Loading summary
A
Ultimately, the game is fundamentally changed and most people don't know it. They're playing a different game. And what I mean by that is somewhere across the past 24 months, as the price of Bitcoin got into the 100k mark and six figures and we'll continue, we'll get back there at that same time. It was a perfect storm of AI starting to proliferate and the cost of computing intelligence to go down. So it reduces the cost of any kind of attacks, whether they're social, whether they're digital, whether they're physical. And people are not prepared for that. And they're still playing the game from 2012, that I can put this thing on a hardware device in a seed phrase and a passphrase and I'll be okay. And there's two aspects. There's a physical aspect which most people in the meat space now know. Bitcoin's valuable and will go find you for it. When it was a pet project in 2012, there's very few people are going to fly across the world to go find you now. They will. And at the same time, AI is proliferating and there's more of a bounty to throw compute and there's more of an attack surface. That's the scary part with of lot a all of this, what you're telling
B
me is that music is about to stop and we're going to be left holding the biggest bag of odorous exc ever assembled in the history of D. 1974-1987-9297-2000, whatever we want to call this. It's all just the same thing over and over. We can't help ourselves.
C
I say when we sell. I say when we sell.
D
Gentlemen, what's going on? It's been a busy morning. It's been a sad morning for for many people and a hectic morning.
A
Tired. I don't know how Brian I think the last message we sent I was already almost two here so it was three there. But yeah, tired and appreciate you guys jumping on so we can at least just share the latest because it's important a lot of people don't spend time on Twitter or have access to may newsletter sub so anybody that gets this in the pod feed they can at least the uprise of what's going on at the latest.
C
Yeah, crazy 12 hours or so. Sympathy goes out to everyone that's affected by this. We'll go through some of the details and talk about what action items people can take at this point, how to think about people's Setup going forward and just kind of give people some clarity around all this stuff.
D
Yeah, that sounds good. So for those who are unaware, I think a lot of the listeners will be kind of keyed into a degree on what's been going on. But there was an exploit with ColdCard and what we're going to be covering today will be what the news was, what happened, why did it happen, who was impacted. For those of you who are not impacted, what does it mean for you just in terms of navigating custody now and then? I also want to talk about like what are the implications for this as an industry? Right. Because self custody has long been kind of the darling. It's been the standard, not your keys, not your coins. People have naturally shied away from exchanges and counterparty risk. But now you hear a lot of people interested in going back to exchanges, even going considering ETFs. And so we're going to talk about all of this. We're also going to talk about multi institution custody. Our, our framing how we think about custody as a business and ultimately why there is no impact to ourselves. We store our personal wealth in the solution, but also our clients as well. So Brian, I'm going to pull up the piece to start here because I know you spent a lot of time and to Michael's point, late last night getting this ready to be shipped out this morning so people could be keyed in on what is actually happening. So this is titled the cold card exploit explained is your bitcoin safe? So Brian, please, if you could just very high level, just share what is the news first like for those who are totally oblivious to the news, what was the news?
C
Yeah, so to just walk through a few points here. So Initially around almost 600 bitcoin, $38 million was swept or stolen from 500 wallets in a very short amount of time. Block security team later identified that that number has basically been growing since then. So unclear exactly what the number is at this point, but at least over a thousand bitcoin that have been stolen or swept through this process. And effectively, you know, at a very high level someone was able to find a bug in ColdCard's firmware that effectively defaulted the random number generation to something that was not nearly random enough at a very high level. And so when people were generating seeds on device, so not rolling their own entropy effectively, they were just trusting the device to create their seed. It was basically saying that it was random enough, but it was actually internally defaulting to something that was not nearly random enough. This was present for basically five years, since 2021. And basically no one saw it. And what is being reported is effectively the original attacker allegedly used an AI model to find this exploit and then began exploiting it. And the difficulty here is that that exploit is now out in the wild effectively. So it has branched beyond just that original attacker. And the original attacker frankly seems to have not been that sophisticated in terms of the amount of compute they were using. And so this thing could escalate. And so initially Coinkite, the company behind Coldcard last night was reporting that it was only the MK3 model that was going to be affected and that MK4 and later models were not affected. Block researchers put out their own report a couple hours after that, basically saying no, that's not exactly true. And so over, over this past evening, early this morning, Coinkite sort of revised what they originally said and aligned with what Block put out in their research. They issued a firmware update for the later models. I think They've fully deprecated MK3, correct me if I'm wrong on that and are not issuing a firmware update is the last I've saw, I saw there. Michael, maybe I'll hand it to you. Any other technical details to walk through here in terms of basically what went wrong? I tried to do it as high level there as possible, but basically people were thinking through using these devices that they were generating enough entropy and randomness for their seeds, but it was actually defaulting to something that was not nearly random enough that then was found and exploited.
