TFTC: A Bitcoin Podcast - 777: Coldcard Is Compromised with James O'Beirne

Episode Date: July 31, 2026

James O'Beirne joins Marty to break down the critical Coldcard RNG vulnerability affecting devices produced after 2021. They discuss how insufficient entropy generation exposes private keys, why MK2, ...MK3, MK4, and Q users must migrate funds immediately, and how AI models accelerated the discovery. The conversation covers multisig risks, passphrase limitations, dice roll safety, and the broader collapse of trust in single-vendor hardware wallets. Essential listening for Bitcoin self-custody security. James on X: https://x.com/jamesob Find the Home Mining Playbook here: https://www.tftc.io/home-mining-energy-playbook STACK SATS hat: https://tftcmerch.io/ Our newsletter: https://www.tftc.io/bitcoin-brief/ TFTC Elite (Ad-free & Discord): https://www.tftc.io/#/portal/signup/ Discord: https://discord.gg/yHGkvYxdqT Opportunity Cost Extension: https://www.opportunitycost.app/ Shoutout to our sponsors: Block: Cash App: For a limited time, new customers can get $21 added to their balance. Just use code TFTC10 when you sign up, and send at least $5 to a friend in the first two weeks. Terms apply. Bitcoin services by Block, Inc. See the Bitcoin disclosures at cash.app/legal/podcast. Square: Visit http://square.com/go/tftc for up to $200 off eligible Square hardware. Bitkey: Use code TFTC10 for 10% off the new Bitkey. Aven https://www.aven.com/bitcoin CrowdHealth https://www.joincrowdhealth.com/tftc Unchained https://unchained.com/tftc/ Salt of the Earth: https://drinksote.com/tftc Join the TFTC Movement: Main YT Channel https://www.youtube.com/c/TFTC21/videos Clips YT Channel https://www.youtube.com/channel/UCUQcW3jxfQfEUS8kqR5pJtQ Website https://tftc.io/ Newsletter tftc.io/bitcoin-brief/ Twitter https://twitter.com/tftc21 Instagram https://www.instagram.com/tftc.io/ Nostr https://primal.net/tftc Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/martybent Newsletter https://tftc.io/martys-bent/ Podcast https://www.tftc.io/tag/podcasts/ Disclosure: Bitcoin services are provided by Block, Inc. Bitcoin services are not licensable activity in all U.S. states and territories, and not all services are available in all states. Bitkey is not available in New York. Block, Inc. operates in New York as Block of Delaware and is licensed to engage in virtual currency business activity by the New York State Department of Financial Services. Bitcoin is a non-deposit, non-bank product that is not FDIC insured and involves risk, including monetary loss. For additional information, see the Bitcoin disclosures: https://help.cash.app/btcdisclosures Get up to $200 off Square hardware when you sign up at http://square.com/go/tftc! #squarepartner. Offer expires December 31, 2026 at 11:59 pm PST. Offer for $40 off the cost of one Square Stand, $75 off the cost of one Square Terminal, $100 off the cost of one Square Handheld, or $200 off the cost of one Square Register, excluding applicable taxes. Limited to one discount per product type per seller account. Each code is limited to one redemption per account holder. Valid for new Square customers located in the US only. Offer not valid with guest checkout. Square reserves the right to modify, revoke or cancel the offer at any time. Offer cannot be combined with any other coupon. Void where prohibited, not redeemable for cash, and non-transferable. #squarepartner #blockpartner

Transcript
Discussion (0)
Starting point is 00:00:00 You've had a dynamic where money's become freer than free. When you talk about a Fed just gone nuts, all the central banks going nuts. So it's all acting like safe haven. I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins. In the world of fiat currencies, Bitcoin is the victor. i mean that's part of the bull case for bitcoin if you're not paying attention you probably should be yeah i don't i don't think we can assume everybody's hurt and i know i think that's a bad assumption just because i've been texting people i know have cold cards and they're
Starting point is 00:00:45 completely oblivious to what was going on last night so yeah um sad day yeah we've uh talked under better circumstances for sure um for those who are unaware uh there is a massive vulnerability in cold cards produced after 2021 all models some um worse than others but essentially uh the random number generator that creates the entropy for private keys that you produce using the cold card is insufficient is that the right word to use yeah it's um you could call it deterministic uh so the the search space required to get the private key to guess the private key basically is highly highly limited relative to what it should be um so basically the you know funds under the mk2 mk3s with firmware between you know 2021 and 2023 are just kind of like
