TFTC: A Bitcoin Podcast - 777: Coldcard Is Compromised with James O'Beirne
Episode Date: July 31, 2026James O'Beirne joins Marty to break down the critical Coldcard RNG vulnerability affecting devices produced after 2021. They discuss how insufficient entropy generation exposes private keys, why MK2, ...MK3, MK4, and Q users must migrate funds immediately, and how AI models accelerated the discovery. The conversation covers multisig risks, passphrase limitations, dice roll safety, and the broader collapse of trust in single-vendor hardware wallets. Essential listening for Bitcoin self-custody security. James on X: https://x.com/jamesob Find the Home Mining Playbook here: https://www.tftc.io/home-mining-energy-playbook STACK SATS hat: https://tftcmerch.io/ Our newsletter: https://www.tftc.io/bitcoin-brief/ TFTC Elite (Ad-free & Discord): https://www.tftc.io/#/portal/signup/ Discord: https://discord.gg/yHGkvYxdqT Opportunity Cost Extension: https://www.opportunitycost.app/ Shoutout to our sponsors: Block: Cash App: For a limited time, new customers can get $21 added to their balance. Just use code TFTC10 when you sign up, and send at least $5 to a friend in the first two weeks. Terms apply. Bitcoin services by Block, Inc. See the Bitcoin disclosures at cash.app/legal/podcast. Square: Visit http://square.com/go/tftc for up to $200 off eligible Square hardware. Bitkey: Use code TFTC10 for 10% off the new Bitkey. Aven https://www.aven.com/bitcoin CrowdHealth https://www.joincrowdhealth.com/tftc Unchained https://unchained.com/tftc/ Salt of the Earth: https://drinksote.com/tftc Join the TFTC Movement: Main YT Channel https://www.youtube.com/c/TFTC21/videos Clips YT Channel https://www.youtube.com/channel/UCUQcW3jxfQfEUS8kqR5pJtQ Website https://tftc.io/ Newsletter tftc.io/bitcoin-brief/ Twitter https://twitter.com/tftc21 Instagram https://www.instagram.com/tftc.io/ Nostr https://primal.net/tftc Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/martybent Newsletter https://tftc.io/martys-bent/ Podcast https://www.tftc.io/tag/podcasts/ Disclosure: Bitcoin services are provided by Block, Inc. Bitcoin services are not licensable activity in all U.S. states and territories, and not all services are available in all states. Bitkey is not available in New York. Block, Inc. operates in New York as Block of Delaware and is licensed to engage in virtual currency business activity by the New York State Department of Financial Services. Bitcoin is a non-deposit, non-bank product that is not FDIC insured and involves risk, including monetary loss. For additional information, see the Bitcoin disclosures: https://help.cash.app/btcdisclosures Get up to $200 off Square hardware when you sign up at http://square.com/go/tftc! #squarepartner. Offer expires December 31, 2026 at 11:59 pm PST. Offer for $40 off the cost of one Square Stand, $75 off the cost of one Square Terminal, $100 off the cost of one Square Handheld, or $200 off the cost of one Square Register, excluding applicable taxes. Limited to one discount per product type per seller account. Each code is limited to one redemption per account holder. Valid for new Square customers located in the US only. Offer not valid with guest checkout. Square reserves the right to modify, revoke or cancel the offer at any time. Offer cannot be combined with any other coupon. Void where prohibited, not redeemable for cash, and non-transferable. #squarepartner #blockpartner
Transcript
Discussion (0)
You've had a dynamic where money's become freer than free.
When you talk about a Fed just gone nuts, all the central banks going nuts.
So it's all acting like safe haven.
I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins.
In the world of fiat currencies, Bitcoin is the victor.
i mean that's part of the bull case for bitcoin if you're not paying attention you probably should be
yeah i don't i don't think we can assume everybody's hurt and i know i think that's
a bad assumption just because i've been texting people i know have cold cards and they're
completely oblivious to what was going on last night so yeah um sad day yeah we've uh talked
under better circumstances for sure um for those who are unaware uh there is a massive vulnerability
in cold cards produced after 2021 all models some um worse than others but essentially uh
the random number generator that creates the entropy for private keys that you produce
using the cold card is insufficient is that the right word to use yeah it's um you could call it
deterministic uh so the the search space required to get the private key to guess the private key
basically is highly highly limited relative to what it should be um so basically the you know
funds under the mk2 mk3s with firmware between you know 2021 and 2023 are just kind of like
dangling in the wind so luckily if you used dice rolls you know if you used say over 99 dice rolls
to initialize the key you're you're safe um and or if you're using a passphrase uh which is
basically like the 25th word you can specify when you're setting up the wallet.
