What Bitcoin Did - The Coldcard Disaster: Everything You Need to Know | Lloyd Fournier & Nick Farrow

Episode Date: August 21, 2026

“They’re saving all their money in Bitcoin and they’re doing all the right things. They’re self-custodying it. And then overnight, it’s just gone.” Frostsnap’s Lloyd Fournier and Nick... Farrow join me to break down the catastrophic Coldcard vulnerability that made supposedly secure Bitcoin keys guessable and allowed attackers to drain more than 1,700 BTC without ever touching the devices. We discuss how a five-year failure in Coldcard’s randomness generation went undetected, why every safeguard failed and the role AI played in discovering and exploiting the bug. Nick also explains how he reproduced the attack himself, what the on-chain evidence reveals about the attackers and why this has shaken trust in Bitcoin self-custody. We also get into whether hardware wallets are really trusted third parties, the limitations of dice rolls and air gaps, how Dark Skippy can leak a seed through a single transaction and why single-signature custody may need to change. Finally, Lloyd and Nick explain how Frostsnap uses distributed key generation and threshold signatures to remove single points of failure, simplify recovery and secure Bitcoin across multiple locations. THANKS TO OUR SPONSORS: LEDN SWAN ANCHORWATCH BLOCKWARE BITKEY CAPE FOLLOW: Danny Knowles: https://x.com/_DannyKnowles Lloyd Fournier: https://x.com/LLFOURN Nick Farrow: https://x.com/utxoclub

Transcript
Discussion (0)
Starting point is 00:00:02 The Bitcoiners, these are people all in on Bitcoin. You know, they're with families, like, they're saving all their money in Bitcoin, and they're doing all the right things. They're self-custying it, and then overnight is just gone. Like, it is really sad because I look at the chart. I can see when, like, when people are buying Mark 3s with this corrupted firmware, and you can see the money starting to go into the insecure wallets. The money keeps going up in the Mark 3s because people are still stacking.
Starting point is 00:00:26 They're doing what they've been told, right, to stack sats. And they, like, more than, like, double the amount of Bitcoin in their... compromise mark three. So it's, yeah, that bit is very sad. Years spent, stacking on thing, and it's gone. Like, this has hit a lot of people. Do we know how much Bitcoin is as of right now? 1,200-ish people and almost 2,000. Criminals who are focused just on this, their skills are there.
Starting point is 00:00:51 They know what they're doing now. And they know how to target and they get information and they know how to do it. Brossnap team, let's go. Yeah. How you do guys? Very good, Danny. Thanks for having us. Here in Sydney.
Starting point is 00:01:03 I don't know where... In fact, the first place to start, I think, is if anyone out there has not heard about this cold card vulnerability somehow, probably time to turn off the show, move your Bitcoin off a cold card. I did a video with Rob Hamilton as soon as this dropped. I'll put a link in the description. Go watch that and do something about it immediately, because we're going to get into the details here.
Starting point is 00:01:25 But let's start with, like, when did you first hear about this? Lloyd, let's start with you. It was in the morning. It was just before a meeting or whatever, and it was good because I was going about to make a point about our feature, you know, feature of Frostnap, which means we don't have to rely on the device entropy. It was just linked in the group chat.
Starting point is 00:01:42 And I said, yeah, there's something wrong with the coal card. I thought it was supply, someone made some fake cold cards or something and give them out, I didn't really know what it was. And then after the meeting, it was in full swing. It was a complete nightmare. And I was transfixed by it. Yeah, luckily, I am almost always on Bitcoin Twitter. So I think I saw it quite early.
Starting point is 00:01:58 And the first thing I thought was like, this is probably, Like, I imagine that it was being, you know, over-exaggerated. Texted Rob Hamilton right away being like, is this real? And he was like, because I had some funds on a Mark 4, luckily. But I'd like generate the keys on the device. So it's still vulnerable to a degree. And he was like, move them immediately. Don't mess around.
Starting point is 00:02:18 This is not a drill. And I was not with the wallet. So I had to do a phone call, managed to get the Bitcoin moved. But, like, scary times. And I don't think we've still digested everything that's happened. as like a Bitcoin industry yet. I don't think so at all. I think people are sort of grieving in a bunch of different ways
Starting point is 00:02:37 without actually having to have time to soak it all in. But one thing I was surprised that was how quick the response was actually from some of the big names like Kevin from Leana. And I think it was Insta Gibbs from I think he's Bitcoin core developer. I think it could be wrong there. He, you know, they were onto this right away and sort of raising the alarm, which is quite a risky thing to do as well, You don't want to be the person who raised the alarm and then be wrong.
Starting point is 00:03:03 And then sort of, you know, but I think Instigivit's found some proof that, you know, once he'd seen what he'd seen, he was like ready to pull the trigger and say that something's really messed up here. Yeah, the thing that sort of surprised me with it is it looks like this was found by an AI model. But this is viewable code. I know it's not fully open source code, but it's viewable code. And I know, Lloyd, people like you actually look through this code. I wasn't, Nick was the one looking through it. Oh, really? But like, why was this overlooked or not found earlier?
Starting point is 00:03:34 I have my theory about it. And I have to put my own hat on, because I didn't look at the code. I needed Nick, to be fair. Like, this part of the code, Nick didn't look at it. And why didn't the AIs and the humans? Everyone failed. And not only that, but like, all the different things failed, you know? Like, all the safeguards.
Starting point is 00:03:52 So this kind of thing wouldn't happen. And they had several checks in there to make sure this kind of thing wouldn't happen. of the R&G, all the kind of things, those all failed. And then all the extra randomnesses also failed, basically. So, like, there's just failure after failure, after failure. So it feels like you're on a different timeline, like it's cursed, basically, this kind of outcome. So why, but in reality, like, it wasn't just bad luck.
Starting point is 00:04:16 There was some contributing factors. So what I think is that the code was actually quite bad. Okay, so not just this problem, but the code around it was actually very bad and I was surprised because I thought cold card, if you're looking at how this generates randomness, the code will just be pristine. You know what I mean? It's like, I'm gonna spend 10 hours doing this. Every line of code will be perfect and just make total sense to everyone who's reading it. And then I started looking at it and it's like red flags everywhere, you know, smoke and fire everywhere. And like, no wonder people have people have been emailing them about it, doing security disclosures,
Starting point is 00:04:57 without ever getting actually at the thing that caused the problem, we're just pointing out, like, man, what are you doing with this randomness? Okay, you get randoms from here, but then you put this yass meringue RNG thing, which is now like a famous meme R&G, because it's not a cryptographic R&G. It is just a toy R&G, basically. And it's being used in weird ways. Was this the one that the CTO, Peter, is Peter, right? Yeah.
Starting point is 00:05:23 Is this the one that his, like, other alt-sudonym came up with? It didn't come up with it. It's been around for a while. Okay. But it's just some random dude on the internet came up with it, right? And it's just for a toy R&G. And it was in Micropython.
Starting point is 00:05:39 And so I think, like, Peter, Doc Hex was probably working with Micropython, and he wanted an R&G over here, and so he just sort of copy-pasteed what's over there. Now, Micropython is not meant for secure applications. It's not something, it's like for toys, basically. It's literally what it's for. And so... As someone who knows nothing about, like, actually coding, why is Micropython not the right thing to use?
Starting point is 00:06:01 Well, it's, you can, you can use it. You just have to be extremely careful. Like, the things that micro... I mean, MicroFi and friends, it's like, make your own IOT device kind of thing. I would guess, right? It's like for embedded devices. It's not for secure embedded devices. People would usually write and see or type safe language, right?
Starting point is 00:06:17 So Python is a hobby, like, it has a reputation as a hobbyist language, right? And Micropython sort of fits in that vein, being a kind of hobbiton. as toolkit so you can whip up cool applications really quickly, right? So you'd like the beer dispenser at like a, you know, a Bitcoin, you know, a conference probably could be built with Micropython, with communicating with a Lightning wallet or something. You could also do a hardware wallet with it. Technically, nothing necessarily goes wrong with it, but you have to be super careful because it creates these layers.
Starting point is 00:06:49 It's very easy to make mistakes. Like it's very easy to, you know, forget. Actually, there's still like these things called linters, which like check that you used variables and stuff that you didn't forget anything, but it's still very easy in Python to introduce logic bugs or sort of, I think what we saw in Cold Card was there was sort of this layer
Starting point is 00:07:08 of sort of, you know, you weren't able to trace the program quite seamlessly through the calling. And one of the reasons was that it wasn't just Python. It was Python stacked on top of C, my understanding. Yeah, and so the most of the bug exists in the C code. Okay.
Starting point is 00:07:27 Okay. But it's not helping that you're trying to finangle it through different layers, right? So the C code just does things that no cryptographer would do. Like I said, it would be pristine. It would be the most cleanest thing, you know, in your code base is how this seeds go from, right from the hardware to the seed words. And instead, it's like these weird loops where you're pulling words out and putting into, like, pulling words out of a chip.
Starting point is 00:07:55 It seems like it's using the chip, so that's what everyone looks like. It all looks like it's using the chip, but then it's like randomly mixing with yass meringue RNG, which why would you do that? Like there's a very simple in cryptography. What you're going to do is you're going to take a cryptographically secure pseudorandum number generator. You're going to pull randomness out of that true random number generate out of the hardware, a lot of it.
Starting point is 00:08:17 Compress it down to a seed for that pseudo random number generate and just pull out anytime you need randomness, just pull out of that pseudo random number generator. Okay, that's what you would do as a cryptography. And what was Cold Card actually doing? They were going to the chip, they were seeding it at the start, but then they were putting in the Yass meringue RNG, and that is not even an R&G pulls out a single word, so it's like 32 bits, integers, and its state is very small. That's the big problem.
