that I was like, okay, let's just go with the RNG, which ended up being a mistake. But again, hindsight's 20-20. So again, it's balancing out where kind of people are on the curve and how do we address this going forward. But Zach, please give me your thoughts. And then Drew.
Yeah, I mean, you guys had a great back and forth, see it in Tamas.
I want to zoom us out maybe a little of them.
We could zoom back in because that was like very zoomed into this dice roll and entropy issue, which is valid.
But I would zoom us out and say, each decision that we make affects how many people are able to self-custody on cold storage hardware.
Right.
So in the example of us going, you know, go to the cave, right, how many people in the world would be able to do that, you know, a thousand, two thousand.
And then in the example of making it so easy to use that you remove all of the security characteristics, you can get to, you know, a broad adoption.
If you look at, and I'm sure, I don't know who is the best few, probably Trezer has the most data as to how many,
hardware wallets exist right now in the world, at least in maybe not China, because that's like
its own kind of market and they have a lot of their own companies. I mean, Ledger has self-reported
in press releases like 8 million devices they've sold total. I'm not going to ask you from Treasor,
but I know Trezor has said something the last year, like over two million or something like that
has been used in your marketing material. So let's say under 20 million devices, let's just say,
maybe even under 15.
And how many of us own more than one device?
Like I own at least 10.
And so how many individual people in, you know, the U.S. and Europe and other, you know,
parts of the world are actually using hardware wallets.
I mean, maybe no more than 10 million.
Maybe 10 million is too much.
So we have to be careful, right?
Because this idea, and this is where I kind of disagree with seed,
but then also kind of agree with seed and it gets very complicated.
it's almost like like a barbell.
Like if you go too far on security,
but you offer this amazing opportunity for the hardcore people to generate their own seeds and set up and everything like that.
But then you got to find some balance,
some blend that will allow more people to self-custody.
Because shouldn't that be the ultimate goal?
Like more people,
more than five to 10 million individuals worldwide using hardware wallets.
And yes,
there's a sales part of it.
Obviously,
we're all incentivized, right, as companies, or at least those of us that are, you know, companies.
I think C and Seed Siner is a little bit of a different, you know, element, which is why I think
it's an awesome different perspective.
Like, we want to sell more devices, but there's also like the philosophical of which we want
more people to self-custody, genuinely.
That's why we're all here.
Like, that's why we're driven to be in this nascent, still nascent industry.
And so you just got to be really careful because I don't think it.
If the way to enter the space is you all got to pull out your dice and you got to go through this whole complicated onboarding and backups and then you put the device in the drawer for a year and then something happens and you take it out and you don't even remember how to use it, that's not good.
And most people are just going to go to exchanges.
And so I think like I'll stop by saying that I do think the solution is like this free market capitalism.
Let us all compete.
We all have our, you know, different ways of doing onboard.
boarding and backups and all that kind of stuff and user experience.
And I do think one of the problems in the hardcore Bitcoin world for the last several years has
been a lot of recommendations for this cold card product and not as much about let me break down
the tradeoffs for all the different, you know, devices.
And I'm not saying that's true of this channel, by the way, which has featured tutorials
for tons of devices.
I'm talking more about kind of a more broader view of the Bitcoin educator and media community over the last several years with CoinCite.
Drew, I want to get your response to Zach's points there.
And then I also want to throw in for conversation as well, too.
One of the things that this whole situation has me reevaluating is what should I prioritize in my Harbor Waltz?
What actually matters?
What might actually just be fluff?
What's really important at the end of the day?
So Drew, just want to get your response to Zach and everything we've been talking about.
And then also maybe some considerations on what people might want to consider as characteristics, things that should be maybe top of mind.
For sure.
And it's a great point.
Seed Siner brings up.
It's a great point Thomas and Zach bring up.
It's like, yes, the hardcore people, dice roll, rock and roll.
Like, we as an industry should make dice rolling cooler.
Like, that's a marketing problem.
So the crazy people, you know, I say crazy.
I'm one of them. We're all crazy here. You know, the maxies should make dice rolling cool again.
Now, to onboard grandma or grandpa or your normie friend and you said, yeah, you're going to write,
don't write a dice roll a hundred times. We're going to scare them off immediately and they're
going to go ETF, which is antithetical to what our goal is here. And the goal, in my opinion,
is to self-custody your value. So if they buy it,
the ETF, okay, fine, we will just slowly onboard them to, you know, their first hot wallet,
and then they're a cold wallet, and then they roll their own dice, and then they do multi-sig.
Like, I think there's levels to this whole thing, and we just have to kind of accept that.
