What Bitcoin Did - EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob Hamilton
Episode Date: July 31, 2026“This is as code red as it can get for Bitcoin self-custody.” Rob Hamilton joins me for an emergency episode on the catastrophic Coldcard entropy bug that has exposed Bitcoin held in wallets ge...nerated on affected firmware. A firmware change introduced in 2021 prevented Coldcard devices from generating the level of randomness users believed they were getting. The result is that attackers may be able to reconstruct seed phrases and drain wallets, even when the device was air-gapped and the seed words never touched the internet. Rob explains which Coldcard models and setups are at risk, why updating the firmware does not repair an existing vulnerable seed, and what affected users need to do now. We also get into the risks facing single-signature and multisig wallets, whether passphrases and independently generated entropy provide protection, how attackers are finding and sweeping vulnerable wallets, and the role AI may have played in discovering the bug. THANKS TO OUR SPONSORS: LEDN SWAN ANCHORWATCH BLOCKWARE BITKEY CAPE FOLLOW: Danny Knowles: https://x.com/_DannyKnowles Rob Hamilton: https://x.com/Rob1Ham
Transcript
Discussion (0)
Rob Hamilton.
Damn man.
Crazy, crazy 24 hours.
We have a legitimate emergency in Bitcoin.
What's been going on?
In the spirit of emergency, I'm just going to start this with.
If you or anyone you know has used a cold card,
MK3, MK4, MK5, Q,
any of those devices with any wallets that were generated from the device.
You clicked, give me some seed words.
you need to immediately stop what you're doing and contact friends.
This is a canceling of weekend plans.
This is getting on planes for any ability for you to be able to recover your Bitcoin.
This is about as code read as it can get for Bitcoin self-custody as it relates to the urgency in which you need to act.
I will go more into the details with that urgency.
I want to caution.
Slow is smooth and smooth is fast.
So you need to act very decisively and you need to be able to act deliberately.
You should reach out to your friend that works and people that can help you support any questions you may have.
But time is of the essence right now.
So maybe we should just start with what happened.
Stop your podcast if you have to.
Like you need to stop.
But we can keep on going now.
This is not a drill.
continue. And so I obviously first saw this pop up on Twitter yesterday. I actually had a cold card
Mark 4 that was using as almost like a spending wallet, but the amount in there had got to a point
where I was like very uncomfortable as soon as I saw this news. I text you being like, I've seen
this thing with the Mark 3. Is it overblown or do I need to do something? And again, you were like,
this is not a drill. You need to do something now. I wasn't with my wallet. Managed to,
manage to sort that out. But this is like a serious problem that's impacting a ton of people.
And where did it all start?
So in early of 2021, there was a change to the cold card firmware as it relates to the entropy that gets created.
And that is when a bug was introduced.
Now, since I will take a moment to explain the nature of the problem.
If you had an air-gapped wallet, never talked to the internet, it doesn't matter.
The things that would save you, if you were using a cold card MK3, MK4, MK5, and Q,
is if you have a sufficiently strong 25th word passphrase.
If you also rolled dice or provided your own entropy from outside of the cold card,
the nature of this bug is that when you turn on a cold card and you have a clean device and you say,
this is amazing, can you please give me some seed words?
Those are not secure.
And from that, everything else needs to go down, yeah.
I just want to be really clear so that we don't miss anyone here.
You obviously said Mark 3, 4, 5, or Q, what about the Mark 1 or 2 if they were on
updated firmware and they still generate those keys after 21?
To my understanding, the MK2 is not supported than any of the impacted firmware.
Okay.
I'd have to go double check.
But if you have an MK1 and MK2 technically, the firmware bug that we're talking about has not been introduced because that is long end of life hardware.
There aren't updates for that really anymore.
And so if you have an MK2 or MK1, you should not be impacted by this.
Okay.
And then I think we should also be really clear on the passphrase because that's essentially a 25th word.
At this point, that's the only word really keeping your Bitcoin secure.
Is that right?
If you really only used one word, that is right, which means you are not secure.
You have to assume with what we're discussing right now is that many attackers, not just one person, there are many attackers right now who are scanning to get the entire table of all possible seat phrases a cold card could generate, whether it was 12 words or 24 words.