If that passphrase is of a sufficient length and complexity, which is longer than most people think, then you may also be safe.
But, yeah, those the MK2, MK3s are affected severely to the point where it's like, you know,
you need to drive home from work and migrate your funds if uh if you're single sig under one of
those uh without a passphrase without dice or with a weak passphrase but we're finding and it's part
of an ongoing investigation as to the current state of the cold card firmware um which would
affect like newer devices like the queue we're finding that the problem still exists there too
but it's partially mitigated. So estimates right now are that current users of cold card devices
are getting about 70 bits of security, whereas you're supposed to be getting 256 bits during
key gen. But that 70-bit number is even going down because we're finding that one of the fallback
RNGs that is used to paper over the original defect is actually less random than we thought
and is specified by the manufacturer. And, you know, they may be doing things like zeroing out
certain parts of this ID. And so it might actually be worse than we were thinking last
night for current devices. So my headline for everybody at this point is if you're working off
of a cold card device, you, after 2021, you need to migrate, you know, your funds pretty
expeditiously. If you did all the dice rolls, don't worry. You're probably in good shape.
But even so, yeah, I think, unfortunately, people should be making moves to get off of the
post 2021 devices yeah i mean we're trying to find some humor in light of this but cold card
hey listen i've been an advocate for cold card for for many years if you listen to the show
i recommended it i have my queue right here i moved my funds off last night um obviously a
part managing partner 1031 we're invested in coin kite which produces a cold card i mean this is
very close to home um for me personally to many people i know that have felt very confident
um recommending this in the past and it seems that the confidence was uh was ill-gotten
we were we were joking before it's like the cold card souped up to secure enclaves but you mess up
one part of it the random number generator so you get a ferrari on top of a lawnmower engine
well pretty devastating i'm in the same boat man i mean i i'm a single sig passphrase guy on a
cold card you know i think mark two uh my firmware is older and unaffected but
um i love coin kite you know they make great products um but the unfortunate nature of security
and hardware wallets is that you screw up one thing you screw up the wrong one thing and
it's toast and and so that's that's the reason why people have you know been sort of paranoid
in this department is because like you just simply can't trust one manufacturer or one source
for your entropy you know when you're doing entropy construction and this is what i do
professionally for the last few years um is you you have to be utterly paranoid when you're
constructing a private key and um you can't just click a button and expect that it'll happen you
know um so it's yes it's really it's really sad to see because i recommended hold card left and
right you know um the people who i thought were savvy enough uh to use them and um i'd say like
aside from you know getting yourself safe my message to people would be think about who
is a sort of more normal person than maybe you are listening to this podcast who you've
recommended cold cards to who maybe isn't like following bitcoin twitter um you know
give them a heads up if you got them set up with a cold card um i've got a few such people in my
life that i've reached out to yeah that's why i wouldn't that's why i hit you up last night to
record this and i'm distracted right now because i'm about to send out a newsletter that just
covers this as well um and i gotta give one more prompt to my clanker to give something make
something very clear here but uh dive in dive into the math so you mentioned like
later versions people are saying potentially 70 bits of entropy he should have 256 mk2 mk3
after 2021 even less i think it's like 30 yeah two bits 20 20 seconds yeah and i mean the nature
of the attack i mean this is obviously very much centered on on coin kite and cold card however
um ai comes into the mix i mean this is a new era of security vulnerabilities and i mean we've been
talking about it for the better part of a couple years now on this show and others that these
models once they get sufficiently intelligent we'll be able to uncover these and it seems like
that may be exactly what happened yesterday it's totally plausible man um you know me and a number
of other researchers uh very quickly independently reproduce this just by giving the ai kind of a
pointer as to hey you know between this window of time between these firmware versions check
for an rng problem and uh kimmy k3 shoot shoot through it and found it readily um
and uh yeah look if you're a sort of unscrupulous attacker um and you're willing to just sit there
there and grind through you know take any open source bitcoin software you can and just say hey
file by file go through look at the entire history um you know find something that's plausibly an