Starting point is 00:08:46 So the amount of data you can put into that, like your secret key, right? Because a pseudorandum RNG, when it's a cryptographically secure one, it has a secret key. basically it's like some 32 bytes or something of secret data and you pull out as many secret values as you want from that thing. And the security definition is that no one can distinguish without knowing the seed the bits that come out of that from a truly random string of bits. That's the actual security theoretical definition of it, right? And so this thing doesn't even have a space, like the state of it doesn't even have enough
Starting point is 00:09:20 input to be secure. It's like a few bits, I think it's one word or like, 32 bits. It might be 32 bits. I think it was 40 bits was the entropy that you were getting on a mark 3, I think. And from the analogy for anyone listening that I heard was, it's like, that's like a needle in a very, very, very large haystack. But like if it's the proper 256 bits, it's like a needle in a million galaxies or something.
Starting point is 00:09:45 Yeah. Yeah, it doesn't, it double. Every bit doubles it, right? So if you keep doubling. But actually it wasn't, it was much easier than that. It wasn't even to the 40. It was just like two to the 20 something. 20 something really in the 20s of bits. That's because I thought also, I initially posted out,
Starting point is 00:10:01 I just got Grock or whatever, just told it like, you know, like let's start posting about whatever the hell was going on here and like get the actual bits of security. I thought it's like 2 to the 40-ish. I think Block sent something similar around the exact same time. And then we found out later, now Kevin and the, or the team at Wizz's Sardine has actually gone through it and figured out what the actual numbers are in this incredible article, which sort of restores your face.
Starting point is 00:10:24 in Bitcoin a bit because it's so people really care about Bitcoin. It shows you, right? Of course, yeah. And I've laid out the thing and it's actually only, there's only millions of possibilities or tens, hundreds of millions of possibilities of seed words for all these cold cards. And actually, when you do the maths, what they've done is it showed that, and it seems to be empirically verified, and we've found people with it, is that some cold card users got the same seed words. So I saw that on Twitter and I don't, like, from my And what I saw, at least, you may have seen something else. I don't know if that was true.
Starting point is 00:10:57 Dee Hoddle, who, to be fair, has done a really good job at sticking around and trying to help people. He replied to a tweet that said, like, it was a tweet from years and years ago saying, like, I got a cold card, generated a seed, and it looked like a collision. But it turned out the guy had just pressed six on his dice rolls a hundred times, or however many times, I've seen a few false flags as well. Yeah. But then I did see one, it seemed more legit, which was actually a guy.
Starting point is 00:11:23 got a cold card and he already had some money on it. And then he already put, he put money on it. He's like, all right, I'll just put my money on that. And then someone took it. It's so unimaginable, right? It's like, you know, in both directions, like, if you're the person who buys a cold card and puts money on it and it disappears. And if you do all the right things, like, no one is going to believe you, even if you're like, and then the flip side, people even believe you less. Like, if you just, if you say, I bought a cold card and like it already had money in it, that's like, even
Starting point is 00:11:53 more unbelievable. But that's the thing that sucks the most is, like, the people that have lost money here are, like, good bitcoins who have done everything right. Like, they've been completely rugged by, by CoinCight in this. And I think that's why it's hit everyone so hard. And I think that's also why we've seen people band together in the way that they have and try and help people out. Like, I've had a lot of DMs about people who've been caught up in this.
Starting point is 00:12:15 The only person I know personally, and I'll only say this because he put it out publicly that lost money was Madex. But, like, this has hit a lot of people. Do we know how much Bitcoin it is as of right now? I know how many people it is. So I even know how many... It's around 1,200-ish people. How do you know that?
Starting point is 00:12:32 Because I ran the attack just last night, so I finally got my clankers to finally just, like, you know, run it all. Like, put it all together. Check, go through, find all the possible seed phrases. Go and check if the first address or whatever has ever been used. Output the public keys from that so I can find them all. And so, yeah, it's about 1,200-ish people. And almost 2,000 Bitcoin. Damn.
Starting point is 00:13:00 Is that 1,000 people, 1,200 people, that have actually had fun sweat or that could have fun sweat? Well, that's wallets. No, that's wallets that got hosed, yeah. I mean, some of them got it away. This is like the total affected Mark 3 that ever had a balance. That had a balance at that moment. Okay. It's more, it's more, it's more people if you...
Starting point is 00:13:20 More people, if you go back to the peak, Mar 3, and it's like, more, it's like, 2,400 Bitcoin was stored on these devices insecurely. So it went down to like 1,900 by the time of the attack, because people are moving on to newer devices, generating new seeds. So that's roughly the numbers we're talking about here. It's like a thousand-ish people. How many people actually got robbed? I'm in the middle of figuring that out.
Starting point is 00:13:46 I think I have a good heuristic on it. Do you know roughly, like, can you say roughly what you think it is? I told my clan gonna start figuring out that number just before this. It's probably working. Let's see if it's done its job. I'll have a look. So you actually ran the exact attack that the attacker will have done? Yeah, I can, I mean, the initial attacker was, they all did different.
Starting point is 00:14:07 There's a few, I think there's four attackers. That's what I think. It looks, they leave quite like obvious fingerprints on chain, like in the behavior of, you know, do they all sweep all these wallets at once? Do they use a fixed 30 sat per byte fee rate? And so you can kind of distinguish all that's like not the same person as, you know, that other attack that we saw. If you hold Bitcoin long enough, there's going to come a time when you need some dollars. It might be a tax bill, a business expense, life getting in the way, but whatever it is, it might come at a time when you don't want to sell your Bitcoin.
Starting point is 00:14:40 That's where Leiden comes in. Leiden lets you borrow against your Bitcoin instead with tiered rates that go as lower 9.25%. So you don't have to sell your stack if you don't want to. Leden have operated through every market cycle since 2018 and have originated over $11 billion in loans. But the important part for me is the way Lairdon handles these loans. Your collateral is held in custody and never lent out to generate interest. And Lennon's more than just loans. Tether gold is now live alongside your Bitcoin with instant trading across 10 pairs.
Starting point is 00:15:08 And later this year you'll be able to borrow against gold in the same way that you do with Bitcoin. Levin really is an awesome company. I've used them multiple times. The applications have taken me less than 15 minutes and you have the dollars in your account within hours. If you want to check out Ledden, go to LEDN.I.O and use the code WBD for 0.25% off your first loan. That's leaden.com. I.O and use the code WBD. If you own a Bitcoin ETF, especially if it's GBTC, you need to listen up. Spot Bitcoin ETFs provide price exposure to Bitcoin, not direct ownership. You can't withdraw it. You can't self-custody it. And they charge you a
Starting point is 00:15:42 management fee every year to hold it. Well, Swan recently announced Swan Real Bitcoin Exchange, and it's ready to use right now. Now. RBX is a structured in-kind exchange that converts your spot Bitcoin ETF shares into real on-chain Bitcoin. It does that without selling on the open market and it's designed to support a tax-efficient outcome. So for example, if you hold GBTC, you're paying 1.5% a year in management fees for Bitcoin
Starting point is 00:16:05 price exposure. But by swapping GBT for real Bitcoin with RBX, you can drop that figure as low as 0% by just holding it in self-custody. This is designed in a way that maintains your cost basis and in a manner that supports the deferral capital gains tax. So if you own a Bitcoin ETF, especially if it's GBTC, you need to talk to Swan Private about RBX today. Head over to swan.com forward slash WBD and booking a call with one of their team. That's SWAN.com forward slash WBD. You wouldn't reuse a Bitcoin address, so why does your phone broadcast the same identifier for life? Every sim has a static ID and carriers, ad networks and
Starting point is 00:16:43 bad actors all use it to track you. The big carriers have been caught selling that data over and over again. Cape is America's privacy first mobile carrier. Their identifier rotation feature changes your ID every 24 hours so you look like a different subscriber every single day. And sim swaps are off the table. Your number can't move without a 24 word phrase that only you hold. There's also no name at sign up, no social security number and there's no profile to build on you. If you're a Bitcoin or in America, I honestly don't know why you'd use any other network. You can head over to cape.co forward slash WBD and use the code WBD for 33% off your first six months. That's CAPE.com forward slash WBD.
Starting point is 00:17:25 So I know the first attacker was basically moving everything into one like pulled wallet. Yeah. And none of those Bitcoin moved. So he was, he got the vast majority right. I think he was over a thousand Bitcoin. Is the rumor that they think he used some sort of like paid on-chain heuristic website that was KYC'd? Is that true?
Starting point is 00:17:44 Oh, I've not heard that rumor. I've heard the rumor. Maybe. Could be, couldn't. It'd be good to figure that out. I guess it doesn't necessarily mean it's the correct K-YC. Like a blockchain like, you know, data provider. Yeah, exactly.
Starting point is 00:17:57 Yeah. But I mean, he could also. You really didn't need to. That's what I can tell you. You don't need to do any of that stuff. Especially as Bitcoin, you can run your own node. The guy probably, yeah, there probably wasn't in big investors to run his own node. You know, I mean?
Starting point is 00:18:09 Why would you invest that? And also, you're in the time limits, like, I've made it. made it. I can buy a small island now or whatever. So let me just take what I've got. Yeah, he took about half of it. That's what I see. So he's like, there's around 2000 there and he took about a thousand on the first, and just in like a few blocks. Well. And it's gone. And then actually nothing happened for like, you know, 16 hours or something. And then Kevin posted. And then nothing still had nothing happened. Actually, people didn't start moving their funds right away. It was only when Coin Kite, actually, as soon as coin Kite put out
Starting point is 00:18:46 their advisory thing, it all just started happening. Oh really? Yeah. That's what the chart shows. I don't know if the time is coincidental or whatever, but, or like people are getting, it was a, it was, they admitted it at 650 New York time. You mean people are getting home from work or whatever, it's all happening at that moment and then like really start things start moving. And then like another attacker hits them and then 12 hours later, another attack hits them. So the attack has came in small bursts, actually. I think there were four of them. Interesting. And so tell me how hard it is to run this attack. Are you assume you did this with Kimmy K3? No. Actually, I did it with Claude.