A
Yeah, so again, lack of sleep and I'm generally a little scattered, so I'll try to be concise that is correct. I think that I wanted to pull up a few notable things that have been floating out there from technical aspects, but the main thing I think to call out is it's been deeply understood that you want to sever the Internet connection if you want to have your bitcoin persistent in the future. And so there's hardware manufacturers and the main ones are Trezor, Ledger and Coldcard. The realization reality has been similar to Bitcoin. How most people don't look at the code they assume because of the game theory, the knowledge and other people looking at the code, that 21 million will be enforced. And that's how you think about a lot of people opting, I think about how much of Tradfi or Wall street has bought Bitcoin based on the premise versus auditing the code. And that's just how societies work on the trust basis. Very similarly with These hardware devices most people cannot navigate and they trust between third party social graphs this just how societies move that they're they work. And it's pretty wild that for five years this thing was out there and nobody picked up on. There wasn't enough randomness being generated. So the key point is that a private key is effectively sufficient. Enough is 256 bits which the the analogy is that it's more than or the equal amount of atoms on the planet Earth. So it's effectively impossible. No amount of compute you could throw at it would be able to crack it. And then half of that 128 bits would still still be sufficient. But that is the threshold, that's the barrier. And this cold card exploit was in the 30 to 40 bits range. And then the rest of at least reported from blocks and others the rest of their hardware devices have this faulty behavior but because of the secure element they can get up to 70 bits meaning that it requires more compute. But it still is a problem and an issue and you want to take action. Now where this gets a little clunkier is and this is conversations I was having last night with other folks in the industry is that you're not necessarily absolved from this if you're leveraging multisig simply because if you're relying on the same vendor, you can effectively back in to those private keys from each of those hardware devices and you need two of three. And then the thing that I don't fully grok but it's my understanding at least reported because of the way it's constructed, you can get that wallet config file effectively the XPubs and Derivation Path so you can reconstitute that multisig wallet. That's why you've seen firms like Unchained and others highlight why you want to take precaution and rotate those keys and move. This opens up just a huge problem across the board because ultimately most people don't have extra devices. Most people don't know how to do this. They haven't touched these things. But before jumping into that I didn't want to because Wizard Sardine or Kevin from Liliana Wallet who I believe works on miniscript part of it. It's like a hybrid bitcoin or multi sig mini script project. He posted earlier today and I think he was one of at the forefront. I will post a blog post later later today. But TLDR it's worse than you think. MK4 MK5Q will get drained. Multisig of coal card devices or multisig or cold card signatures are sufficient to reach the threshold at risk. Miniscript wallets are also at risk if you use cold cards. Only cold card signatures are enough to spend or recover. No need to panic. But time to move to new mnemonic devices in the next few days if you have cold card. If you use cold card in your set. So I'll pause there. I have some other things to share but just does that cover what you were looking for? Any thoughts, questions that we should talk about?
D
Yeah, I think that that certainly helps me. It is wild to me that this went unnoticed for five years and I think that is particularly concerning for me and others because naturally then where my head goes to as well. Do these types of vulnerabilities exist with other hardware device manufacturers? And so I am curious like it sounds like the scale of the impact as of right now has been identified. First it was the MK3 device and now it's kind of broadened out to Coin Kite's broader suite of hardware wallets. But my question would be then what about other people? Right? Like Michael, you mentioned Ledger and Trezor as other the main manufacturers of these devices. How should people start to be thinking about this? And you know, there's generally just a lot of angst online about and uncomfortability online about. Well, okay, I don't have a cold card, but what does this mean for me? Like this is. These are the questions that people are asking now and it's like a question I would have as well.