And they are sitting on all of those words and they are taking all of the low hanging fruit of single signature key.
my assumption is they're going to move on to other things but we'll get to that yes and so the
passphrase is the only thing keeping it secure if you've done that you should still probably
move funds would you agree absolutely especially if it's one word so like a one word password is not
strong um there are different perspectives on exactly how to mitigate this rather than if you're in
the zone where you're kind of debating it might say
or not, you just need to stop what you're doing and recover your Bitcoin before it gets stolen.
In theory, if you had 12, like 12 random words that you added on top of that, okay, like,
you're in a better spot, but now your entire security model was, oh, an attacker needs my seed words
and my passphrase. And the seed phrase is now known by multiple actors at this point, or will
be imminently over the coming couple of days, if not, like maybe a week.
but honestly this is something that you need to move as fast as possible.
So the only way you're secure is if you create your own entropy
and doing that obviously comes with its own risk.
You have to do that very carefully, very consciously.
Is it kind of to the point where if you're using a cold card device,
just move off it for now, wait and let the dust settle,
then see what happens?
Yeah, like there are a couple things.
So if you have a cold card and you generated your own entropy,
there is no identified bug in any of the firmware from the operations of anything else
besides the generation of the seed.
Now, to be very clear, the most important thing a hardware wallet can do
is give you a secure seat phrase.
Power users will roll dice and do other things to bring their own entropy into it
so it exists outside of the cold card.
Tragically, exactly for reasons like this, of not trusting the cold card
and that you're not going to trust it to provide that information reliably.
if you have a very strong passphrase or you roll dice for the time being there's no urgent need to move as long as you're very sure that you roll those dice
to add to that for migrations and things to do that is there's a longer conversation we need to have there
if it's a single signature specifically with the mk3 you need to do that right now the mk3 is identified to have 2 to the 32
bits of entropy. Now, if you're familiar with seed phrases, right, like these words,
is that there's a list of 2048 of them. And each time you can pick one, you can even have them
sometimes be the same word. Each time, you're basically picking 2048, multiply by 2048,
multiply 2048. So if you take 2048 times 12, you're close to 128 bits of entropy, which is really good.
And if you do the 24, you're at 202 to the 256. Both of the, like we're talking. We're talking.
numbers that are in the scope and size of there are more possible seed word combinations
than there are atoms in the observable universe. And to explain why this is a problem,
the nature of cryptography and Bitcoin security ultimately is that everyone,
your Bitcoin address, ultimately, in one way or another, results back to a large number,
some number between zero and two to the 256. That is the universe. That is the, the universal
proverbial needle in a haystack.
And the idea is not that someone can't know my number.
It is for someone who doesn't know the number to be able to guess it,
they have to basically guess all of the numbers in the universe,
and the universe will go through a heat death
before someone's able to get there with All of Mark Modern Computing, right?
The problem with the cold card firmware,
with this firmware change, was with some of the changes,
I saw it succinctly summarized as there was code that said,
said, hey, use extra secure entropy, and then continue.
There was basically a one-line error that just said, oh, does this function exist somewhere?
If so, you can skip the entropy.
And rather than, is this function true?
Right.
It was like a true false statement.
And rather than it being, is this true, we should invoke that you can skip the entropy.
It was like, oh, this exists.
So we can skip the entropy.
That's the best highest level.
It is one line of code of how I can describe this issue.
But the thing is, with the MK3, since you have two to the 32 bits that is trivial for consumer hardware to be able to brute force all of the C phrases.
The MK4, the MK5 and the queue have updates to the firmware.
Those updates to the firmware are not better in the sense of you don't have to worry about this.
They are extra entropy.
What people in the industry are estimating right now,
somewhere between 45 and 50 bits of entropy,
which is more.
That is a significant amount more extra protection.
But with someone with a data farm of GPUs,
they will get this information.
And now the people that know that money's being stored on it,
it will be consumed rapidly and quickly.
So if you did not use a passphrase,
if you did not use a C phrase,
like if you did not roll dice,
you need to right now stop what you're doing.
and you have to treat those funds
as you're in a race against the clock
across many teams of hackers
who are going to get your Bitcoin.