Starting point is 00:19:28 I am in the security whatever, cyber security program. Maybe not for long. But I did, like, I put safeguards in that I never get the seed words. Okay. And I only ever get, only ever get, out puts me the public descriptors. Oh, nice. Okay. And so, it was willing to go along with it, as well. Did any of them still have money in it? Uh, yeah, but like the crap, like, James O.B. has been, like, putting...
Starting point is 00:19:52 Dusting tests once. I think no one's going, there's no money there, so there's no point. But there's still, there's tiny amounts of money. We could probably pay for dinner tonight if we took it all right now. Let's not do that. But tell me how hard it is to actually run this attack. Like, especially for someone like me who I can't do any coding. Like, could I still have done this time?
Starting point is 00:20:11 Yeah, you could have. Yeah. It does look like it was someone who ran Kimmy. I do think it was Kimmy, so I do not think it was an insider attack. Yeah. I think it was someone who said, let's just throw it at these hardware wall and had the goal to go at the cold card, the great most secure hardware wallet of all time,
Starting point is 00:20:27 and say, you know, go look at the entropy. They must have, like, because they would have, usually you would clone, like, the latest version, right? So, in the latest version is not as bad, but they probably would have found the price and said, okay, so how bad is the problem across all these different versions? And then you would have found the Mark 3's complete catastrophe. And then you say, like, let's write something to find these things and spend them.
Starting point is 00:20:51 And the code was, I mean, it got half of it. You could have got too much more. And I think they made mistakes. Like, I think, I believe one of the issues was that it was going through the potential private keys, and if there was a gap, it was then stopping. Yeah. Yeah. But, like, if it was me doing this, I put Kimmy on the case.
Starting point is 00:21:15 Could I have spun something up in, like, a few hours and an ex parte who's this vulnerability? I don't think... I'm thinking about... Lloyd, you're doing a lot of research into, like, asking, like, models prior to Kimi, whether those models, like, the ones when I was looking for this kind of bug, whether those models at that time could have found it. And you sort of came to conclusion that not really, like, with Opus and these other models, models. They were not, not at the time you were looking, but the time that the attacker was looking, yes. Yes, Kimmy K-3 was there. So, yes. So I think he, I don't know how it, like, the thing is, you need, you probably want to use the GPU.
Starting point is 00:21:54 Okay? You can, you probably, but you can, if your laptop has, like, the special instruction for Shar-512, which is the real time-consuming thing, needs to be done over the password derivation thing in BIP 39, this has, like, this password derivation algorithm. I think, you can do it. I was looking at how long it would take my laptop and it would take, it would take the whole day or something. It would take a half a year at my original estimates at two to the 40. But now it's two of the 20. That's a million times easier. So I don't think it would take a long very long at all actually. Now think about it. So if you're using, yeah, you would be able to do it in a very little time, sweep the space. And that wouldn't get you everything because there's also how many times people click buttons. Like there's all kinds of little finesse things you have to do. This got the real low-hanging fruit. Yeah. And to get the low-hanging fruit was like
Starting point is 00:22:43 a thousand Bitcoin, yeah, you can do it on your laptop. Crazy. It's crazy that this was just looked over for so long. This was out in a while for five years. It's not. It's absolutely not. Yes. And that is a, that is a reason, that is a real fault. Like, whatever you say, that is a fault on behalf of CoinCard, because I think it could have been, I think people, like, there was so much smoke around it, including people getting the wallet or someone else. It seems to be, maybe those were all like, you know, people. I mean, still, listen, if you've got a feature, people, like, get rugged on it, like, don't have that feature.
Starting point is 00:23:16 Or, like, do it, because you could put in one dice roll, right? So people are coming, like, I lost my money and there's, oh, it's just another, you know, you come and comes in and says, oh, I lost all my money. It's like, oh, it's just another guy who put in one dice roll. Yeah. Because we let, but if you. And I think that gets to like, and many people have said this since, but I think that gets to the sort of arrogance of coin kite that they were widely regarded,
Starting point is 00:23:36 I think, is the best hollow wallet before this happened. And I think they had believed their own hype with that. And maybe they felt they were too, you know, this couldn't happen to them. It must be. Yeah. I think, and maybe a distraction on like all the, you know, away from the fundamentals of what's most important and onto some of the more fancy features. Yeah.
Starting point is 00:23:56 You know, that distraction and takes away the time from really like making sure the really... Which is insane. The mission critical thing. All you need from it is three things. You need it to generate good entropy, sign transactions and store your private key. Like, that's really all you need to do. And it failed at, like, the most key fundamental one of those three things. Though it is true, like, if you're a developer, you were sort of, you put in the safeguards,
Starting point is 00:24:18 you believe that was correct, you know? You don't gonna, like, randomly revisit it. Except when people are complaining they lost their money. That's when you should be, like, revisiting, and people are sending you things about Yasmarang R&G in your security disclosure and saying, what are you doing with this Yasmareng anywhere near any of this stuff? Like, that should have been, let's say, you take another look at this. But should they not have been having audits on that code, like, especially the key parts of the code every, like, six months or something?
Starting point is 00:24:43 I don't know. It's a new question. Audits are an interesting one. We probably have a lot to... In retrospective. If I was ordered, like... Yeah, but people in the community did order it. And like, James O.B. audited it.
Starting point is 00:24:56 And he says, like, shit. And you can bet that Ledger Don John, like, I bet they looked, you know, through that code, like... Maybe not through that exact code, but, you know, they would have looked through the hardware, TR&G, surely. You would have thought so. Maybe. You would have thought so, but it is very easy to get fixated on a certain thing, because I had the cold card firmware. And I was doing it, I was planning to do a little attack on it.
Starting point is 00:25:16 I was planning to do Dark Skippy on the cold card, because we'd done it first on. For education purposes. Yes, of course. Yeah, and I was going to tell NVK about it and all that stuff, you know, to tell him it's coming, to demonstrate for educational purposes, to show that, you know, that it doesn't matter how many secure elements you have on the thing, if it's got malicious firmware on the main ship, it doesn't matter what the secure elements do. Because when we did it on the seed signer,
Starting point is 00:25:40 what we found is people like, oh, yeah, luckily I use secure elements. Nothing to do with that, actually. And so I had the firmware there, and I was fixated on how to deploy my malicious firmware onto the coal card, which I managed to do thanks to the charlatan, a Bitcoin Core developer, who also pointed out problems in cold card security, not this problem, but other problems, and was dismissed. And he pointed out this one.
Starting point is 00:26:04 And I thought, oh, I can use that to do Dark Skippy. So I was like, I had the code there and, you know, whatever, and I didn't look at anything to do with R&Gs. Of course I did. Because I was too, I was, of course, that's not gonna, that's gonna be correct, right? Yeah. I also don't want to look at a bunch of Python either and like, and see and how it all links together. It's like, and people looked at it and they didn't catch them as basic thing. Like all this mess of pseudorandomness was a mess and it was bad and it should not have been
Starting point is 00:26:30 in the cold card itself. But that chip, R&G, was a, you know, it was a mess. was not from the chip. That was the whole, the real, you know. It was bypassing the actual, the R&J. It was not even used. It was all a circle jerk of cryptography, like all these different operations done on no randomness at all, just going round and round of nothing.
Starting point is 00:26:48 No one expected that. I mean, it's so hard to think that that would be real if you were a reviewer, right? Yeah. Yeah, I mean, for someone like me, I just assumed that, like, randomness on the cold car would be elite. Like, that's just... Absolutely, absolutely. So I do want to come back to the dark skippy thing, but before we do,
Starting point is 00:27:03 Before we do, on the Mark 4s, fives, and cues, there was better entropy, but not great entropy. Yeah. I've not seen any reliable source that any of those have been cracked yet. Do you know where that's at? Yeah, I think that Kevin's analysis here is good. So, I mean, not Kevin. We're in Sardine, because he has a whole team there, and they're really good. And their analysis shows it actually is really hard to do the Mark 4. I was initially, that's what I thought.
Starting point is 00:27:28 But then I started seeing that the people were saying that the timer, they also add entropy from the time. timer. And I started saying that that wasn't done at all correctly. And in fact, on the Mark 3, there is nothing from the timer. Actually, the timer value get read in, but it's basically irrelevant because one of the timers was not set up. Okay? So on the Mark 4, it was set up, and so you get some entry from the timer. And so that plus the actual, and this is a massive red flag. How do you improve it in the Mark 4 and not just totally fix it? Like, how the hell does that even happen. You said it again.
Starting point is 00:28:04 How do they improve the Mark 4 without fixing it? You know what I mean? How do you just get one, 32 bits in there instead of fixing the whole thing? Right, slightly better. How do you make it slightly better? Is that easily explained in the sense that I think, is it right that the Mark 4 had an extra secure element? Does that do something?
Starting point is 00:28:20 No. It was from, so the randomness from secure elements, I don't think, is not used in the Mark 3 in this pathway. The randomness from the secure elements was used in the Mark 4. Yeah. But once again, for some reason, this randomness is taken from it and passed through this thing called Yasmarang R&G, which doesn't allow much data into it, which is not a cryptographic, it's cool.
Starting point is 00:28:41 And so you only got 32 bits in there, which is like, what the heck? And so that's why you got 32 bits. It receded from these secure elements. But they have much more randoms than that in them, and you just pull out like this tiny, a little bit, and then it improves it. But it actually, in the end, like, it is much harder to do the Mark fours. You can do it, though.
Starting point is 00:29:01 And presumably those will happen. Like, there's plenty of compute out there in the world right now. Yeah, if it keeps going, like, you would think... I guess maybe everyone's moving their funds quicker. I think that's the thing. Because there are people moving it too fast, maybe if someone's lost their pin and they didn't write down their passphrase, like something... Some will be there for a while.
Starting point is 00:29:19 And in 10 years when GPUs are just like falling out of our ears, we'll be able to like find those funds. But it's pretty... It's not economical. I thought it was because... But only the Mark 3 is economic. to attack. I don't believe the Mark 4s are actually profitable to attack right now. Okay. Unless sailors putting it all his money on one of them and then it changes the average.
