Loading summary
Michael
But the angle is like that now. It's shown bad actors that this can be done. And bad actors obviously live here in the US and they live all over the world. And so now there's more compute, there's more power being thrown at this problem. And that's the scary thing. And that's going to be a big part of this conversation is where do we go from here? Because naturally there's going to be a lot of technical custody conversation, but there's a lot of philosophical conversations going around business building how people are going to adopt self custody. Because anybody listening to the show understands even if they never used a coal card, it was supposed to be the gold star. It was supposed to be the thing that the most vigilant hardcore people used. And they all missed this and they trusted. They didn't verify.
Liam
It all comes down to computers communicating.
Michael
The information superhighway can be a confusing mix of on ramps and off ramps. Bitcoin is worthless. Artificial gold, is it still rat poison? Probably rat poison squared.
Brian
We need to get into the world of.
Liam
Okay, this is actually foundational technology.
Michael
What the Internet of money does is it creates a single network which can do a micro transaction to a giga transaction. The Internet is going to be one
Brian
of the major forces for reducing the roll of government.
Michael
The one thing that's missing that will soon be developed is a reliable E cash.
Brian
All righty, gentlemen, welcome back to another episode of Final Settlement. Today is Monday, August 3, 11:49am Eastern Standard Time. Boys, wild few days. I think this is going to be a little bit of a different episode. You know, normally we're hitting an array of headlines, but there's one main headline that obviously sticks out. If you're hearing for this for the first time, if you haven't been on Twitter, cold card exploit last week began on Thursday night and continued, really is ongoing. And we'll get into that in terms of sort of where we are. But I guess first and foremost, if you have funds on any cold card device, move funds immediately as fast as you can. We'll get into some of the details and specifics around it, but at a very high level. On late Thursday night there was reports that around 600 Bitcoin were swept out of MK3 cold cards. And really the underlying issue here is that the random number generator in those devices, the firmware was defaulting to basically a less random generation of seed phrases. And so people thought that they had, you know, on device generated a random enough seed phrase and they actually hadn't. This has existed in the firmware since 2021. It was only found seemingly last week. And this has escalated and continued to the point where now other models are also being drained. So there's various reporting on this. I think Block did a fantastic job late Thursday evening, basically providing some transparency around. Maybe it's not just the MK3 that's vulnerable to this. And then also Alex Thorne and Galaxy have been doing a job of tracking sort of where things stand. And so maybe I'll pull up a tracker here that just shows the current estimates of what has moved. And Michael, maybe I'll hand it to you in terms of any other details and sort of where we are right now. You're on mute.
Michael
Sorry, I. I want to gather my thoughts for one second. So I'm going to throw it to Liam and then I will. I will come back because frankly, there's so many different facets to this and I want to go and, like, try to order because I think we had maybe one thing is we had a podcast that came out Friday. We did an emergency pod to share the latest because to Brian's point, like, if you have any level of cold card, you should stop the show, go on Twitter, go on our blog and realize that this is very serious. You need to move the asset. So we put that out. But ultimately from there till now, there's a lot to discuss on what's going on while the models are vulnerable and then ultimately, what else is potentially vulnerable. Where do we go from here? So I'll pause there. If, Liam, if you have anything. If not, I. I can. I can riff, but just wanted to talk to you.
Liam
Yeah, for sure. I think that, to Michael's point, would, you know, not move too fast, that you're going to make a mistake, but definitely move quickly and move your bitcoin off of any cold card device. I wouldn't try to, you know, use a different one and try to roll dice the right, the right way. I'd either move it to an exchange, a custodian, a different hardware device that is not made by coin kite pretty much as quickly as you can. If you're not in the area of your device, I would either have a trusted family, friend, relative, somebody go to your house, wherever you have it, and get the device and either use QR codes to sign and broadcast transactions or just figure out how to wait to do it because otherwise, like, you're. You're still at risk of losing funds. There have been, you know, almost 2,000 Bitcoin lost to the date and the attacks are getting more widely known all over Twitter and kind of making their way into the mainstream news at this point. And so thus far we've seen pretty unsophisticated attacks, but they're only going to ramp up as there is this known bounty that, you know, black hats are going to go after with more compute and more sophisticated attack methods. So your funds, if you use cold, if you use any coin kite product, whether it's single sig, there have been at least instances of people saying that they rolled dice 5,000 plus 200 times and they have been lost, especially with passphrases. It's very tough to verify every one of these claims just given how fast things are moving as well as multiple devices on a cold card. So I would do your own research as quickly as you can and try to move the devices off to another platform asap.
