TFTC: A Bitcoin Podcast - #780: Dissecting The Coldcard Hack with Alex Thorn
Episode Date: August 5, 2026Alex Thorn joins Marty to break down the Coldcard vulnerability draining Bitcoin wallets across multiple attack waves. Galaxy Research traces stolen on-chain funds while victims race against time to s...ecure self-custodied BTC. They dissect AI-driven exploit patterns, white hat ethical dilemmas, casino exfiltration attempts, and why multisig collaborative custody is now essential infrastructure. Bitcoin security, private key entropy, and monetary sovereignty hang in the balance as attackers leverage frontier models against antiquated hardware. If you hold Bitcoin in cold storage, this conversation covers exactly what moves to make before your keys become the next target. Alex on X: https://x.com/intangiblecoins Galaxy: https://linktr.ee/galaxyhq Find the Home Mining Playbook here: https://www.tftc.io/home-mining-energy-playbook STACK SATS hat: https://tftcmerch.io/ Our newsletter: https://www.tftc.io/bitcoin-brief/ TFTC Elite (Ad-free & Discord): https://www.tftc.io/#/portal/signup/ Discord: https://discord.gg/yHGkvYxdqT Opportunity Cost Extension: https://www.opportunitycost.app/ Shoutout to our sponsors: Block: Cash App: For a limited time, new customers can get $21 added to their balance. Just use code TFTC10 when you sign up, and send at least $5 to a friend in the first two weeks. Terms apply. Bitcoin services by Block, Inc. See the Bitcoin disclosures at cash.app/legal/podcast. Square: Visit http://square.com/go/tftc for up to $200 off eligible Square hardware. Bitkey: Use code TFTC10 for 10% off the new Bitkey. Aven https://www.aven.com/bitcoin CrowdHealth https://www.joincrowdhealth.com/tftc Unchained https://unchained.com/tftc/ Salt of the Earth: https://drinksote.com/tftc Join the TFTC Movement: Main YT Channel https://www.youtube.com/c/TFTC21/videos Clips YT Channel https://www.youtube.com/channel/UCUQcW3jxfQfEUS8kqR5pJtQ Website https://tftc.io/ Newsletter tftc.io/bitcoin-brief/ Twitter https://twitter.com/tftc21 Instagram https://www.instagram.com/tftc.io/ Nostr https://primal.net/tftc Follow Marty Bent: Twitter https://twitter.com/martybent Nostr https://primal.net/martybent Newsletter https://tftc.io/martys-bent/ Podcast https://www.tftc.io/tag/podcasts/ Disclosure: Bitcoin services are provided by Block, Inc. Bitcoin services are not licensable activity in all U.S. states and territories, and not all services are available in all states. Bitkey is not available in New York. Block, Inc. operates in New York as Block of Delaware and is licensed to engage in virtual currency business activity by the New York State Department of Financial Services. Bitcoin is a non-deposit, non-bank product that is not FDIC insured and involves risk, including monetary loss. For additional information, see the Bitcoin disclosures: https://help.cash.app/btcdisclosures Get up to $200 off Square hardware when you sign up at http://square.com/go/tftc! #squarepartner. Offer expires December 31, 2026 at 11:59 pm PST. Offer for $40 off the cost of one Square Stand, $75 off the cost of one Square Terminal, $100 off the cost of one Square Handheld, or $200 off the cost of one Square Register, excluding applicable taxes. Limited to one discount per product type per seller account. Each code is limited to one redemption per account holder. Valid for new Square customers located in the US only. Offer not valid with guest checkout. Square reserves the right to modify, revoke or cancel the offer at any time. Offer cannot be combined with any other coupon. Void where prohibited, not redeemable for cash, and non-transferable. #squarepartner #blockpartner
Transcript
Discussion (0)
You've had a dynamic where money's become freer than free.
When you talk about a Fed just gone nuts, all the central banks going nuts.
So it's all acting like safe haven.
I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins.
In the world of fiat currencies, Bitcoin is the victor.
I mean, that's part of the bull case for Bitcoin.
If you're not paying attention, you probably should be.
Alex, the vibe has shifted from the last time we saw each other, which was a Thursday at the Galaxy event in D.C.
Yeah, it was just shifting.
I think you came maybe an hour before that PubKey event started and said there might be some issue with cold card.
and i in my head i was like you know oh no but i was hosting that event so i got all
tied up and i didn't realize that i didn't really see the rest of the night until and then the next
day i listened to your episode with james ob where you said that you were in a had to be in a corner
on the phone the whole time which i of course now totally understand yeah pretty rough it's been a
shitty week but uh i wanted to get you on because you and the team at galaxy have done an incredible
job of tracking the um the attackers it looks like there's multiple waves of attacks of people
brute forcing private keys of those that were generated on cold card devices and contacting
victims and i think the knowledge you guys have gathered the information that you've gathered
over the last five days is important for people to understand what's going on and so i have um
i have the chart here maybe we start there um just what you guys have have found um based off
of the information the outreach they've gotten from victims and i think you said so far 94 have
reached out to you yeah it's in the mid 90s i mean um it's growing i mean all the time i mean
And especially as I do, I did Nick Batia's show yesterday.