And trying to get them to the last level possible of multi-sig, dice roll passphrase,
boy, we're going to speak to like seven people, and shoot, we have a real issue at hand.
So I don't know if I answer that.
the question, but that's what I personally think. I don't know, you know, left bell curve bro here.
We need more people self-custiting and meeting people where they are. And then also to seat
signers point of like, if you dice rolled and you spent the hour of learning of what that
actually means, you would not have had an issue. So now people are like turbo running crazy
pass phrases, which like, okay, but remember, if you forget to have passphrases, you. But remember,
If you forget that passphrase, you lose your Bitcoin.
If you do a multi-sig and you lose your descriptor, you are in deep, deep trouble.
So don't do something that emotional that you don't know what you're actually doing.
And then actually you lost your funds, but it was two years later and you don't know what you actually did.
That's what something I learned from this whole situation.
Seeing people not being able to sign a transaction out of their cold card was scary.
Terrifying.
to the least.
No, agreed.
Seed, I'll come to you even just for a second there too.
In terms of, you know, when we're talking to people and we're trying to think about what we should be prioritizing in terms of what we're looking for in a hardware device, I know that yours is going to definitely allow for user input in terms of user provided entropy, but what other kind of things are you thinking about or what other considerations you think people should have at this point in time?
I'm honestly reevaluating all the things I used to give a shit about.
It's like, because it didn't matter, right?
the analogy that I used is like, I had a great car, but there was no engine in the oil, so the thing didn't fucking go anywhere. And so I'm trying to basically challenge even all my own prior assumptions and really think about things moving forward. So see, I'll get your initial thoughts. And then Thomas and Zach will come to you. Hopefully I didn't come off too pugnaciously on the beginning of the call. I know I was strong feelings. I think it's important. And I tend to express them bluntly. What I'm hearing from in some of the other comments here is that,
your Bitcoin's security process is a journey and not a destination.
And right out of the gate, multi-sig may not be for everyone.
And right out of the gate, rolling dice 50 times may not be for everyone.
So I'd like to hear more of a narrative, hopefully going forward that, like, it's a journey.
And also, people like, we all have a tendency as human beings to simplify things in our minds
because we can only handle so much cognitive overload.
And like a lot of people, when they think about owning Bitcoin,
they have a number in their head of how many Bitcoin they own or how many stats they own.
And for whatever reason, people have a tendency to put all of their eggs in one basket.
And they want to be able to open up their wallet coordinator and just see that balance.
And like, ta-da, that's how many Bitcoin I have.
I also think we should start encouraging people.
There are other ways to diversify your risk too.
And maybe keeping 10 or 20% of your Bitcoin.
that you own on an exchange or a custodial platform, you know, that maybe there's an okay
risk reward with that as long as it's, you know, a provider that you feels reputable and you feel
like you have a good balance between what you're holding in self-custody and what you're not.
So having people thinking more carefully about their buckets of Bitcoin and what security
restrictions are in place for those different buckets is, I think something that is constructive
too.
And also one more thing, when we talk about, because at the core of a private key is random data.
And some people use the RNG that's built into a secure element to get that.
Some people roll dice.
Some people do a bit 39 lottery.
I think maybe as an industry, we can come up with more creative ways to just enable people to gather truly random data from the world around them.
With Seed Center, we have a pretty innovative feature
that I think we were the first to come up, maybe not,
but definitely the first time I saw it in a lot of places
was this idea of using the onboard camera
to gather random data from the world around you
and then incorporating that into the entropy
that goes into the private key.
And Keith, our lead developer has published
a pretty in-depth workup on this,
and we still feel pretty confident
that it's a great way to create
create a private key, but it does involve putting the most trust in our software stack and what
the seed center is doing. So people who really want the trustless option are still going to roll dice.
They're still going to do a BIP 39 lottery. But the pulling in entropy through the camera is
kind of a creative new way to think about creating a private key. And maybe there are other ways
to do this with devices that we haven't even thought of yet that could help create secure
private keys or at least salt the RNG data to get a couple of sources in there.
That's, I think I addressed your question, hopefully.
One company I like pointing people to when they ask about Bitcoin mining is abundant mines.
They were founded by Bo and Christine Turner after losing over half a million dollars to broken
promises in the mining industry.
And they built their hosting model to remove the usual headaches.
With abundant mines, you own your machines and keep.
100% of the Bitcoin you mine. There's no revenue share, no hidden skims. Pricing is simple. One flat
monthly fee covers power, parts, labor, and repairs. They also guarantee uptime. The machine goes down,
their hash rate redirect system routes hash power from their fleet, so earnings don't just stop.