Michael
Yeah, I think Liam had a long weekend. I don't know if he was reporting 200 dice rolls and getting taken, but just if they are, I mean correct me, But I think 200 dice rolls are probably okay. But obviously you have to, you have to be able to do that. So look, take it, take it a step back. At the end of the day, these hardware devices are made to do one thing and one thing only. It is to generate a random number that secures that bitcoin. That number generally if you have 24 words, 256 bits is ultimately a number for context or the way that's explained is larger than the number of atoms in the universe and that secures that private key. Now sometimes you hear 12 words and that is 128 bits and that's still large enough to protect against any kind of attack with GPUs compute AI to back into that private key it was found through. It's still speculating whether Kimi, their latest model is a Kimi K3. On Monday came out open sourced. Somebody started pointing GPUs at the code base of probably different various platforms. This is one theory. They looked across bitcoins and realized, or I'm sorry, coincides and realized that there was this vulnerability to Brian's point that when they powered on and tried to generate the randomness, it didn't click on to the rng, the random number generator. And it ultimately was deterministic and deterministic meaning that it was tying back into the serial number and like other attributes that were relevant to the UID of that specific device. So what that means in layman term is that if you were able to recognize that this vulnerability existed, you could ultimately come up with a window. So for the cold card Mach 2, you would be able to come with the firmware post 21, you would be able to come up with a window that I think the number is 32 bits. So the context there is that it would take, you know, call it, I don't know, maybe an hour depending, give or take how much power you're using to be able to back in and find out the number of words out of the BIP 39C phrase that fit in that window. So once you got the words that fit in that window, so you're effectively shrinking the, I think believe it's 20, 48 words in a traditional bip 39 standard. That's what gives you the 256 bit encryption. You got down to that small window. You could now with a bunch of power, get the number of private keys back into the public keys and then ultimately start or get the public keys and back in the private key on the blockchain and be able to start to see what addresses were associated. So that's effectively what happened there. Now once that came out, the problem was that it was rumored that, okay, well the rest of the devices, while they had this issue, that there was a secure element that was helping get it up to like roughly 70 bits. So it was, would take at least days, if not weeks. But to Brian's point, again, that it would take sophisticated actors because right now, again, this is like the perfect time to call out specifically with us if you want to talk about custody venture some other stuff. I'd say like we, you know, a decent amount, but for this you should go verify like everything we're saying and you should always be verifying because this is how we got in this mess was nobody verified any of this stuff was actually working. And so point being is they effectively went down and realized that or it was rumored that the secure elements helped it get to like roughly 70 bits of encryption. And ultimately it wasn't the case. It's more of like anywhere between 40 to 50. And that's why you've seen the sporadic wallet trainings because to everyone's point here, this may have started by an innocent or not innocent, but like naive didn't have it's. I saw a rumor that supposedly set up for a KYC chain analysis or like blockchain explorer firm. So he was able to like get info on that and then now they, you know, the authorities may have info on him. Point being is that. But the angle is like that now it's shown bad actors that this can be done. And bad actors obviously live here in the US and they live all over the world. And so now there's more compute, there's more power being thrown at this problem. And that's the scary thing and that's going to be a big part of this conversation is where do we go from here? Because naturally there's going to be a lot of technical custody conversation, but there's a lot of philosophical conversations going around business building how people are going to adopt self custody. Because anybody listening to show understands even if they never used a coal card. It was supposed to be the gold star, it was supposed to be the thing that the most vigilant hardcore people used and they all missed this and they trusted, they didn't verify. And so we're at a real kind of like pickle. But I think that's like maybe the back half of this conversation because I think right now it's still trying to just like discern everything that happened and is happening because it's still ongoing.