Starting point is 00:29:38 I don't think of you. One of the things that's so messed up about this situation is even if they'd have found the vulnerability or someone else in the community had, there was really nothing they could do. Like they would have had to put out a blog post, I imagine. I can't think of another way around it, saying these are not secure, you need to move your funds. And then it's basically a race against an attacker then. To find it. Yeah. I think you have to just literally call up every single person that you know. But they don't have the data on people. I mean, it turns out they managed to keep emails.
Starting point is 00:30:05 Every bit-kigner knows another bit-kiner and you just do word of mouth. Yeah. You word of mouth it for a while and don't tell anyone shady about it. That's the only way. I was originally thinking, like, and other people were thinking that because there was this weird thing with the serial number from the individual device got mixed into the randomness, that when you recover, you can sort of see part of the serial number, you actually can't.
Starting point is 00:30:29 So that was an initial thing that many of us thought we could keep these serial numbers, and then you could actually get people to make a video. Like, I've got this cold card and show the serial number, and you could actually give it back to them. Prove that you owned that. Yeah, but in the end, it's why people were telling people not to actually destroy them. Yeah, that's the reason why it doesn't really work. Kevin has convinced me that this was crap. And his article destroys the idea.
Starting point is 00:30:50 So you can burn the cold cards. There were lots of duplicates, right? Lots of cold cards have the same damn thing, the same damn number. I mean, that's right. I don't understand. It's called a serial number. Why is it? It's not serial.
Starting point is 00:31:01 Serial means one after the other anyway. It's such a mess. And one of the things, I was at the Bitcoin meetup in Brisbane last week. And obviously, entropy was the topic of the day and we're talking about it. And before this attack, I would imagine the vast majority of at least, like, I guess, part-time Bitcoin. People who just store their money in Bitcoin, they don't care about it. They're not listening to every Bitcoin podcast. Probably never even heard of entropy when it comes to, like, generating a private key.
Starting point is 00:31:27 And everyone at that meetup was convinced that everyone rolling dice is the only way forward. And I just can't accept that. Like, I think it's great. I think people should be able to generate their own entropy. I would never want to take that away from people. But you also can't expect this to scale to millions and millions and millions of people if everyone's doing 100 dice rolls. And I think there's also the problem that I know there was at least one person,
Starting point is 00:31:48 I'm not going to dox them, that was at that meetup who had set up a cold card Mark 3 and done dice rolls, but instead of actually rolling dice had just pressed random numbers. And like, so people are, are going to accidentally generate less secure private keys if they don't do this properly. And so I just, I don't know how we're meant to address this as Bitcoin is now, where it's like, generating your own entropy is great.
Starting point is 00:32:09 People should be able to do it, but we also need to accept that that's not going to be the case. Like, how good are actual proper random number generators on the Trezors, the ledges, the Bitters, like, all the other hardware wallets that are out there right now? I'd say they're fantastic. Actually, one of the things humans are good at is actually making these high precision,
Starting point is 00:32:27 microcontrollers and these instrumentations. You know, that's, we're not good at politics, economics, or any of these other things right now. We can damn cut a little silicon thing and, you know, make these little microelectronics, you know. So the randomness is good. You have to read the manual a bit on them still. But yeah, you can, I don't want to say you can trust them,
Starting point is 00:32:47 they function with overwhelming probability in your particular device. Now, does that mean what people are thinking is like, they're right. Why would I just trust, like, I've got this device, right? I've taken my funds off the exchange. So, because I don't want to have a trusted third party of custody of my money. And then I put it on this device, but then what's to stop those seed words I get from that device,
Starting point is 00:33:11 like living in an Excel spreadsheet on some guy's computer? Like, how do I fundamentally know that that's not the case? And the point is you do not. And that, so hardware wallets are trusted third parties. Unless you're dice rolling. Well, yeah, I mean, there's the nuance, right? And if they're doing it properly, which is the, yeah, this is one of the things we're concerned about is that because of the sort of how this one bug manifested, the sort of the lesson that most people have learned is that if you add your own entropy, then you're good. If you roll dice, you're good or add passphrase, you're good.
Starting point is 00:33:50 But like, it could have very well been the case that this, there could have been, you know, a very similar bug that, it just so happens that if you add dice rolls, maybe that sets your entropy to just being, like, you know, maybe a few dice rolls or something. It could have made it worse, right? Rolling dice could have made it worse. Some people suspect that Doc Hex was doing a malicious rug pull, right? I do not think so.
Starting point is 00:34:10 Mainly because of how, if I was to do that, you know, I wouldn't make the code so bad around the R&G. It's a weird strategy to like draw all this attention to how terrible that thing is just so they sort of notice the main, don't notice the main problem, right? And I think I've met the guy also and it's like, had a little conversation. It doesn't seem, didn't seem like it at the time. I found that whole theory hard to believe, although I'm not at the point where I'm willing to write anything off.
Starting point is 00:34:38 Yeah. Yeah, we should be sort of paranoid. Like, what if a psycho, this is one guy, right? He could have been a more psychopathic version of himself, right? And done this. And so all the dice rolling and all the thingies doesn't actually do anything in that situation. Right. choosing your own seed words and giving them to the device, how do you know then that the public keys and the addresses
Starting point is 00:35:02 are actually from those seed words? Yep. Right? It's more steps. And like you said, like Bitcoin spreads memetically, right? We give it to our friends. We see people we respect and they like Bitcoin and we want to be like them. And if you start saying now, this person I respect breaks the illusion and say, now get out your dice and we start doing all these wacky stuff. And we need a second device to verify the dice. It ruins the process of spread.
Starting point is 00:35:24 Bitcoin so you cannot actually be doing this. So in our product, we really thought about this. We had to think about a lot of things from the ground up because we used totally new cryptography. And one of the things we said is like, listen, we're not going to trust the device to generate randomness. I can say it does generate randomness. It does have a TRNG on it. It does get the randomness, but it's not the only randomness that goes into the public key. Okay. Every other architecture is just let's just take what that device says and that we say, okay, and there's the addresses and we just take what the device says. We don't take the device says, the device says, here's my public key that I want to use sort of thing. We say, okay, that's cool story and we're going to use it. We're going to randomize that before it goes on the chain.
Starting point is 00:36:08 That's the phone or like the app, right? It is doing that. So that was our solution. And it was very comfortable for us in this situation because we did, I did have a panic. I'm like, how deeply did I look at the T. actually, because I just trust that the manufacturer, you know, the APIs that they gave us, and like, how does it actually work? And I did some analysis and it turns out we're okay. Not totally, not, it's a little bit less than I thought it was, actually, but still way more than you need from the TRNG. But I was not panicking while investigating because I know.
Starting point is 00:36:41 It was never a single point of failure. It was never a single system. Exactly. So when you plug your devices into your phone, the phone is also mixing in randomness verifiably to that public key in it, the device cannot escape it. And so that's one other solution. But the thing is, that solution is only our product, and it's sort of a niche thing. It's very different.
Starting point is 00:37:03 We're in a position where we're rethinking everything, and we're having a lot of fun doing that. Not everyone is in a position where they want to go and join the next revolution, right? And so the problem is taking something like this is BIP 39, those seed words, the actual specification for those makes it very difficult for you to mix in randomness from multiple different sources, verifiably. So it's like one device produces that seed words thing, and no one can really get in the way of that and inspect it, because otherwise they'll know the secret, right?
Starting point is 00:37:35 So when we mix- So there's no way of actually proving your randomness. Yeah, it's like, here's, I mean, you can get the randomness yourself and say, here's the seed words, right? You can do that, you can choose your own seed words. But that doesn't mean that the ex-pub you give is those seed words either, right? So this is the difficulty thing.
Starting point is 00:37:52 When you have a malicious device, it can say, here's the public key, let's receive money to it, and you can say, no, I'm going to mix into that. Public keys, the public key is actually algebraic. You can add publiclies together. You cannot add BIP 39 entropys together, sort of thing. That's the issue. And so what people will suggest is either, like, yeah, you have to verify to multiple devices. You take the same seed words, you look at the Xpubs and multiple devices.
Starting point is 00:38:15 Okay, that does, that will work. You have to expose your seeds to multiple devices. to multiple devices then, but if you're very careful about it, and you're a one-time thing can be done. You know, I think the people who say just get a Linux laptop and forget about hardware wallets are not, you know, totally wrong in this kind of situation, right? Do you want to pay less in taxes and stack more Bitcoin?
Starting point is 00:38:35 Of course you do. Well, by mining Bitcoin with Blockware you can. Under section 168K of the US tax code, Bitcoin mining servers qualify for 100% bonus appreciation. This means every dollar you spend on miners can directly offset your income in a single year. And it's true for both business owners and W-2 earners. So if you have $100,000 in ordinary income,
Starting point is 00:38:54 you can purchase $100,000 in miners and potentially offset your tax liability entirely. Blockware's mining as a service does all the heavy lifting. They secure the rigs, they source the low-cost power, and they handle all the day-to-day maintenance. So you get to stack Bitcoin every single day while drastically shrinking your tax bill. Get started today at blockwheresolutions.com forward slash WBD
Starting point is 00:39:14 and use code WBD for $100 off your first miner. That's blockware solutions.com forward slash WBD. If you're already self-custody Bitcoin, you know the deal with hardware wallets, complex setups, clumsy interfaces and a seed phrase that can be lost, stolen or forgotten. Bitkey fixes that. BitKee's self-custody built for real life. It gives you an intuitive, easy-to-use wallet with no seed phrase to sweat over, and it has a strong recovery system and built inheritance for long-term peace of mind.
Starting point is 00:39:42 And BitKee's just had a massive upgrade. The new device now has a screen, so before you approve something, you can check it on the Bitkey itself, the transaction, the address, or any account changes. It's a big difference. You're not just trusting what's on your phone, you're seeing it for yourself on the device. It's simple, secure self-custody without the stress.
