What Bitcoin Did - EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob Hamilton

Episode Date: July 31, 2026

“This is as code red as it can get for Bitcoin self-custody.” Rob Hamilton joins me for an emergency episode on the catastrophic Coldcard entropy bug that has exposed Bitcoin held in wallets ge...nerated on affected firmware. A firmware change introduced in 2021 prevented Coldcard devices from generating the level of randomness users believed they were getting. The result is that attackers may be able to reconstruct seed phrases and drain wallets, even when the device was air-gapped and the seed words never touched the internet. Rob explains which Coldcard models and setups are at risk, why updating the firmware does not repair an existing vulnerable seed, and what affected users need to do now. We also get into the risks facing single-signature and multisig wallets, whether passphrases and independently generated entropy provide protection, how attackers are finding and sweeping vulnerable wallets, and the role AI may have played in discovering the bug. THANKS TO OUR SPONSORS: LEDN SWAN ANCHORWATCH BLOCKWARE BITKEY CAPE FOLLOW: Danny Knowles: https://x.com/_DannyKnowles Rob Hamilton: https://x.com/Rob1Ham

Transcript
Discussion (0)
Starting point is 00:00:02 Rob Hamilton. Damn man. Crazy, crazy 24 hours. We have a legitimate emergency in Bitcoin. What's been going on? In the spirit of emergency, I'm just going to start this with. If you or anyone you know has used a cold card, MK3, MK4, MK5, Q,
Starting point is 00:00:23 any of those devices with any wallets that were generated from the device. You clicked, give me some seed words. you need to immediately stop what you're doing and contact friends. This is a canceling of weekend plans. This is getting on planes for any ability for you to be able to recover your Bitcoin. This is about as code read as it can get for Bitcoin self-custody as it relates to the urgency in which you need to act. I will go more into the details with that urgency. I want to caution.
Starting point is 00:01:03 Slow is smooth and smooth is fast. So you need to act very decisively and you need to be able to act deliberately. You should reach out to your friend that works and people that can help you support any questions you may have. But time is of the essence right now. So maybe we should just start with what happened. Stop your podcast if you have to. Like you need to stop. But we can keep on going now.
Starting point is 00:01:29 This is not a drill. continue. And so I obviously first saw this pop up on Twitter yesterday. I actually had a cold card Mark 4 that was using as almost like a spending wallet, but the amount in there had got to a point where I was like very uncomfortable as soon as I saw this news. I text you being like, I've seen this thing with the Mark 3. Is it overblown or do I need to do something? And again, you were like, this is not a drill. You need to do something now. I wasn't with my wallet. Managed to, manage to sort that out. But this is like a serious problem that's impacting a ton of people. And where did it all start?
Starting point is 00:02:01 So in early of 2021, there was a change to the cold card firmware as it relates to the entropy that gets created. And that is when a bug was introduced. Now, since I will take a moment to explain the nature of the problem. If you had an air-gapped wallet, never talked to the internet, it doesn't matter. The things that would save you, if you were using a cold card MK3, MK4, MK5, and Q, is if you have a sufficiently strong 25th word passphrase. If you also rolled dice or provided your own entropy from outside of the cold card, the nature of this bug is that when you turn on a cold card and you have a clean device and you say,
Starting point is 00:02:55 this is amazing, can you please give me some seed words? Those are not secure. And from that, everything else needs to go down, yeah. I just want to be really clear so that we don't miss anyone here. You obviously said Mark 3, 4, 5, or Q, what about the Mark 1 or 2 if they were on updated firmware and they still generate those keys after 21? To my understanding, the MK2 is not supported than any of the impacted firmware. Okay.
Starting point is 00:03:22 I'd have to go double check. But if you have an MK1 and MK2 technically, the firmware bug that we're talking about has not been introduced because that is long end of life hardware. There aren't updates for that really anymore. And so if you have an MK2 or MK1, you should not be impacted by this. Okay. And then I think we should also be really clear on the passphrase because that's essentially a 25th word. At this point, that's the only word really keeping your Bitcoin secure. Is that right?