So the obvious question is,
like, how is this bug not spotted?
Like, for me, like,
this is obviously source viewable software,
but I can't read that code.
You can, like, did you ever go through
and read the cold card code?
Like, how was that not spotted early?
Yeah, I had gone through it previously.
I had gone through it with my own eyes
and I had also had gone it through
earlier versions of large language models.
And what I have observed, and I think this is an important part of the story,
is the latest open source bleeding edge model, Kimmy K3,
which is from China, it's an open source model,
does not have the safety guardrails that Open AI and Anthropica.
And so when this incident started happening, myself and many people in the industry,
started looking exactly at where this would go wrong in the code.
and Fable would downgrade me
so you can't use the leading model.
This is a cybersecurity thing.
And then using Open AI,
it would kind of like be coy
and generally nudge that something may be going on
but not tell me details.
I put into Kimmy K3 and it instantly
just read out the entire incident
and exactly what went wrong.
And so there is something to be said
that for a long time,
security through obscurity was used in places
and that is no longer possible.
If the code exists and people are able to walk through and see it, it will be exploited.
So when I first saw this, I assumed that it was a Lazarus North Korea type hack, very sophisticated.
But I've read some stuff online that says it's maybe a bit of an amateur doing this, doesn't really know exactly what he's doing, but still managed to exploit this bug.
The first attacker was, I would say, an amateur.
There's a lot of on-chain heuristics of what you could tell in the movement patterns.
they only moved Bitcoin addresses that were more than 0.15 Bitcoin.
Why someone wouldn't run a little extra logic and just get 0.1 Bitcoin at $6,000 for no extra cost, really?
That's weird.
They did not properly scan full addresses.
So people were getting hacked and they still had funds that were sitting in the addresses.
Was that?
I did see something about that.
Was it because it was only looking at like the first 200 UTXOs or something like that?
It was looking, what it was doing was looking for the first gap.
So if you create an address and you didn't use it,
and then you made another address and you used that second address,
the moment the bot saw that there was no more addresses,
it stopped looking.
And this is initially would have kept you safe,
but this is going back to the point now,
there are multiple attackers now executing this,
and I'm assuming they're getting more and more sophisticated.
So, like, that's, and that's why you can see different on-chain movements and seeing different wallets being used, different transaction behaviors.
You can just tell by some basic fingerprinting that different actors are going about this.
That makes sense.
So, but this is something you can do trivially.
Like, I could do it on my laptop if I had, like the skills.
Yeah.
There are reports of white hackers, which is people who are trying to do it for the good, who started seeing this exploit, started running code and came into dozens of that.
And they swept them because they were trying to do, they'd rather at least try to find a way to give it back to the right owner and then try to let an attacker take it.
So people will be in a panic hearing this if they're using a cold card.
I want to talk about some of the other devices because cold card was initially like a fork of treas.
And since then, Foundation has fought coal card.
Are those other forks from the same thing safe, from the same original source code?
Yeah, neither treasurer nor a foundation use the library that was compromised with the cold card.
Okay, so basically anywhere, anywhere is safe apart from cold card right now.
This isn't like a broader self-custly attack.
This is a specific call card.
The use of this library was specific to cold card or realistically mainly cold card.
So what should people do if they're panicking right now?
Where should they be moving funds?
This is something that is for each individual person to kind of make that judgment call.
I am, while I am the co-founder and CEO of Anchor Watch, I want to be fair to everyone and talk about
how I would console someone if I did not run this company and I was trying to help a loved one
through this. If you had used a Bitcoin exchange and your Bitcoin is, you know, in the system,
you give an exchange dollars, you get Bitcoin, you withdraw it to self-custody.
Immediately short term, sending it back to that exchange is not a bad idea if you have no better
a place to do this. I'm a big fan of River personally. I have high confidence in the infrastructure
over at River if you're looking for a good Bitcoin exchange. I'm talking to other people in industry.
I just know that River runs their own custody. They're not outsourcing it to someone else. And I think
that's an important thing to be aware of and they do proof of reserves. I think really genuinely
proof of reserves is kind of table stakes if you're going to leave your funds out in exchange.
