Unchained - Is Any Cold Wallet Safe? Inside the Coldcard Hack's Wave Three

Episode Date: August 4, 2026

📢 Bits + Bips has its own channel now — full episodes here: https://www.youtube.com/@Bitsandbips  A firmware bug quietly introduced into Coldcard hardware wallets in 2021 has let attacker...s drain an estimated 1,600 to 2,000 bitcoin, over $100 million, from cold storage addresses that sat untouched for years. Galaxy Digital's Alex Thorn has been tracing the exploit in real time, and in this clip he breaks down exactly how the random number generator meant to secure private keys "failed silently" into "way too weak entropy," and lays out the wave-by-wave forensic trail he is using to track the attacker. Alex Thorn identifies three confirmed attack waves and a possible fourth, and Chris Perkins makes the case that even a "trustless, permissionless" system still requires trusting something, in this case, a hardware wallet's own firmware. Hosts: Austin Campbell - Host of Bits + Bips, Founder of Zero Knowledge Group, and Adjunct Professor at NYU Stern Ram Ahluwalia - Co-host of Bits + Bips and CEO of Lumida Chris Perkins - Co-host of Bits + Bips and Head of Franklin Crypto Guest: Alex Thorn - Head of Research at Galaxy Digital and host of Galaxy Brains This clip is from a longer conversation on the Coldcard hack, U.S. AI guardrails, and the case for self custody. Full episode here. https://youtu.be/0oYZGw2DSj0?si=TwubhLQ35L8cXyG_  We go live every Monday at 4:30pm ET. Subscribe to catch it live. 👉 Cape: Your biggest crypto vulnerability isn't your wallet, it's your phone number. Cape is America's privacy-first mobile carrier that rotates your SIM identity daily and blocks SIM swaps before they happen. Get 33% off your first six months at https://cape.co/unchained (use code: UNCHAINED). Chapters 🔐 00:00 Coldcard's reputation as Bitcoin's gold standard hides a deep systemic flaw 🎲 03:42 How a 2021 firmware update let key generation fail silently into weak entropy 🕵️ 09:56 Alex Thorn traces three confirmed attack waves, and a possible fourth 🤝 14:05 'They trusted Coldcard to do the right thing': what broke when a hardware wallet failed Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to a brief segment from one of the Bits and Bips episodes this week. The full show is now only available on its own dedicated Bits and Bips channels. So be sure to go to X, YouTube, and your favorite podcast platform and search for Bits plus sign Bips, spelled BIPS, and subscribe. So Cold Card was a hardware wallet, largely marketed in some places as the gold standard in the Bitcoin ecosystem, and it had a deep systemic flaw. So an exploit tied to entropy, aka key generation, cold card Mark 3, Mark 4, Mark 5 had Bitcoin drained from, I believe, well over 1,000 wallets at this point. And the reported total has been climbing throughout the week up, up, up, up. CZ via Zero Hedge said nothing is 100% warning Bitcoin holders after the exploit.
Starting point is 00:00:59 We also have an expert who's been commenting on it extensively here, Alex Thorne, who, Alex, I saw in Coin Telegraph, you said a fourth organized wave is likely in progress, 208 transactions across some specific blocks sweeping about 389 Bitcoin from 462 suspected victim addresses in roughly 2.5 hours. Human cost is real here. Good example, the retail bull had said, I've had all my Bitcoin stolen while away on holiday. It was on a cold card mark three. I was led to believe this was really secure. The two Bitcoin was supposed to be to give to my two children to give them a good start to life. And the ETF crowd has been speaking up here. Eric Balanchunas said such an intermediary upgrade for Bitcoin, safer, more secure, and almost always cheaper.
Starting point is 00:01:56 speaking about ETFs, 33-year-old industry, 15 trillion in AUM, and never once lost someone's money. So I could go on and on about this, but Alex, you've been observing the whole thing. Could you start by telling us, like, the core of how did people get this wrong? Why was all this money sitting out there in a way that it could be stolen? Yeah, it's been a brutal four days. This sort of started early in the morning, Thursday, UTC time. And it is still ongoing. Before I even go, if any viewer or listener has funds on a cold card and a single signature address, as in not part of a multi-sig quorum, you should move those coins off as soon as possible. And by the way, I like Eric Belshunis quite a lot.