I did Unchained yesterday, where, of course, I called for victims to not be ashamed.
You did nothing wrong.
You did not deserve this.
Share.
First of all, file police report.
Well, first of all, secure.
If you haven't secured your funds on a potentially vulnerable cold card, please do that immediately.
But also share your drained addresses and the transaction IDs that drain them.
I know, you know, it's hard for people to do it, but because I've been saying that people have been sharing and it's because of that sharing that we've been able to identify so many of the coins and where they are, what addresses they're sitting in.
So, you know, it's also and sort of in exchange, although I don't think of it, in fact, that initially I wasn't even doing it this way, but I can fulsomely trace anything in Bitcoin.
I have a very powerful proprietary Bitcoin stack with some clankers sitting on top of it that help me traverse.
So I've been providing back like forensic reports to victims that they can then use to report to their local authorities, to the FBI, to and that we can use as well to report to, you know, crypto exchanges and analysis and all that so that, you know, there's a chance that the funds get frozen.
But please do continue to reach out and share those addresses with me so that we can keep building up the picture of the attack as it unfolds.
Yeah. And let's dive into the nature of these attacks. Obviously, it started
late Thursday afternoon, early Thursday night. And I think it's become clear that AI was used
to identify this vulnerability and then exploit it. And you can see that in the patterns of the
waves of drainings that we've seen in the first wave. It seems apparent that the person who
started draining the wallets of cold card users didn't really understand best practices or or how
to actually scope through a wallet there was a very specific pattern to this first wave correct
yeah so this this pattern i i don't i think they were the first there certainly were i learned of
the pattern which was the engineers at block uh ink obviously the guys behind cash app at key
spiral um etc square right um they identified this pattern as a pattern right a key piece of
the pattern was a fixed 30 sat per v-byte fee on all draining transactions that was substantially
higher um than the median fee rate at the time which being higher than the median is not in
itself that surprising right attackers are willing to overspend to make sure they you know get the
funds. But, you know, normal people with urgent transactions don't have many bursts of transactions
from previously unknown addresses with a fixed fee rate, right? Like your wallet, your typical
wallets will suggest fee rates, you know, if you want to confirm in this amount of time, right?
Fee estimation is actually a big thing Bitcoin Core itself has worked on in Core, let alone all
other wallets, right? So that was a key feature of pattern of wave one. This is the only pattern
of coins we have very high confidence in are stolen due to this vulnerability that was solely
based on a pattern, right? And so they identified this pattern. It was very mechanical looking,
right? There's a lot about it that looks like it was designed and then executed by automation,
i'll say right and and there are others other patterns um that also look like that right these
aren't um they don't all look like that but many of them have features in the topography of the
movements and the design of the transactions themselves the fee rates that look automated
what in terms of where these these coins are going to i think the first wave
had a lot of address for use too yeah so so waves one and two and in fact um there's almost a better
chart that i tweeted earlier um well i have a chart of wave one as a perfect example wave one
alone these are like called sankey charts um and like they show like fun movements this is like
just the highest level overview chart right this shows the various waves waves one two and three
are high confidence promoted that's where people are getting this like 13 you know 56 type number
i've also promoted like a lot of what's what we call footprints a through n these uh some of them
are pattern matched um all but what i should say is that wave one was designed and then later
confirmed but first designed solely by pattern matching from block i took the pattern they
described they saw. I set off across the entirety of not just confirmed blocks and their transactions,
but also the entire UTXO history. So that's not the UTXO set. That's the UTXO set at every single
state in Bitcoin ledger ever, right? It's literally like 3.8 billion rows that I have.
Yeah. So if you look at wave one here, this is all wave one. Now, like each of these four funnels,
right these are many addresses in each case being consolidated into four independent what we call
collectors right they're collectors because they consolidate stolen funds into one step and then
that collector sent to three second hop holding addresses and you can see for some reason there's
this little gray band that comes out of the first funnel here that's not another second hand that's
actually still sitting in the collector but i put it on the right side here just to show that like
the right side is where the funds sit so this is actually a pretty typical looking um siphoning
topology um or topography i'm not sure which i think what people know what i mean that you see
in like um other types of crypto hacks right it all gets drained immediately into an address the
hacker controls and then often they move it to like the proper setup that they want right
now sometimes what you see especially in a hacker determined to exfiltrate the funds you know into
the fiat system or into whatever other chosen currency they want then you start to see radical
things like peel chains where they blow up the fund the held coins into like hundreds or thousands
of different pieces and then later they they you know rejigger them into 20 pieces that don't look
the same they do it again and again right just to make it really difficult to track um also often
they siphon them into like if stable coins are ever stolen they often immediately transfer them
into eth right because it's more immutable than the stable coin um or bitcoin sometimes immediately
get sent through thor chain and then sent onto eth and then sent through another bridge into
this thing because bridges are harder to track funds through unlike those all of the coins here
wave one are just sitting inert in these three addresses on the right so they have not moved
right and this is also true for waves two and three but one of the other things that's interesting
here about wave one and i didn't in the thread where you pulled this don't have the wave two
wave two looks quite similar as well and where it's many uh victim addresses consolidated into
a holding address and then moved to a second address where they currently sit inert um that
is a very clear pattern right like wave three which is the other one that's in that thread
just maybe if you pull up as an example looks totally different um and and i will say also
um there is no co-spend between waves one two or three attacker addresses um
there were co-spends between those bottom two funnels so this is wave three this is actually
much more sophisticated there is no common collector address this is
293 chains and by chains here we mean like you know inputs like category you know groups of
inputs so three 293 transactions funding 293 staging addresses funding 293 p2swh vaults right
So each group of victim addresses was by itself moved into a staging one and then by itself moved into a vault, which could be a multi-sig.