exploit all that stuff's going to get unearthed so um somebody i was talking to yesterday put it
this way he said uh you know security by obscurity is going to zero rapidly um and everything you
know the the tide's washing out um so it's going to be really wild a few weeks and months and
probably years yeah i mean outside of bitcoin i mean matt and i discussed some on rhr where
there was a water system in minneapolis that was attacked it looks like with some vibe coded
um llm attack and
what um how big of a setback do you think this is
well you know me man i'm i i tend to be um somewhat pessimistic in the short to midterm
um and my real worry aside from like the horrible tragedy of a bunch of good
people losing their coins um that's obviously horrible um i'm i'm a bit worried about the
second order effect of this being a hit against kind of the most reputable hardware wallet vendor
you know among hardcore bitcoiners that kind of like rippling out into a notion that well
even the smart guys screwed up self-custody and how can we expect that anybody you know will
comfortably self-custody after this point um yeah so i don't necessarily agree with that because
again if you kind of followed best practices that were recommended you know you'd have avoided this
pickle purely by obeying that principle that you can't trust a single manufacturer or you know you
have to bring your own entropy to the table somehow but even so i i i worry this event's
going to get a lot of play and um you know maybe the general public is going to be like
that bitcoin thing that's impossible to keep safe by yourself so just got to use a custodian
i mean the irony the whole situation is with all the eyes and compute focused on the
cold card repository right now by the end of the week and maybe the most secure
secure system in in the space but again the trust is very hard to build very easy to break
yeah that and that's the problem um and um you know in some ways this is is a sort of inexcusable
error if you are uh a company making the product that they make and so i i you know again the coin
card coin kite guys are friends of ours certainly of of yours and mine and uh even so it's like
i think huh what the yeah it's it's going to be hard to trust anything that comes out
of that brand anymore you know um so it's uh you know i mean the thing like
it feels like every single hardware wallet manufacturer has made some kind of
like fatal misstep again because this domain is just very hard you know let a ledger spilled
you know all of their clients information essentially back what was that like 20
you hit it twice okay yeah yeah probably most multiple times you know bitbox had some pretty
um pretty obvious physical defects that allowed key x filtration um i don't know specifically
if anything has befallen trezor or not um but you know it's just it's kind of the nature of the
the game that these things get hit with something um and even if they aren't obviously hit with
something the very fact that it's a security critical bitcoin device means that their whole
supply chain is probably targeted the companies themselves are targeted for for intervention so
So, um, custody is tough, man.
It's really tough.
Um, and I spent many years, you know, hoping we could make it easier with better scripting
primitives and covenants and vaults.
Um, but, uh, you know, I think given the community is more fractured than ever, I'm not sure
we're going to get there.
And it's certainly not in the next year or two, but I don't know.
I think, I think this may light a fire in our people's ass to figure that out.
figure out how to get that stuff through i mean a lot of the conversation there's back and forth
people on both sides of the aisle like now's not the time to talk about this and i think
alex b from from uh arc labs um arcade was making some good points it's like hey like don't worry
about obscure covenants when we haven't even verified like ren number generation on some of
with these wallet
providers. There's a point there
but again, you're going to
there's a sort of inescapable
point, which is that
even if you supposedly
verify all the RNGs, you just
can't, again, you can't trust one
manufacturer. Even, you know, like
look, I'll pick on
say BitKey because that's being touted
as like a migration
target. And I think the world of that team
and I know a lot of the guys who wrote that
they're super smart, but
You know, like, are you really auditing their whole software stack?
You know, like, BitKey requires on-device software, you know, that's closed source.
I know a lot of it is open source, but some of their backend services are closed source.
So it's like, you know, until you move some of that security into the chain itself, you're not going to be able to, like, trust one provider.
And that until we get until we solve that, you know, it's like, OK, well, all right.
So I go to two providers. I set up a multi-sig for myself.
So that's that's kind of a horrible user experience or a worse one for sure.
So, while, yeah, I mean, Alex's point is taken that, like, there are fish to fry in the auditing department.
I think the only categorical fix for a much better UX and multi-level security is going to be something at the Covenant layer.