Starting point is 00:01:51 dangling in the wind so luckily if you used dice rolls you know if you used say over 99 dice rolls to initialize the key you're you're safe um and or if you're using a passphrase uh which is basically like the 25th word you can specify when you're setting up the wallet. If that passphrase is of a sufficient length and complexity, which is longer than most people think, then you may also be safe. But, yeah, those the MK2, MK3s are affected severely to the point where it's like, you know, you need to drive home from work and migrate your funds if uh if you're single sig under one of those uh without a passphrase without dice or with a weak passphrase but we're finding and it's part of an ongoing investigation as to the current state of the cold card firmware um which would
Starting point is 00:02:55 affect like newer devices like the queue we're finding that the problem still exists there too but it's partially mitigated. So estimates right now are that current users of cold card devices are getting about 70 bits of security, whereas you're supposed to be getting 256 bits during key gen. But that 70-bit number is even going down because we're finding that one of the fallback RNGs that is used to paper over the original defect is actually less random than we thought and is specified by the manufacturer. And, you know, they may be doing things like zeroing out certain parts of this ID. And so it might actually be worse than we were thinking last night for current devices. So my headline for everybody at this point is if you're working off
Starting point is 00:03:55 of a cold card device, you, after 2021, you need to migrate, you know, your funds pretty expeditiously. If you did all the dice rolls, don't worry. You're probably in good shape. But even so, yeah, I think, unfortunately, people should be making moves to get off of the post 2021 devices yeah i mean we're trying to find some humor in light of this but cold card hey listen i've been an advocate for cold card for for many years if you listen to the show i recommended it i have my queue right here i moved my funds off last night um obviously a part managing partner 1031 we're invested in coin kite which produces a cold card i mean this is very close to home um for me personally to many people i know that have felt very confident
Starting point is 00:05:01 um recommending this in the past and it seems that the confidence was uh was ill-gotten we were we were joking before it's like the cold card souped up to secure enclaves but you mess up one part of it the random number generator so you get a ferrari on top of a lawnmower engine well pretty devastating i'm in the same boat man i mean i i'm a single sig passphrase guy on a cold card you know i think mark two uh my firmware is older and unaffected but um i love coin kite you know they make great products um but the unfortunate nature of security and hardware wallets is that you screw up one thing you screw up the wrong one thing and it's toast and and so that's that's the reason why people have you know been sort of paranoid
Starting point is 00:05:58 in this department is because like you just simply can't trust one manufacturer or one source for your entropy you know when you're doing entropy construction and this is what i do professionally for the last few years um is you you have to be utterly paranoid when you're constructing a private key and um you can't just click a button and expect that it'll happen you know um so it's yes it's really it's really sad to see because i recommended hold card left and right you know um the people who i thought were savvy enough uh to use them and um i'd say like aside from you know getting yourself safe my message to people would be think about who is a sort of more normal person than maybe you are listening to this podcast who you've
Starting point is 00:06:56 recommended cold cards to who maybe isn't like following bitcoin twitter um you know give them a heads up if you got them set up with a cold card um i've got a few such people in my life that i've reached out to yeah that's why i wouldn't that's why i hit you up last night to record this and i'm distracted right now because i'm about to send out a newsletter that just covers this as well um and i gotta give one more prompt to my clanker to give something make something very clear here but uh dive in dive into the math so you mentioned like later versions people are saying potentially 70 bits of entropy he should have 256 mk2 mk3 after 2021 even less i think it's like 30 yeah two bits 20 20 seconds yeah and i mean the nature
Starting point is 00:07:48 of the attack i mean this is obviously very much centered on on coin kite and cold card however um ai comes into the mix i mean this is a new era of security vulnerabilities and i mean we've been talking about it for the better part of a couple years now on this show and others that these models once they get sufficiently intelligent we'll be able to uncover these and it seems like that may be exactly what happened yesterday it's totally plausible man um you know me and a number of other researchers uh very quickly independently reproduce this just by giving the ai kind of a pointer as to hey you know between this window of time between these firmware versions check for an rng problem and uh kimmy k3 shoot shoot through it and found it readily um