We wouldn't know until they spend transactions, but none of those have been spent.
I think all but six of the staging of the 293 staging addresses only contained funds from one wallet.
And now we can see that because of like co-spends of the wallets.
And I also have a lot of victims that I've identified that are in these, right?
And so the other thing is like wave one was a pattern that was described by Block, which I expanded and later has been confirmed by many victim testimonies, reports.
Waves two and three were identified by Galaxy Research solely by victim reports, right?
Like people started saying my coins were lost.
And when I gathered like 10 from wave two or like 10 from wave three, it started to become apparent.
It didn't actually take 10.
It takes fewer than you realize, because once you get like two or three that look alike, you send the clankers off to look at all the blocks all around that and say, does anything else look like a bunch of addresses into a staging address into a, you know, pay to what script witness script hash script witness, whatever, into a vault.
right then you say oh my gosh there's an entire burst of of transactions that look exactly like
that and that's how you know and then of course i start publishing about it people start saying
i think i might be in wave three they send me their stuff we get further corroboration it
becomes like high confidence so you know one the another interesting feature of one and two i told
you they look similar right many victims into very few staging addresses then into second hops where
they're inert um the only two of one like of really there's a couple down talk about footprints
which are these smaller operators that have emerged but there are a pretty sizable number
of people who were drained in wave one that were not completely drained who were later fully
drained in wave two so there's a number of those that gives us some i would say medium to high
confidence that wave one and wave two are the same attacker now you know someone could and by the way
wave one to your point was all just after midnight uh july 30th utc so some people were like oh i was
july 29th and it was like no if you look you were like you know west coast uh july 29th at night
that was actually early morning utc july 30th um we use utc because that's like the default
bitcoin core and stuff so it's just like easier to you know pick one um wave one happened in 41
minutes very identifiable right like you don't usually because another big identifying feature
is that not one of the high confidence what i call promoted meaning like we're saying these
are drained like these is no longer a question not one of those utxos was created before march
17th 2021 when the you know cold card firmware bug was introduced um and i will say like there's
other patterns like the the median dormancy of all these coins is like four years an enormous
portion of the coins in waves one two and three which are the majority still of you know high
confidence um victim addresses the vast majority had never spent a coin right so these are just
receiving coins very indicative of people stacking sats into their cold card and um you know in cold
storage um so you know i think like there's co-spend which can help identify but again
everything after wave one were pattern to the extent we found patterns there are some where
i'm not seeing a pattern but i have a victim report it the one that i see it looks credible
and drained. And so we've incrementally added those two. But also we found something like we're
up to, I think in the graphic, the first graphic you showed, we were up to footprint N. That means
we have multiple, the footprints are, we have multiple victims where the topography looks
similar. They don't necessarily co-spend. A few of these co-spend. And so we're very confident
and have promoted. But as you can see, this graphic is everything that we haven't yet confirmed.
this goes up well over 2000 Bitcoin. The shaded ones are, I think, not confirmed, right? By any
owner, right? These are patterns that we found, but haven't yet gotten a confirmation at all.
Some of those footprints are, they're identified by the fact that victims showed us. And we've,
you know, said, is there anything else that looks like this? But we don't quite have enough
confirmation that we should extrapolate it out to transactions that we don't actually have
confirmed by a victim, right? Because there are plenty of transactions in waves one and two
and three that we haven't actually gotten a victim report about, but we're very confident
are part of the wave. So that's just some background on the methodology that we've been
doing. And just as background, like I have direct victim confirmation for about 400 Bitcoin of the
1500 or so that we currently call high you know value promote uh promote so a sizable amount have
i've talked to yeah it's so heart-wrenching um yeah but and i think explaining if you haven't
if you have a cold card i don't care what your setup is i mean if you roll dice you should be
fine but if you don't have confidence that you did it correctly just get it off i agree
Yeah. And another important thing to say, but again, and I have a cold card MK3, I believe with no password and no dice in a multi-sig quorum that cannot reach signing threshold. So it really can't be affected at the moment. And in that quorum, I've never spent.
So there the address isn't known to hold coins on chain, for example, because it's, you know, like a it's a script hash address that has never revealed its script.
Right. So but I and I haven't because I know that that isn't vulnerable at the moment.