So that's why it's important to kind of keep focus on that.
i do think focus will become we'll be coming back to covenants pretty strongly here that's my
my gut feeling um and as we've discussed throughout the years i mean the covenants
vault conversation has been probably the most consistent continuous thread that we've had on
the show which the conversation that you and i have had on the show over the last two or three
years i don't think it is time to have that conversation but i mean bringing this back to
like lms and security that's that's another frustrating thing is like in your mind as
somebody who is a protocol engineer somebody's building custody systems for enterprises
what is the importance of basically fuzz testing your system with the latest models as soon as
are dropped yeah i'm doing it all the time now um both on the level of like analysis um
as well as generating you know permanent test fixtures that are really solid which is that's
a total blessing it's easier than ever to say hey cross test every cryptographic implementation
i'm relying on against like two or three other alternatives make sure everything marries up
um you know oh and then by the way run a full audit of my entire system at both the conceptual
level and implementation level like that's incredible and um those are the same tools
obviously that enable you know unearthing these kinds of attacks and so um it's the arms race
like if you're not a diligent user of the latest ai models and techniques uh and you're building
this stuff then you're at a real disadvantage um and it really points you back in the direction
of man this stuff has to be simple and rock solid and it's incredibly frustrating well i mean
in parallel to all this happening we have like the the model wars here in the u.s and the
government stepping in and cucking like fable 5 and chat gpd 5.6 and so that's it's like if you're
trying out of these systems you can't use the american frontier models because you get immediately
nerfed and you're forced to figure out a way to get access to kimi k3 which i think many people
are assuming that that is the model that was used to discover and then exploit this particular
vulnerability with cold carb um and uh
what are we doing in the u.s like like the the operation glass wing because i know many
bitcoin teams are like hey anthropic like we have a pretty important system over here in bitcoin can
we get access to this to make sure that we're um audited and finding any vulnerabilities or bugs
that may exist and i've heard that some teams in space and maybe even core
developers got access to it but um when it comes to something like a system like bitcoin
we need the ability to audit this immediately now like you're just thinking about like i think
people really need to get through their minds so like the the landscape of defensive technology
is completely shifted and like the the way in which you secure your systems has changed and it's
being proactive and consistently proactive from here on out 100 i was using kimmy exclusively
last night to do the triage and investigation um and i was working with some colleagues and
And the U.S.-based models were just shutting, locking up, refusing to, you know, go further on certain lines of inquiry.
You know, I don't have a lot to say about the policy side.
I haven't thought much about that.
I'm sort of a freedom guy.
And, you know, I bless, I feel blessed that we have VPN technology.
technology but um yeah the the fact of the matter is if you're not kind of on the bleeding edge and
you're doing security stuff you're at a real disadvantage yeah um bringing this back to
cold card walking through many scenarios like just thinking of the questions that many people
were just becoming aware of this may have in their mind let's like walk through the scenarios
going from mk3 past 2021 and like obviously mk4 mk5 q what's the difference in terms of
vulnerability exposure and urgency to move coins and then beyond that you mentioned the dice so
to be clear if you set up a cold card and you added you brought your own entropy by rolling
dice if you did it more than 100 times you're very confident that you did you should be good
you basically rolled your own entropy um and they're not affected by the the rng bug that
exists on the firmware or existed on the firmware so they have updated the firmware um so you can
update that too for mk4 mk5 and q if you want to um get on get on something that's more secure
than what existed yesterday but if you do that if you just update the firmware that doesn't make you
secure you have to create a new private public key pair and move the bitcoin from your existing
wallet to to that new wallet that you set up there um yeah key point right there is is it's not the
firmware that's currently running on your device it's what you generated your key with um so i
could see that tripping some people up um yeah but uh yeah we initially thought the red zone
was basically cold cards from 21 to 23 that footprint has expanded because we're hearing
about mk4s that have been stolen from and we have some indications of why that might be um but again
to reiterate at this point you know if if you've generated a single sig with no passphrase no dice
roll on a twin kite device post 21 you know you got to get off um pretty expeditiously
Yes. Multi-sig. I've talked to a number of people that are using cold cards in a multi-sig setup.
Some are using two MK3s and a two out of three. What are the intricacies there?
There's some nuance depending on if you've ever spent from that wallet, if you haven't.