Starting point is 00:08:43 and uh yeah look if you're a sort of unscrupulous attacker um and you're willing to just sit there there and grind through you know take any open source bitcoin software you can and just say hey file by file go through look at the entire history um you know find something that's plausibly an exploit all that stuff's going to get unearthed so um somebody i was talking to yesterday put it this way he said uh you know security by obscurity is going to zero rapidly um and everything you know the the tide's washing out um so it's going to be really wild a few weeks and months and probably years yeah i mean outside of bitcoin i mean matt and i discussed some on rhr where there was a water system in minneapolis that was attacked it looks like with some vibe coded
Starting point is 00:09:37 um llm attack and what um how big of a setback do you think this is well you know me man i'm i i tend to be um somewhat pessimistic in the short to midterm um and my real worry aside from like the horrible tragedy of a bunch of good people losing their coins um that's obviously horrible um i'm i'm a bit worried about the second order effect of this being a hit against kind of the most reputable hardware wallet vendor you know among hardcore bitcoiners that kind of like rippling out into a notion that well even the smart guys screwed up self-custody and how can we expect that anybody you know will
Starting point is 00:10:46 comfortably self-custody after this point um yeah so i don't necessarily agree with that because again if you kind of followed best practices that were recommended you know you'd have avoided this pickle purely by obeying that principle that you can't trust a single manufacturer or you know you have to bring your own entropy to the table somehow but even so i i i worry this event's going to get a lot of play and um you know maybe the general public is going to be like that bitcoin thing that's impossible to keep safe by yourself so just got to use a custodian i mean the irony the whole situation is with all the eyes and compute focused on the cold card repository right now by the end of the week and maybe the most secure
Starting point is 00:11:34 secure system in in the space but again the trust is very hard to build very easy to break yeah that and that's the problem um and um you know in some ways this is is a sort of inexcusable error if you are uh a company making the product that they make and so i i you know again the coin card coin kite guys are friends of ours certainly of of yours and mine and uh even so it's like i think huh what the yeah it's it's going to be hard to trust anything that comes out of that brand anymore you know um so it's uh you know i mean the thing like it feels like every single hardware wallet manufacturer has made some kind of like fatal misstep again because this domain is just very hard you know let a ledger spilled
Starting point is 00:12:40 you know all of their clients information essentially back what was that like 20 you hit it twice okay yeah yeah probably most multiple times you know bitbox had some pretty um pretty obvious physical defects that allowed key x filtration um i don't know specifically if anything has befallen trezor or not um but you know it's just it's kind of the nature of the the game that these things get hit with something um and even if they aren't obviously hit with something the very fact that it's a security critical bitcoin device means that their whole supply chain is probably targeted the companies themselves are targeted for for intervention so So, um, custody is tough, man.
Starting point is 00:13:34 It's really tough. Um, and I spent many years, you know, hoping we could make it easier with better scripting primitives and covenants and vaults. Um, but, uh, you know, I think given the community is more fractured than ever, I'm not sure we're going to get there. And it's certainly not in the next year or two, but I don't know. I think, I think this may light a fire in our people's ass to figure that out. figure out how to get that stuff through i mean a lot of the conversation there's back and forth
Starting point is 00:14:03 people on both sides of the aisle like now's not the time to talk about this and i think alex b from from uh arc labs um arcade was making some good points it's like hey like don't worry about obscure covenants when we haven't even verified like ren number generation on some of with these wallet providers. There's a point there but again, you're going to there's a sort of inescapable point, which is that
Starting point is 00:14:31 even if you supposedly verify all the RNGs, you just can't, again, you can't trust one manufacturer. Even, you know, like look, I'll pick on say BitKey because that's being touted as like a migration target. And I think the world of that team
Starting point is 00:14:48 and I know a lot of the guys who wrote that they're super smart, but You know, like, are you really auditing their whole software stack? You know, like, BitKey requires on-device software, you know, that's closed source. I know a lot of it is open source, but some of their backend services are closed source. So it's like, you know, until you move some of that security into the chain itself, you're not going to be able to, like, trust one provider. And that until we get until we solve that, you know, it's like, OK, well, all right. So I go to two providers. I set up a multi-sig for myself.