Brian
Yeah, that's helpful context. And I think one thing that you mentioned in there which I think is worth sort of reiterating and it can sort of get into semantics, but I thought this was a good tweet from Matteo Pellegrini saying, you know, it wasn't that the RNG itself failed it, that it said this wallet was defaulting silently downgrading, in other words to a weaker randomness and the user was unable to see that effectively. So, you know, throughout all of this the, I think some of the knee jerk reaction has been like, well, you know, if you did it yourself and you didn't just trust the device to generate the entropy and randomness and you were rolling dice yourself, then you know, maybe you're fine. And I think the higher level sort of meta of like, you know, it's already difficult enough to, to get someone to do self custody, but now you're saying, well, you know, you should have really done this the, the really right way and rolls your own dice and created your own entropy. And it's just, I think it's a big ask and I think like you said, there's sort of a reckoning of where do we go from here. This was BTC sessions last night saying, important update. We just had our first confirmed loss of an MK3 plus two word passphrase. So again, initially it was thought that it was just impacting MK3s with no passphrases and no dice roll. So meaning using the devices seed generation, but that has sort of expanded out not only until to the later devices, MK4s, maybe even Qs but also MK3s that did have a passphrase. Now a two word passphrase is not a ton of help necessarily, but worth noting there and then I was also going to pull up tweet from Jameson Lopp Coldcard Funds Migration if you need to move funds off of a weekly generated seed phrase, I suggest doing it before you upgrade the device firmware There's a non zero chance that the firmware upgrade will break the device according to some reports. So this was again over the weekend basically Cold Card or Coinkite had issued a firmware update for models post the MK3. The MK3 I believe is fully deprecated so they weren't going to issue an upgrade there. But there have been reports that basically people were updating the firmware on those later devices and then their devices were being bricked. So if you were trying to basically fix the situation on the same device, that may not be the best best path here based on some some reports.
Michael
Hey everybody, appreciate you tuning in. I wish we were connecting or the topic was a little bit more positive today. It's unfortunate what's going on, but we'll get better, stronger for this have had no shortage of conversations consults this morning and the sentiment's positive. People are reaching out. They haven't been directly affected by loss of assets, but they also recognize they've been listening to these podcasts. They've been seeing what we've produced over the past few years and they realize they want to get started. So I'd encourage you if that's yourself. You don't necessarily have to go through onboarding. It takes only a few minutes. We've simplified the process. We can start accounts with no costs on Ramp Finance. All custody solutions come with insurance, but I would really encourage just shooting me an email, included it below or schedule time with our team. We hands down have the best people in this industry. I was specific about when we built this firm. Everyone here has 10 plus years, whether it's in Bitcoin, tradfi, risk management, and even if you're not ready to use On Ramp, you can book a call and just talk through your setup, what you're doing, what you should be doing. Are you at risk? We're here to help. So yeah. I hope you enjoy the rest of the show and look forward to talking with you soon. Yeah, the that's something we I don't know how much we called out. But the passphrase, it used to matter a lot. It, it helped slightly here. And the core idea is that using those bits of randomness, you were able to back in to the private key via the words. And ultimately once you got those words, if they weren't able to, you know, get it, you could brute force by, you know, throwing numbers and, or they're throwing words. And generally it's looked at if you use a certain number of words, I think it's like either 6 or 12. I think it's 12 of bip 39 words in the C phrase. But I don't necessarily know who knew that or who did that. Like when I set up a passphrase, it was nothing like that. So if they weren't part of the BIP 39, I don't think they were. But you had some time. But eventually you can just run enough again intelligence through this to be able to get into that the. So, so that's really where that started to, to go. And there's still all the. I don't, I mean there's no data. That's another interesting dynamic. It's less relevant, but it's still interesting. That cold car was supposed to be deleting all this information and where I was going to go is there's no data on how much like cold card value actually store. So we don't know how long this can go. But they were rumored or they were shown they were emailing clients over the weekend because it's really hard to get a hold of somebody if you don't have it their info and people aren't glued to it. I don't know, Liam, if you want to share some of your personal anecdotes, because I do think there's a component to all of this that we're going to get to around user behavior and where do we go from here and what are people supposed to do just today? Because I think like the whole issue around bitcoin, I think we talked about it on, on the last pod, which I would encourage. If anybody's trying to get their bearings on this. That was a good one. That gave a recap of in real time on Thursday or Friday morning is ultimately like, you know, people understand there's an enforceable 21 million and you can look at the code via a node. But a lot of people don't ever do that and they rely on webs of Trust, Social Trust, BlackRock, whoever it is, and they can credibly Understand there's only 21 million Bitcoin there's a difficulty adjustment and everything that makes Bitcoin