So if you have a two or three multi-sig using two MK3s or an MK3 and MK4s,
goes through those different scenarios what and you you've only sent bitcoin to you've never spent
from or you've both sent bitcoin to and spent from what is the exposure there yeah so so multisig is
where it gets pretty complicated um i think it had helped to maybe step back and just explain
a little bit how multisig works or you know um pay to win the script hash or taproot scripts
in general in Bitcoin, when you spend from a multisig, you actually have to present the script
that locked up the coins in the first place, which means you have to present the pub key
for each key involved in the multisig. And so what that can mean is if you're using a multisig
with all cold cards and you've you know used say that address um before uh you've revealed all of
your pub keys and so an attacker could theoretically grind out all the private keys
you know and uh construct a valid spend um and be able to present a valid signature or a valid
script um if uh you have a multi-sig quorum where you have like any device that isn't a
a cold card or a coin kite product um and that's that has to be part of the the critical spend
threshold then you're in good shape basically your coins are um protected by that segment of
multisig um so you know for example if you have like a three of five and you have you know not
that i hope anybody out there as a consumer has a three to five but um a three or five but uh you
know that would require signing with a device that isn't a coin kite device affected by this so you'd
be you'd be in good shape um if for example you're like an unchained customer let's say
and you're doing a two of three, and let's say that you yourself used two affected cold cards
at home, that's sort of an interesting situation because depending on what Unchained does,
their pub key may or may not be on the chain. I don't know, you know, they'd be able to field
this question if their pub key is available then you are vulnerable um so i think the the safe
guidelines there are um basically if in your multi-sig you have a situation where you could
move the coins with only coin kite products i would move to get off of that um because there
are a lot of subtleties around well you know are the pub keys out there aren't they out there
don't get too clever by half and you know if you have a critical threshold of your multi-sig that
can be provided by coin type products i would just move don't don't think twice um so that's
the the long short answer there and what is the um the assumed
time you like the same again multi-sig 203 to mk3s maybe the um the pub keys exposed but
compared to just a single sig mk3 no bring your own entropy no passphrase like i've heard that
if you have multi-sig you probably have a couple days the way these these attacks are yeah it's
it's that's that's that's my inclination to say but with this stuff you kind of have to
assume that now that the vulnerability is out there that the entire internet is going to be
just like grinding on this and so yeah a multi-sig is harder to scan for for an attacker but that's
just a shallow throw more compute at it type problem um yeah and i i wouldn't uh i wouldn't
back up to that and let me reiterate there when i say you know if you have a critical threshold
of coin kite devices able to sign for your multi-sig that is assuming you didn't use dice
you don't have aspirates and so on and so forth that's just a kind of naive you know single sig
so so don't if if you've used 99 dice rolls you know on on some of your coin kite keys i have
verified by hand that that code path is safe so you're okay um don't worry about those it's
really just yeah if you just trusted the device to give you a good key uh um
i'm trying to think of all the scenarios that
oh the the one question like have you heard of any white hats
going after this because it's going to be messy and there was some discussion there was a twitter
space this last night i was listening in on him it was a the moral conundrum a lot of people
were discussing like should we rent gpu and just sweep the people are exposed um
yeah that's a that's an ethically gray area that um i haven't sat down and put the right
amount of consideration into i have been contacted by people with prospective plans for that um i
don't know if it's actively happening um there's obviously the problem of attribution you know if
do sweep those funds as a white hat how do you then verify um back there's some indication that
given the uid if you bring the physical device yeah exactly if you can present you know but
that's you know the the mechanism for that hasn't been demonstrated to me conclusively so
um so on the one hand it's it's it's it's very difficult uh and i personally wouldn't like be
rushing out to white hat this but on the other hand the real argument for that kind of thing
is that there are a lot of users out there who are affected by this who probably are not listening to
to podcasts and browsing bitcoin twitter and and those are the guys that are going to get
ground down over the next few weeks if they're not made aware of the situation and so um that's
a real tricky one man i yeah um there's a big ethical dimension to that one as as well as
probably like a legal dimension that um you know you need to think through yeah yeah
i mean that's like does the um
does the uh
collapse in confidence of
the
coin cake cold cards
lead to like a lack of confidence in other
and like it goes back to the importance
like I've been a big believer
of multi-vendor
multi-sig for this exact reason
for many years
and
it's like there's a bunch of people wondering like
okay cold card i don't have a cold card i'm looking at my treasure look at my ledger like
are these okay should i worry like um i think no you shouldn't be worried as of right now
um and maybe you won't ever have to be worried there's a potential that the way they
do their entropy and create their private public key pairs is is really top-notch and gives you
uh enough it gives you 256 bits of entropy that is secure and very hard and impossible to break
statistically uh improbable to break um and so if you're out there in that situation like do not
panic that's what i would say um yeah that's like because that's one of the other big mistakes that
many people will make many people will lose coins by panicking and but foot gunning themselves in
the process of trying to sweep coins or something like that yeah you always want to be doing test
transactions of small amounts whenever you're sending anywhere you know um and that's crucial
to keep in mind um throughout all this if you're migrating your own stuff yeah um
how do we know that exchanges have secure setups well i i know that a few do uh firsthand um
But, yeah, I am not aware of any exchanges that, you know, would be vulnerable to this.