Starting point is 00:15:33 So that's that's kind of a horrible user experience or a worse one for sure. So, while, yeah, I mean, Alex's point is taken that, like, there are fish to fry in the auditing department. I think the only categorical fix for a much better UX and multi-level security is going to be something at the Covenant layer. So that's why it's important to kind of keep focus on that. i do think focus will become we'll be coming back to covenants pretty strongly here that's my my gut feeling um and as we've discussed throughout the years i mean the covenants vault conversation has been probably the most consistent continuous thread that we've had on the show which the conversation that you and i have had on the show over the last two or three
Starting point is 00:16:27 years i don't think it is time to have that conversation but i mean bringing this back to like lms and security that's that's another frustrating thing is like in your mind as somebody who is a protocol engineer somebody's building custody systems for enterprises what is the importance of basically fuzz testing your system with the latest models as soon as are dropped yeah i'm doing it all the time now um both on the level of like analysis um as well as generating you know permanent test fixtures that are really solid which is that's a total blessing it's easier than ever to say hey cross test every cryptographic implementation i'm relying on against like two or three other alternatives make sure everything marries up
Starting point is 00:17:21 um you know oh and then by the way run a full audit of my entire system at both the conceptual level and implementation level like that's incredible and um those are the same tools obviously that enable you know unearthing these kinds of attacks and so um it's the arms race like if you're not a diligent user of the latest ai models and techniques uh and you're building this stuff then you're at a real disadvantage um and it really points you back in the direction of man this stuff has to be simple and rock solid and it's incredibly frustrating well i mean in parallel to all this happening we have like the the model wars here in the u.s and the government stepping in and cucking like fable 5 and chat gpd 5.6 and so that's it's like if you're
Starting point is 00:18:21 trying out of these systems you can't use the american frontier models because you get immediately nerfed and you're forced to figure out a way to get access to kimi k3 which i think many people are assuming that that is the model that was used to discover and then exploit this particular vulnerability with cold carb um and uh what are we doing in the u.s like like the the operation glass wing because i know many bitcoin teams are like hey anthropic like we have a pretty important system over here in bitcoin can we get access to this to make sure that we're um audited and finding any vulnerabilities or bugs that may exist and i've heard that some teams in space and maybe even core
Starting point is 00:19:11 developers got access to it but um when it comes to something like a system like bitcoin we need the ability to audit this immediately now like you're just thinking about like i think people really need to get through their minds so like the the landscape of defensive technology is completely shifted and like the the way in which you secure your systems has changed and it's being proactive and consistently proactive from here on out 100 i was using kimmy exclusively last night to do the triage and investigation um and i was working with some colleagues and And the U.S.-based models were just shutting, locking up, refusing to, you know, go further on certain lines of inquiry. You know, I don't have a lot to say about the policy side.
Starting point is 00:20:07 I haven't thought much about that. I'm sort of a freedom guy. And, you know, I bless, I feel blessed that we have VPN technology. technology but um yeah the the fact of the matter is if you're not kind of on the bleeding edge and you're doing security stuff you're at a real disadvantage yeah um bringing this back to cold card walking through many scenarios like just thinking of the questions that many people were just becoming aware of this may have in their mind let's like walk through the scenarios going from mk3 past 2021 and like obviously mk4 mk5 q what's the difference in terms of
Starting point is 00:20:52 vulnerability exposure and urgency to move coins and then beyond that you mentioned the dice so to be clear if you set up a cold card and you added you brought your own entropy by rolling dice if you did it more than 100 times you're very confident that you did you should be good you basically rolled your own entropy um and they're not affected by the the rng bug that exists on the firmware or existed on the firmware so they have updated the firmware um so you can update that too for mk4 mk5 and q if you want to um get on get on something that's more secure than what existed yesterday but if you do that if you just update the firmware that doesn't make you secure you have to create a new private public key pair and move the bitcoin from your existing
Starting point is 00:21:45 wallet to to that new wallet that you set up there um yeah key point right there is is it's not the firmware that's currently running on your device it's what you generated your key with um so i could see that tripping some people up um yeah but uh yeah we initially thought the red zone was basically cold cards from 21 to 23 that footprint has expanded because we're hearing about mk4s that have been stolen from and we have some indications of why that might be um but again to reiterate at this point you know if if you've generated a single sig with no passphrase no dice roll on a twin kite device post 21 you know you got to get off um pretty expeditiously Yes. Multi-sig. I've talked to a number of people that are using cold cards in a multi-sig setup.