And River is the main place that does that.
As it relates to other options, now you could, in theory, go to a Best Buy and pick up a ledger in the States today.
You can get Bit Keys there as well.
You can get bit keys as well.
Those are good immediate emergency options to get things set up properly.
And to be clear, the whole context of this advice is your funds are imminently going to be hacked if you're on a cold card without the entropy and without the dice.
and without pass phrases.
So my advice is not set this up and hang out for the rest of your life.
This is you need to do something in the next 24 hours.
Now there are other services like there are unchained.
There's CASA.
There's us of Anchor Watch.
There's a Swan Vault as well.
There are many products across the industry that offer these things in collaborative custody.
I think those are all great measures to be able to provide extra support to people.
If you have a friend, we won't say who, but as we were starting this podcast, you and I got a call from a mutual friend who was basically breaking into a friend's house who was on vacation and getting the pin over the phone to then move the funds before they got hacked.
They had a reliable self-custody wallet to be able to do that, right?
the universe and space of this has to be very carefully thought out.
And this goes back to something I believe I said before is that slow is smooth and smooth
as fast.
So you need to have a decisive plan that is good enough for the tradeoffs right now and decisively execute.
You do not have days to really war game out your optimal option here.
It's just most important that you take action now.
there's so many things that are very unfortunate about this from a user perspective like one of them
especially comes down to sort of privacy because if you're in a panic now you might have a ton of
UTXOs on a cold card some of which may be like non-KYC bitcoin stuff that you don't really want to mix
but at this point you kind of just have to move everything together like that's one of the
really unfortunate outcomes indeed yeah uh while you could if you are technical enough spend the time
building a careful transaction graph, I'm going to assume most people aren't. And so you have to make a
cost-benefit analysis for your own position to understand is that with any of these movement
options and how you're going to execute about them, you are the best person to be able to understand
your circumstance. And that's why I try to keep the advice very open-ended in general to meet
different people depending on where they could be in their self-custody journey and their Bitcoin
journey and their technical competency.
And then the other side of that is the thing that is very harsh about this situation
that's completely unlike a Mount Gox or an FTX is that the people that have been affected
by this have done everything so right.
Like they've taken the time to learn self-custody.
They've bought what was sort of perceived as the most secure Bitcoin hardware wallet.
They've done everything correct and they've still been fucked in this situation.
I think that, do you think this sets back Bitcoin self-custody in a significant way?
I think it would be naive to say that in the short term, that there's going to be a massive re-evaluation of this.
Many people lost their life savings because of this.
I think it's important for Bitcoin as a technology, as people who send and receive Bitcoin regularly to be thinking about where to go from here.
The capturing of Bitcoin as a decentralized network is accelerated if the only place you can hold it is at a specific exchange.
That is inevitably, Bitcoin is freedom money cannot work if you're not able to freely be able to call your money and own it and touch it yourself.
Now, I think this is so pressing and breaking.
It is difficult for me to come out with my prescriptive list of these are the things.
we should be thinking about and doing. I think most important right now, what we should be doing
is informing people, letting them know that this is happening, giving them ideas for contingencies.
There's a couple of more threat models. I do want to go over for maybe more advanced users
as it relates to ways that your funds could additionally be put at risk. And I'm going to start
there, because I think that's actually more important than like the bigger question is if you have a
multi-signature wallet and they are only using cold cards and those cold cards are only generated
using this entropy your funds are at risk and you need to immediately make whatever moves you need to do
to get that fixed if you have let's say a two of three and you have two cold cards in a ledger
and you did not do the passphrase and you did not do the dice rolling your funds are at risk
and you need to make moves immediately to rectify that.
Now, to explain, I feel fairly confident this is what's going to happen.
Can I ask you a question on that part first?
So you said if you have a two of three and say one device is a ledger, one device
of treasor, one device is a cold car mark three, even in that situation, your funds are at risk.
No.
So if you have a treasor, a ledger, a cold card, your funds are not at risk.
If you have two cold cards and a ledger, your funds are at risk.
Yeah, because those two can...