Starting point is 00:02:47 But obviously an ETF holding a DTC registered stock inside it is not the same thing as one that holds a digital bearer. set. But we move on. The saddest part is that to your direct question, Austin, these people did nothing wrong. In fact, they did everything right. And the cold card itself is very popular among a cultural demographic in Bitcoin that believes in cold storage, self-custody, stacking sats, working hard. You know, not that anyone deserves to have their money stolen, but this isn't a drain of a D-Fi bridge where you were, you know, bridging between. you know, Ethereum L2s to harvest, you know, altcoin inflation yield, right? This is not people speculating on crypto exchanges on mean coins, right? These are people, by and large, and I can tell
Starting point is 00:03:41 you, I know this community quite well that are working hard and saving and stacking sats and then putting them away for a long period of time. The average dormancy of coins that has been siphons like almost four years. So these are not like short-term holders. That makes it particularly devastating because they did nothing wrong. To your point, just to underline it a little bit of how this happened, when you generate cryptographic keys, you need entropy. You need a random number generator to seed the key generation with randomness, which is
Starting point is 00:04:18 what makes it difficult to brute force attack. And Cold Card had updated. their firmware on March 17th, 2021 to add their own version of a random number generator. And it's not even that that version wasn't good. They miswired it into the firmware, such that it would fail. It would never be routed through that random number generator. And it would fail silently and it would backfall to this other crappy random number generator that has way too weak entropy to create secure keys. That means that attackers with compute that know this vulnerability can go and use that random number generator that it did end up using
Starting point is 00:04:59 and compute billions of public keys, then go and private keys, seeds, seed phrases, and then derive the public keys across the whole derivation space, and then go and see if any of them have coins. And if they do, bam, submit transactions to move those coins to new locations. It's the worst type of attack. These people did not accidentally drop their hardware wallet on the ground or post their private key in a chat. They didn't even click a link, a fishing link that siphoned their metamask, right? Like so many that we see.
Starting point is 00:05:34 I think that's what makes it particularly devastating, you know, when compared to other hacks, all of which are devastating. But this is really not supposed to happen. So to unpack this one, the problem here, ironically, had nothing to do. do with Bitcoin specifically, this was a core, like, cryptography exploit where you had a poorly generated, at best pseudo-random function to create your seeds. And as a result of that, whatever was secured with that cryptography could have been hacked. So if this had been, for instance, a, I don't know, email provider using encryption instead, you would have been able to get into everybody's email, correct? Like, this is not a problem unique to blockchains. It is a
Starting point is 00:06:19 Cryptography problem? Yeah, absolutely true. And not, yeah, not only not a Bitcoin problem. Could have been an ether Solana problem. And to your point, could have been, you know, an encrypted zip file problem or any type of key generation. And the worst part is it's not even really even the crypto. The software and the firmware just failed to route the key gen through the number number,
Starting point is 00:06:42 number, random number generator. This is not the first time that we've seen random number generator problems even in crypto, to be clear. I think one of the other things that's so astonishing, though, is how popular this hardware is. It's great hardware, to be clear. They also make the block clock and the OpenDyme extremely popular Bitcoin native hardware. This is a software development failure that somehow went unfound for five years. It probably was found with the help of AI.
Starting point is 00:07:13 People have proven now that it's known that AIs can find it. But it didn't need AI to find. There are simply not enough eyes on this codebase. There were obviously issues as well with the code base. It was not fully open source. And when you look at the code base, there's hundreds of commits right to the master branch with no comments, right?