And I would like to think that almost every exchange has put more thought into entropy generation than, hey, we're going to click a button on a consumer device and hope for the best.
Um, but, uh, this, you know, I, this is a wake up call for everybody, including enterprises that, um, you really have to put tremendous amount of care and thought into this part of the process.
And what I've always tried to emphasize to clients is you need at least one component of your entropy that you can physically reason about and that you understand in terms of how it's being incorporated into the entropy.
And so I think probably guys like us, consumers are going to have to start to think about this.
You know, how do we take a very simple piece of code, you know, that we can reason about or have audited by somebody we trust and say, oh, yeah, this is a part of the key now for sure.
Because, yeah, I can see how this event would keep you up at night.
You say, well, why couldn't this happen to Ledger?
Why couldn't this happen to Trezor?
Um, you know, what I will say is that like, uh, CoinKite was a very lean, is a very lean
company and, um, most other hardware wallet manufacturers, certainly Ledger and Trezor,
um, have, have pretty big teams, uh, you know, who are doing a lot of internal auditing.
I mean, Ledger's, you know, there's some phenomenal people there.
This isn't an advertisement for Ledger or anything.
i don't even use ledger personally but there are some phenomenal people um there who have done some
very novel hardware attacks um it's a don john team it's like it's fun yeah joke last night
it's like they figured out a way to use 250 000 lasers to hack a cold card but all they had to do
was uh yeah yeah exactly um so yeah i i mean i i still think you know a multi-manufacturer
approach for guys like us is is a is a really solid approach but
you know as nick zabo said it just echoes you know
all the time trusted third parties are security holes and uh there's something like this you
you know there's a certain level you can't delegate um to uh to a packaged product
not easy man it's really not easy um especially at the enterprise level thinking about this stuff
designing it it's you know it's a tough thing well uh trying to find the silver lining in all
this i mean it is a horrible disastrous but something that bitcoiners have said for a while
i think bitcoin creates this honeypot to surface these vulnerabilities because the ability to
send the bearer asset and actually have control of it with no clawbacks creates that incentive
to to find these vulnerabilities now with the ai tools obviously that that is accelerating so
i'd get i'd be interested to get your thoughts is there a silver lining where we're going to
find these vulnerabilities and obviously there's already been collateral damage there's
likely going to be more collateral damage in the weeks to come but on the other side um
it's darkest before the before the dawn like on the other side could you see
see bitcoin actually being significantly more secure and the products around it being more
secure a year from now because of the wake-up call that we just got in the last 24 hours
yeah it's possible this could be like a step along the anti-fragile path to
essentially discovering the final form right of individual level bitcoin security because
Because it's possible that we could get to some kind of deterministic endpoint where, you know, there's a system or a set of software or an arrangement where, you know, humans, machines have done all the analysis and have said, yeah, if you do it this way with this binary on this platform, like, you know, if it's simple enough, we could get to a point where ultimately this event has catalyzed a bunch of people.