I haven't actually rotated the cold card out yet, but I absolutely will.
um so and i will say um i haven't updated this analysis since like midday yesterday but
i can say in waves one two and three for sure there are zero multi-sigs identifiable so as far
as i'm concerned there's no evidence that any multi-sig setup has been breached here now of
course if you had like say a two of three multi-sig quorum where two of three are cold card mk3s like
mine with no passphrase and no dice roll that is vulnerable um i haven't seen one instance yet of
it being attacked it's probably you know rob hamilton and the red team working on this is
probably more and james ob are probably more apt to actually talk about that but i i understand
that's probably lower on the tier of priorities that the black hats are looking at to search
namespace for it's more complicated um but all that being said like i i am of the view that like
anything on a cold card at all including my sub threshold uh quorum key should be rotated i mean
it's there's just no reason to to stick around if you have any doubt whatsoever in my opinion
sup freaks this rip was brought to you by our good friends at square if you run a business you need
payments you need hardware you need software invoices point of sale tools and a system that
does not turn every basic operational task into a headache. Square spent years making it easier
for small businesses to get paid and keep moving. And now with Block leaning deeper into Bitcoin,
Square sits at an important intersection. Real world merchants, payment infrastructure,
and the future of Bitcoin commerce. We're making Bitcoin everyday money freaks. You are starting
or upgrading your business setup. You can get up to $200 off Square hardware at square.com
slash go slash TFTC. All right, freaks, you know I don't take sponsor money from products I wouldn't
use myself. So listen up. The Avon Bitcoin Visa card is one of the most interesting things I've
seen in the Bitcoin lending space in a long time. Here's the deal. You can get a line of credit up
to a million dollars backed by your Bitcoin without selling a single sat. No games, no annual
fees, no minimum draws. And your Bitcoin is custodied by Bitco, one of the most trusted
names in digital asset security. Avon never lends it out. There's no rehypothecation. You stay in
control. You can lock in a fixed rate for up to 10 years. 10 years. That's 10 times longer than
most lenders out there, or go interest only for up to five years. Rates start at 8.99% APR. For
a product that lets you keep your stack and still access liquidity, it's hard to beat. On top of
this, guess what? You also get 2% unlimited cash back every time you use the card. Spend fiat,
keep your Bitcoin. That's the whole game. If you've been stacking for years and need liquidity
without triggering a taxable event, this is worth a serious look. Go to aven.com slash Bitcoin.
that's aven.com slash bitcoin check it out yeah it's a timing thing that i mean bringing this
back to the waves um obviously waves one and two at a very specific pattern but that is the game
theory at play right now it's just a ticking time bomb if you have private keys generated with the
affected versions of the firmware which started being released in march of 21 so i think version
4.0.0 and beyond are affected different models have different levels of entropy
older models i think have more pretty confident of more entropy but still not a sufficient amount
of entropy to protect you from a brute force attack so move your coins if you haven't already
and the game theory is such that once the alarm bell was sounded last thursday and it became
obvious that this was exploitable you just have to assume that other actors are going to enter
the fray to try to exploit this too so the time bomb could be accelerating the pace of the clicking
ticking of the talk can be accelerating so move with haste um and i i think that's another
weird factor that's entered the conversation too is there's i mean i've been listening to spaces and
following this discussion since thursday night on the train ride back people were already talking
about this because you had people like wicked bitcoin portland hodl rob hamilton praveen like
basically downloading the scripts to brute force private keys or seed phrases on their computers
and they were able to identify wallets and the ethical conundrum of do we sweep this as white
hat hackers into addresses that we control and the hope that we can get this back to
the original owner that conversation started pretty early thursday night i think there has
been confirmation that some people have engaged in white hat sweeping of these coins but it gets
into the again the ethical dilemma but then the just the logistics of even if you do that how do
you get the coins back and i think that's another important detail um in if there is a scenario in
which um we identify the attacker or white hats have swept funds and they want to return them
I think the ability to prove that you were the individual that actually created the private key initially depends on you actually having your physical device.
Yeah.
And you mentioned a couple people there, too.
You got a shout out to Wicked.
Wicked's, I think, what is he, Wicked Smart Bitcoin?
is that and he didn't even say that anymore but um that guy's been doing like spaces just helping
people who you know answering q a on self-custody at the most granular level i have literally
listened to him help dozens of people like move coins off their cold cards live uh reminds me of
the old clubhouse days a bit yeah what um because i know you identified somebody i forget from which
wave that sent it to a casino yeah this this one was pretty ugly like um not from waves one two or
three those coins are inert they're not they haven't moved right and those are the key ones
that we were watching um because they comprise the largest share of the known stolen coins one two
and three um yeah there was a victim uh that we traced and that i think seven or ten of their
17 bitcoin was instantly moved to thor chain which is a cross chain dex that lets you effectively
send bitcoin into a multi-sig controlled by their validators um and you can put an ethereum address
for example and a trade order in an op return um and then they spit out the equivalent eth on the
other side uh in ethereum and so you enter your ethereum address in the hop return plus some other
instructions about the trade that you want done um luckily that way it works is it's pretty easy
to trace through there at least in my limited experience tracing um and then then it's a matter
of using the ether scan api to follow where it goes and ether scan has a lot of deposit addresses
for exchanges and services labeled um these were something like i don't know four hundred and fifty
thousand dollars worth of the bitcoin now eth was deposited in an offshore uh casino that i'd never
heard of called dual.com and so i told the victim this and gave instructions on how to send a
preservation request and a freeze request to the casino um and they this was like at 1 a.m on
sunday morning so like late saturday night eastern time and they did get a response and it was like
we're not going to freeze until we get a police report demanding the freeze.