And every machine is insured at full replacement value. Everything is hosted in the U.S., powered by
hydro and mining equipment may qualify for 100% year one bonus depreciation.
Learn more at abundant minds.com slash sessions.
That was great. Thomas, I'm going to get your response to.
And I do, I do want to just echo.
I do like that sentiment, both from UC and EZAC in terms of like,
best thing we have going for us is the free market and competition and trying out
and creative and thinking about new solutions going forward.
So Thomas, I want to get your response.
And then also in terms of when people, because they're trying to decide,
when people are trying to decide what maybe is the first of hopefully
many hardware walls that will end up in a multi-vender multi-sick.
When they're trying to decide what's important to them, what are you suggesting?
What are you thinking about in terms of what you want to see from your device?
Yeah, I just, when we talked about the camera and entropy, it reminds me, I'm going slightly
off topic here, but as you probably know, Cloudflare, you know, the CDN network company,
they actually have this, you know, wall full of lava lamps because that's...
We all need lava lamps now.
We all need them at home, right?
So just a cool story.
Anyway, I really like the journey, you know, angle because it really is a journey.
Like, honestly, it doesn't really make much sense to store $20 of Bitcoin in a hardware wallet that costs $100, right?
Like, it does make sense, you know, to test it out and everything, but it doesn't make sense to secure 20 bucks, you know, using a device that is five times the price.
I don't think it's a journey.
So you maybe even start with the software wallet, right?
You test it out.
You know how Bitcoin works.
You educate yourself.
Maybe later on you get a hardware wallet.
Again, you play around.
And then I totally agree it makes a lot of sense to end up in some form of multisic.
As you put it, exactly, it should be multivander.
It doesn't really make sense to have three treasers in one multisic.
It gives you some security.
Like additionally, it does.
But, you know, it doesn't really appreciate it.
protect you against these kind of failures as what happened with Cold Card.
So it makes a lot of sense.
And I think it's a journey where you start somewhere and then gradually as you learn,
you can end up in some more comprehensive setups.
Zach, I want to come to you and ask, like, how do you think maybe even as like your own business,
as an industry, as the podcasters and everybody hanging out here, how do we maybe continue people
on this journey?
How do we try and maybe push that message where, because it feels like people kind of said it
and forget it. We all maybe get kind of a little bit lazy. So be curious your thoughts on that.
And I also just want to highlight too, because this one kind of stuck with me that,
um, to your point, Tom, I was like, even if I had like a three or five multi-sig and four
were a cold carb, but just one was a treasurer or a passport or a jade or a seed signer,
that would have been enough to protect me so long as I wasn't reusing addresses and that
public key information wasn't out there, I could have, they, even if they had the four keys,
they wouldn't have the descriptor. And so as long as I use something like slipstream,
I still would have lost my fun. So even in that circumstance, but there was a quorum of cold
cards. I still would have actually been in the clear so long as I didn't publicly broadcast.
And thank God, Mara was letting everybody use SlipStream. But it is, I think, I think ultimately,
at least that's the way I'm leaning that I think that's the direction we want people to end
targeting is I hope that one day you're in a multi-vender, multi-sign, you're very comfortable
with it. Anyways, tons of stuff there, Zach, journey. Where's your head at, pal?
Yeah. This multi-vender multi-sig thing, I think is great.
But I also think I was just pretending that I was a new Bitcoin or listening to
to that.
Slipstream multi.
No, I mean, it's.
No, you're right.
You're right.
Right.
I mean, just listen to that conversation of the last couple minutes.
I think that.
So just to go back to as well, like just this entropy conversation and random number generators,
everything like that and what to look for in a hardware device, what features are valuable.
I mean, I think that this.
I think you have to trust that the random number generator is going to work properly on these devices.
I mean, you don't have to if you're hardcore, but for most people, there has to be some level of trust.
But this idea of open source and reproducibility and getting lots of eyes on the code,
both human eyes and, you know, the clinker eyes as well, is really important.
And all of us have now gone through this in the last two weeks with the Bitcoin Red team.
And so I do think that a big takeaway for this is demanding free and open source software and hardware that is reproducible,
that you know, where the company is being transparent about, you know, everything and publicly engaging with the security researchers and the red team.
because then you could have some confidence that the initial setup and onboarding,
which could include allowing the device to generate, you know, a seed word for you, is secure.
And so I think that this is a really interesting group that you assembled because all of us are free and open source projects.
And all of us are reproducible projects, I believe.
And that's amazing.
And we have to understand that we represent a sliver, or maybe not a sliver, a chunk of the industry that does this.