Starting point is 00:39:59 Go to bitkey.orgh. And use the code WBD to get 10% off the new Bitkey. That's bitkey. Dot world and use the code WBD. Every Bitcoiner eventually has to answer one question. If something happened to me, would my family know what to do? Could my wife or parents recover my Bitcoin? and would my children inherit the Bitcoin that I spent years stacking.
Starting point is 00:40:19 That's where Anchor Watch builds Bitcoin custody models to protect you and your family against real life, accidents, errors, kidnappings, and even your own death. Every Anchorage custody solution includes their inheritance protocol. Designed so when the unthinkable happens, your Bitcoin reaches the people you intended it for. Whether you're a self-custody expert or what multi-institutional support, your Bitcoin estate plan shouldn't be an afterthought.
Starting point is 00:40:42 Bitcoin is only generational wealth if it can actually be passed down, through the generations. So make sure they can access in the future what you've built today. Anchorwatch is your custody your way. Visit anchorwatch.com to get started. That's anchorwatch.com. It's hard though because I do understand those approaches and maybe if you look like if your goal is for like absolute perfect security, maybe they're the right way of doing it. But you also have to think about everyone in this side, like every Bitcoin or not everyone's going to do these things. So like obviously there'll be going to be people freaked out about everything that's happened over the last few weeks. In terms of the other major hardware wallets, do you think
Starting point is 00:41:19 there's any sort of huge red flags with any of them? Cool. Well, we've been focused on ourselves. We've not been focused on other people. I don't think this is a once in a lifetime one where the actual entry, like the thing on chain, or the address is on chain, you can just be discovered from a guy's laptop in his jackoff chair that's like totally, it's totally unbelievable that this happened. It's like, I still almost believe that it happened. Yeah, it's unbelievable.
Starting point is 00:41:46 So this will not happen again, ever. Except we already had this happen in Bitcoin, live Bitcoin. They actually did this some purpose, but that was another. That's another rabbit hole. They said the TR&Gs are not good enough, so we're not going to use them at all. And so people generated wallets, they're totally not random at all. And so, yeah. So I don't think the security of those other devices, I think everyone's going to be taking a hard look at them.
Starting point is 00:42:12 I think that the key point, that I would make at this point is like, are we gonna just fix this one, like, outlier, or just treat it as like a Black Swan event? We're gonna say, yeah, actually, we should not just get this device in the mail and put our life savings on some words that gave out. You know what I mean?
Starting point is 00:42:28 But we also should not roll dice and do also wacky stuff. You know, we should just like say, hey, you, cryptogic, like mixing randomness is actually one of the oldest problems in cryptography. There's this old, very old paper called coin flipping by telephone by Manuel Blum. It's like in 1970. It's like explaining how you can have a phone conversation
Starting point is 00:42:47 and flip a random coin. Collaboratively. Yeah, collaboratively. And both of you agree that the coin is random at the end. Right? And so there's a trick today. It's commitment schemes, use hash functions, things like that. It's very much a solved problem, okay?
Starting point is 00:43:05 But we don't do it in Bitcoin. We just don't do it in Bitcoin. So there's two things. Like, you're going to do all this dice rolling and interrogation of the device, right? It's like, I'm going to interrogate this thing. so much, making her air gap and all this stuff. But the other thing is I'm just going to get multiple devices, right?
Starting point is 00:43:23 So even if I don't really need multi-sig, I'm just going to get, do multi-vender, multi-sig. And so now I don't have to interrogate each device as much because one of the devices, or at least the majority of the devices will be okay. And these are two solutions, right? I think they are solutions. If I were to choose either one of them, if I really didn't have a reason to use single, you know, multi-sig, like multi-sig, I think is very important.
Starting point is 00:43:46 That's my whole company does that, right? We do it because we shouldn't have your money in your house. Not for randomness. Randomness is actually a very easy one to do. So I would, if I was like an everyday person, I would actually consider doing the cutting out of the seed words, getting a laptop. Filling them out of a hat, getting a laptop,
Starting point is 00:44:07 checking the X-Pub is correct, taking like some other device and putting it on there, checking they have the same addresses, clearing it off the laptop. But it's obviously unacceptable. You cannot spread Bitcoin that way. And the other thing we haven't even mentioned is like if you really want to have this system work
Starting point is 00:44:25 where you don't trust the device to generate randomness, you have to do this dice. If you really want to do it properly, you have to do this dice rolling every time you sign a transaction because the device also gets to choose a random number as a nonce. It's like a one-time throwaway random number.
Starting point is 00:44:42 And it's in this non-a-old. that if it's weak or malicious, it can leak your seed phrase. And so that people don't actually dice roll to generate these noncers. If they really want to do it properly, they check what's called deterministic noncers, that with the same private key and the same message, the transaction signatures will be the same. So they essentially, they get the transaction on two different devices, sign the same thing, and then compare the transaction signatures and check that, oh, actually these devices are being honest,
Starting point is 00:45:18 which is just crazy again. Like, you can't do this to spread Bitcoin. Totally. It might be the perfect solution if you're only worried about security, but if you're expecting 100 dice rolls to generate your seed and then 100 dice rolls every transaction, like the vast majority of people are never, ever going to do that. And the thing that I'm nervous about is, like,
Starting point is 00:45:38 this has been a real hit to single-sig. And I really like the simplicity of a single-sig wallet. And I know, obviously, if you generate your own entropy, then it doesn't really affect it anyway. But I do think the sort of just social blowback of this is going to be, everyone's going to move to Malteseeag collaborative custody, which are great. And people should use those, like, if they're storing, you know, their life savings in Bitcoin. But the simplicity of single-sig is awesome.
Starting point is 00:46:02 The sovereignty of it. I agree. So I used to be single-sig person, but then I realized that my entire life savings my house. my house. At some point it gets a bit scary. At some point you're like, my children are here and all my money is just over there or something and it's like, traveling. It's too much. But yeah, if you travel, if you are, if you're a digital nomad or whatever and you just, you reckon you can do it, you're in a safe environment. There's something very simple about this USB device or whatever that has a pin number and it's just all my money is there and no one can get it without physically getting to me.
Starting point is 00:46:36 I think it is right for some people. And yes, we have to somehow make it work. It's just not what our company does, but I'm hoping that some, maybe we can try and do it, I don't know. But I think that, like, listen, like, like, like I said, whenever someone, I always said, listen, our device, we don't let them generate their own randomness. Whether you even using one device, right?
Starting point is 00:47:00 Our device do not generate their own randoms by themselves. They mix it in. And you can use a single Frostnap device, and it will work. It just doesn't have a pin number. It's designed for geographic distribution, right? And I always said, listen, I mean, this is what we say, and this is important.
Starting point is 00:47:14 We think this is really important. This means we don't have to worry about our TRNG's being broken or any of that stuff, because we know that your phone is also mixing it in there. So it's very unlikely attacker control of your phone and everything else is broken, right? It's a really hard gate to get through, as Claude always says. But all these companies are fine.
Starting point is 00:47:31 You know, like, luckily, we have some great companies in Bitcoin, and you can pretty much just trust them to generate the thing for you. Yeah. It irritates me that we do that because you're so many easy ways to do that in cryptography. We don't have to do it. But you can just let them do it. And now I gave this advice to so many people when they're asking me about our product
Starting point is 00:47:48 and whether these is how important this fact is. And now, it's like a crucial fact. It's like bad minimum. It feels like a bare minimum. It feels like a bare minimum. Like why would you not be doing this? So that's where I'm at with that. I think that, listen, it is a black swan sort of thing.
Starting point is 00:48:03 All these other devices are probably okay. And I think the silver lining of this, like, it'd be easy to hear this conversation and be totally freaked out about the state of self-custy. But the silver lining is it's going to get much better on the back of this, I think. There's going to be more eyes on code. Like, people are... Maybe this wasn't an issue for any of the other companies, but it's only going to make it stronger, I think. Yeah. Yeah, the open source is important now.
Starting point is 00:48:25 Because now open source, the longer it's been alive, the harder that thing is to kill. Before, now, Colquard existed in this state of terrible code for a while, and now it cannot. It's just killed one of them, right? And so the longer these companies stay alive and keep their code open source, the more maturity you have in each of their product. Is that a double-edged sword? I think there's an interesting thing, actually, that also, like, it's not so much that it's the length of time that it's sort of, you know, withstood, you know, survived for.
Starting point is 00:48:58 But, you know, we saw this new model gets released, and then all of a sudden, overnight, it's no longer secure. It's very interesting for us because we haven't had these paid audits done, but we've had an equivalent level audit done to Coldcard with Kimi K3 now and these other... The audits are just out in the open now. Yeah, which is interesting. And, you know, I don't think it says that there's no value in human audits. I think, you know, having a good human auditor guide that LLM audit would be probably optimal.
Starting point is 00:49:30 but it's very interesting. Yeah, it is. And it's like, it's the open source thing, can it that be a double-edged sword? Because like if your source code is closed source, then the LMs can't pass through it in the same way, and they can't necessarily find those vulnerabilities. Yeah, I mean, though, I think the, I think we all agree that the level of trust you put in a close source thing is like, it's a bit, the rug pull could be at any moment. Like if Doc X or whatever, he's malicious and he's working at ledger or whatever, like, it's not really acceptable.
Starting point is 00:50:05 It doesn't solve the problem, but does it make it harder to exploit the vulnerability? Yes. I think so, yeah. Yeah, it does make it a bit harder because you're going to, unless you can get, you have to dump. Because at some point you can maybe dump, like the firmware or something, you know, that's on a ledger. Because you have the firmware updates and all that stuff. Like, I don't know. That would be interesting, right?
Starting point is 00:50:24 Because some people are taking it and going to the machine code and decompiling things, right? taking old, you know, PlayStation games they always loved and, like, decompile them, putting new things in it because the LMs are so good at that. And what if, I wonder, I wonder if Ledger, that would be a technical question, can ledger, does it literally encrypt their firmware? Because, I mean, is maybe like, compiled binaries that you can't see the source code of is the same as, you know, or open source in the end. So that's the question.