Yes, and this is to get a little bit for those that need to know,
because I have talked to,
I've probably talked to at least a half dozen people specifically in the situation,
if not more, where they have two cold cards and a ledger
or two cold cards in a treasor or two cold cards in a jade
or two cold cards in a foundation device, whatever,
two cold cards and a seat signer, right?
The necessary thing to understand is that when you,
go to spend Bitcoin in the Bitcoin network.
Let me actually just take a half step back here.
What is going to very likely happen across multiple hackers
is they are going to build an entire list of every single seed phrase combination
that the cold card would do without entropy.
What they are going to do from there is they are going to start realizing,
wait, if I have all these seed phrases, I can actually see if my wallet's being used on chain.
And they're going to say, okay, out of this billions, we're going to say that we have
have this many that could be in use at the moment. They're going to look at those and they're
going to see what are they doing with it. And to be clear, if you use your cold card in a multi-sig,
they can see, wait a second, that person spent from this address and that public key is tied to
my list of seat phrases here. They're going to be able to basically monitor your wallets.
Here's what happens. If you have reused addresses, those reuse addresses have the raw public keys,
of how you spend that Bitcoin sitting on chain.
And if it's a two of three and the attacker says,
oh, I have key A and key B,
they'll just take the funds.
They don't need to wait for you to do anything.
If you have not reused addresses,
you are in a very delicate position,
and this is a little bit advanced.
And I want to be clear,
this is a very specific circumstance.
If you have a multi-signature wallet,
and that multi-signature wallet
is a majority for the threshold,
cold card signers that are impacted by this issue,
you should look into using something like Mara Slipstream.
And the reason why is when I go and broadcast a transaction to the Bitcoin network,
anyone on the network can see the transaction data before it gets confirmed,
but it's not in a block yet.
So they can replace by fee.
Exactly.
So an attacker will be able to replace by fee and change the address from your address to an attacker's address.
If you use something like Mara Slipstream,
you will be able to have it broadcasted to a mining pool that has over 5% network cash rate.
They find multiple blocks a day.
And it will just appear confirmed on chain, which will mean the attackers will not be able to do anything.
And so I know it's a very specific circumstance, but I've talked to easily a half dozen people who are in this exact position.
And you can reach out to, like, there are ways for you to be able to do that.
If you only have cold cards, if you have three of three, if you have three cold cards,
and it's a two of three, they will find your funds.
They will look at all of the seed phrases.
And once they have all of the possible seed phrases,
they're going to run through all of the common metrics
of different multisig thresholds among those keys.
If they haven't already been spent on chain,
if you've spent from your multi-sig address once on chain,
they will be able to trivially scan and see that it's there
and be able to attack you.
And know that.
Yeah.
So in that situation, slipstream doesn't help you.
So what do you do?
You just have to set an incredibly high fee rate
and hope it gets quickly quickly.
You just have to go.
but you don't have a, yeah.
So if you've, and to explain this,
let's say you have a two of three multi-sig
and they're all cold cards.
You, and you've spent from it before,
attackers will be able to see,
oh, key A, key B, key C,
that matches seed one, two, and three.
Boom, boom, connected.
I'll be able to move my fun.
So if you have an N of N, two of two,
three of three, whatever multi-sig wallet
that is only cold cards that are impacted by this issue,
you need to move funds right now.
Like you are marginally safer than a single SIG.
And the reason why is because you need to have an attacker know all of the seeds in the universe to be able to attack it.
But that is a ticking time that you're racing against the clock.
You need to immediately make moves if that is the position you're in.
It's such a terrible situation to be in.
Do we know how much Bitcoin's been stolen from this attack so far?
I saw yesterday it was like 600, but I'm sure it's increasing.
It's over 1,100 at this point, and there's probably more clusters going on all the time.
I occasionally was poking around the men pole to see if I can find more things.
It's going to be thousands of Bitcoin before this is done.
And it's going to happen in waves.
What I'm describing right now, this race against the clock, the lowest hanging fruit were hit.
And that was probably one attacker.
The starting gun has been fired off.
Everyone has declared to the emergency.