work. And in that same way that people did that, they did not go and audit this code. I mean, for five years this sat out there. And most people, not only and they did audit some levels of the code because it was somewhat open source, but they missed this. And the point in calling that out is like, how can we come back from somebody storing their life savings on a device that is made from another vendor? You don't know what's there. You don't know where the gaps or potholes exist or traps. And then you specifically don't know where they live. In this AI world, as newer and newer models are coming out, are going to continue to find vulnerabilities. And because over this weekend it also came out that Claude had multiple agents that jumped out of their sandbox, I believe it came out that now OpenAI also had others that they just recently reported on. And so we're just moving to this brave new world at the same time that it's not a coincidence that people are finding these vulnerabilities. And it just opens up the whole notion of the fact that people were explaining and telling people to park all their wealth on these single devices and just put a passphrase on it and you're good or so easy your grandma can do it. There's just a real, like reckoning and, you know, like, come to Jesus moment this industry is going to have to like go through to get to the other side because a lot of credibility is being lost. And the sad part is on the other side of it, there's people waiting with open arms to say come into an ETF and come to an exchange and that's going to be much more detrimental. It's like, I'm not going to use the analogy around Covid, but if anybody knows me, you know where I was going there. But it's like this issue was the real thing. This isn't the real problem. This is the problem that's going to get people to go to a centralized exchange and then that's going to be the problem. And you can't let that be the solution for people.
Liam
Yeah, for sure. I think it does make sense to talk about just personal anecdotes in a bit. But I do think that one thing that was notable too is there at least were reports circulating of these types of vulnerabilities happening back in 22, 23, 24. And the team at Coinkite was notified of them and they didn't act you know, it's tough to really blame them. And I'm sure that they've gotten many reports of somewhat similar instances just because there have probably been people who have used cold cards with, you know, devices that were impacted, like vulnerable laptops or just, you know, user error around it. But it's, it's a small team and the fact that they, if it was a larger team and had been able to, you know, have additional folks look at how this, these errors were really happening, I think that there's a chance that this might have been caught a little bit earlier. So it really does make sense to have a lot of strength in numbers and how people are really, you know, dissecting how if there are user funds that are lost, any sort of vulnerabilities and be able to work quickly because obviously some of the updated firmware did brick devices too, which also isn't great. But yeah, just like, honestly, I'm happy to share a personal experience. So I had some devices or funds on a queue maybe.
Michael
Sorry. Just one thing to quickly call out for anybody listening because I think we didn't mention it, is if you're in a multisig, you're also affected with the similar device setup. And that's, I think, important to call out because it's generally understood multisig being safer. And it is. The problem is if in your quorum, whether it's a 2 of 3, 305, if the majority of the key set is tied to this firmware and this vulnerability, you effectively can back into that, especially if you've already spent from it and the public keys have been shared. And so that's actually another interesting aspect of this. There's a number of firms, I believe Unchained did a hotfix, along with a few others that were allowing people to go via. I believe it's Mara's Slipstream, which allows you. It's like, what is it called, Dark pool to effectively put a transaction, a block without it propagating to the network first. So you can get. And this gets a little technical, but it has to do with replace by fee. And so I think that's just worth calling out. This is really where all turtles all the way down start to fall apart on what has been given to the market when it comes to roll more dice. Multi vendor, multi jurisdictional. Like, part of Liam's sharing is like travel. Like there's going to be all these anecdotes of like, well, you still have all these problems that ultimately end up in a single point of failure. And it's been great to see the industry and the people, you know, rally around a lot of this. But a lot of that reason is because they literally sold everyone that cold card is the solution. And their majority of keys are at least one the keys. And collaborative custody or any of these scripting type languages are literally tied to the cold cart. So they have to go and, you know, attack this or they're gonna, they're gonna have egg on their face because they literally put their clients in these products. And that's the crazy part, is that this whole story doesn't matter if individuals, podcasters, collaborative custody providers, all ultimately said this is the best solution, or we're offering it to our clients and nobody was able to spot this. And I don't think that's a failure on them per se. But it also brings in a question. If this is the model that's ultimately having people lose assets. Well, when we pivot from this and we go out of it, is it more dice rolls, is it more hardware devices, is it more vendors, a solution, or is there a real architecture problem? And that's really something that we're just going to have to discuss because if Bitcoin's going to go to 7 billion people on the planet Earth, it was always already understood it was going to be via self custody. But now we have to really rethink even in the next like couple of years. Are we going down the right path with the existing models we have?