A
Yeah. So I mean hopefully this is helpful to take like a step back and from a, from a meta perspective I think it's deeply important. We've kind of been told a lie and it started or built into it is the risk free rate. We've shared this on pause before. There's no such thing as risk free rate. We can wake up, can die in our sleep, we can wake up crossing the road and get hit by a bus. In the same way that there is no perfect solution to custody of a bare asset, whether it's gold or Bitcoin, you're going to naturally take trade offs. The idea is you want to minimize those trade offs and specifically for your risk profile or risk preference and attack surface how people live, interact, their kids, inheritance, et cetera. And you bring up the most valid point I think, which is how, where do we go from here and how do people think about risk? And the thing that I keep coming back to and it's embedded in a lot of the conversation we've been having Is ultimately the game is fundamentally changed and most people don't know it. They're playing a different game. And what I mean by that is somewhere across the past 24 months, as the price of bitcoin got into the hundred k mark and six figures and we'll continue, we'll get back there at that same time. It was a perfect storm of AI starting to proliferate and the cost of computing, intelligence, intelligence to go down. So it reduces the cost of any kind of attacks, whether they're social, whether they're digital, whether they're physical. And people are not prepared for that and they're still playing the game from 2012, that I can put this thing on a hardware device and a seed phrase and a passphrase and I'll be okay. And there's two aspects. There's a physical aspect which most people in the meat space now know. Bitcoin's valuable and we'll go find you for it. When it was a pet project in 2012, there's very few people are going to fly across the world to go find you now. They will. And at the same time, AI is proliferating and there's more of a bounty to throw compute and there's more of an attack surface. That's the scary part with all of this, is that now this is out in the wild and so you can have anybody anywhere, specifically North Korea or China, using their power and intelligence to go and figure out what's going on, not only with cold cards, but across all hardware device vendors. And so the key idea here is because of that, it doesn't mean go to a third party exchange. It doesn't mean to go to a digital asset treasury company. That's why those things exist, because people don't want to deal with this. But embedded in all of this is you want to at the end of the day do the same thing you do with physicians, insurance, with your house or anything in life. You want to make sure that if one bad thing happens, you are not knocked out of the game. It doesn't matter for people that have 0.01%, no exposure or very nominal exposure to Bitcoin. But it matters for a of people listening here, people that have material wealth, that material is, I. E. If I lost it, I'd feel sick to my stomach, I'd throw up. And if you're in that position, you need to deeply reflect. Do I have a setup where tomorrow, if one thing went wrong, because everything always goes wrong in life, that I will not lose these assets because if you do, then the second question is have the people that have been telling me that I need to do X, Y or Z are thinking at my best with the best intentions and also if it's even less than the best intentions, do they have a prudent and pragmatic view of the world? Because that's the thing we've been talking about. I deeply understand these, these people are my friends. Is that like if you got into Bitcoin in 2012, you really have no taste for 2026, how you should be managing this asset and it goes back to well, just so easy a grandma can do it. It's like that's just not true. Grandma lost her bitcoin and there has to be better ways. It's what we've been talking about and we've been okay with being non consensus because we understand this industry deeply, we understand commercial behavior. And ultimately this in our view is the only realistic way we're going to get out of this is by distributing the risk, maintaining the sovereignty and the underlying fundamentals of Bitcoin's multi signature technology while reducing the friction for anybody to get exposure. It's not to go throw it on a third party exchange and tomorrow find out FTX sales is in block by happened. We've already played that out. So that's just a cop out in my mind when people are saying a moving assets there.
C
Yeah. And, and just to sort of reiterate what you're describing, I think there's this natural tendency or inclination to have a reaction to an event like this and say, well you know, you should have rolled your own, rolled your dice and you should have told your family members to do so. But I think something that we've talked a lot about over the past few years is like that is just not a palatable solution for most people who may still want exposure to this asset. And you just have to think through self custody is great. And I think this is a very unfortunate event in terms of the perception and the willingness for people going forward to even try to learn self custody. I think that is going to be something that the industry has to grapple with. But at the same time I think we do need to come to terms with finding other solutions that allow for people to have real ownership of this asset without necessarily the burden of what you described Michael, of like needing to do everything exactly right and not knowing if it's going to be there tomorrow. It's just a very difficult, you know, position to put someone in as you've described in the past, Michael, like you know, you're giving people a problem effectively if you just say hey, like this is how you got to do it. Go figure it out, learn, learn the technical expertise because most people don't take the time. If you did roll your own dice in this situation, you're most likely okay. But the sad reality is that most people haven't done that. And so that's why people are because they trusted a single vendor, a single point of failure.