Starting point is 00:03:51 If you really only used one word, that is right, which means you are not secure. You have to assume with what we're discussing right now is that many attackers, not just one person, there are many attackers right now who are scanning to get the entire table of all possible seat phrases a cold card could generate, whether it was 12 words or 24 words. And they are sitting on all of those words and they are taking all of the low hanging fruit of single signature key. my assumption is they're going to move on to other things but we'll get to that yes and so the passphrase is the only thing keeping it secure if you've done that you should still probably move funds would you agree absolutely especially if it's one word so like a one word password is not strong um there are different perspectives on exactly how to mitigate this rather than if you're in the zone where you're kind of debating it might say
Starting point is 00:04:51 or not, you just need to stop what you're doing and recover your Bitcoin before it gets stolen. In theory, if you had 12, like 12 random words that you added on top of that, okay, like, you're in a better spot, but now your entire security model was, oh, an attacker needs my seed words and my passphrase. And the seed phrase is now known by multiple actors at this point, or will be imminently over the coming couple of days, if not, like maybe a week. but honestly this is something that you need to move as fast as possible. So the only way you're secure is if you create your own entropy and doing that obviously comes with its own risk.
Starting point is 00:05:29 You have to do that very carefully, very consciously. Is it kind of to the point where if you're using a cold card device, just move off it for now, wait and let the dust settle, then see what happens? Yeah, like there are a couple things. So if you have a cold card and you generated your own entropy, there is no identified bug in any of the firmware from the operations of anything else besides the generation of the seed.
Starting point is 00:05:56 Now, to be very clear, the most important thing a hardware wallet can do is give you a secure seat phrase. Power users will roll dice and do other things to bring their own entropy into it so it exists outside of the cold card. Tragically, exactly for reasons like this, of not trusting the cold card and that you're not going to trust it to provide that information reliably. if you have a very strong passphrase or you roll dice for the time being there's no urgent need to move as long as you're very sure that you roll those dice to add to that for migrations and things to do that is there's a longer conversation we need to have there
Starting point is 00:06:37 if it's a single signature specifically with the mk3 you need to do that right now the mk3 is identified to have 2 to the 32 bits of entropy. Now, if you're familiar with seed phrases, right, like these words, is that there's a list of 2048 of them. And each time you can pick one, you can even have them sometimes be the same word. Each time, you're basically picking 2048, multiply by 2048, multiply 2048. So if you take 2048 times 12, you're close to 128 bits of entropy, which is really good. And if you do the 24, you're at 202 to the 256. Both of the, like we're talking. We're talking. numbers that are in the scope and size of there are more possible seed word combinations than there are atoms in the observable universe. And to explain why this is a problem,
Starting point is 00:07:28 the nature of cryptography and Bitcoin security ultimately is that everyone, your Bitcoin address, ultimately, in one way or another, results back to a large number, some number between zero and two to the 256. That is the universe. That is the, the universal proverbial needle in a haystack. And the idea is not that someone can't know my number. It is for someone who doesn't know the number to be able to guess it, they have to basically guess all of the numbers in the universe, and the universe will go through a heat death
Starting point is 00:08:04 before someone's able to get there with All of Mark Modern Computing, right? The problem with the cold card firmware, with this firmware change, was with some of the changes, I saw it succinctly summarized as there was code that said, said, hey, use extra secure entropy, and then continue. There was basically a one-line error that just said, oh, does this function exist somewhere? If so, you can skip the entropy. And rather than, is this function true?
Starting point is 00:08:37 Right. It was like a true false statement. And rather than it being, is this true, we should invoke that you can skip the entropy. It was like, oh, this exists. So we can skip the entropy. That's the best highest level. It is one line of code of how I can describe this issue. But the thing is, with the MK3, since you have two to the 32 bits that is trivial for consumer hardware to be able to brute force all of the C phrases.
Starting point is 00:09:05 The MK4, the MK5 and the queue have updates to the firmware. Those updates to the firmware are not better in the sense of you don't have to worry about this. They are extra entropy. What people in the industry are estimating right now, somewhere between 45 and 50 bits of entropy, which is more. That is a significant amount more extra protection. But with someone with a data farm of GPUs,
Starting point is 00:09:31 they will get this information. And now the people that know that money's being stored on it, it will be consumed rapidly and quickly. So if you did not use a passphrase, if you did not use a C phrase, like if you did not roll dice, you need to right now stop what you're doing. and you have to treat those funds
Starting point is 00:09:49 as you're in a race against the clock across many teams of hackers who are going to get your Bitcoin. So the obvious question is, like, how is this bug not spotted? Like, for me, like, this is obviously source viewable software, but I can't read that code.