Starting point is 00:07:37 So it doesn't seem like it was properly reviewed either. But just for some numbers, you know, I'm not an expert in, I'm not a software developer. I'm not an expert in cryptographer. and I'm not an expert in this type of computation to derive these seeds, which is what the attack is. I am an expert in on-chain forensic tracing, and that's what I've been doing. I've been following the funds here and trying to identify victim and attacker addresses,
Starting point is 00:08:09 and along with helping victims, if they reach out to me, also submitting those addresses to relevant U.S. federal government law enforcement, crypto exchange, exchanges, crypto isax, right, seal, all of the relevant cyber investigators to try to make sure that these addresses get flagged by chain analysis at TRM labs and elliptic and all the exchanges so that if they do appear at a centralized intermediary, there's a chance of recovery. It's quite interesting. This started, you know, I've got three defined waves, we call it, wave one, wave two, wave three, any prospective wave four, which is still sort of in the medium to high confidence. I haven't actually promoted into what I'm considering a high confidence part of the attack.
Starting point is 00:08:54 That's one reason, by the way, why it's so difficult to trace, not because it's Bitcoin specifically, but because these are like thousands of previously unconnected cold storage addresses. You know, if a bridge gets hacked, we go and look at the smart contract address and we see all the funds flowing out of it and we see where they go. this to actually gather and find all the examples of people's cold storage addresses being siphoned, we basically have to rely on patterns of attacker transaction patterns and victim reports. And so wave one, which started just after midnight UTC on Friday, on Thursday morning, July 30th, was really identified by victim reports around the community.
Starting point is 00:09:37 And then the pattern described and identified by engineers at Block Inc. right, which Cash App Square are the Vickey, those guys, brilliant engineers there who have their own hardware wallet, the Big Key, they identified the transaction pattern that then I extrapolated to go find the totality of Wave 1. I've since talked to dozens of victims who are confirmed part of Wave 1, and those victim confirmations are sort of how we verify that our pattern analysis is accurate. Alex, can I ask a question, wave one through four, same attacker? Are people piling in and saying, oh, I found an exploit?
Starting point is 00:10:16 Yeah, so wave one is like a bunch of, obviously, seeds broken and funds transferred in bulk into one or two collector addresses and then one or two attacker holding addresses and they're sitting there inert. Wave two is a very similar topography. Again, tons of confirmation from victims in Waves 1 and wave 2. so we're very confident in that set. Wave 3 has a totally different topography, a very internally consistent one.
Starting point is 00:10:44 So we think each of these wave 1 and 2 and 3, we're confident are waves. Wave 3, though, rather than siphoning many users into one big address, which is sort of what 1 and 2 do, wave 3 has one victim per vault storage by the attacker. So it's like if my 10 address is all get siphoned in one transaction. They stop at one spot intermediary that's just for me.
Starting point is 00:11:11 And then they go into one vault that's just for my funds. And they're all. So there's 293 victims, we think. And there's 293 vaults. So I don't know if one, two and three are the same. If I had to guess if there is any overlap, I would say one and two are probably the same. One and two comprise like 70 plus percent of all the funds we think have been stolen. Three has a bunch, two. If it if three is the same as one and two, then the attacker demonstrably changed their operational process. Wave 4 is still not totally confirmed. I don't actually have victims yet that I can confirm or in Wave 4. Wave 4, I identified solely by a burst pattern.
Starting point is 00:11:55 Think about the pattern we're looking for. The addresses have to have been funded and created after the firmware upgrade on March 17, 20, 21. They likely are dormant for a while in general, because again, these are long-term holders. They're fully swept. They're swept with a fee that typically most of these patterns have dramatically exceeded the median fee rate, right? Attackers, they'll overpay for fees to get the coins.