Starting point is 00:50:54 Interesting. But you think open source is still the way to be doing all of this? Yes, I think so. I think that the Darwinian selection process now is probably the right one. It probably also means you should probably centralize more on libraries and things. One of the interesting thing about multi-vender, multi-sig and people saying, yeah, you know, but the thing is, do you really want everyone to be using a different software stack and, like, bugs over here, bugs over there?
Starting point is 00:51:19 Like, everyone agrees sort. I think everyone agrees that LibSecP266-1 is really good and that everyone should be using that. In fact, moving over to that was part of what Cole Card was doing when they missed everything up. So if we agree that well-ordered single libraries are good, then probably people should just use those, right? So having all these different implementations and different things is maybe not so good. I think the seed sign of people are not totally wrong, right? in creating like a sort of a standard thing that you can create yourself. It's all open source.
Starting point is 00:51:57 I don't agree with the fact that you can just swap out an SD card and steal everyone's money with, you know, with Dark Skippy. But, you know, you can see the idea there, right? The idea is correct. It just so happens that unfortunately due to the way, you know, signatures work and stuff like that, you're trusting that device. So I think that probably more of that, I think standardization on how the hardware should be, more open hardware and more that those kind of things is probably the way things are going. And to be fair, like the companies in the space are pretty good with that stuff that's open source
Starting point is 00:52:27 hardware. You can, some people can, you can create your own jades. I think you can create your own treasurers as well if you really want to. And so you have companies that let you just create their thing. It's pretty difficult, so you can probably just buy it from them. It's sort of the business model. And it's probably not like a huge business also. Like we're in the business and we never thought really it was going to be an amazing business. because the number of UTX owners is not going to grow incredibly, right?
Starting point is 00:52:50 My 2x, 3x, 5X or something. But maybe even 10x, but that's not exponential growth. Like, no one's looking at that. It's like, I need to invest in that, right? So probably consolidates and gets a bit more boring around more homogenous software packages and things that are more well-ordinated. I want my hardware to be boring.
Starting point is 00:53:09 That's everything I need. I did a show with the C-Signer guy maybe, I don't know, over a year ago probably. That has aged like fine wine. Like, one of the things he was calling out was R&G on things like cold card. And it wasn't because he, like, had inside knowledge on it or anything. He was just saying, these are the problems you have. And seed signer has always been one that I've...
Starting point is 00:53:29 I've never really used a seed sign. I've played around with a seed signer. The thing I don't like is having to have my private key always there to actually sign a transaction. But I don't know, this makes me rethink a lot of things. Yeah, I mean, I think a lot of people forget, though, when they analyze it. Like, I want my pin number. And then they have the piece of words there without any pin.
Starting point is 00:53:47 Yeah, yeah. Or they put a passphrase on the words then because they're thinking about it. And then they lose the passphrase and they lose all their money. Back it up. It's just like, oh, this, the trade, I think you really like... Simplicity and boring sounds great. Yeah, with Frostnet, we go, we'd really take it to the most boring extent. Our devices do not even have pin numbers.
Starting point is 00:54:04 Your only way of getting security is to put them in different locations. So it's multi-sig pretty much only. And there's no pin numbers, there's no pass-rays on the thing. There's no descriptor backups either. So that's most multi-sig solutions, you actually have to backup some funny digital file. And if you don't have that, you lose all your money. We don't have that. So you just need two out of the three backups or whatever, whatever threshold and number you choose.
Starting point is 00:54:27 And you'll get all the money back and it's all super boring. It's very, like, it is a risk. The user has a serious job to do, right? To make sure their devices and those backups are not obtained by anyone else. It usually is a job you have to do anyway. But it is a serious job. There is no pin numbers in those device. Those backups are probably with that device.
Starting point is 00:54:48 But for me, once you do that job, it's like really comfy. Right. Because there's nothing I need to remember. I know my wife can get them because there's nothing she needs to remember. She just knows, she has to figure out where they... She knows the people who have them. She knows how to contact them. Anything should happen to me.
Starting point is 00:55:05 There's nothing that can... There's nothing really that can go wrong in this kind of set up. It's really... I struggle to think about the things that can go. wrong, right? That's the main thing that go wrong is that someone, you know, goes around and finds them, right? And so it's really just my job to make sure how well-disposed they are. Exactly. That's the, I have one job. Maybe back on the community, like the ecosystem damage for a minute, I think it's, you know, I've seen some people compare it to say they're comparing
Starting point is 00:55:32 like the magnitude of the theft. They're saying, oh, you know, it's only a thousand Bitcoin, look at Mount Gawks or look at FDX. Yeah. I think, you know, these are completely different populations of people. Like the FDX people, you know, it's like, people in their 20s, like degenerate, long, like, you know, gambling shit. You know, they go from 1K to like 100K and then they lose it. Okay. The Bitcoiners, these are people all in on Bitcoin. You know, they're with families. Like, they're saving all their money in Bitcoin and they're doing all the right things. They're self-custying it. And then overnight is this, is gone. Yep. And it's with like probably what was perceived as the most sort of hardcore Bitcoin
Starting point is 00:56:09 a solution. Like this was, this was. the gold standard. Yeah. Bitcoin only. And that being rugged, I think, is going to have ramifications for quite a long time. And I just, the thing that I'm really nervous about is this going to push people to use custodians, which it will already have done. Like, there's certainly been people that have moved Bitcoin off, cold cards to, you know.
Starting point is 00:56:27 Definitely. A river, a swan, a coin base, whoever. And even if those companies are like semi, like, are reasonable solutions, it's not what we want Bitcoin to be. No, not at all. And that's the problem. Yeah. On that point, like, it is really sad because I look at the chart.
Starting point is 00:56:44 Because I can see when, like, when people are buying Mark 3s with this corrupted firmware. Yeah. And you can see the money starting to go into the insecure wallets. And then you can see the Mark 4 come out. Yeah. But the money keeps going up in the Mark 3s because people are still stacking. They're doing what they've been told, right, to stack sats. And they, like, more than, like, double the amount of Bitcoin in their compromised Mark 3s, even after the Mark 4 is out.
Starting point is 00:57:08 So it's, yeah, that's that's, that's, that's. That bit is very sad. Years spent, stacking on thing, and it's gone. Probably the only thing that saved me, because I had a Mark 3 before I had the Mark 4, is that I'm a nerd for light devices. So I bought the new one. Like, that's the only thing that really saved me.
Starting point is 00:57:25 Otherwise, I would have been one of those people. But it could have been the other way around. It could have been the Mark 4 had the problem. It's just so random, right? Before we go on to the Frostnap devices, can we talk a little bit about Dark Skippy? Because I remember this coming up, but I'd never followed it very closely. Like, tell me what that attack was.
Starting point is 00:57:45 It was an improvement on an existing class of attacks where a malicious device can choose these random noncers it uses during signing. And previously it was thought in the literature, you know, maybe a malicious device can leak its seed phrase over like maybe 50 transactions. Like maybe each signature has like one or two bytes. And if you're the attacker, you can look on chain and you can sort of grab all these two bytes. And if you get enough of them, you get the seed phrase. But in a sort of a game of, I guess, cryptographer, sort of code golf, Lloyd and Robin Linus, we're going back and forth on Twitter a few years ago.
Starting point is 00:58:28 And together, they essentially figured out you can do it in just two signatures. So one transaction is enough for a malicious device. to leak your seed phrase inside the signature itself. And this is any device? Any device. Yeah. That's allowed to choose its own random number for its nonce and that isn't, you know, that it's acting maliciously and you don't, you don't check that it's doing deterministic nonses or you don't, or it's not doing an anti-X-fill protocol like Jade, Bitbox, or Frostnap. Yeah.
Starting point is 00:59:07 So this is why Nick is saying, you know, you probably need a right. roll random numbers during signatures as well. There's no API to do that. It would be totally insane to roll random numbers, but that's the issue. Is you can do everything, make sure your seed is set up totally trustlessly, and make sure everything's correct. But if I take your seed signer or a cold card and I get the malicious firmware on there,
Starting point is 00:59:27 like that's still a trusted party. How would you get the malicious firmware on there? On a seed signer, you literally just take the SD card out and you put a different, you flash it and you put the SD card in. You have to have physical access to the nice. Yeah, so it's like you get physical access to the seed signer. Or a much better retirement attack would be to do Dark Skippy, probably. If you were a malicious manufacturer, it'd be a much better, rather than making weak
Starting point is 00:59:51 randomness for the seed phrase, it might be a better attack just to say on, okay, if this, if this transaction is spending over one Bitcoin, just fiddle with the nonceal a little bit bit and exfiltrate the whole seed phrase. And it's completely covert, pretty much, unless they're signing on a second device. As the manufacturer is very trivial to do it. I guess if you want to try and hide it a bit, you want to ship it with them if they update firmware or maybe you want to, you can still do it.
Starting point is 01:00:20 Even if they try and update firmware, there's nothing really you can do. Like hardware is just a trusted party. It's a black box. You can't really penetrate without x-rays or something to figure out what it really, really is doing. But yeah, so the problem is it doesn't matter what you do. It ends up being this trusted, third party and that's the that's the and it doesn't matter how many secure elements there are right
Starting point is 01:00:43 because what i can do is if i can change the firmware and even if i'm uh like not the company i'm an attacker i don't have to go through all these very secure chips i can just go through the main chip right the main chip is enough to uh change if i can change the firmware and this actually ledger demonstrated this on for what it's worth on treasor they went and they changed was able to change the firmware of the treasor with the secure element on it and so now and it doesn't do anything. I remember them extracting keys from a treasurer. Is this how they did it?
Starting point is 01:01:12 This is a more reason one. They didn't extract keys. They just changed the firmware. Okay. So they got rid of the secure boot thing and they just were able to change the firmware. And so what this means is, yeah, you can, what this attack looks like is someone, crazy person from Ledger comes in. They take your treasor while you're on holiday or whatever and they go into lab a bit and
Starting point is 01:01:30 then they put it right back where it was. They still don't know the secret key at this point, right? They don't know anything secret on it. And then, but you put your pin number and you sign something and you sign something. and then that gets posted the blockchain, and that signature has the data in it. Right. So this is the kind of thing, it's very, very difficult.