A
Well, let's break that down because I think it's an important distinction of hey, you can still roll your own dice. And if you didn't have enough entropy, enough roles, then you still failed. And so I think that this gets severely like this is a true eat glass stare in the abyss soul search for this industry and people that expound upon self custody simply because they got full. We got full. I'm still sitting, like frankly I don't, I don't know what I'm going to do. I haven't touched these wallets. I lost one of them. I cloned it. I have significant bitcoin because I take the barbell approach where I use mic and then I have some and I can't even remember because there's so many years ago if I did it on passport or found A or Q and I cloned it. But I know I have a passphrase and I'm just making a bet that I know this weekend or right after this. We've just been so busy and the worst thing to do is move assets unless you really have to. When you're just like not clear eyed because you don't necessarily want to, you don't want to make a mistake. But with all of that said, so the most sophisticated people here got fooled by this. They didn't look, they didn't audit, they didn't think to audit, they couldn't audit. So how can we expect others to blindly do that? And then you have to layer in the intelligence factor of it becomes easier to look at exploits and find bugs. We saw this just yesterday while this was happening. Anthropic had another or an issue similar to OpenAI where the agents jumped out of their sandboxes. And so the point in that is that you can go down the spectrum of okay, well what's the rational solution? If I was going to steel man this well, okay, I go get another hardware device that doesn't have this issue. It's like, okay, well how do I figure that out? Well, let's just pretend I can. I know that the secure element and the randomness is generated in a credible way. Well, you still have to trust third party vendor. So you don't want to do that because you don't want to risk this happening again. So now you got to start rolling dice. So now this person has to go get dice and then they have to sufficiently roll enough dice. So what is sufficient enough? And then how can they credibly understand that that's sufficient enough? That doesn't even bring into the fact of how do you manage around the inheritance getting hit by a bus, somebody attacking you, et cetera, et cetera, accessing financial services. So now you go, okay, let's go to multisig. So now you have to go and you have to figure out do I roll my own multisig, do I go to another third party vendor? And so you're adding now two devices. That and you ideally the common thought is you need to add multiple vendors. If you keep going down this progression, you can actually get to very robust security. I wouldn't say it's bulletproof, but you can get to very robust security. But how? And like how and how in the hell do we expect to further an industry, gain credibility if we expect people to do that? And so then the last part as it came up, well last night, and this guy I think was me in good intention was saying, well what's the difference to I can roll the same thing as on ramp? And I think that's where a lot of these things get lost is because there's a fundamental difference between how an institution generates entropy and that private key versus how a consumer grade hardware does. We've talked about it before, but it gets, it's not sexy, but the core component of it is when you generate a private key from a hardware or consumer grade device, whether it's a mobile phone or Trezor, it's a one to one relationship, meaning that private key lives on that piece of hardware. And then you generally get that 12 or 24C phrase and so you have either one of those positions that live in meatspace and if they're ever found, you effectively can back in and get that private key. Well, when you generate an institutional private key, it's using purpose built devices and the private key never leaves that device. It's effectively wiped. The second the memory is taken out and they're all, you know, air gap, they have all these different things that don't ever allow it to touch the real world connectivity. And then that private key, after additional entropy is verified, that private key is effectively sharded. So when it comes into the real world, it never lives in that one to one aspect. So it ends up in a 203, 305, 507. And then there's audit logs and those different individuals take those shards and they move them to bank vaults and then there's different video verifications and this whole process. And that's one institution. But we still can never credibly understand if an institution does that correctly. Hence multi institution. So this is just some of the aspects that you just get deeply lost. And we're so early. It's not a fun, but it's crude and it's the reality. It's like we're just in the wild west in this space. And every year, every two years, there's a huge exploit, there's big ways that the assets lost and to get to the other side of like settling the wild west, there's going to be these mishaps and the market's going to learn. And our view has been since the founding of this business that on a long enough time horizon, what we do here will just be naturally done. Just like somebody was downloading a coal card and moving their assets to. Except for this has redundancy and no single point of failure as we found out in the past 24 hours.