And I found that to be offensive because it was midnight on weekend.
There was literally zero chance that a police report was going to be sent
anytime soon.
And I thought the prudent measure for any sort of financial institution when
receiving a credible cryptographic forensic report,
effectively proving that the funds emanated from a stolen address um would be sufficient to just
i'm not saying take the coins from the casino depositor i'm saying don't allow them to be
withdrawn right um until an investigation is complete i guess they declined to do that though
they did promise me via dm that they would preserve the information about it which you know
And I don't know what jurisdiction this dual.com is actually registered in or if they are, but that may be all that's required.
And, you know, they wrote back on X that there it was unreasonable to demand solely based on a report that their customers could not withdraw.
It is an interesting thing about raise a lot of interesting ideas.
One is that, you know, I have the victim report.
um the victim can prove they do possess the keys but the nature of this exploit is that they are
not the only one who now possesses the keys and um eventually everyone might possess the keys to
all of these coins right um and that's that's tricky that's one reason why we really encourage
people to formally file like victim reports with the local police um the fbi's ic3 um canada's
anti-fraud center the um you know royal canadian mounted police i've got a whole list by the way
if people need to know who to contact in their jurisdiction these exist all over the world right
there some of them share information with each other and all that is to establish victimhood
early because there could be a time if funds are recovered where many people use keys to claim that
they're theirs right and it becomes a whole cluster that's why i also tell people not to
destroy their cold cards even after they've moved funds off of them or had their funds
drained because there might be forensic evidence on the cold card that can be used to
establish their you know in this you know that they're the primary uh owner in the chain um and
another thing that it raises is the question of hold authority this came up once uh recently
uh with an uh a hack and a defy hack and it's forgetting which one it is there's been many
um where zack xbt and others notified very early to circle that funds were being
exfiltrated and bridged sorry bridged over circles uh sort of i think it's called cctp
uh cross-chain stablecoin bridge which is an interesting version of a bridge by the way that's
more secure than some of the like lockup funds on one side, reissue them on the other because
it goes through Circle, but it goes through Circle.
So Circle is the issuer of USDC, just cancels them on one chain and reissues them to you
on the other, which is actually safer in a lot of ways because it's not like locking
them up to create a honeypot on one side of the chain, which is how so many DeFi bridges
are exploited.
Anyway, they didn't.
They circle declined to stop this, even though they'd been warned for like six hours loudly on Twitter that this was happening.
And they said that they needed what was called hold authority.
This is now in clarity, this idea of hold authority.
It says that, you know, if you credibly know that or have reports that there is, you know, this type of fraud, whatever, going through your centralized platform, you you can hold it, freeze it on your platform for some amount of time.
I think in clarity, it's 48 hours while you investigate and you are totally immune from civil liability.
So I understand, you know, I think there's an argument to be made in the case of the dual dot com with this one that I talked about.
Like, you know, are they worried about being sued by their client who they promised, you know, their user, you know, instant withdrawals?
like i you know i get that it's a little tricky but i'm becoming a little bit like you know tay
vano if people follow her who used to was like had a security at metamask and had my ether wallet
big big i think participant in the seal you know rapid response crypto hacks team she is just zero
patience for this type of behavior and just the more people i've talked to from the cold card hack
and seeing this type of thing and just like knowing the funds are there and not being able to get them
to act is incredibly frustrating so um yeah we haven't i gotta say the vast majority of coins
we have not seen that type of exfiltration behavior from um maybe there's luck maybe they
do have kyc at dual.com and you know with the police report maybe they'll be able to identify
that hacker but that's the other part of the story marty that is definitive well it could also be but
Very doubtful. I would say definitively not the same hacker from Waves 1, 2, and 3.
Well, didn't Block report that Waves 1, 2, and 3, the hacker was obviously using some chain analysis tool that was a paid service?
Yeah, I think this is Wave 1 in particular, which is the one that they really blogged about where I got that first pattern to work with.
they said that and i don't know how they figure this out but i think that clay from block said
that they from from bitkey i believe right said that they confirmed this uh with the blockchain
infrastructure provider i i don't want to i don't know the details but what i do know and what they
said was and and what i assume is the blockchain infrastructure provider is like um a in this case
a party that you can uh connect to their rpc right and pull blockchain data from potentially
for many chains right they have apis or rpc providers there are many of these to be clear
it's a great service especially for you know blockchains like ethereum and solana which are
even more cumbersome to run than bitcoin right many people use these for many obviously to be
clear obviously totally legitimate reasons but somehow block said that they had identified that
the same entity they believe to pattern they observed that what i now call wave one
had queried like i guess a lot of the addresses that they ultimately attacked
through this blockchain provider and that in talking with the blockchain provider they learned
that this entity had used a paid account at the blockchain provider so i think this is very
promising as potentially uh the ability and that authorities have been notified so potentially the
wave one attacker could be identified and and that that could be very very promising you know
knock on wood i don't want to you know get ahead of ourselves here but um you know you say run your
own node verify your own transactions in the blockchain apparently wave one hacker did not
do that even though it would have been pretty trivial to do so yeah he didn't spin up his own
node and that i mean that that begs the question too like what what can these attackers do now if
they have the coins obviously you mentioned like thor chain and split there are things i i think
yeah i've seen some bitcoiners who aren't as haven't you know followed or been as close to like
most of these hacks are like centralized exchanges or like smart contracts and d5 right historically
Bridges, DEXs, obviously centralized exchanges, you know, many such instances.