But if you look outward to the larger crypto industry, that's not the case.
There's a lot of closed source black box, sometimes a little sketchy stuff going on.
And so when I think about what do you look for, sure, I can put forward some bias around user experience and features and foreign,
factor and onboarding and backups.
But I do think that everyone needs to demand this open source, like actually open source,
right?
Like real open source licenses that actually engage with the security community,
which has grown massively in the last couple weeks.
And everyone will know that like this code for the most important stuff on the device,
the signatures, the entropy, all of that stuff has been looked at by other people.
and that I know that the code that's on GitHub matches the code that's on the device because of the reproducibility.
And I think that's just going to become a requirement.
I can't imagine that all of these like closed source black box companies are going to be able to move forward in the coming years after this incident has taken place.
The only reason why, too, everyone was able to respond and help so many people save their funds was because at least the code was source available.
and everyone was able to figure it out within minutes or hours what happened
and then guide people to safety.
So maybe that's a different reframing of your question.
But it also comes back to that like original second question from Ben about the,
how do you don't trust verify, right?
There's probably going to be some trust,
but you're almost trusting that many others have been able to verify
that this hardware works the way it was supposed to.
So I just don't want to drag this conversation into,
to a multi-vender, multi-sig dice roll conversation.
I just am still very worried we're going to turn away a lot of people.
But on your journey, obviously, I think that's a pretty cool place to end up if you're
able to end up there.
Now, quickly, before I come to you, Drew, I think it's worth highlighting for people that
might not necessarily know.
It's at least worth addressing because there are probably some questions in the audience.
What is the difference for source viewable and why did it mess?
Why do you think, where do you speculate it may have failed in this instance?
I think that if having the source code online does allow people to view it, but it does not allow other people to build with it or on it.
And so an example would be that many of us are building on open source libraries that other companies have published, whether they're for-profit or nonprofit.
of it. So example, you know, Cold Card was built back then before early 2021 on the Trezer
crypto libraries. Passport, the first two generations of Passport Founders Edition, Passport Core,
also included some Cold Card code and then also the Treasor crypto libraries. We now use things
like BDK, which is, you know, from Block, many other companies use. You know, we use Rust Bitcoin,
which is quite popular as well. If you have a, uh,
free and open source block of code that other companies are using, I personally think while there's
pros and cons, because of course, if you found a bug, it could affect now more than one company.
So I want to be transparent about that. But the pro is that I think you have a dramatically
higher likelihood of finding something wrong if multiple companies are building on it. And so when I
say free and open source, it's about using the license that allows this permissionless use of the code.
because we all build on each other's stuff.
That's how the entire internet was built.
And then also there's an aspect, well,
doesn't necessarily affect the FOSS side of things.
So maybe I won't dwell on it,
but of just the way that you engage with security researchers
over time as well.
And I found personally just looking at everything,
that the companies that are doing the FOS stuff
also have wonderful relationships
with the security researcher and the security community.
Beautiful. Drew, I want to get your thoughts on the open source nature of being a necessary kind of requirement and the benefits of it and just, well, a lot that we've said here today so far.
Sure. I won't speak so much on the tech side of it. I'm going to speak more on the culture side of it. If we as a team, as a community have the culture of, yeah, audit our stuff and let us know when things are broke. And we encourage that behavior. I think we as a community, have the culture of, yeah, audit our stuff and let us know when things are broke.
and we encourage that behavior.
I think we as a community benefit greatly from it and not carrying a massive ego along with it.
Sometimes, sorry, shit happens.
And we as a community need to accept that and be okay with fixing things.
And when we belittle people or belittle problems and be like, ah, not an issue because we're,
were false or were source viewable,
no one is actually going to look at it
if you don't fix the problems.
So fix the problems and encourage people
to help you fix the problems.
That's my take on this.
I want to quickly tag in there before I come to Thomas
and see it again.
Drew, I'm curious if we assume that the vulnerability
was a result of an open source AI model
found it and then somebody was exploiting it,
if I take that theory and just kind of run with it,
has that changed the practices
at Blockstream at all kind of going forward
in terms of maybe frequency of your own audits.
The other thing I kind of thought of is like,
I don't know if it doesn't necessarily evolve,
but I kind of half expect in the same way,
like on the back of my food,
it gives me the nutritional requirements
and a whole bunch of information that I might look at,
but I'm getting chips.
I already know it shit, so I don't care.
That I almost kind of expect that like when I go
and maybe get the latest firmware update,
there might also be an option to download
like latest Kimi report on the code, right?
That might just be something that just becomes standard,
like, yep, go ahead it.
You can buy it.