D
So a lot of you don't even know that you can buy bitcoin on our platform. Onramp indeed offers bitcoin brokerage and actually we just launched DCA last week, dollar cost average, so you can set up recurring purchases on the platform so you can buy bitcoin, set it and forget it. I think this is the best way to do it. Take advantage of this deep bear market, set up a DCA. And you can also, if you use code TLT BASICS, get 50% off of all bitcoin purchases through the end of the summer. This is also for all existing clients as well. It's already set up on your account. So Smash Buy, if you're looking to allocate more to bitcoin, now's the time to be doing it. We're in a bear market. You may be kicking yourself a year or two from now and we want you to own more bitcoin. So that is why we halved our fees. So reach out to me if you have any questions. My email is jacksonramp bitcoin.com but 50% off buys 0 fee recurring purchases and we also have a few other offers as well. So use Code TLT Basics. So let me try to just encapsulate what has been said so far. If I go back a couple of minutes ago, my question was, well, who else is impacted? How do people think about this? And so if I'm understanding correctly, there are potential vulnerabilities at other companies, but we just don't know that. Just like how this coin kite vulnerability went unnoticed for five years. And so let's assume for right now that other hardware wallets are, let's just say they're safe for now. But what you guys are suggesting or what the market is suggesting right now in terms of options that exist is you either need to be a fully self sovereign individual, you need to be rolling your, you need to be rolling dice. I feel like some people don't even know what that means. Right, like rolling dice to create entropy so that you're not relying on the entropy of the hardware device manufacturer. So that's one option. Or you have to do multi sig, ideally rolling your dice with multiple vendors, multiple hardware wallets and then you should probably be geographically distributing those because then you don't want to have a physical threat vector. But then it becomes a question of like I've seen some people online today saying I can't even check right now. Like assuming they don't have a watch wallet like a node they're running, they can't even check to see if they've been impacted because they're not able to get to their devices because they're geographically distributing. So it almost sounds like for self custody to be sufficient at this point, you need to be probably in like the top 1% of technical expertise is at least my assessment from what I'm hearing from you guys and what I've read online today. And then for everyone else who doesn't feel like they can get there, they are starting to actually tear up their assumptions of the past of not your keys, not your coins, and are even considering going into like ETF products at this point or at least at a minimum single exchanges. So is it fair to say at this point if you were go, go back to first principles and Michael, you say the game has changed. People essentially have to discern if they are going to be technically competent enough and also if they have a family, their family needs to be technically competent enough to have roll your own multisig, geographically distributed, different vendors or the other perception is okay, well I'm just gonna trust, put my trust in a single institution and obviously we propose a third path. But is that like essentially the gist of it or is there anything that I Missed while you guys are describing it.
A
Yeah, I think you covered it nicely. I think the main thing that ties into all of this is effectively artificial intelligence. It just lowers the barrier and allows for people to like the puck is only is going to continue to move. So to your point, if you go down the long tail of how to protect yourself, you have to be vigilant. And I've always kind of talked about it as like, it's very similar to a firearm. The problem with like firearms, they're, they're beautiful, they're an elegant way from asymmetric defense. But it requires like maintain maintenance, you know, weekly, bi weekly, monthly, because you don't never want to be in a position where you need to pick it up three months later, a year from there. And it's, it's a problem.
C
Right.
A
And so that's very much what's happened with Bitcoin is that we take the quickest path and download a seed phrase, maybe roll some bones, roll some dice, maybe add a passphrase. But the reality is like that could have been good a year ago, it could be good a year from now. But is it good 18 months from now? Is the question. And that's the problem that exists today is that all this is moving so fast and everyone needs to check their priors and they're just the conversation' happening and it's not going to happen for a while. I can almost guarantee the conversation coming out of this is like going to end up be you seeing it already. It's like well, we got to do multisig, we got to do X, we got to do another vendor. And it just completely bypasses like the whole structure of are you a single point of failure or is there any point, single point of failure in this stack? Because if there is, we should just be rethinking from first principles how do we manage this in a digital world? Because the last thing is like what happens at 250k and 250k is probably 18, 36 months from now. AI is probably, you know, where we stand there. Like that's a very frightening thing and that's, they're both going to happen. The price is going to rise as AI gets better. So what's the plan?