Starting point is 00:10:05 You can, like, did you ever go through and read the cold card code? Like, how was that not spotted early? Yeah, I had gone through it previously. I had gone through it with my own eyes and I had also had gone it through earlier versions of large language models. And what I have observed, and I think this is an important part of the story,
Starting point is 00:10:25 is the latest open source bleeding edge model, Kimmy K3, which is from China, it's an open source model, does not have the safety guardrails that Open AI and Anthropica. And so when this incident started happening, myself and many people in the industry, started looking exactly at where this would go wrong in the code. and Fable would downgrade me so you can't use the leading model. This is a cybersecurity thing.
Starting point is 00:10:51 And then using Open AI, it would kind of like be coy and generally nudge that something may be going on but not tell me details. I put into Kimmy K3 and it instantly just read out the entire incident and exactly what went wrong. And so there is something to be said
Starting point is 00:11:09 that for a long time, security through obscurity was used in places and that is no longer possible. If the code exists and people are able to walk through and see it, it will be exploited. So when I first saw this, I assumed that it was a Lazarus North Korea type hack, very sophisticated. But I've read some stuff online that says it's maybe a bit of an amateur doing this, doesn't really know exactly what he's doing, but still managed to exploit this bug. The first attacker was, I would say, an amateur. There's a lot of on-chain heuristics of what you could tell in the movement patterns.
Starting point is 00:11:43 they only moved Bitcoin addresses that were more than 0.15 Bitcoin. Why someone wouldn't run a little extra logic and just get 0.1 Bitcoin at $6,000 for no extra cost, really? That's weird. They did not properly scan full addresses. So people were getting hacked and they still had funds that were sitting in the addresses. Was that? I did see something about that. Was it because it was only looking at like the first 200 UTXOs or something like that?
Starting point is 00:12:12 It was looking, what it was doing was looking for the first gap. So if you create an address and you didn't use it, and then you made another address and you used that second address, the moment the bot saw that there was no more addresses, it stopped looking. And this is initially would have kept you safe, but this is going back to the point now, there are multiple attackers now executing this,
Starting point is 00:12:37 and I'm assuming they're getting more and more sophisticated. So, like, that's, and that's why you can see different on-chain movements and seeing different wallets being used, different transaction behaviors. You can just tell by some basic fingerprinting that different actors are going about this. That makes sense. So, but this is something you can do trivially. Like, I could do it on my laptop if I had, like the skills. Yeah. There are reports of white hackers, which is people who are trying to do it for the good, who started seeing this exploit, started running code and came into dozens of that.
Starting point is 00:13:10 And they swept them because they were trying to do, they'd rather at least try to find a way to give it back to the right owner and then try to let an attacker take it. So people will be in a panic hearing this if they're using a cold card. I want to talk about some of the other devices because cold card was initially like a fork of treas. And since then, Foundation has fought coal card. Are those other forks from the same thing safe, from the same original source code? Yeah, neither treasurer nor a foundation use the library that was compromised with the cold card. Okay, so basically anywhere, anywhere is safe apart from cold card right now. This isn't like a broader self-custly attack.
Starting point is 00:13:49 This is a specific call card. The use of this library was specific to cold card or realistically mainly cold card. So what should people do if they're panicking right now? Where should they be moving funds? This is something that is for each individual person to kind of make that judgment call. I am, while I am the co-founder and CEO of Anchor Watch, I want to be fair to everyone and talk about how I would console someone if I did not run this company and I was trying to help a loved one through this. If you had used a Bitcoin exchange and your Bitcoin is, you know, in the system,
Starting point is 00:14:26 you give an exchange dollars, you get Bitcoin, you withdraw it to self-custody. Immediately short term, sending it back to that exchange is not a bad idea if you have no better a place to do this. I'm a big fan of River personally. I have high confidence in the infrastructure over at River if you're looking for a good Bitcoin exchange. I'm talking to other people in industry. I just know that River runs their own custody. They're not outsourcing it to someone else. And I think that's an important thing to be aware of and they do proof of reserves. I think really genuinely proof of reserves is kind of table stakes if you're going to leave your funds out in exchange. And River is the main place that does that.