Here's the latest report from August 7th in what we found.
I'm just curious that there's,
any changes or even thoughts for your process as a block stream.
A thousand percent, the thoughts are being had.
The conversation is being had.
It's how you best go about doing that and sharing that information.
Obviously, we want people to do their own research and audit our own code and anyone's code.
It's how you best share that with people for them to use that information to better audit
the code themselves or just trust.
The big word for today is trust.
the Kimi report. It's what's the most beneficial and again like how do we not scare
grandma at the end of the day like oh Kimi audited it like cool and what does that
mean for the average person? Thomas your thoughts? Yeah I totally agree with
everything that has been said. I wanted to also add one more thing to the you know
open source source available close source topic.
I think open source is a very vital part of the whole security story, right?
I think sometimes we do this shortcut where we say open source equals secure.
I don't think we should put it that way.
I think open source is really very important part of the puzzle, right?
But that doesn't mean that we shouldn't do all the other things, right?
We should still exactly do free and open source, right?
so other companies can build on top of it.
We should have good bug bounty programs, you know,
to have researchers incentivize to actually look for bugs.
We should have good relationships with them.
We should do independent audits from regular companies, not just AI.
We should also do the AI.
What I'm just trying to say, I think it's a piece of,
it's one big puzzle and open source is a very big chunk of it.
But I don't think, you know, it needs to imply the security right away.
I'm looking at the required condition on top of which we can, you know, build all the, all the other stuff.
Beautiful. Seed, I want to get your thoughts. And I also want to throw in there. I think even for like me personally, I was so fixated on like, let me say, like the physical security of the device.
Nobody could get into the secure element. Nobody could figure out the pin that I maybe even didn't necessarily give enough waiting to the other threat models.
I mean, I think more coins are lost or lost through scams, and now we're looking at bugs,
and we're also talking about foot guns.
I just wanted to throw that out there, because, again, yours particularly being a stateless device
is a very different sort of setup.
What are your thoughts on maybe where the, we'll say yourself or the industry,
should be putting its attention in terms of prioritizing the different risks that are out there?
Off the top of my head, just real quickly, most conventional harder wallets are actually doing three jobs.
They're creating, hopefully secure private keys.
They're then storing a digital copy of the key and putting access restrictions around it in a reasonable fashion such that if someone got a hold of your device,
they wouldn't be able to very quickly at least steal your Bitcoin.
And then the third thing is, of course, creating signatures for transactions and relaying them to a coordinator application that in turn can broadcast them on the blockchain.
I don't know, I don't know if this will actually happen in the industry, but I would, I would kind of like to see more thoughtfulness around those three functions.
And maybe one of the, one of the things that make seeds that are so powerful is like we're less ambitious about what we're trying to do.
We're not trying to store private keys securely.
We're very intentionally not trying to store private keys.
we really have thought carefully about the private key creation and offloading some of that responsibility on the users.
And we focus really on just like it's a secluded environment where you can work with your private key and create signatures so that you can spend Bitcoin.
Maybe we need to think more about those three distinctions and how ambitious products are in terms of what they're trying to accomplish for people.
that I'll
like I
personally do want to scare grandma a little bit
I think
I think grandma can take it
and I think
I think grandma can take it
and I think we don't give grandma enough credit
maybe like a seed center
shouldn't be grandma's first stop
but I get a lot of insight
in the people who are who are kind of uncle
jimming and being that hand holder
that walks people through things
and I constantly get deem from people that say,
like I set my wife down with a seed signer.
I've tried to teach her other harder wallets before,
and for whatever reason,
that's the one that she grocks,
and that's what makes sense to her.
And maybe that'll be the case for like,
maybe Trezer scratches somebody's itch or Jade does,
and that's the one they understand.
I think diversity in the industry is also really important too,
and we're probably moving in that direction.
But, yeah, that's,
That's what I was thinking.
Nope, fair enough.
Seed, I got another question for you.
And gentlemen, I'll actually pass the question to all of you because this is the one
that people keep asking me.
And so I do want your honest opinion, whatever comes to mind, whatever you'd like to share
with the audience.
So Seed, starting with you, if I say, hey, you know, you should check out SeedSider,
maybe consider it as your signing device.
And their immediate first question is, well, how do I know that it's safe?
How does someone know that SeedSider is safe?
And I think you have the easiest job here, but how do we know that Seed Siner is safe?
Oh, gosh.
That's like, that's actually, you may think it's a softball, but that's a tough question because there are so many caveats.
There's no ultimate security.
There are only tradeoffs.
Agreed.