D
So could we talk about the plan then from a business perspective? Because I know you, you went through it pretty quickly in terms of how this is done from a consumer grade device versus a single institution to a multi institution approach. We have that graphic. I could pull it up if that would be helpful. But like I Think we should probably talk about just high level architecture, multi institution custody. What does it mean? And then maybe dig into the institutional key generation component of it and help to educate me, help to educate the audience how this is actually different than the exploits that we've been discussing today.
A
Yeah, if you want to pull up the, the graphic, I think in its simplest form, you know, there's probably a lot of individuals here that feel Coinbase will never go down. ETFs potentially will never go down.
E
They're safe.
A
So take that like mental model of Coinbase and that they, like we talked about before, there's not a hardware device sitting. There's not Brian Armstrong. Armstrong that has access all the things associated with institutional grade, industrial grade, key generation, key management. Now multiply that times three. That's in its simplest form what's happening. And at the end of the day, you need two of those three institutions to work on behalf of the client. Like that's in a metaphor. Without getting too much of the details now, what it means ultimately for an individual is, and this is actually, you know, we've tried to be, think, we've, we thought about this very deeply for a very long time and we're very well equipped to help individuals right now simply because there's a lot of people scrambling and they have to think about do I get a new C phrase, a new hardware device, do I add entropy? Like, what if I don't have it? What do I do? You know, we're going to rush to a third party exchange, et cetera, et cetera in individuals. In the past six to 12 months, our engineering team has invested heavily making onboarding as efficient and streamlined as possible. So an individual, I like to say, or we like to say, can get access to 10x of security at 1/10 of friction of self custody within 3 to 5 minutes. And why that has happened from a technical perspective is those keys already generated, sharded, secured, offline and cold storage long before the individual goes to the onboarding. What's effectively happening Is we're hitting APIs via different institutions and just adding an additional XPub. If anybody's familiar with XPub, it's just a master address. I was explaining to a client like before is if you think about public addresses, they're very similar to email addresses in the sense that you can send anybody, anything to a public email address or a public address, but you need your credentials to the email to read it in a similar format. If you want to move assets on the public blockchain, you generally hear Single sig, single signature. Well, in this format you're taking that public key derived from that offline sharded private key and you can continue to go down a long tail of public addresses. And so the angle from an email address is you can have Brian Cabellis at gmail, you're Brian Cabellis one, Brian Cabellis two, Brian Cabellis three, effectively have these emails that the market doesn't know. And that's what's taking one public address from OnRamp, one from BitCo, one from CoinCover. They're cryptographically combined in that three to five minutes when you onboard and that address looks indistinguishable from anything else on the blockchain. And that's what's effectively powering your multi institution wallet. Now all the legalities are also embedded there where each institution only works on the client's behalf via video verification. The client retains title and the assets are segregated on chain, verifiable and also insured by Lloyd's of London. The beauty is you add all of that coupled video verification and then you still have access to financial services. Now this will not be perfect forever. It'll probably be perfect for a very long time. But you can infer that as the price appreciates, you have larger balances. Maybe it's a three or five, maybe it's a two or four or three or four. And the client holds a key if they want to. Like there's a lot of different permutations, but at the, the current environment, at its scale, this is the most streamlined way to effectively communicate security while reducing the friction and economic burden on the individual. Because we've lowered our price since we started because of our scale where somebody can onboard for $100 a month and be able to sign up and get access to what we believe is the best bitcoin security on the planet Earth.
C
Yeah, that's, that's well stated. The other just sort of high level thing I would articulate is there's, it seems to me like there is, you know, as a result of this incident, there is now a forming consensus that like you obviously need to be using some form of multisig. And as we described, like not all multisig setups are necessarily immune from an attack vector like this. But what on ramp really provides in my mind is like multisig really simplified. Like you don't need to be that technical expert in order to achieve this level of security where there is fault tolerance not just at the key level, but at the institutional level, at the legal titling level. And so it really is like you said, Michael, it's the utmost security, but with none of the friction. And ultimately, importantly, not the burden of you needing to be vigilant as we described earlier, like constantly checking for firmware updates, making sure there's no bugs. All of that is handled for you. And so you don't have that burden, you don't have that burden on your family. Importantly, you can plan for inheritance and instead of thinking about the next six to 18 months, you can actually plan generations ahead and know that your assets are going to be safe in perpetuity.