to put, put the effort in, um, and create something where you truly can't be hacked
unless you get, you know, some physical component. Um, and then even then, you know,
if, if something like this motivates, uh, a re-interest in vaults, well, even if you do
get hacked, then you have a six hour window to, to clot into a, you know, a trusted counterparty,
like an exchange um so yeah i think conceivably this this could be the kind of kick in the butt
that the industry needed to start thinking about some of that stuff um
i uh you know there's a long timeline on that and right now the community is pretty fractured so
um uh i don't know yeah i will say i mean in terms of like protocol development
certainly is fractured but another silver lining i mean it was
encouraging to see people come together publicly behind the scenes i mean i think it was
i mean i was in dc at an event in pub key and like
at the beginning of it was like oh what's going on then it became clear what's going on it was
like in the corner on my phone the whole night like all right all hands on deck and i think there
was um it's weird too bitcoin there is no ceo to call so it's like people like rob hamilton yourself
um portland huddle others hopping on spaces to try to educate people about all this and
i know behind the scenes many people reaching out one node to many like hey my god i uh wound
up texting a friend um being like hey are you aware of this he's like no i've been heads down
all day and his brother um is a is a coin or two and was on vacation and like he was able to like
go over to his house like and he had he did sit on a bear single seat mk3 with no dicentropy or
passphrase and was able to like move it and so that like was like okay and i think there was
much of that going on um and i think that's the spirit that um we need to lean into heavily
particularly as this is unfolding is obviously there's going to be a lot of
justifiably angry angry people um very very much justified but um
i don't think this is the time to like sling and throw people under the bus it's like okay
this is happening while it's happening let's just make sure we get as many people um
into out of harm's way as possible totally agree and this thing is still
ongoing so you know it's still critical to give people heads up and just be
racking your brain for anybody who may not be listening to podcasts you know
who has a cold card because I think probably we're going to continue to see
uh you know funds flow around um so uh yeah i mean it's it's it's hard to this the sentiment
thing's difficult because like there is a kind of like um excitement and camaraderie that comes out
of an event like this but that we we can only experience that because we didn't lose our life
savings you know and there are people that happen to um and that's horrible uh that's really
horrible um it's not it's not the worst thing you know um if you're one of those people uh
god has a plan and um you need to keep that in mind um but
uh yeah it's um it is good to see the the community kind of reorient in certain ways and
come back to you know the the real stuff of bitcoin um rather than you know
scattering about 110 or whatever yeah um i think we can keep this short is there anything we missed
we should be getting out there i mean it's probably we should keep it short so we can
get out there to people um as quickly as possible no i mean i think we hit the headlines you know
there's obviously tons of technical detail you go into um but the investigation is still ongoing so
um you know again my headline is if you have a point kite device uh post 2021
uh and you didn't use dice rolls um don't have a super strong passphrase that you know is
cryptographically strong you know you need to expedite um getting your funds my you know my
recommend recommendation for a lot of people would be find an exchange that you trust um and just
if you don't mind doxing yourself park park your funds there while you figure out what the long
term is and just kind of get out of dodge um do a small test transaction um you know don't uh
don't panic don't don't rush anything but um you know uh
steady is smooth smooth as fast yeah the um and just to clarify if you're sitting there like did
i roll the dice enough is my passphrase strong enough if you have 99 or more dice rolls and you
did it correctly you're confident in that you should be fine passphrase if you have six
or more BIP39 words as a passphrase, you should be good.
Is that the sort of thresholds that are correct there in my mind?
Sorry, repeat passphrase criteria?
Six BIP39 words or more.
Maybe.
I wouldn't hinge on that per se because there are things like,
you mixing case for that um uh you know each bit 39 word is like a drawn from a set of uh 2048 so
2048 times six isn't a big search space that's that's why passphrases are tough because
something you might think is is pretty strong like given enough gpus is not okay so so unless you
unless you're like a specialist and you know your passphrase is like crazy and strong um i
would not i would not rely on that i'll be moving my you know my small number of uh fractional
bitcoin around um even though i have you know i'm not affected by the firmware version and i have a
strong passphrase but even so um out of an abundance of caution i'm just moving all right
well um i hate that we had to to meet here under these circumstances but i really appreciate that
you hopped on to walk through this we'll get this out and warn people about all this of course man
yeah good to see you to see you too peace and love freaks thank you thank you for listening
to this episode of tftc if you've made it this far i imagine you got some value out of the episode
if so please share it far and wide with your friends and family we're looking to get the
word out there also wherever you're listening whether that's youtube apple spotify make sure
you like and subscribe to the show and if you can leave a rating on the podcasting platforms that
goes a long way last but not least if you want to get these episodes a day early and ad free
make sure you download the fountain podcasting app and go to fountain.fm to find that five dollars
a month get you every episode a day early ad free helps the show gives you incredible value
so please consider subscribing via fountain as well thank you for your time and until next time