Starting point is 00:22:46 Some are using two MK3s and a two out of three. What are the intricacies there? There's some nuance depending on if you've ever spent from that wallet, if you haven't. So if you have a two or three multi-sig using two MK3s or an MK3 and MK4s, goes through those different scenarios what and you you've only sent bitcoin to you've never spent from or you've both sent bitcoin to and spent from what is the exposure there yeah so so multisig is where it gets pretty complicated um i think it had helped to maybe step back and just explain a little bit how multisig works or you know um pay to win the script hash or taproot scripts in general in Bitcoin, when you spend from a multisig, you actually have to present the script
Starting point is 00:23:36 that locked up the coins in the first place, which means you have to present the pub key for each key involved in the multisig. And so what that can mean is if you're using a multisig with all cold cards and you've you know used say that address um before uh you've revealed all of your pub keys and so an attacker could theoretically grind out all the private keys you know and uh construct a valid spend um and be able to present a valid signature or a valid script um if uh you have a multi-sig quorum where you have like any device that isn't a a cold card or a coin kite product um and that's that has to be part of the the critical spend threshold then you're in good shape basically your coins are um protected by that segment of
Starting point is 00:24:38 multisig um so you know for example if you have like a three of five and you have you know not that i hope anybody out there as a consumer has a three to five but um a three or five but uh you know that would require signing with a device that isn't a coin kite device affected by this so you'd be you'd be in good shape um if for example you're like an unchained customer let's say and you're doing a two of three, and let's say that you yourself used two affected cold cards at home, that's sort of an interesting situation because depending on what Unchained does, their pub key may or may not be on the chain. I don't know, you know, they'd be able to field this question if their pub key is available then you are vulnerable um so i think the the safe
Starting point is 00:25:39 guidelines there are um basically if in your multi-sig you have a situation where you could move the coins with only coin kite products i would move to get off of that um because there are a lot of subtleties around well you know are the pub keys out there aren't they out there don't get too clever by half and you know if you have a critical threshold of your multi-sig that can be provided by coin type products i would just move don't don't think twice um so that's the the long short answer there and what is the um the assumed time you like the same again multi-sig 203 to mk3s maybe the um the pub keys exposed but compared to just a single sig mk3 no bring your own entropy no passphrase like i've heard that
Starting point is 00:26:40 if you have multi-sig you probably have a couple days the way these these attacks are yeah it's it's that's that's that's my inclination to say but with this stuff you kind of have to assume that now that the vulnerability is out there that the entire internet is going to be just like grinding on this and so yeah a multi-sig is harder to scan for for an attacker but that's just a shallow throw more compute at it type problem um yeah and i i wouldn't uh i wouldn't back up to that and let me reiterate there when i say you know if you have a critical threshold of coin kite devices able to sign for your multi-sig that is assuming you didn't use dice you don't have aspirates and so on and so forth that's just a kind of naive you know single sig
Starting point is 00:27:28 so so don't if if you've used 99 dice rolls you know on on some of your coin kite keys i have verified by hand that that code path is safe so you're okay um don't worry about those it's really just yeah if you just trusted the device to give you a good key uh um i'm trying to think of all the scenarios that oh the the one question like have you heard of any white hats going after this because it's going to be messy and there was some discussion there was a twitter space this last night i was listening in on him it was a the moral conundrum a lot of people were discussing like should we rent gpu and just sweep the people are exposed um
Starting point is 00:28:20 yeah that's a that's an ethically gray area that um i haven't sat down and put the right amount of consideration into i have been contacted by people with prospective plans for that um i don't know if it's actively happening um there's obviously the problem of attribution you know if do sweep those funds as a white hat how do you then verify um back there's some indication that given the uid if you bring the physical device yeah exactly if you can present you know but that's you know the the mechanism for that hasn't been demonstrated to me conclusively so um so on the one hand it's it's it's it's very difficult uh and i personally wouldn't like be rushing out to white hat this but on the other hand the real argument for that kind of thing
Starting point is 00:29:22 is that there are a lot of users out there who are affected by this who probably are not listening to to podcasts and browsing bitcoin twitter and and those are the guys that are going to get ground down over the next few weeks if they're not made aware of the situation and so um that's a real tricky one man i yeah um there's a big ethical dimension to that one as as well as probably like a legal dimension that um you know you need to think through yeah yeah i mean that's like does the um does the uh collapse in confidence of
Starting point is 00:30:12 the coin cake cold cards lead to like a lack of confidence in other and like it goes back to the importance like I've been a big believer of multi-vendor multi-sig for this exact reason for many years
Starting point is 00:30:29 and it's like there's a bunch of people wondering like okay cold card i don't have a cold card i'm looking at my treasure look at my ledger like are these okay should i worry like um i think no you shouldn't be worried as of right now um and maybe you won't ever have to be worried there's a potential that the way they do their entropy and create their private public key pairs is is really top-notch and gives you uh enough it gives you 256 bits of entropy that is secure and very hard and impossible to break statistically uh improbable to break um and so if you're out there in that situation like do not
Starting point is 00:31:12 panic that's what i would say um yeah that's like because that's one of the other big mistakes that many people will make many people will lose coins by panicking and but foot gunning themselves in the process of trying to sweep coins or something like that yeah you always want to be doing test transactions of small amounts whenever you're sending anywhere you know um and that's crucial to keep in mind um throughout all this if you're migrating your own stuff yeah um how do we know that exchanges have secure setups well i i know that a few do uh firsthand um But, yeah, I am not aware of any exchanges that, you know, would be vulnerable to this. And I would like to think that almost every exchange has put more thought into entropy generation than, hey, we're going to click a button on a consumer device and hope for the best.