A
Yeah, I think this is an important part to pause on because there's a lot of folks that have listened and I think they've gleaned from this, but it's important to call out that the team here on this podcast and everyone working at the firm is incredibly principled. And I would go to the point of caring more about bitcoin than the business. And that's how I thought about this business. There's a stories if we can really make it, they'll be told how this got launched and it was more important that this existed in the world versus that we were successful. I wanted it to be seen and be known that there was a different layer because we came deeply from onboarding to self custody while watching FTX and blocked by collapse and realized that these issues were only going to continue. I forecasted actually on the third party exchange side, which I still think will come. Didn't see this coming at all, but it still stands. Single point of failure. And why I'm sharing that is because at the end of the day a lot of this podcast ties into being able to protect your wealth like it is bleak out there and there are not a lot of options and there's a lot of people that have found a safety in bitcoin, but if you can't hold it, you can't maintain it for your family and generations, well, what good is it for you? And so there's. That's the core mission. That's what we're on is the point of okay, you give somebody the answer in bitcoin, but how do you give them solution and how do you hold it, secure it for your family? And so I always go back to like the PC and in the 70s when it was first built, like people got value but it was a lot of early stage people, hobbyists arguing on what was the right and best version versus there was just people that realized there was an insane amount of value for an individual to log on to a Mac or a PC or a Windows computer and get access to the world wide web and all the efficiencies. But this is like 10 to 1000x more impactful because it's somebody's wealth and value. And so that's why we can show up every week. That's why we're building in this way, is because at the end of the day, people in 2026 and as we move forward with inflation will need a way to opt out of the system. And if we give them the solution of rolling dice and 10 hardware devices in multi sig, they're either not going to do it, they're going to go to a third party exchange. And on a longer time horizon, a third party exchange holding all the bitcoin if it's split between a few is effectively failure for bitcoin in the same way as a failure for gold.
D
So apparently a lot of you want merch. The good news is I am coordinating with Michael to get some things out to those of you who have asked. So here's my offer. If you are not a client already and you want some on ramp merch, use the code TLT basics on signup and we will send you on ramp merch. You'll also get 50% off all Bitcoin buys through the end of the summer. No cost dca, a free IRA account if you'd like one of those. And then also discounted multi institution custody. If you are an existing client of Onramp and you want some merchant, just reach out to me directly. JacksonRamp Bitcoin.com and I will take care of you. Look, don't be mad at me, take it up with Michael. But we're going to get the merch out, we're going to get shipped out as soon as possible. So reach out to me. And if you are a new client who wants to sign up, use the code TLT basics. Yeah, that's very well said. It reminds me of something that I used to say more often and was thinking about more last year. But just the idea of if you were to take at face value that we are early to bitcoin, which I think most people who generally participate still think that we are, then that would also imply that the industry has been early.
B
Right.
D
And so Michael, to your point, these, the infrastructure and the solutions need to evolve over time. And so I think the big lesson here is that if you're relying on a standard of securing the asset from five years ago or 10 years ago. That's no longer going to cut it. It's not going to cut it from a physical perspective as the price appreciates. But more importantly and probably more urgently, given the light of this news, it's not going to cut it anymore from a digital perspective. And so I think the whole idea with this business and having been here from very early on with, with Brian as well is that things naturally evolve. And so I think that for most people, if you were to take like what appealed to me about the solution was that it was a rational way and a rational approach to wealth, but then also recognizing that most people are just never going to get to the dice, roll the multi vendor, spin your own multisig. And so I really feel strongly about what we built here because at the end of the day I think it is really not, you know, nothing is going to be the perfect solution. But I think that this has minimized the most amount of trade offs possible. And to Michael's point as well, we'll just have to continue to iterate. I mean maybe the solution looks different 12, 24, 36 months from now as the security and threat vectors change as well. And also the whole idea of our business is that we're also not immune to risk. I mean no one is immune to risk in this space. But the whole idea behind the business is you don't need to solely rely on us being immune to risk. Right. So there's the whole reason why there's multiple institutions. There is no single point of failure. And that is probably the most important part about all this.