And so with Seed Siner, we work hard to try to put more of the variables under people's control in terms of maintaining their privacy because they can build it themselves and they can source the components in a more discrete fashion.
And I feel like they understand more about the process of creating private keys, using those keys to set of wallets, and then drafting transactions and moving signatures around.
I feel like the way our workflow kind of happens, just people feel like they have more understanding of the process.
And then also the simplification of like, we're not going to store your private key.
You need to take that physical copy of the private key.
And you need to figure out, like, is that part of a multi-sig?
Are you keeping that in your gun safe?
Did you add a bit thoroughied passphrase to it because you're worried somebody's going to find it?
Are you putting in a state deposit box in a bank?
Is it in Tampa Evident packaging?
Like, you need to carefully think through the steps of how you're physically securing your private keys.
But, like, we need hardware wallets.
That's probably like a contradiction as it came out of my mouth.
But, like, people need wallets where they can have the keys nearby in a convenient way with reasonable access.
restrictions placed around them because again like I said before we don't want people
putting all their Bitcoin in their one bucket people are going to have like
smaller accounts and medium size like Bitcoin wallets like a checking account
where they're going to make purchases and they want to have those keys handy
and harder wallets are a really important part of that and they're a really
important part of this whole multi-vendor multi-stake thing that we've talked about
multiple times so gosh like seed sider is one of those things you got to do the
work you got to educate yourself
it's a great option, but it's not the only option.
So I probably flubbed your question there, but those are my thoughts.
Hey, that's perfect.
Zach, someone comes to me and says, well, how do I know passport safe?
What can we tell them?
Yeah, so a few things.
So one is I might sound a little bit like a broken record with the open source and
reproducibility, but I mean, we do all that.
It's a really core part of our DNA.
You know, you can have confidence that what's running on the hardware, you know,
matches, of course, what's on GitHub.
For random number generation, we do something cool, a little different.
We combine what we call an avalanche noise source into the mix.
So we're not only relying on the black box random number generators from like the secure element or MCU type chips.
We have a series of components on the circuit board that allow for a more auditable and inspectable way of generating random numbers.
Then we combine that with other entropy sources as well.
So that's kind of cool.
another thing is that we exclusively manufacture in the United States and I'm at the factory frequently
and I think that whole idea of like what's the manufacturing process look like what's the provisioning
process look like you know where is it made where is it shipping from is something that in my
opinion is important and I think is kind of overlooked you know when looking at the industry and
thinking about how you know all these devices are made and then finally just like and I think
this is the case for probably most of us here at least that are you know
companies that are, you know, selling and making these kinds of products and devices.
But like, we have real code reviews, right?
We have real engineering team.
We have AI-assisted, you know, automated reviews now.
And we just released a new version of our firmware, very minor update last Friday,
but we began to include in the release notes details about what AI models were used.
Just like you were saying, not, I don't think we have a full downloadable report,
but we include like, did it find any critical issues?
Did it find any high issues?
And we also have, you know, a long history of engaging really well with like the security
community and everything like that.
So that's how I would answer it, right?
It's some cultural aspects.
It's some, you know, development process and company aspects.
But then it's also a couple of things about the hardware or how we make it that I think stand
out.
Yeah.
Beautiful.
Drew.
How do I know the Jada safe?
Yes, free and open source.
And we said we never repeat that.
But there it is.
If you don't trust Blockstream to send it and build your device, that's totally fine.
You could build it yourself with off-the-shelf parts for ranging from $10 to $50.
So have at it.
Beautiful.
I love it.
Straight to the point.
Thomas, same question.
How do we know Treasur's safe?
And I actually be curious, too, if you're pulling entropy from other sources, because I believe
the Treasers pulling from the computer's RNG as well.
Yes, yeah.
So I'm going to disappoint, Drew.
I'm going to repeat it as well.
So free and open source, you know, reproducible builds, all that.
To your question, yes, we're sourcing entropy.
So already from Treasure Model 1, you know, it was 2013 or 14 or whatever, already back
then we generated the entropy on the chip and we actually mixed it from with the entropy from
the host, from the computer or your phone.
So, you know, we mixed it.
So even though if there would be some issue with the chip,
one on the chip, we would actually at least get the one from the computer, right?
And with our latest Treasor Save 7, we actually have four sources.
So this one, the generic chip, one secure element, secure element, and the one from the
computer.
So the more, the merrier.
And we are, yeah, mixing all those together.
So that's part of the story.
Then we also, you know, we have this device check that proves that the device is genuine.
also playing with some post-quantum protections, but hopefully there is soon enough for that.
Bug bounty program. Should I say open source again? Before I already said it. That's probably it.