Starting point is 01:01:46 Stop it. But this is way further out on the risk curve that people should be thinking about because they have to have actual access to your device. With the devices that you plug into your computer, could it be loaded by malicious firmware on the computer? No, no, you need a malicious firmware on the device. But what I'm saying is, like, if it's not an air gap device
Starting point is 01:02:04 and you're plugging it in, could it then be transferred to the device? Some device, like most devices, they, like, I'm talking about not our device. Most devices need a pin number. Yeah. Before you can do a firmware upgrade. So it's kind of like you're in the security model where you kind of just do it by itself. But yeah, I mean, if it can be exploited and it's not signed firmware and you really don't know what you're doing, yeah. So like, same with Seed sign like, you could just put an SD card from your computer, you think it's all good and then bam, it's gone. Yeah.
Starting point is 01:02:30 But this is like, this isn't actually going to, we're not going to see this in the wild and the large scale. We hope not. Yeah. I mean, now the clankers exist. Like, you can just point it at darkskippy.com and tell it to do it. Right. And you could have your actual device. Or they could release maybe a firmware of, you know, a device that doesn't check,
Starting point is 01:02:50 you know, that it's signed by a manufacturer. They make a fake website or a fake GitHub and say, here, download the latest release. I see, okay. People download that. And then they're trusting the device to generate that randomness. Yeah, it's cold card included, they will check this. They will not be able to just install random firmware. Yeah.
Starting point is 01:03:07 There's no fud there. Like, they check the secure boot. Although on call call mark three, you could, because it's a bug. But other ones, you can't. And so you would really be, it's really more the point about this is, you're trusting the manufacturer. Doesn't matter if you do all this stuff yourself, you're trusting the manufacturer, just deal with that reality, right?
Starting point is 01:03:25 I'm trying not to totally freak people out here. I don't think you're doing a good job at that. Some people think Doc X was like a malicious guy, and he was playing. So this, you could have done Doc Skippy, right? It would have been much better to do dark Skippy in some ways than what he did, which was like, I mean, if he was, it was like incredible galaxy brain, you know, attack. Because it is, yeah, so messy and so, so it doesn't look at all like someone was doing it maliciously. It looks totally like a mistake. And so I guess if you're very clever, you can make everything look totally like a mistake.
Starting point is 01:03:56 Okay, let's talk about Frostnap. Can I see the device? Yeah, of course. So I don't think I've ever actually seen these in person. So tell me how these work. Let me, I want to... Yeah, open a few up, yeah. I want to show the camera how they...
Starting point is 01:04:12 These ones... I'm not the first person to make the joke, but it's the human centipede of hardware wallets. You love it or you hate it. Yeah, you can daisy chain them together. You daisy chain them. Tell me how they work. Yeah, so you just, you want to make a multi-signature wallet. You just connect a few into them like that and then download the app on your phone or your laptop. click create a wallet, you know, give each device a name.
Starting point is 01:04:36 And then it'll interactively generate a group private key that never lives on any one device. So this is that the phone actually contributes entropy during this step, which is what Lloyd was talking about before. And at the end of this, what's called a distributed key generation, you have, each device has sort of a share of this, or a key to this wallet, and you need, say, two out of three to spend the money. And so from there, you would leave them in different secure locations. Each device has its own backup. So underneath those tins is a backup recovery card. And then, yeah, you would leave them in secure locations. And when you want to sign,
Starting point is 01:05:22 you visit them one at a time. So you... Oh, so you don't need them all together at the same time? Yeah. That's cool. So you would make your transaction on your phone or your laptop and then pick which devices you're going to go and sign on and yeah, visit them and get those signatures. The really cool thing is yeah, it's using threshold signatures. It's not using like script multi-sig. This has a bunch of downstream benefits.
Starting point is 01:05:50 Like it looks like a single-sig on chain, which is really nice. Like you know, one can tell you're using a multi-sig. What's the benefit of that? Well, it's kind of, it's a very strange feeling when you pay someone in Bitcoin from a multi-signature and you reveal that they can look your transaction up on chain and say, oh, Nick's using a four out of five or is using a three out of five. And that isn't like, you shouldn't have to reveal this information when you're spending. Because you're just giving away something about your setup. It's your security setup. Yeah. It's a bit crazy. That's just one of many, many issues with it. Like, there's the privacy heuristics on chain are. you know, much more easier to do when there's, you know, this script is very easy to follow.
Starting point is 01:06:31 And this uses Frost, which I don't really know what it is. Can you tell me about Frost? Yeah. So, it's... Maybe some people heard Shemir's Secret Sharing. Or maybe like one in three people listening to them. Shemir Shik secret sharing. Which essentially where you like break a private key up into three pieces and spread them. Yeah. And two out of three of them can spend or whatever you choose, right? Trezor, for example, does this for backups. You can do that. I don't think many people do it, but it's a cool feature. I think Ledger can do that as well, right?
Starting point is 01:06:58 There was a, that was the backdoor thing that everyone was upset with them about. Which I don't think it was actually a back door, but... No, but it wasn't a real back door. It was opted, right? So it wasn't like instant backdoor. But yeah, they would split it up across different places. And so same tech. I mean, it's the same tech that is used in Coinbase custody to secure Michael Saylor's funds.
Starting point is 01:07:20 So different computers have different shares of the key. Yep. And you need three, you need to corrupt, like, three out of five of them or whatever to actually steal the money, right? So one location is not going to be enough. And so the way it works is, yeah, you mathematically split up the secret key. And then our devices, when they sign, they don't give a signature, actually. They give a Shemir secret share of a signature.
Starting point is 01:07:44 Okay. And then the phone is actually taking those Shemir secret chairs of the signature and turning them back into an actual signature. And that goes on chain. That's why there's one public key and one signature. Now, the real, like Nick mentioned several of the benefits, but the real killer benefit for me, like the life-changing benefit, is there is no descriptor backup.
Starting point is 01:08:02 So you take that footgun out of the equation. Yes. That's what scared me off doing script multisig. Like when I learned about, you know, I was fully ready to go script multisig for my own, you know, setup. And then I learned about this descriptor backup thing on like a Bitcoin stack exchange, like, you know, post. And I'm like, in no way am I doing this. Like I'd never heard about it before. It scared me senseless.
Starting point is 01:08:25 It was terrifying. So I just couldn't imagine my wife with this thing. Right? Like this extradive information, like Frost snap, what it really is, it's what Maltisig, you think multi-sig is. Right? It's got multiple keys and any two out of three of them can spend the money or three out of five, whatever you choose, and there is no if so buts.
Starting point is 01:08:47 That's basically it, right? So that's the key feature of it. You know, multi-sig and when you have different hardwaters, you know, when you have different hard wallets, you know, multi-manufactured, it's like, it's complicated because of that. There's different hardware walls you have to learn, but that thing where you have this possibly, like, people want to move to that because of the cold card thing, right? And yes, now you've, it does do that. So it does get rid of this entropy, buggy entropy on the device problem in the sense that
Starting point is 01:09:16 two out of three devices would have to be buggy, right? But it adds this thing, this other way of losing money. So you got to, when you're thinking about attackers, you always have to think about what does the attacker want you to do? Right? And there's one attacker that, Tim, you know, Wizard of Oz, he, or BTC Shelling Point, no, BTC Shelling Point, right? He calls it the fuck-up fairy.
Starting point is 01:09:36 Yep. Right? You always got to think about the fuck-up ferry and you've got to think about the actual attackers. And so we, in Frostnap, we think, like, the fuck-up ferry is not super happy that you're going on to the Frostnap because although it's a new company, it's new technology, and the fuck-up ferry might find something in there. at least the backup situation, you know, is totally pristine.
Starting point is 01:09:58 It's like, you got two out of three and that's it. You got all the money back, you're good. And there's nothing else that needs to be backed up. And the thing that I always said about self-custody, which is not aged well, is that like, the most likely way you're gonna lose funds is by your own fuck up. Yeah. And at the same time, I would have told anyone that asked me if cold car was good, I would have said, yes, it's good.
Starting point is 01:10:17 So, like, clearly that didn't age very well. And no one fucked up who, like, those people didn't fuck up. That's what I mean, yeah. Yeah, exactly. They did everything right. But I still think that's probably the way that most people will lose Bitcoin. It's not like a nation-state attack. That's not what's gonna get most people. It is the fuck-up.
Starting point is 01:10:31 So taking that away is awesome. Yeah, but also, also, if you have all your life savings in Bitcoin, don't leave it all in your house. Yes. Spending five minutes. Although the fuck-up ferry may come for you. Like, there are actual people doing this now, like people who are focused,
Starting point is 01:10:49 criminals who are focused just on this. It's come down a bit since the price has gone down. down. But their skills are there. They know what they're doing now. And they know how to target and they get information and they know how to do it. I think this is a good time to do a little bit of a one I want. Because I'm sure there's someone listening to this that's like, my life savings is in my house. Yeah. Like what would be your sort of, I know it's different for everyone, but what would be a ideal situation for someone to actually, like, where should people be storing the private keys? Oh, interesting. You want, having, yeah, go ahead. A good, like having, if you start, if you're thinking about multi-sig, having, having,
Starting point is 01:11:23 one key, at least one key, in a place where you have to speak to someone or if there's like office hours, that's a really good one. Because like if someone comes to you in the middle of the night and you say, well, you're going to have to take me to this person between nine to five. Like that really throws them out of their, you know, their comfort zone in carrying off the attack. Yeah. But some of a much more risky situation. Like Nick said, I think like you can have a, what we found, okay, is that when we study the data is that the criminals in when people have this thing where it's far away okay multiple if it's in multiple flights you're rock solid but of course COVID or
Starting point is 01:12:01 whatever you know World War III and then you're really in trouble so yeah if you're trying to predict things that people think like putting it far away one common one common one is the holiday home right wealthy person has lots of Bitcoin they put it in their holiday homes a couple hours away that is in practice not worked they actually will just drive you yeah to the holiday home yeah it's much better to have it with your accountant lawyer or whatever down the street who's only open 9 to 5 and is very, you know, ein's fide rye with how they operate things, have, you know, security, have a safe or whatever and have it with them. Even your friend
Starting point is 01:12:35 who's an apartment in a security building, you have to like dial up, you know, to get into the building and go up a lift where you might encounter other people. Lots of cameras. And yeah. The attackers don't want to do that stuff usually. The thing that scares me about is like, as someone who's like somewhat known in Bitcoin, like if one of these attacks happened, someone could grab me off the street and say, give me the Bitcoin, and I could be like, I can't, and you still might get fucking killed. Like, it's a really horrible situation. Yes.