Starting point is 00:32:29 Um, but, uh, this, you know, I, this is a wake up call for everybody, including enterprises that, um, you really have to put tremendous amount of care and thought into this part of the process. And what I've always tried to emphasize to clients is you need at least one component of your entropy that you can physically reason about and that you understand in terms of how it's being incorporated into the entropy. And so I think probably guys like us, consumers are going to have to start to think about this. You know, how do we take a very simple piece of code, you know, that we can reason about or have audited by somebody we trust and say, oh, yeah, this is a part of the key now for sure. Because, yeah, I can see how this event would keep you up at night. You say, well, why couldn't this happen to Ledger? Why couldn't this happen to Trezor? Um, you know, what I will say is that like, uh, CoinKite was a very lean, is a very lean
Starting point is 00:33:44 company and, um, most other hardware wallet manufacturers, certainly Ledger and Trezor, um, have, have pretty big teams, uh, you know, who are doing a lot of internal auditing. I mean, Ledger's, you know, there's some phenomenal people there. This isn't an advertisement for Ledger or anything. i don't even use ledger personally but there are some phenomenal people um there who have done some very novel hardware attacks um it's a don john team it's like it's fun yeah joke last night it's like they figured out a way to use 250 000 lasers to hack a cold card but all they had to do was uh yeah yeah exactly um so yeah i i mean i i still think you know a multi-manufacturer
Starting point is 00:34:38 approach for guys like us is is a is a really solid approach but you know as nick zabo said it just echoes you know all the time trusted third parties are security holes and uh there's something like this you you know there's a certain level you can't delegate um to uh to a packaged product not easy man it's really not easy um especially at the enterprise level thinking about this stuff designing it it's you know it's a tough thing well uh trying to find the silver lining in all this i mean it is a horrible disastrous but something that bitcoiners have said for a while i think bitcoin creates this honeypot to surface these vulnerabilities because the ability to
Starting point is 00:35:38 send the bearer asset and actually have control of it with no clawbacks creates that incentive to to find these vulnerabilities now with the ai tools obviously that that is accelerating so i'd get i'd be interested to get your thoughts is there a silver lining where we're going to find these vulnerabilities and obviously there's already been collateral damage there's likely going to be more collateral damage in the weeks to come but on the other side um it's darkest before the before the dawn like on the other side could you see see bitcoin actually being significantly more secure and the products around it being more secure a year from now because of the wake-up call that we just got in the last 24 hours
Starting point is 00:36:21 yeah it's possible this could be like a step along the anti-fragile path to essentially discovering the final form right of individual level bitcoin security because Because it's possible that we could get to some kind of deterministic endpoint where, you know, there's a system or a set of software or an arrangement where, you know, humans, machines have done all the analysis and have said, yeah, if you do it this way with this binary on this platform, like, you know, if it's simple enough, we could get to a point where ultimately this event has catalyzed a bunch of people. to put, put the effort in, um, and create something where you truly can't be hacked unless you get, you know, some physical component. Um, and then even then, you know, if, if something like this motivates, uh, a re-interest in vaults, well, even if you do get hacked, then you have a six hour window to, to clot into a, you know, a trusted counterparty, like an exchange um so yeah i think conceivably this this could be the kind of kick in the butt
Starting point is 00:37:43 that the industry needed to start thinking about some of that stuff um i uh you know there's a long timeline on that and right now the community is pretty fractured so um uh i don't know yeah i will say i mean in terms of like protocol development certainly is fractured but another silver lining i mean it was encouraging to see people come together publicly behind the scenes i mean i think it was i mean i was in dc at an event in pub key and like at the beginning of it was like oh what's going on then it became clear what's going on it was like in the corner on my phone the whole night like all right all hands on deck and i think there