Every black cat hacker on the internet with an LLM is going to be able to start poking around, seeing what they can find.
they and because there are multiple attackers now there's a
an inevitable outcome where well capitalized ones are going to come in
spend millions and millions of dollars on graphics GPU computing
because they know that they can pop one vault
what you'll be able to have an attacker do is they're going to be able to look through the full list
and just pop it right out and you are just
marginally safer because it's not the lowest hanging fruit but you are not safe period
So this started as obviously like an amateur attack as we spoke about a little earlier,
but this is now, you have to assume the best attacks in the world are now having to go at this.
Yeah, this is everyone.
It's a, it is a real mess.
So when you compare this to like a Mount Gawks or a FTA, it's like the number of coins is going to be far lower.
But is the damage going to be greater?
Because it kind of arose people's trust in self-custody, essentially.
Like, Cole Card was the golden child of Bitcoin self-custody, essentially.
I, like I said earlier, it would be naive to say that in the short term that this is not going to be a very negative downward pressure on self-custody.
And for I know multiple people who've lost either some money or their life savings, I have spent the past 24.
hours. I have talked to directly on a one-on-one context, dozens of people. In a larger platform,
I've talked to now thousands of people trying to raise the alarm bell about this and the stories
keep on coming in. This will have a downward trend on self-custody. I think that doesn't have to be
the end of the story, but I think there needs to be, as the post-mortems wrap up, and
we do a full debrief of this.
The entire ecosystem has an opportunity to build from here and find improvements.
We are now almost 30 minutes into the podcast.
So in some conversations, people are talking about we need covenants and vault-like structures.
Things that can improve self-custody.
My biggest concern for the health of Bitcoin as a network is that the default option being holding it
a custodian or an ETF wrapper, I am not opposed to those instruments existing.
I think those are inevitable structures that happen with hyper-bitquinization.
But the value proposition of Bitcoin itself will be diminished greatly if those are the only
real options.
And being able to explain this, the way Bitcoin works today, if you have the requisite
amount of signatures, you can send any amount of Bitcoin anywhere within reason.
There's weird corner cases, but let's just say for the...
the sake of conversation. That's true. Things like Covenants would allow you to be able to have
things like, I only want to be able to send to these addresses. I only want to send this much Bitcoin.
This is something at Anchor Watch, we are able to offer as a product level service, right? It is an
application that sits on top of Bitcoin where we say Anchor Watch is a required co-sider to move funds.
but we will, in exchange for us being able to help you out,
we'll say, okay, well, you only can send to the addresses you give us,
so addresses A, B, and C.
Otherwise, we at Anchorage, won't sign.
It's effectively a covenant.
As us acting as a co-signer gives that feature.
Or I only want to send one Bitcoin a month.
That's something we can do at Anchor Watch.
It's something you can't do on the Bitcoin blockchain level.
If it were to be democratized to the Bitcoin blockchain level,
anyone in their basement would be able to have orders of magnitude, better security than any of the enterprise leading custodians today.
And that's an important point because when Bitcoin is in flight, once it gets confirmed in a block, it's over.
Whereas with Covenants and in general vaulting, you would be able to send to like a staging address.
So you'd be like, wait a second, why did my funds move?
It's sitting in my staging address.
And then you can pull the emergency rip cord to like pull the funds out.
Now, it doesn't solve the key management problem, right?
I think it's an important thing to call out that it is a mitigation.
It is necessary, but not sufficient to be able to improve these things.
But ultimately, you need to send Bitcoin to an address somewhere,
and those addresses have to ultimately be tied to keys.
So there is a lot of learning, I think, within the ecosystem about where do we go from,
here. And I think there'll be plenty of time to discuss that in the coming weeks after the
initial incident response and everything can be done as much as possible to keep people safe.
Right now, I think the main focus is just letting everyone know this is happening and they need
to immediately remedy this if they're impacted. How do these, like an unchained or a caset,
let's say you have a two of three with one of those. If I have, so one key, one key,
will be on your phone generally.
One key will be held by,
the company one key is held by you.
If I'm holding my key,
let's say on a cold card,
how do I know that the counterparty,
the unchained or the CASA is not?
The unchained or the CASA counterparty is not what?
Like holding one of their key on a,
on a call card?
Because that would then put the multi-sigar risk.
You can't, you can't prove that.