Brian
Yeah, I mean, maybe just a couple things before we get to some. Some anecdotes. But you know what, you referenced Liam, around the idea that there are multiple reports of people claiming that they found these, this bug earlier than last Thursday and reported it to the company and that nothing was done. I think there is an interesting sort of game, theoretical dynamic there where if that is the case, you know, what should have. What should have coincide do. Because once they basically say that there is an issue, it creates this panic and it creates an environment where it would be out in the wild then and you know, it would be very difficult to basically get everyone to update their firmware or move funds before any funds were lost. So it's, you know, I'm not saying it's the right thing to do, to ignore it. It's obviously not. But they were, if that is true, they were in an interesting spot because how do you alert users of that bug without actually causing funds to be lost yourself? And then the other thing I did want to mention was, you know, I think Michael, you sort of pointed this out that we don't have full numbers around like how much BTC is on these devices in general. And I think if we zoom out in the context of past vulnerabilities and breaches, if you think about Mount Gox FTX on the centralized custody side, the losses have been way, way higher than the 2,000 bitcoin that we're looking at currently. We're talking tens of thousands of bitcoin if not hundreds of thousands of Bitcoin in the case of something like Mount Gox. Now obviously the price of bitcoin was lower, but I think it is important context that the reason this is such a, maybe a dramatic event is because for lack of a better phrase, like this is happening. You know, the call is coming from inside the house in the sense that all these other breaches and hacks for the most part have happened on the centralized custody side of things, which has actually influenced people to go down the path of self custody, severing the Internet connection, getting a cold card device and then you have a breach on that side of the house. It's very difficult because the people affected by this thought that they were doing everything right to avoid these types of incidents. And so yeah, we'll get to this. But I think there is a conversation to be had about, I think the knee jerk reaction here was, look, okay, multi vendor, multisig, that's the standard. It's like, okay, but is everyone capable of doing that themselves? No. Is everyone capable of geographically dispersing those multi vendor, you know, that multi vendor hardware device? And then it's like, well, do you even want to do that? Because then how do you access it if you need to? But then you don't want them all in one place because that poses a physical attack vector. So there's just a lot of sort of knock on effects of all this. But yeah, I think maybe both of you could, could talk anecdotally about your, your weekends because Michael, you had tweeted this over the weekend as well. You were on a road trip and, and migrated some things off of a queue as well.
Michael
Yeah, let's do that. And then I'd be interested.
Liam
I mean we could.