Starting point is 00:38:29 was um it's weird too bitcoin there is no ceo to call so it's like people like rob hamilton yourself um portland huddle others hopping on spaces to try to educate people about all this and i know behind the scenes many people reaching out one node to many like hey my god i uh wound up texting a friend um being like hey are you aware of this he's like no i've been heads down all day and his brother um is a is a coin or two and was on vacation and like he was able to like go over to his house like and he had he did sit on a bear single seat mk3 with no dicentropy or passphrase and was able to like move it and so that like was like okay and i think there was much of that going on um and i think that's the spirit that um we need to lean into heavily
Starting point is 00:39:23 particularly as this is unfolding is obviously there's going to be a lot of justifiably angry angry people um very very much justified but um i don't think this is the time to like sling and throw people under the bus it's like okay this is happening while it's happening let's just make sure we get as many people um into out of harm's way as possible totally agree and this thing is still ongoing so you know it's still critical to give people heads up and just be racking your brain for anybody who may not be listening to podcasts you know who has a cold card because I think probably we're going to continue to see
Starting point is 00:40:13 uh you know funds flow around um so uh yeah i mean it's it's it's hard to this the sentiment thing's difficult because like there is a kind of like um excitement and camaraderie that comes out of an event like this but that we we can only experience that because we didn't lose our life savings you know and there are people that happen to um and that's horrible uh that's really horrible um it's not it's not the worst thing you know um if you're one of those people uh god has a plan and um you need to keep that in mind um but uh yeah it's um it is good to see the the community kind of reorient in certain ways and come back to you know the the real stuff of bitcoin um rather than you know
Starting point is 00:41:23 scattering about 110 or whatever yeah um i think we can keep this short is there anything we missed we should be getting out there i mean it's probably we should keep it short so we can get out there to people um as quickly as possible no i mean i think we hit the headlines you know there's obviously tons of technical detail you go into um but the investigation is still ongoing so um you know again my headline is if you have a point kite device uh post 2021 uh and you didn't use dice rolls um don't have a super strong passphrase that you know is cryptographically strong you know you need to expedite um getting your funds my you know my recommend recommendation for a lot of people would be find an exchange that you trust um and just
Starting point is 00:42:13 if you don't mind doxing yourself park park your funds there while you figure out what the long term is and just kind of get out of dodge um do a small test transaction um you know don't uh don't panic don't don't rush anything but um you know uh steady is smooth smooth as fast yeah the um and just to clarify if you're sitting there like did i roll the dice enough is my passphrase strong enough if you have 99 or more dice rolls and you did it correctly you're confident in that you should be fine passphrase if you have six or more BIP39 words as a passphrase, you should be good. Is that the sort of thresholds that are correct there in my mind?
Starting point is 00:43:06 Sorry, repeat passphrase criteria? Six BIP39 words or more. Maybe. I wouldn't hinge on that per se because there are things like, you mixing case for that um uh you know each bit 39 word is like a drawn from a set of uh 2048 so 2048 times six isn't a big search space that's that's why passphrases are tough because something you might think is is pretty strong like given enough gpus is not okay so so unless you unless you're like a specialist and you know your passphrase is like crazy and strong um i
Starting point is 00:43:55 would not i would not rely on that i'll be moving my you know my small number of uh fractional bitcoin around um even though i have you know i'm not affected by the firmware version and i have a strong passphrase but even so um out of an abundance of caution i'm just moving all right well um i hate that we had to to meet here under these circumstances but i really appreciate that you hopped on to walk through this we'll get this out and warn people about all this of course man yeah good to see you to see you too peace and love freaks thank you thank you for listening to this episode of tftc if you've made it this far i imagine you got some value out of the episode if so please share it far and wide with your friends and family we're looking to get the
Starting point is 00:44:46 word out there also wherever you're listening whether that's youtube apple spotify make sure you like and subscribe to the show and if you can leave a rating on the podcasting platforms that goes a long way last but not least if you want to get these episodes a day early and ad free make sure you download the fountain podcasting app and go to fountain.fm to find that five dollars a month get you every episode a day early ad free helps the show gives you incredible value so please consider subscribing via fountain as well thank you for your time and until next time

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.