Beautiful. Okay, a couple more things I do want to hit on. We actually, just this morning at the time
of recording too, we had an unfortunate one of the, I believe it's a third party distributor for
Trezer that the customer data was leaked, was hacked, was stolen. And I know that distribution is
ultimately going to be an issue, I think, for all of you guys here. So, Thomas, I'll start with you,
but I wanted to get your thoughts on kind of what happened. I know we have very little information,
but maybe even just some suggestions that people can use going forward if they're concerned about
those sort of things happening in the future. So I think as a whole, we're going to constantly
be under attack. We've got to kind of maybe start to think about these things. Again, for the
crazies like us that are going to do the multi-vender multi-sick stuff. Yeah, so, yeah, as you've said,
this is very fresh. So we found out just on August 10th,
So, you know, it's just a few days ago.
We try to, because, you know, transparency is part of what we do.
So we really try to, you know, inform the public as fast as we can.
So we are still, it's still very early on the details.
But, yeah, what happened?
Our fulfillment partner, you know, the company that is actually sending out treasures,
they had a security incident.
And somehow, and again, we don't know the details.
You know, someone accessed the data that unfortunately, you know,
our customer data are part of. Again, I want to stress, you know, that treasure device is safe,
you know, this is no vulnerability in our systems and our devices. It's always, you know,
important to say. That being said, and I should also say that out loud, I'm really sorry for
all of those affected because we don't take this slightly. What we're actually doing at treasurer is,
you know, limiting the data to 90 days. Luckily, we are actually, we're able to push these policies
also to the fulfillment centers that we use.
So they are also scraping data after 90 days.
So at least, you know, the exposure is limited.
And honestly, yeah, I mean, this is such a loose-lose situation
because we have to use these partners.
I know a lot of people, you know, it's not going to believe us.
And, you know, we're getting a lot of feedback.
Why are using these?
But it's we are, you know, selling to the whole world.
And we just cannot send it, you know, from one.
place ourselves, right? We cannot really drive the parcels ourselves to everyone who order
the treasure. So we do have to use these third parties. We're using reputable companies,
you know, with all the fancy certifications and all that. It's really, we are doing due
diligence, but this is a tough job and unfortunately it is still not enough. So as said, I'm
really sorry for everyone affected. It is very hard.
It is a loose, as I've said.
What are we trying to do to improve this?
We want to actually launch an anonymous delivery.
It's something that we are working on for a few months already actually.
So basically, no delivering into those delivery boxes.
So I think it's quite big in Europe.
In US, it's maybe not that big of a thing, but still there are options.
So we're actually trying to push this.
Actually, I believe next month, by the end of the September,
we should be able to launch it in Europe.
Europe, US will come next probably towards the end of the year.
You know, the irony here is that we need these fulfillmentes to collaborate with us on that.
Like, we cannot again do it ourselves.
So, you know, it's part of the story as well.
So that's part of that.
And then again, yeah, like ideally order, you know, on fake emails or, you know, just do burn addresses and all that.
But again, like, we don't expect all the grandmas to do that.
So we're also trying to do more on the product side of things.
and launch stuff like anonymous delivery.
Drew, any thoughts there on distribution?
Yeah, sucks.
It's not something to dunk on anyone for.
It is an unfortunate reality of the business.
Yeah, right.
Everyone has delete data after 90 days.
You rely on third party to ship your stuff.
You have them delete the data,
but they need the data exists for legal reasons.
So use burner names, use burner emails, use PO boxes, use drop places.
And this might be a controversial take.
Look into your local resellers, see if they have a store you can go pick up from.
They are vetted to make sure that the legit people.
And like kudos to Ledger, right?
They have, and maybe Trezer too, like you can go pick them up.
in big box stores looking to that.
Yeah, it's not a fun situation.
And I, my heart goes out to Trezer and the customers.
Not fun.
Not fun.
I agree.
And you're right.
There is,
there is an advantage to even like at a conference or something buying directly
from somebody.
I know we're introducing other risks there,
but you can pay in cash,
right?
So you can go and get your hardware wallet.
Nobody knows your name.
You're paying cash and you kind of move on.
Zach,
your thoughts on that?