It doesn't happen very often in the Bitcoin ecosystem directly outside of centralized exchanges because there is no DeFi on Bitcoin, right?
It's a pretty simple protocol, which makes it a lot more secure, in my view, at the protocol level than many of these others, which are much more complicated.
it and um and it doesn't have the generalized scripting that others do so like you know you
don't have people creating novel new programs and stuff like that multisig is native on bitcoin
whereas it's not on ethereum etc etc um so people have been saying like what what can they do we can
track it everywhere um they can be just the hackers can themselves be expert money launderers
um they can pay money launderers these people exist they have methods like it is possible for
them to exfiltrate these coins it is hard it's definitely hard right there are mixers and tumblers
you know in the bitcoin world that they could use but those are like very uh uh watched targets by
law enforcement right so you can bridge to another network that has privacy protocols right the fact
that the one we talked about the one to dual.com didn't go through like tornado cash first on
before going to dual.com is surprising suggest they really were not very sophisticated even
even though this attack seems so sophisticated and it is pretty sophisticated that shows you
like how it's degrading like waves one and two and three are more sophisticated and who knows
why they're sitting inert on bitcoin i can tell you it's it's not because it's impossible for
them to exfiltrate the funds but it is difficult to do so without getting caught right and that
that is a silver um or a potential positive that it isn't easy but it but i i would caution
don't hang your hat on that it is possible to launder money out of bitcoin freaks look at me
i'm glowing i've got like an angel's halo going around me you know why that is is i feel good i
feel taken care of i feel blessed healthy happy and that is because i'm a crowd health member
My family and I have been CrowdHealth members for five years now, literally this month. Five years
ago, we joined CrowdHealth. We've had two babies. We've had multiple health events, and we're never
going back to health insurance. CrowdHealth is crowdfunded healthcare. So you sign up for
CrowdHealth, you pay a monthly fee, you help out with other people's bills, and it's significantly
cheaper than health insurance. We were on COBRA as a family of three when I left my last job
before I went full-time to CFTC, went on the CrowdHealth. Now as a family of five, we pay,
I believe, $700 a month. It's significantly cheaper. They're going to negotiate prices
lower for you. They've consistently negotiated healthcare prices as much as 50%, 60%, 80%
in many cases. They help out with babies. If you have a pregnancy, you pay the first $3,000
and the crowd covers the rest. If you have a regular health event, you pay $500
and the crowd pays the rest.
Go to joincrowdhealth.com, sign up today,
use the code TFTC, opt out of health insurance.
I'm uninsured, baby, and I love it.
Use the code TFTC at joincrowdhealth.com
and you'll get $99 a month for the first three months
that you're on the CrowdHealth platform in the community.
Bitcoiners, you found sovereign money,
now find sovereign health and sovereign healthcare.
So freaks, when you take Bitcoin seriously,
you start with custody.
You want to control your keys,
avoid single points of failure,
and make sure your savings cannot disappear
because you or someone else screwed up.
That is what Unchained has been focused on since 2016.
Unchained is the leader in collaborative multi-sig custody
and Bitcoin financial services that keep you in control.
They secure over $12 billion in Bitcoin
for more than 12,000 clients.
That means about one out of every 200 Bitcoin
sits inside an Unchained vault.
Their model is simple.
You hold two keys, they hold one key.
It always takes two keys to move Bitcoin,
meaning their single key can't access your Bitcoin on its own.
Just resilient, shared custody
that gives you institutional-grade security
while keeping you sovereign.
Unchained also lets you trade straight from your vault,
access bitcoin-backed commercial loans open a bitcoin ira where you hold your own keys and
set up personal business trust or retirement vaults they even offer inheritance solutions
built for long-term hodlers or opt for the highest level private client service with unchained
signature and get a dedicated account manager discounted trading fees exclusive access to
events and features and much much more if you want a partner that helps you secure and grow
your bitcoin without giving up control go to unchained.com and use the code tftc10 at checkout
to get 10 off your new bitcoin multisig volt that's tftc10 at unchained.com i mean there's
been a massive reaction obviously you and your team are tracking this but it seems like um there
has been somewhat of a immune response to not only obviously for um cold card victims but it has
incited this urgency across the industry to begin auditing every system and that's yeah something
that's been fascinating to watch unfold
over the last five days is the speed
with which Rob Hamilton, the new CEO of Bitcoin
and the Red team that are working on
basically auditing as many projects as possible
are uncovering, I mean, they haven't disclosed any,
but Rob did come out and confirm
that all the vulnerabilities that they have found so far
do not put funds at risk immediately.
or funds at risk at all, I believe he said.