You can't, with any wallet,
well, in a very tragic sense,
of irony, very soon people will be able to prove if they were using the cold card keys,
because attackers will have them, right?
The ideal structure, though, is that it's not something that can be an issue.
Because if you have sufficient randomness, you should not be able to fingerprint and say,
oh, that ex-pub came from a ledger and that one came from a jade.
That would be a breaking in the underlying cryptography assumptions that is a truly
random number that is seeding all of your secrets.
So I guess the point I'm trying to make,
I'm trying to make people feel comfortable here if they are using a
cassero and unchained.
Like, have either of those made a statement about how they're generating their keys?
Like, because I'm like, I'm convinced that neither of those companies are using the on-device
random number generator.
But have they made an statement?
To my understanding, unchained has made a statement.
I believe CASA has made a statement as well.
And we at Anchor Watcher have also made a statement.
this does not impact us, right?
And so I think it's an important thing to look in your vendors to see if this is an issue.
I think that's a very reasonable concern.
But I think everyone at this point has made some public statement to the effect of that.
I'm not aware of any Bitcoin business, even through like hushed private circles who are impacted by this.
I haven't heard anything yet.
They may exist, but I have not heard anything.
I definitely don't want my words to be twisted there.
Like I think Acaster and Unchained, like Angot, I'm sure.
those companies are set up brilliantly.
I just want to try and make people comfortable with moving funds to those places
if they need to.
Understood.
Ankerwatch, how do you set up your multisig?
Yeah.
So the nature of what we do is somewhat different is we use what's called miniscript.
And that allows us to do more advanced scripting functionality.
Rather than just a two of three, we are able to say, we have a two of three, you have a two of three.
We all have to get together and sign and move things.
we can do is we have a two of three
and you have a single key, right?
And we act as that cosiner still, right?
The nature of how anyone
generates keys is an extremely
sensitive thing
because you just need to
keep that on a need to know the exact mechanics,
but our process has been peer reviewed.
There are many,
I think most actors in the industry have their own
very rigorous key generation ceremonies
of what they go about for
for being able to evaluate that.
So when, like, I really like single-sig self-custody.
Like, I think you should have different trade-offs for different amounts of Bitcoin
you're holding.
Like, if maybe you have one sort of deep cold storage, which is geographically dispersed
multi-sig, and that's great.
But the simplicity of single-sig is really important, too.
I think I would definitely still use that occasionally.
How do people think about that going forward?
because I've always said that the most likely you are to lose Bitcoin is through your own complexity and your own setup, like complexity being the enemy of security.
Do you think people are going to make the mistake now of jumping too far into multisig because they're scared of this attack and actually add too much complexity to their own setups?
I think multi-sig is no longer that complicated.
I think this is not 2017 anymore.
Additionally, if for whatever reason you want to do a single signature, you could do single signature with a passphrase.
That effectively is a two-of-two multi-sig because you have to have both.
pieces to be able to constitute a spend. If you were doing that with a reasonably strong
passphrase going into today, you're still safe. I would still make a new wallet because
if you fell under this and your initial 12 or 24 words were actually part of this hit of
known possible seed phrases, all that's keeping you safe now is your passphrase.
but I think there's a lot of opportunity for everyone to grow and learn from this to even further improve the user experience because this will be in the front mind of anyone who discusses self-custody for a very long time.
So this is the first, like in the wild case that we've seen of AI essentially hacking and taking down a Bitcoin and self-custody solution.
Do you think this is the start of that era?
Do you think we're going to see more and more attacks like this?
I think in general, across the whole web,
there are going to be more and more attacks like this.
The trivial ability for me to be able to open up to open router
and use Kimmy K3 and point at the cold card firmware
and instantly read out everything,
everyone needs to be, and we regularly do this.
At Anchorage Watch, I know most companies that I know of
in the Bitcoin industry are regularly doing this
and kind of defensively trying to deploy these tools to find things.
We've always found, we've never found anything that was a money losing bug.
Nothing in the universe of bad of what we're seeing here with the cold card.
But you find bugs.
Software has bugs.
It always will have bugs, right?
Like there are some emerging research around things like formal verification.