Starting point is 00:12:23 And they have other transaction fingerprints. I saw all of that at the chain tip last night and in the mempool. And that's why I flag that. You know, there can, there definitely are some false positives in there. We need some victim reports to really help us confirm. The last thing I'll say, which I haven't yet really reported, but I will on X sometime tonight, there are like 14 other identifiable patterns that we have found that do not appear related to any of those waves, but do have verifiable victims. Identified because victims have come forth. And then I've looked at the patterns and behavior of, their attackers and found several others, or at least one other, right? So more than one instance, you know, those are literally footprints A through L that I'm calling them at the moment. I think N actually now. Those have crept up the count. While we may not be able to yet extrapolate like a giant amount to each of them, they are confirmed victims. And so, you know, we've been saying,
Starting point is 00:13:25 I think the last numbers we put out were near 1400 Bitcoin yesterday at the end of Wave 3. If you add the amount, you know, we're saying maybe two or three, I think three or 400 in Wave 4, but I'm not adding that yet. I really do need confirmation. And I encourage victims to DM me on X. I've been diligently helping people for several days now, not just cataloging it for us, but providing back basically fulsome chain alice style reports that they can use to report to authorities. But I have it now at, you know, if we include wave 4, we're almost at 2,000 Bitcoin. So we're well over $100 million of self-custodyed Bitcoin. Even without Wave 4, we're over $100 million. I would place it more in the 1600 BTC range. Again, for a distributed
Starting point is 00:14:16 self-custody storage hack, that's unprecedented, as far as I'm aware. Quite devastating. That's awful. The thing that jumps out at me is that we operate in this trustless, permissionless environment. And the problem was is that as trustless and permissionless as you try to be, you have to have trust somewhere. And they trusted Colt Card to do the right thing. And that's where everything broke down. And so it's really, really hard.
Starting point is 00:14:47 Hopefully, you know, there's some good things that come out of this, which you hate to even emphasize right now because it's so terrible. But, you know, Alex, you're very much in the Bitcoin world. if a high level of compute allowed people to derive seed phrases, to me, this is a precursor to what quantum could do not only in Bitcoin, but across all of financial services and beyond. So maybe this is a wake-up call for the community to really focus on these high compute threats. Yeah.
Starting point is 00:15:21 Do you agree with that? I do. Of course, the threats are a little different. Yeah. But, you know, they're not, they're really not that different, right? I mean, if you had substantially, you know, industry standard entropy, you're not affected here, but you could be, you know, because the world's GPUs combined probably couldn't break it. But that, you know, you're talking about multiple step function increases in the case of quantum. They might be able to derive seeds across that whole space. That's the fear. I think this, you could call it a trial run. Perhaps if quantum does emerge, it wouldn't look that. different, right? Because the attacker, this is one thing that's going to be tough with the recovery, if it can happen. How does the victim prove their ownership, right? Like, the attackers have their keys, right? So it can't be solely by a cryptographic proof. That's why we're encouraging people to make, you know, fulsome, formal victim refilings and reports to FBI's IC3, their local
Starting point is 00:16:22 police to establish their victimhood. And keep the cold card device. Don't, use it necessarily. Don't use it. But keep it because it could be evidence that shows that you did actually, you actually were the one that first had the keys. You know, I think another point worth raising is that it's not just the cryptography or the generation of the keys that's an issue. AIs, of course, across other domains as well are finding substantial code-based issues all over their world right now. There's a red team of Bitcoin security engineers working as we speak. And for days, unfortunately forced to use like Kimmy and GLM and not frontier U.S. models, which won't allow this type of cyber work, literally going over every hardware wallet
Starting point is 00:17:08 code base, every open source library that's used in crypto and in Bitcoin, fulsomely to try to patch and, you know, fight back against what is becoming an increasingly dangerous threat environment. That work is ongoing. If you like this segment, please like, subscribe, and tune in. in every Monday at 4.30 p.m. Eastern Time. I'm Austin Campbell, the host of Bips and Bips, along with my friends Rahm Alawalia and Chris Perkins and our slate of exceptional guests. Every week, we're going to discuss macro, crypto, and the collision of worlds, covering topics that move markets and shape the financial landscape.
Starting point is 00:17:46 If you hold crypto on your phone, your biggest vulnerability isn't your wallet. It's your carrier. AT&T, Verizon, and T-Mobile have been breached again and again. and SIM swaps are still one of the easiest ways for attackers to drain accounts. That's where CAPE comes in, America's Privacy First Mobile Carrier. Same premium service, but CAPE rotates the identifier on your SIM every 24 hours, deletes your call-and-text metadata after a day, and protects against SIM swaps with a 24-word recovery phrase that only you control. You also get two middle-to-end encrypted secondary numbers for banking and sign-up.
Starting point is 00:18:26 so you stop handing your real number to every app that asks. Go to cape.co slash unchained and use code unchained for 33% off your first six months.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.