Don't quote me on that.
I could double-check that.
But I think it's, I said this yesterday on RHR,
like by no means is this something that this cold card hack,
this cold card vulnerability was human error.
It seems like AI was used to discover from these attackers
and they've exploited it, but there have been reports of others in the past
that we've all been made aware of now that were reporting that they had collisions
and their coins were getting out there.
So this has objectively been possible for five years.
It seems like there were some users who were reporting that they went to their wallet
and funds were swept, and maybe that wasn't an attacker,
was just a coincidence of somebody creating a private public key pair using a cold card and
sweeping the funds once they noticed there were some there already but um ai is a very
very big and is becoming a larger sub theme to all this both the exploit side and the reaction
to it as well yeah absolutely and you know it's worth noting i think and i'm not going
going to cite any of the names because i forget them but um bugs in the entropy uh random number
generators in crypto wallets have existed before and have been found without ai um so it's not that
it ai was needed to find this bug in the implementation of cold cards random number
generator but it is pretty likely that it was used and it's definitely being used by attackers
to operationalize the vulnerability uh rob and the red team uh there's a bunch of efforts going
on right i'm focused on on-chain tracing of funds because that's what i'm good at
um rob and and many others are just burning tokens like evaluating doing code review
um with frontier cyber enabled models but also like kimmy and glm the open source models
on like basically anything they can get their hands on in the bitcoin community so other hardware
wallet code bases like libraries that underlie important bitcoin infrastructure like everything
you can think of which is a huge effort there's also like we said people like wicked literally
helping individuals migrate coins there's people that are trying to replicate the attack in order
to like determine how many addresses are still at risk right like and you need substantial compute
for that people are chipping that in there is a huge immune response from the bitcoin community
in reaction to this exploit um but to your broader point marty about attacking and defending with ai
that's been a you know a huge problem right like you remember there's the opening i know you guys
covered this the open ai lab leak uh that hacked into hugging face which itself is an ai model
repository um hugging face said they couldn't use frontier models to defend themselves they kept
hitting all the cyber safeguards and so they had to fall back on chinese open source models and
to me the idea that american companies have to rely on chinese ai models to defend themselves
is absurd and something needs to give here i don't know if it's just the sort of safetyism
emanating from the frontier labs or if it's in reaction to the u.s government's midnight
phone call to anthropic that halted the release of mythos but something needs to change and i
wrote this on x you know to the extent that i have any reach i'm escalating that to the highest
levels i have access to because it's absolutely insane even myself i primarily am using claude
code and codex um and even asking again on a database that's local of bitcoin data which is
public right even saying hey i have a report from a victim that they were drained you know in this
transaction id can you like pull the transaction information out of my own computer and i'm
hitting fable five safeguard and getting downgraded to opus right like it's insane it's just insane
um something's got to give here no it does to think that i mean it's
i try i mean it's something that we've been saying in bitcoin just in the concept of like
trying to throw kyc aml restrictions on bitcoin bring it to the chain level or
prevent people from accessing privacy preserving tools it's like well yeah you can you can try to
prevent people from using bitcoin in a peer-to-peer fashion or using it in a private way but criminals
don't care they're gonna they're gonna use it that way no matter what they're criminals because they
do not have a high regard for the law in the first place and so when it comes to this discussion
around ai and defending against attacks and being proactive to secure your systems and make them
more robust from a security posture it's insane that we have to fight this battle particularly
in the u.s right now i think everybody's using kimmy i believe gwen came out with a new model
just yesterday that that's in the mix and i think the red team i saw rob or cali say that um they
did get access to open ai's edge enterprise frontier model yeah and i can just say i i know
of some crypto big crypto companies that have access to uh either glasswing or open ai uh
frontier cyber models and are have been doing work on you know code base review and vulnerability
reporting uh responsible disclosure stuff like that and stuff that also helps bitcoin um and
also i think there's i don't know if it's pronounced like this you know when you've only
read something you never heard it said out loud project lupe uh is an open source uh like llm
security vulnerability project and i don't know who runs it but i know steve lee is involved
and they're also working on this so there are a lot of efforts it's not just bitcoin or even
blockchains like this is a global question like every company needs to upgrade we're in an arms
race right now i do think like it's like going to be episodic and we'll get to a you know it'll
plateau where the defenders have caught up to the attackers and so there's a little bit of a detente
i think governments will impose some actual like pausing and safeguarding as these things get
better and better um for better or worse i think they will even i think the chinese government
will eventually not allow like the most danger because you know the open source models can be
used by their people as well um and so like i think you'll see but we are definitely still in
early innings where it is like attackers are outpacing defenders and so uh defenders and by
the way that's like true for like every weapon on earth you know like the mongols like defeated the
whomevers because they had horses they were shooting arrows from horses and that had never
been seen before right like we're kind of in that era right like you know the american revolution
they kind of invented guerrilla warfare and that was overwhelming to the british's column warfare
So, like, we're still in that stage, but I think it'll be episodic where, you know, you reach plateaus and then who knows, maybe step function increases cause another episodic arms race and blah, blah, blah.