So you can actually do formal mathematical proofs as to how code executes.
that's an emerging field of research
that I think may get more important
over the coming decade,
but software is written by humans
and humans inevitably have bugs
and even LLM sometimes have bugs, right?
You don't want to be blindly passing everything
you've built to just have it go get figured out
later by the LLM and the LLM may not be complete, right?
The rapid development of these models,
there's a kind of a funny software motif
if you write, if you like vibe code a website
and you launch it, in three months,
the new model comes out and it says,
wow, this codebase is a mess.
Let me fix this for you.
And that's just been happening continually for two years now.
Right.
So like we're at a place in a time where you need to be hyper vigilant with your own
individual judgment, with your ability to understand the nitty gritty details of risk
and however it emerges to be able to keep you and people you work with safe.
All right.
Awkward question time because I know you're friends with MVK, but like the blame obviously
ends with them.
But how incompetent was?
this because this has been five years that this firmware issue has been there?
Not acceptable as a starting place.
Like, not like there is no, yes, I've known NVK for a long time.
There is no excusable, there's no set of circumstances that excuses this.
The one job a hardware wallet has, if it were to have a single job, more important than
all of the other jobs.
is that it can securely generate a sufficiently large random number with sufficient entropy.
That is the entire game in which everything else gets derived from.
There are bugs that have happened in hardware wallets in the past where maybe how they signed a transaction wasn't secure.
And then basically if you reused addresses, you could lose your funds.
Or maybe you would have bugs where it wasn't checking the change address.
So if I sent you Bitcoin, if I have 10 Bitcoin, I send you one Bitcoin, I have to send myself nine back in change.
There were bugs in software and hardware wallets that didn't check the change,
which was the most important part of the transaction in that sense, right?
This bug is so foundational to the actual security of Bitcoin.
That it is a nuclear event.
Right.
This is the most catastrophic thing.
That is why someone could be entirely air-gapped,
never have talked to the internet,
and someone's able to peer through the vast space of randomness
and get your Bitcoin, which should never happen.
Do you think it's the end of Cold Card?
Do you think they'll be able to recover this?
Because trust is everything when it comes to these devices.
It is.
I think it's too early to say.
I don't know.
I'm not a lawyer.
I don't understand any of the liabilities or fallouts or all of these things.
It's hard for me to say.
Truly.
I don't know.
All right, Rob.
I appreciate you doing this last minute.
I wanted basically just to get this out there.
If one person listens to this show, they're not, they're not permanently on Bitcoin
Twitter like you and I and they haven't seen this news.
Like that makes it 100% worth it.
Any closing words for everyone who's listening?
Closing words again.
If you or someone you know has used in MK3, MK4, MK5, Q, any of those cold card products
with out either rolling your own dice or having a sufficiently strong passphrase,
and if your question is, is my passphrase strong enough, it means you don't
understand the entropy, which means you need to go fix this immediately, even if it is, right?
You just, you, if you don't know for a fact, oh, yes, I have this many bits of entropy in my
passphrase because you are super in the details. Your passphrase is not strong enough at the
moment. You need to immediately make any moves and plans. You need to cancel your weekend plans.
You need to get on a plane if you have to. You need to call a loved one who may be able to help you
out remotely. This is a, this is a full five alarm fire. This is all hands on deck. I think
everyone in the Bitcoin community has been trying to help through back channels and through
direct messages through being able to have people call you, find people, get connected to people.
My DMs are open on Twitter.
Like I said, I've talked to dozens of people across the whole ecosystem.
None of them even Anchor Watch customers, because Anchor Watch customers don't have an issue at the moment.
This is not related to anything of how your funds are being kept safe at Anchor Watch.
So all of that to be said, like reach out to those you may know people you've ever referred to using a cold card and do what you can to try and help them out.
And I think there's going to be an opportunity in the coming week, two weeks to when the initial race is over, we can focus on triage.
We can focus on, well, once we move beyond triage, we can start focusing on.
where does the industry go from here?
All right, Rob.
I appreciate you, man.
Thank you for all the work,
helping people out on this.
Terrible, terrible event,
but Bitcoin will get through it, man.
Thank you.
Thank you.