Starting point is 00:15:06 As it relates to other options, now you could, in theory, go to a Best Buy and pick up a ledger in the States today. You can get Bit Keys there as well. You can get bit keys as well. Those are good immediate emergency options to get things set up properly. And to be clear, the whole context of this advice is your funds are imminently going to be hacked if you're on a cold card without the entropy and without the dice. and without pass phrases. So my advice is not set this up and hang out for the rest of your life. This is you need to do something in the next 24 hours.
Starting point is 00:15:47 Now there are other services like there are unchained. There's CASA. There's us of Anchor Watch. There's a Swan Vault as well. There are many products across the industry that offer these things in collaborative custody. I think those are all great measures to be able to provide extra support to people. If you have a friend, we won't say who, but as we were starting this podcast, you and I got a call from a mutual friend who was basically breaking into a friend's house who was on vacation and getting the pin over the phone to then move the funds before they got hacked. They had a reliable self-custody wallet to be able to do that, right?
Starting point is 00:16:29 the universe and space of this has to be very carefully thought out. And this goes back to something I believe I said before is that slow is smooth and smooth as fast. So you need to have a decisive plan that is good enough for the tradeoffs right now and decisively execute. You do not have days to really war game out your optimal option here. It's just most important that you take action now. there's so many things that are very unfortunate about this from a user perspective like one of them especially comes down to sort of privacy because if you're in a panic now you might have a ton of
Starting point is 00:17:07 UTXOs on a cold card some of which may be like non-KYC bitcoin stuff that you don't really want to mix but at this point you kind of just have to move everything together like that's one of the really unfortunate outcomes indeed yeah uh while you could if you are technical enough spend the time building a careful transaction graph, I'm going to assume most people aren't. And so you have to make a cost-benefit analysis for your own position to understand is that with any of these movement options and how you're going to execute about them, you are the best person to be able to understand your circumstance. And that's why I try to keep the advice very open-ended in general to meet different people depending on where they could be in their self-custody journey and their Bitcoin
Starting point is 00:17:53 journey and their technical competency. And then the other side of that is the thing that is very harsh about this situation that's completely unlike a Mount Gox or an FTX is that the people that have been affected by this have done everything so right. Like they've taken the time to learn self-custody. They've bought what was sort of perceived as the most secure Bitcoin hardware wallet. They've done everything correct and they've still been fucked in this situation. I think that, do you think this sets back Bitcoin self-custody in a significant way?
Starting point is 00:18:23 I think it would be naive to say that in the short term, that there's going to be a massive re-evaluation of this. Many people lost their life savings because of this. I think it's important for Bitcoin as a technology, as people who send and receive Bitcoin regularly to be thinking about where to go from here. The capturing of Bitcoin as a decentralized network is accelerated if the only place you can hold it is at a specific exchange. That is inevitably, Bitcoin is freedom money cannot work if you're not able to freely be able to call your money and own it and touch it yourself. Now, I think this is so pressing and breaking. It is difficult for me to come out with my prescriptive list of these are the things. we should be thinking about and doing. I think most important right now, what we should be doing
Starting point is 00:19:36 is informing people, letting them know that this is happening, giving them ideas for contingencies. There's a couple of more threat models. I do want to go over for maybe more advanced users as it relates to ways that your funds could additionally be put at risk. And I'm going to start there, because I think that's actually more important than like the bigger question is if you have a multi-signature wallet and they are only using cold cards and those cold cards are only generated using this entropy your funds are at risk and you need to immediately make whatever moves you need to do to get that fixed if you have let's say a two of three and you have two cold cards in a ledger and you did not do the passphrase and you did not do the dice rolling your funds are at risk
Starting point is 00:20:27 and you need to make moves immediately to rectify that. Now, to explain, I feel fairly confident this is what's going to happen. Can I ask you a question on that part first? So you said if you have a two of three and say one device is a ledger, one device of treasor, one device is a cold car mark three, even in that situation, your funds are at risk. No. So if you have a treasor, a ledger, a cold card, your funds are not at risk. If you have two cold cards and a ledger, your funds are at risk.