But we're definitely still in a period where the defenders don't have access to good enough defensive tools, I don't think.
No, I mean, obviously, Bitcoin is being affected right now, but there was a report out of Minneapolis, I believe, or Minnesota a couple of weeks ago about water.
treatment plant being affected by some virus and shutting down if you think of how antiquated
the software around grid system grid systems are today energy systems like this is i mean when it
comes to the broader discussion about getting access to frontier models to people that need
to defend these systems i think it's it's an imperative it is a national security issue at
this point yeah it it is and i have to say like i don't have the answer on what the policy
should be exactly i just know that current status quo isn't good enough
no i know you got to jump here thank you for taking some time to hop on um i really want to
get you on so that anybody who may be a victim out there and isn't aware of the research that
that your team is doing and the the data gathering yeah following you can see we publish
fair amount on glxy research on x but um so you can get all the info on how to contact me and us
through that but um that accounts uh dms are not open so you can dm me on x at intangible coins
i would love to help and marty i just wanted to say like um thank you for you know being in this
community i know it's um been a really tough time for uh you know you guys as long-time users of
cold card as well i've used cold card i think the first rap i ever did on galaxy brains had a line
about um using cold card keys because we hold hard cheese so um and and also i i've been explaining
this attack to journalists to uh institutional investors who are interested but not affected
because, you know, they use custodians and stuff like that. And one of the things I've been saying
about why this is so demoralizing and such a tragedy, though I believe anyone having their
money stolen for basically any purpose is terrible, is that these victims didn't do anything wrong
and they didn't even do anything risky. In fact, if, like I said, the vast majority of the coins
being stolen, their addresses had never spent their coins and they'd only received. And the
average, the median dormancy of the coins being stolen is like 3.8 years. These are long-term
DCA Bitcoin believers, the cultural demographic of people that use CoinKai. I mean, I've got a
over my shoulder the last 250 episodes of Galaxy Brains. The people that use these are largely
the most philosophical believers in Bitcoin. And this sort of strikes at the core of the self
custody, you know, work hard and save in Bitcoin. You know, again, nobody deserves to have their
money stolen, but these people didn't put their coins on a shady crypto exchange to speculate.
They didn't accidentally, which, you know, leak their coins, didn't drop their hardware wallet unlocked on the ground.
They didn't accidentally upload their seed phrase.
Not that those, you know, those are mistakes, but these people didn't make any mistakes.
And that's what makes it so upsetting and why people are worried about sort of the future of the self-custody movement.
Now, just say self-custody is not dead.
This was a poorly implemented thing.
random number generators do work they are proven to work this one is not proven to work and that's
why rob and the red team and many others portland and calais and others who are helping are so
essential but i think the wake-up call for us in the bitcoin world is that you know verifying and
auditing code is not like a checkbox like it's something we've got to be doing you know 24 7
365. But I personally do believe this will damage the single-sig, keep your hardware wallet under
the bed and put your seed in a seed plate. I think the future of self-custody is multi-sig
collaborative custody. I do believe that firms like Casa and Unchained and Nunchuck and
the Miniscript-based ones like Liana Wallet and Anchor Watch and others, I'm sorry if I'm
forgetting others. There are ways to provably and to really diversify the exposure to hardware
wallets or specific key generation mechanisms that might sound difficult when I say multi-sig
collaborative custody, but actually there are many strong companies that provide this as a
relatively cheap service. So, you know, if you are hell-bent like I am in doing self-custody,
look into those. I think we need to be a lot more deliberate about the risks that people take.
I do think telling people to roll a hundred dice is just not going to work for the majority of
people. But there are easier ways. You don't have to be permanently demoralized about self-custody.
I agree there. I'm not going to give any advice at the moment, but I think the only advice I will
give is if you have a cold card if you're for some reason just becoming aware of this just move
your funds asap alex thank you brother um if you aren't following alex and the team of galaxy
research if you're a victim um make sure you're following them make sure you're reaching out
again i think police reports if there is a chance of recovery of funds like having that police
report and holding on to your device will be be critical so make sure you follow that that advice
And this is obviously a developing situation, so make sure you follow the teams that are on top of this, which Alex and the team at Galaxy is very much on top of this right now.
Thanks a lot, Marty. Good to be here. Yeah. Please reach out if you're affected.
Peace and love, freaks.
Thank you for listening to this episode of TFTC. If you've made it this far, I imagine you got some value out of the episode.
If so, please share it far and wide with your friends and family. We're looking to get the word out there.
also wherever you're listening whether that's youtube apple spotify make sure you like and
subscribe to the show and if you can leave a rating on the podcasting platforms that goes a
long way last but not least if you want to get these episodes a day early and ad free make sure
you download the fountain podcasting app and go to fountain.fm to find that five dollars a month
get you every episode a day early ad free helps the show gives you incredible value so please
consider subscribing via fountain as well thank you for your time and until next time