Just that like,
this shows how much of the legacy infrastructure.
structure is dependent on multiple third parties because it's not just that you have to use a
fulfillment provider or you might use a shipping label provider but then like the carriers also
maintain all this information for much longer than 90 days you know UPS FedEx in the U.S.
and so on so I don't want to say that there's a perfect solution because there's not and it's
actually one of the things that I'm concerned about, just to echo what everyone else has said,
just if you do have a, you know, if you are worried about this, you should be picking it up
or shipping it somewhere that's not your home. But it's just kind of like how you said,
turtles all the way down earlier. It's kind of the same thing for the shipping. You get the, you choose,
like, you just choose one of them and then maybe they're using UPS, maybe they're using Amazon
fulfillment. Maybe they're using FedEx, but all those companies are also retaining data no matter
what you do. So it's just a really difficult situation. And I'm sorry, obviously, this happened
just now to the Treasur guys. And it's one of the things that I'm constantly worried about. And,
you know, we're going to try to add like the pickup points to our site as well. But like,
just because you add them doesn't mean people are going to use them. Just because you recommend using
a pseudonymous email address does not mean that the majority of people will.
and you can't force anyone, you know, to do this.
Agreed.
Seed, any thoughts?
Just kind of a unique perspective.
It is a really hard problem to solve.
And from what we've seen with Seed Siner is a lot of people that, like, discover Seed Siner
hear about it or first encounter it through their local Bitcoin meetups.
And I've been talking about for a while, it'd be kind of cool if some of the larger meetups.
like New York and triangle bit-debs and something like that,
if one person that is like a known person with a meetup that has a good reputation
and is to some degree trustable could kind of become,
I don't know if you call it like the armor for the meetup or whatever,
but like one person could take delivery of, you know,
smaller batches of devices from Trezer and,
and, sorry, foundation and blockstream,
and keep these devices on hand for those monthly or bi-monthly meetups
where somebody comes and they need to buy a harder wallet.
You know, the person selling them can maybe tack on an extra 10 or 20 bucks
to make it worth their while.
But they basically take the entire hit as far as identity goes.
And I think that's not going to solve everybody's issue
and not everybody goes to meetups,
but it is a way to get more of these devices into, like,
really active bitcoiners hands without requiring them to give up their identity and close. So just a
thought. That's a very interesting, a very interesting thought. And I think that's exactly what we
kind of need at this point in time. I, for one, am looking forward to the four of you collaborating
on a carrier pigeon service that can then distribute other hardware across the globe. I think that's
probably the safest and best way to go. Gentlemen, this has been absolutely phenomenal.
And I think it was hugely important. I'd maybe love to do it again in the future if everybody
is down. I look forward to hopefully maybe some more collaborations amongst you.
yourselves moving forward. Maybe I'll get my hardware advent calendar, like a different device for each day
come Christmas. I think that'd be great. We'll go around the table just make sure everybody knows where
they can check out your stuff, find things. Seed, I'll start with you. Where can everybody go to learn more
about the SeedSiner project? Let's see, seedcenter.com. We'll go into the details, but we
are not. Dotnet.org.org.edu or any of that, make sure you go to Seedcenter.com.
We're active on Twitter and post information about the project there from the dot com website.
You can find a telegram community where we have a really healthy discussion and great helpful
people there who, if you're intimidated by the idea of building a seed signer, can walk you
through on where to find the components and how to think about it and put it together and all
that sort of things.
So great telegram community.
Follow the seat center account on Twitter.
And one thing, one other thing I'll throw out is on
the dot com website.
If you go to the explainers tab,
we have a bunch of great videos,
a few by Bent sessions,
as well as some other great Bitcoin educators
who kind of walking through the process
of building one and using one
if people are just curious to see,
like, what is this thing like?
But that's all I've got.
Beautiful. Thank you.
Zach, where can everybody go
to learn more about you or foundation devices?
And just the reason I almost spit out my beverage there
was because if you go to one of the,
these other SeedSigner websites, you may find yourself directed to Bitcoin Notts website or
somewhere else. And I think we kind of know who is responsible for that. But anyway, so you can
learn more about foundation at foundation.xyZ or Foundation HQ on X, and I'm at Z Herbert on X,
and you can learn everything about passport and purchase on our website. Drew, where can we go
to learn more about you and about Jade and Blockstream? Great. Thanks for having all of us. This was a lot
of fun. Maybe we should get Advent calendar together. Most active on Twitter X at Blockstream, Jade,
and then me personally, Drew Fisher. I hope everyone comes out of this conversation,
more white-pilled than black-pilled. It's an unfortunate series of events that have occurred,
but Bitcoin is better because of it. So onwards.
Beautiful. And Thomas, where can people go to learn more about yourself and Treasurer?
Sure. Treasurer.O. is our website. Treasurer basically everywhere, X, LinkedIn and all that.
Me personally, T. Susanka on X or LinkedIn.
If you enjoyed this roundtable with all the hardware manufacturers, please do like and subscribe
and check out the previous episodes with either Parker Lewis or Simon Dixon.