Starting point is 00:20:57 Yeah, because those two can... Yes, and this is to get a little bit for those that need to know, because I have talked to, I've probably talked to at least a half dozen people specifically in the situation, if not more, where they have two cold cards and a ledger or two cold cards in a treasor or two cold cards in a jade or two cold cards in a foundation device, whatever, two cold cards and a seat signer, right?
Starting point is 00:21:22 The necessary thing to understand is that when you, go to spend Bitcoin in the Bitcoin network. Let me actually just take a half step back here. What is going to very likely happen across multiple hackers is they are going to build an entire list of every single seed phrase combination that the cold card would do without entropy. What they are going to do from there is they are going to start realizing, wait, if I have all these seed phrases, I can actually see if my wallet's being used on chain.
Starting point is 00:21:52 And they're going to say, okay, out of this billions, we're going to say that we have have this many that could be in use at the moment. They're going to look at those and they're going to see what are they doing with it. And to be clear, if you use your cold card in a multi-sig, they can see, wait a second, that person spent from this address and that public key is tied to my list of seat phrases here. They're going to be able to basically monitor your wallets. Here's what happens. If you have reused addresses, those reuse addresses have the raw public keys, of how you spend that Bitcoin sitting on chain. And if it's a two of three and the attacker says,
Starting point is 00:22:32 oh, I have key A and key B, they'll just take the funds. They don't need to wait for you to do anything. If you have not reused addresses, you are in a very delicate position, and this is a little bit advanced. And I want to be clear, this is a very specific circumstance.
Starting point is 00:22:49 If you have a multi-signature wallet, and that multi-signature wallet is a majority for the threshold, cold card signers that are impacted by this issue, you should look into using something like Mara Slipstream. And the reason why is when I go and broadcast a transaction to the Bitcoin network, anyone on the network can see the transaction data before it gets confirmed, but it's not in a block yet.
Starting point is 00:23:15 So they can replace by fee. Exactly. So an attacker will be able to replace by fee and change the address from your address to an attacker's address. If you use something like Mara Slipstream, you will be able to have it broadcasted to a mining pool that has over 5% network cash rate. They find multiple blocks a day. And it will just appear confirmed on chain, which will mean the attackers will not be able to do anything. And so I know it's a very specific circumstance, but I've talked to easily a half dozen people who are in this exact position.
Starting point is 00:23:44 And you can reach out to, like, there are ways for you to be able to do that. If you only have cold cards, if you have three of three, if you have three cold cards, and it's a two of three, they will find your funds. They will look at all of the seed phrases. And once they have all of the possible seed phrases, they're going to run through all of the common metrics of different multisig thresholds among those keys. If they haven't already been spent on chain,
Starting point is 00:24:06 if you've spent from your multi-sig address once on chain, they will be able to trivially scan and see that it's there and be able to attack you. And know that. Yeah. So in that situation, slipstream doesn't help you. So what do you do? You just have to set an incredibly high fee rate
Starting point is 00:24:21 and hope it gets quickly quickly. You just have to go. but you don't have a, yeah. So if you've, and to explain this, let's say you have a two of three multi-sig and they're all cold cards. You, and you've spent from it before, attackers will be able to see,
Starting point is 00:24:35 oh, key A, key B, key C, that matches seed one, two, and three. Boom, boom, connected. I'll be able to move my fun. So if you have an N of N, two of two, three of three, whatever multi-sig wallet that is only cold cards that are impacted by this issue, you need to move funds right now.
Starting point is 00:24:54 Like you are marginally safer than a single SIG. And the reason why is because you need to have an attacker know all of the seeds in the universe to be able to attack it. But that is a ticking time that you're racing against the clock. You need to immediately make moves if that is the position you're in. It's such a terrible situation to be in. Do we know how much Bitcoin's been stolen from this attack so far? I saw yesterday it was like 600, but I'm sure it's increasing. It's over 1,100 at this point, and there's probably more clusters going on all the time.
Starting point is 00:25:25 I occasionally was poking around the men pole to see if I can find more things. It's going to be thousands of Bitcoin before this is done. And it's going to happen in waves. What I'm describing right now, this race against the clock, the lowest hanging fruit were hit. And that was probably one attacker. The starting gun has been fired off. Everyone has declared to the emergency. Every black cat hacker on the internet with an LLM is going to be able to start poking around, seeing what they can find.