Starting point is 01:13:04 Though it doesn't like, people say that, but when I look at the data, it doesn't happen that, like, people randomly killing people because they had Bitcoin and told it- Or might get finger chopped off. That one, yeah, so that does happen in the kidnapping case, right? In the kidnapping cases, kidnapping is a separate situation. And it's a really interesting situation. And I've been reading about it and I super want to come up with a solution with it. And I want to get it, let's be fully honest, Frostnap doesn't help you with kidnapping.
Starting point is 01:13:34 Yeah. If someone... Nothing does. Yeah. Well, maybe I'm not... And watch insurance. That's a spicy... Does it.
Starting point is 01:13:42 Yes. Okay, does it. Okay. I think it does, because if that in that scenario, you send them all your Bitcoin. Yes. And sure you have price risk before you get paid out by your insurance. Right. This is why when I was reading a book on kidnapping, written by a guy who's, you know, does lots of kidnapping stuff. It's to teach negotiators. Like, one of the risk factors, one of the biggest risk factors in these kind of kidnappings that happen in Middle East or whatever, like a guy working in an oil rig or whatever.
Starting point is 01:14:11 They want to take the guy who has the insurance, right? And so if they know you have insurance, you become the number one target. Because, yeah, there's no reason. They just got to pay it out. And so actually, the insurance, probably with Anchor Watch, but I would double-check with Wob, you can't disclose, you have that plan. Probably not, I don't know. Well, you can't get outside the US, so that's my disclosure. I do not have it, don't kid. Oh, you can't get outside the US.
Starting point is 01:14:35 Okay. I wonder if it protects you if you go abroad, but the key thing is, yeah, you can't disclose it, but the really good thing about it, the insurance, is it not the bit where they pay you back, but the bit where they do the negotiation for you. That's a thing you can't technically solve. That is a real skill. I don't know if you get the message on WhatsApp or whatever, how you say things is just so critically important.
Starting point is 01:15:03 And how you use whatever leverage you have is just so critically important for the safety of the person and for not giving them all your money. That's what I'd say. So that's what I'm really interested in is how can you provide that expertise to people without putting them in a situation where they say, yeah, you got insurance, I was just, because then the attackers get more money and Bitcoin, they keep doing it. Right? And that's the other thing. You don't want to, you want to make sure they get as little money as possible. But you can't really do it yourself. You can't roll your own hostage negotiation system, unfortunately.
Starting point is 01:15:38 It's not DIY. This has been a bit of a black bill, this episode. I mean, if we all, if we all get on, you know, strong multi-sig setups, there'll be no more like low-hanging, and the attackers will just be like, oh, we're gonna go find something else to do. Right now, the low-hanging fruit is just people have all their money in the house. If you're doing physical attacks, it's just in the house. And you just figure that out, you figure out where they live,
Starting point is 01:16:01 and you do a home invasion style thing. And it works very often. It works very often, especially if they're prepared. Often the guy who's actually handling the money is remote. Right? And they're talking to them on the AirPods or whatever, and telling them everything. They're looking up everything. You have to give them your phone first thing,
Starting point is 01:16:17 and get all the passwords for everything. for everything, they're in your email, looking at all the exchange you signed up to, you're logging into them, you know, just like doing a quick audit on you. So keep that in mind. That is the situation that's the most experienced crews do put you in and you will not be able to like pretend like you have some, oh, these my decoy C words or whatever. That kind of stuff is not going to work. That's always been my problem with decoy wallets.
Starting point is 01:16:42 It's like, again, none of this stops you get your fingers chopped off and your teeth pulled out. And like, it's... Might make it worse. Oh, it can make it. can encourage them to do it because now you've started deceiving them, right? You want them to think you're super cooperative. That's my only advice.
Starting point is 01:16:55 Just telling straight truth. Just be cooperative. Yeah. And the best thing to do is not have it in your house so you can be like, yes, let's go see my accountant tomorrow at 9 a.m. sharp, you know, about this the problem. Or let's call him now and let's hope that he doesn't call the police. One thing is that they don't want the police called on them when they're in your house. That's the difference between kidnapping.
Starting point is 01:17:16 In kidnapping, they're going to pretend, like, they're going to expect that you're going to call someone, right? But when they're in your house, like any little trigger or whatever, someone's suspicious of something, they're doing a, they're practically doing a kidnapping, but they're in your house. And that's not where they want to be. They're in an environment they're in control, and they could just get surrounded and go to jail for a very long time of getting no money. So anything that can trigger someone coming to check on you is good in that situation. Well, I'm terrified. But it's not a problem to the next bull market, actually. So it's a good problem. This is the benefit of the market.
Starting point is 01:17:49 Can relax for a while. So with these, this is a bit of a gate shift, with these devices, I can't use them on my iPhone, right? Not yet. Not yet. Is that coming? We're working on it. It can't use the same hardware. Okay.
Starting point is 01:18:03 So we're working on a new edition at some point in the future. And that's just because Apple locked down the U.S. E.T. If they even let us get into the app store and stuff. Yes. We believe that they will. You know, you never know. They might ban all Bitcoin wallets. by the time that we get there.
Starting point is 01:18:20 I would not pull that out of the equation. Exactly. So, yeah. But like, I could use these like with my MacBook. Yeah. Yeah. Yeah. Awesome. Android, Windows and Linux. And Android, so Android phones you can do with, just not the iPhone. Okay. Cool. And is that because you can side load apps?
Starting point is 01:18:35 Or does... We're in the Play Store as well. It's just using the USB port is a lot less restricted on Android. And what about when they all get rid of the USB port? What do you do then? Oh, are they going to get rid of the USB port? At some point, I'm sure. It's all going to be wireless charging. I'm sure. We'll have to do NFC or something.
Starting point is 01:18:50 We'll figure it out. This is the first time hearing of this. No, I have no news, but it's the way we're going, surely. And so, like, obviously, everyone cares about air gap devices, and these are not air gap. Yes. You plug these in. Is there any risk in that? We don't think so. And I'll be one to admit that I was, before I got into these deep conversations with Lloyd, I was sort of an air gaping proponent. Like, to me, it felt like something that was, you know, it felt like it was adding security, right? There's the communication has to like go through this sort of this hop before it
Starting point is 01:19:23 gets to the device. But Dark Skippy is one of the good examples that like it doesn't actually matter so much. Like the communication, the information has to flow regardless. Whether it's through SD card, a QR code, a USB serial, there's always got to be some communication that flows. And what really matters is does the firmware under the device, like does it handle that communication securely. And we think we've done a really good job at that by using, you know, solid programming languages and taking the time to do things really carefully.
Starting point is 01:19:59 But you totally understand the intuition, right? You don't want to delve into all these topics, so you're like, if it's not connected to the thing, then it can't hack that thing, can't hack that other thing. And actually, in practice, that has been true. People have plugged in had USB protocols. I can think of Trezor, Bitbox, I think, maybe even Jade. Like, they all had some kind of thing where they rolled their own decoder and see.
Starting point is 01:20:29 And when they're reading stuff off the wire, it had a buffer overflow or something. It didn't do the code quite correctly. And you could execute code on the device. And so the theory is that this is actually harder to do via images, QR codes. Which I think is not true. This is actually why I was looking at the cold card firmware in the actual first place. My initial prompts, it was like eight weeks ago now, the reason I started looking into it was I wanted to find a memory bug in animated QR codes. I wanted to find something that's sort of demonstrated that actually, you know, this air gaping with animated QR codes is really no different to doing communication over serial, like over the USB.
Starting point is 01:21:12 No one is like, you know, inspecting these animated QR codes and like, you know, checking it all. And even if you did, you know, there could be stuff covertly going through that anyway. Yes. But in practice, we can find anything. And in practice, like, these companies have been owned by the USB. But it's actually, it's a street, it's not a technical phenomenon. It's a strange social phenomenon. An engineer gets the job. Okay, we have to talk over USB.
Starting point is 01:21:35 There's so many different ways to do it. You can make a mistake. With QR codes is like very one way to do it. And one guy has written that code correctly. Right? So it's like, and everyone uses that thing. And so that for some reason actually works. So the much simpler thing is just to talk over a wire, but everyone goofs that up.
Starting point is 01:21:53 And so the main, it's really a social engineering thing, not really a technical thing. And so when we're looking at it, we use the Rust programming language. So this means you would not be able to do that kind of thing where you just send crazy bits over and it like starts taking control over the thing, which can happen if you see. and C is what the cold card was trying to fiddle together with Python. We think that you should not use Python and C mangled together. Just use rust. And then you get rid of all these possible errors with memory and corruption. And so this idea that you're going to plug your device in and it's going to become corrupted by the laptop or something,
Starting point is 01:22:31 sort of goes out the window just at that level. That's what we bank on, at least. So we're all fucked and we should buy the ETF. Yes, ETF will hopefully be custody by Frost Naps. I love it. This has been awesome. This has been a real deep dive. I think there's a lot of value in that.
Starting point is 01:22:52 Thank you, guys. We're off to the Bitcoin meet up in Sydney. Let's go. You've got to do the same thing all over again. Yes. All right. Thank you, guys. Thanks very much, Danny.
Starting point is 01:23:03 Thanks very much. That was so good.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.