A
Yeah, it's well said. I think the two quick things to add are make no mistake about it, this is not advocating that self custody doesn't have a place in bitcoin. It's that you just realistically should know the risk. And then once you know the risk, you realize you should have put all your eggs in that basket. That's one. And then the other one in credit to Jackson is like we've had a lot of demand for multi institution but whether it was the price, different ways the price was formatted have kept barriers out. So part of the back to the basics that we were already rolling was lowering that barrier. For a hundred buc a month you can get access to this. But at the same time we work with individuals with thousands of bitcoin that have already come to these realizations. And so we never want price to be the barrier. We have a whole slew of financial services from whether it's buying, selling Bitcoin, IRAs etc and so if you have a situation, just show up, book a consult, shoot us an email if you want question. If you have questions you just want more of inside see our engineers are producing some more technical analysis. We'll share it all with you. But the core idea is like price shouldn't be a barrier for how you maintain your family's wealth. And so we're happy to work with clients as long as it's within reason. So yeah, I just want to get that across that like if you get that what we, what we're building makes sense for you, but the price is an issue like don't let that be one.
D
Cool. I think we can wrap it here. I would say for anyone who is interested in taking advantage of what Michael mentioned where we have the discounted multi institution rate, just use the code TlT BASICS when you sign up and also if you have any questions before doing so, you can always reach out to me directly. Jacksonnrampbitcoin.com there's also plenty of links throughout the website to book a consultation if you want to speak with us before making any decisions. And so gentlemen, appreciate the time. I think it's important just to be able to speak to things as develop so if there are any significant developments over the weekend we can always provide an update on the next podcast as well. But appreciate you guys jumping on today.
A
Yeah, I think we're going to do a Spaces after this, so if anybody listens, we'll try to get the audio and then just ship it later over the weekend because I'm sure things will evolve throughout the day. So if somebody's just trying to stay ahead of what's happening, we'll probably ship something over the weekend from the Spaces aspect on the podcast feed.
D
All right, sounds good.
A
Thanks guys.
C
Thanks boys.
E
Thanks for listening to this week's episode of the show. If you found the information valuable, please share the episode with a friend or leave a rating on your favorite podcast app. All the links we discussed in today's show will be in the show Notes inside your podcast app. Before we finish, a quick reminder that On Ramp Media is for informational and entertainment purposes only and nothing should be construed as investment or legal advice. Regardless of where you are on your bitcoin journey, we'd love to hear from you. Visit on rampbitcoin.com contact to schedule a consultation with one of our private client advisors.
Onramp Bitcoin Media
Episode: An AI Just Cracked Coldcard (Is Your Bitcoin Safe?)
Date: July 31, 2026
This urgent, informative episode of Onramp Bitcoin Media’s flagship show addresses an alarming security exploit affecting Coldcard hardware wallets. The panel — comprised of leading voices from Onramp — unpacks the incident where an AI-driven attack compromised Coldcard's random number generation, resulting in large-scale Bitcoin theft. With self-custody under renewed scrutiny, the hosts explore what this means for individual users, the industry at large, and the evolving landscape of Bitcoin custody options.
[03:43] C:
[06:36] A:
[10:18] D:
[11:15] A:
[06:36] A → quoting Wizard Sardine/Liliana Wallet:
[16:59] A:
[15:23] C:
[24:56] D:
On the AI Dynamic Worsening the Threat:
On the magnitude of the Coldcard failure:
On the myth of 'risk-free':
On the flawed expectation of user expertise:
On multi-institution custody solutions:
| Timestamp | Segment Description | Speakers | |------------|--------------------------------------------------------------- |-----------------------------| | 00:00–02:01 | Context: Massive AI-powered exploit, why the stakes are now higher | A, B, C, D | | 03:43–06:36 | Detailed breakdown of the Coldcard flaw, AI exploitation, and multisig risk | C, A | | 10:18–11:15 | Fear spreads to users of other hardware wallets | D, A | | 11:15–16:59 | The custody game has changed: why conventional wisdom fails | A, C | | 24:56–27:43 | Self-custody is now top-tier expertise only — what are the real options? | D, A | | 27:43–32:27 | Introduction and explanation of multi-institution custody | A, C, E | | 34:42–35:45 | If the industry stays technical, mass users will leave | D, B | | 37:26–38:48 | Risk, pricing, and access: Onramp's self-reflection | A |
This summary aims to capture the urgency, the technical nuance, and the shifting philosophy of Bitcoin custody in the wake of a new kind of threat: supercharged, AI-powered exploits. The panel urges vigilance, adaptability, and a sobering reassessment of old security assumptions.