Starting point is 00:25:49 they and because there are multiple attackers now there's a an inevitable outcome where well capitalized ones are going to come in spend millions and millions of dollars on graphics GPU computing because they know that they can pop one vault what you'll be able to have an attacker do is they're going to be able to look through the full list and just pop it right out and you are just marginally safer because it's not the lowest hanging fruit but you are not safe period So this started as obviously like an amateur attack as we spoke about a little earlier,
Starting point is 00:26:22 but this is now, you have to assume the best attacks in the world are now having to go at this. Yeah, this is everyone. It's a, it is a real mess. So when you compare this to like a Mount Gawks or a FTA, it's like the number of coins is going to be far lower. But is the damage going to be greater? Because it kind of arose people's trust in self-custody, essentially. Like, Cole Card was the golden child of Bitcoin self-custody, essentially. I, like I said earlier, it would be naive to say that in the short term that this is not going to be a very negative downward pressure on self-custody.
Starting point is 00:27:06 And for I know multiple people who've lost either some money or their life savings, I have spent the past 24. hours. I have talked to directly on a one-on-one context, dozens of people. In a larger platform, I've talked to now thousands of people trying to raise the alarm bell about this and the stories keep on coming in. This will have a downward trend on self-custody. I think that doesn't have to be the end of the story, but I think there needs to be, as the post-mortems wrap up, and we do a full debrief of this. The entire ecosystem has an opportunity to build from here and find improvements. We are now almost 30 minutes into the podcast.
Starting point is 00:28:01 So in some conversations, people are talking about we need covenants and vault-like structures. Things that can improve self-custody. My biggest concern for the health of Bitcoin as a network is that the default option being holding it a custodian or an ETF wrapper, I am not opposed to those instruments existing. I think those are inevitable structures that happen with hyper-bitquinization. But the value proposition of Bitcoin itself will be diminished greatly if those are the only real options. And being able to explain this, the way Bitcoin works today, if you have the requisite
Starting point is 00:28:39 amount of signatures, you can send any amount of Bitcoin anywhere within reason. There's weird corner cases, but let's just say for the... the sake of conversation. That's true. Things like Covenants would allow you to be able to have things like, I only want to be able to send to these addresses. I only want to send this much Bitcoin. This is something at Anchor Watch, we are able to offer as a product level service, right? It is an application that sits on top of Bitcoin where we say Anchor Watch is a required co-sider to move funds. but we will, in exchange for us being able to help you out, we'll say, okay, well, you only can send to the addresses you give us,
Starting point is 00:29:20 so addresses A, B, and C. Otherwise, we at Anchorage, won't sign. It's effectively a covenant. As us acting as a co-signer gives that feature. Or I only want to send one Bitcoin a month. That's something we can do at Anchor Watch. It's something you can't do on the Bitcoin blockchain level. If it were to be democratized to the Bitcoin blockchain level,
Starting point is 00:29:39 anyone in their basement would be able to have orders of magnitude, better security than any of the enterprise leading custodians today. And that's an important point because when Bitcoin is in flight, once it gets confirmed in a block, it's over. Whereas with Covenants and in general vaulting, you would be able to send to like a staging address. So you'd be like, wait a second, why did my funds move? It's sitting in my staging address. And then you can pull the emergency rip cord to like pull the funds out. Now, it doesn't solve the key management problem, right? I think it's an important thing to call out that it is a mitigation.
Starting point is 00:30:18 It is necessary, but not sufficient to be able to improve these things. But ultimately, you need to send Bitcoin to an address somewhere, and those addresses have to ultimately be tied to keys. So there is a lot of learning, I think, within the ecosystem about where do we go from, here. And I think there'll be plenty of time to discuss that in the coming weeks after the initial incident response and everything can be done as much as possible to keep people safe. Right now, I think the main focus is just letting everyone know this is happening and they need to immediately remedy this if they're impacted. How do these, like an unchained or a caset,
Starting point is 00:31:03 let's say you have a two of three with one of those. If I have, so one key, one key, will be on your phone generally. One key will be held by, the company one key is held by you. If I'm holding my key, let's say on a cold card, how do I know that the counterparty, the unchained or the CASA is not?
Starting point is 00:31:23 The unchained or the CASA counterparty is not what? Like holding one of their key on a, on a call card? Because that would then put the multi-sigar risk. You can't, you can't prove that. You can't, with any wallet, well, in a very tragic sense, of irony, very soon people will be able to prove if they were using the cold card keys,
Starting point is 00:31:46 because attackers will have them, right? The ideal structure, though, is that it's not something that can be an issue. Because if you have sufficient randomness, you should not be able to fingerprint and say, oh, that ex-pub came from a ledger and that one came from a jade. That would be a breaking in the underlying cryptography assumptions that is a truly random number that is seeding all of your secrets. So I guess the point I'm trying to make, I'm trying to make people feel comfortable here if they are using a
Starting point is 00:32:18 cassero and unchained. Like, have either of those made a statement about how they're generating their keys? Like, because I'm like, I'm convinced that neither of those companies are using the on-device random number generator. But have they made an statement? To my understanding, unchained has made a statement. I believe CASA has made a statement as well. And we at Anchor Watcher have also made a statement.
Starting point is 00:32:39 this does not impact us, right? And so I think it's an important thing to look in your vendors to see if this is an issue. I think that's a very reasonable concern. But I think everyone at this point has made some public statement to the effect of that. I'm not aware of any Bitcoin business, even through like hushed private circles who are impacted by this. I haven't heard anything yet. They may exist, but I have not heard anything. I definitely don't want my words to be twisted there.
Starting point is 00:33:08 Like I think Acaster and Unchained, like Angot, I'm sure. those companies are set up brilliantly. I just want to try and make people comfortable with moving funds to those places if they need to. Understood. Ankerwatch, how do you set up your multisig? Yeah. So the nature of what we do is somewhat different is we use what's called miniscript.
Starting point is 00:33:29 And that allows us to do more advanced scripting functionality. Rather than just a two of three, we are able to say, we have a two of three, you have a two of three. We all have to get together and sign and move things. we can do is we have a two of three and you have a single key, right? And we act as that cosiner still, right? The nature of how anyone generates keys is an extremely
Starting point is 00:33:51 sensitive thing because you just need to keep that on a need to know the exact mechanics, but our process has been peer reviewed. There are many, I think most actors in the industry have their own very rigorous key generation ceremonies of what they go about for
Starting point is 00:34:08 for being able to evaluate that. So when, like, I really like single-sig self-custody. Like, I think you should have different trade-offs for different amounts of Bitcoin you're holding. Like, if maybe you have one sort of deep cold storage, which is geographically dispersed multi-sig, and that's great. But the simplicity of single-sig is really important, too. I think I would definitely still use that occasionally.
Starting point is 00:34:34 How do people think about that going forward? because I've always said that the most likely you are to lose Bitcoin is through your own complexity and your own setup, like complexity being the enemy of security. Do you think people are going to make the mistake now of jumping too far into multisig because they're scared of this attack and actually add too much complexity to their own setups? I think multi-sig is no longer that complicated. I think this is not 2017 anymore. Additionally, if for whatever reason you want to do a single signature, you could do single signature with a passphrase. That effectively is a two-of-two multi-sig because you have to have both. pieces to be able to constitute a spend. If you were doing that with a reasonably strong
Starting point is 00:35:12 passphrase going into today, you're still safe. I would still make a new wallet because if you fell under this and your initial 12 or 24 words were actually part of this hit of known possible seed phrases, all that's keeping you safe now is your passphrase. but I think there's a lot of opportunity for everyone to grow and learn from this to even further improve the user experience because this will be in the front mind of anyone who discusses self-custody for a very long time. So this is the first, like in the wild case that we've seen of AI essentially hacking and taking down a Bitcoin and self-custody solution. Do you think this is the start of that era? Do you think we're going to see more and more attacks like this? I think in general, across the whole web,
Starting point is 00:36:04 there are going to be more and more attacks like this. The trivial ability for me to be able to open up to open router and use Kimmy K3 and point at the cold card firmware and instantly read out everything, everyone needs to be, and we regularly do this. At Anchorage Watch, I know most companies that I know of in the Bitcoin industry are regularly doing this and kind of defensively trying to deploy these tools to find things.
Starting point is 00:36:32 We've always found, we've never found anything that was a money losing bug. Nothing in the universe of bad of what we're seeing here with the cold card. But you find bugs. Software has bugs. It always will have bugs, right? Like there are some emerging research around things like formal verification. So you can actually do formal mathematical proofs as to how code executes. that's an emerging field of research
Starting point is 00:36:58 that I think may get more important over the coming decade, but software is written by humans and humans inevitably have bugs and even LLM sometimes have bugs, right? You don't want to be blindly passing everything you've built to just have it go get figured out later by the LLM and the LLM may not be complete, right?
Starting point is 00:37:15 The rapid development of these models, there's a kind of a funny software motif if you write, if you like vibe code a website and you launch it, in three months, the new model comes out and it says, wow, this codebase is a mess. Let me fix this for you. And that's just been happening continually for two years now.
Starting point is 00:37:30 Right. So like we're at a place in a time where you need to be hyper vigilant with your own individual judgment, with your ability to understand the nitty gritty details of risk and however it emerges to be able to keep you and people you work with safe. All right. Awkward question time because I know you're friends with MVK, but like the blame obviously ends with them. But how incompetent was?
Starting point is 00:37:55 this because this has been five years that this firmware issue has been there? Not acceptable as a starting place. Like, not like there is no, yes, I've known NVK for a long time. There is no excusable, there's no set of circumstances that excuses this. The one job a hardware wallet has, if it were to have a single job, more important than all of the other jobs. is that it can securely generate a sufficiently large random number with sufficient entropy. That is the entire game in which everything else gets derived from.
Starting point is 00:38:35 There are bugs that have happened in hardware wallets in the past where maybe how they signed a transaction wasn't secure. And then basically if you reused addresses, you could lose your funds. Or maybe you would have bugs where it wasn't checking the change address. So if I sent you Bitcoin, if I have 10 Bitcoin, I send you one Bitcoin, I have to send myself nine back in change. There were bugs in software and hardware wallets that didn't check the change, which was the most important part of the transaction in that sense, right? This bug is so foundational to the actual security of Bitcoin. That it is a nuclear event.
Starting point is 00:39:11 Right. This is the most catastrophic thing. That is why someone could be entirely air-gapped, never have talked to the internet, and someone's able to peer through the vast space of randomness and get your Bitcoin, which should never happen. Do you think it's the end of Cold Card? Do you think they'll be able to recover this?
Starting point is 00:39:30 Because trust is everything when it comes to these devices. It is. I think it's too early to say. I don't know. I'm not a lawyer. I don't understand any of the liabilities or fallouts or all of these things. It's hard for me to say. Truly.
Starting point is 00:39:48 I don't know. All right, Rob. I appreciate you doing this last minute. I wanted basically just to get this out there. If one person listens to this show, they're not, they're not permanently on Bitcoin Twitter like you and I and they haven't seen this news. Like that makes it 100% worth it. Any closing words for everyone who's listening?
Starting point is 00:40:04 Closing words again. If you or someone you know has used in MK3, MK4, MK5, Q, any of those cold card products with out either rolling your own dice or having a sufficiently strong passphrase, and if your question is, is my passphrase strong enough, it means you don't understand the entropy, which means you need to go fix this immediately, even if it is, right? You just, you, if you don't know for a fact, oh, yes, I have this many bits of entropy in my passphrase because you are super in the details. Your passphrase is not strong enough at the moment. You need to immediately make any moves and plans. You need to cancel your weekend plans.
Starting point is 00:40:41 You need to get on a plane if you have to. You need to call a loved one who may be able to help you out remotely. This is a, this is a full five alarm fire. This is all hands on deck. I think everyone in the Bitcoin community has been trying to help through back channels and through direct messages through being able to have people call you, find people, get connected to people. My DMs are open on Twitter. Like I said, I've talked to dozens of people across the whole ecosystem. None of them even Anchor Watch customers, because Anchor Watch customers don't have an issue at the moment. This is not related to anything of how your funds are being kept safe at Anchor Watch.
Starting point is 00:41:18 So all of that to be said, like reach out to those you may know people you've ever referred to using a cold card and do what you can to try and help them out. And I think there's going to be an opportunity in the coming week, two weeks to when the initial race is over, we can focus on triage. We can focus on, well, once we move beyond triage, we can start focusing on. where does the industry go from here? All right, Rob. I appreciate you, man. Thank you for all the work, helping people out on this.
Starting point is 00:41:55 Terrible, terrible event, but Bitcoin will get through it, man. Thank you. Thank you.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.