Michael
There's a lot of angles. I definitely want to just have some time here to talk about rotary go. And I think less philosophically I think we can talk about that. But for the like, the cohort and sentiment of this show from like capital markets, investing, we're business and vision, I do think that there's just been a fundamental misalignment on how like bitcoin was scale. And I think it's worthy of a discussion because it matters if you're going to join a business, start a business, et cetera. So but before that, Yeah, I mean so this just really ties into a huge part of the fundamental. I think this really gets lost on whether it's on ramp or this business. There are early riders that it was all built not because of vision per se, it was just bad experience or experience in the markets. And you know you can go back to WeWork is a great example lighting money on fire or just like building on chain and collaborative custody seeing the gaps. And so the main point here is that this idea that like self custody for everyone just never made sense. And the best example I can come up with is like firearms. It's firearms and actually we play out where AI goes and the reality that people are going to host large language model frontier large language models versus just hit APIs and there's a spectrum as far as how you do it and it's just not rational for people especially as you think of bitcoin only have 21 million as the price appreciates that it just gets harder and harder to protect that wealth and people are still protecting it like in 2012. And that's what's been propagated and nobody's come into the market and said maybe there's another way. And so this ties directly into it because there's a extreme value not only in the network from a decentralized perspective and being able to take delivery of having that hardware device or like that metaphorical bar of gold, there's value there. But we've always positioned the barbell approach which is effectively for people that are sophisticated, that want that where they can use multi institution custody and then they could take delivery in any kind of hardware, device, passphrase, whatever it is and then they could have their welfare. So that's kind of what I had set up. It's like majority of my family's wealth and multi institution have that, that barbell. Now I hadn't touched that. Now this is the key point is that like the firearm people don't touch these things for months, if definitely not years. And so when I set it up I couldn't remember if I had used a passport which wasn't affected. I really like the team there. They have other devices that have come out and so I couldn't remember if I generated there or the cold card. That was the first thing. But the other thing is I had cloned it and have the same passphrase. So I had these different devices. One of them I completely. I didn't lose. I know it exists somewhere, but I don't know where. So I couldn't find that one. And that's the one that was easiest for me to use. It was a passport because I knew I could just, like, download the app, et cetera, et cetera. The cold car doesn't have an app. So then I was like, eh, I'm gonna be okay. Have a passphrase. It's a queue. And so this is Thursday, Friday, and I'm on a long road trip Saturday. And I finally, like, took, you know, got in the back seat because, you know, I'm, like, looking on Twitter and I know I shouldn't be driving and tweeting, but it's a long trip. I don't have a Tesla, so whatever. Anyway, so I like, see these things, like, continue and continue and continue. And I'm like, oh, shit. So I tell my wife to drive, get in the back seat, and I'm just, like, fumbling because I knew I was taking all this stuff because I knew I had to do it. And yeah, I just. I was able to move it off, throw it in on ramp, and, like, had just true, like, peace of mind knowing, like. Cause, like, there was a component of me was like, I could just get this swept and that would suck. It was meaningful wealth. But on the other side of it, I'm just looking at is like, well, that's me rolling the dice. But also it's kind of like, hedged because I was like, well, this business is. This isn't the whole reason why we exist is because if I lose my assets, like, I think it's less about even me. It's like, I was on Spaces and you were on too, that day, driving. I'd never get to join Spaces. And I was listening while I was driving. And it's, like, heartbreaking to hear people that just, like, lost their wealth or even lost a little bit of it and are now, like, gun shy because they're like, what do I do? Who do I go trust? Nobody's technical enough to go spot if this has occurred to me. Others, nobody knows who they trust. And then we've gotten emails in the same respect. And one that I think I forwarded to you last night, which was ultimately a family and an individual. And they're, I believe, a physician. And they're the person, because this is everyone listening to this is usually the bitcoin person in their circle, and they are almost at their wit's end because they've had to do all these things, had to go down all these rabbit holes to get their bitcoin off the coal cart. The price has naturally been, you know, somewhat flat over the past couple years. And so they're like is this worth it? Like what am I doing here? And that's just insanely unfortunate that we are here now in this spot where people are like what are we doing? All I hear about is exchanges losing their bitcoin now this is there. And so anyway that's just kind of a little bit of like the individual side. And I guess where I started with all that was because ultimately we build these products for ourselves and then it just so happens to be that we believe that the rest of the market naturally will come up these curves of realizing that again I will in this post take bitcoin off and park it probably in a foundation device or something. I'll figure it out. But I could not leave it there or just go and directly hop to multisig or another vendor because at the same time all these new models are coming out like by the day and who's to say the next one now they know there's a bounty on all bitcoin software, right? So who's to say that the next time this will happen? And so I just like know that like mic the architecture all et cetera. So anyway that's just a little bit about like how my Saturn everyone appreciate you making it this far. You know at times like this this is really, really when the industry is going to figure out what they're made of. Very confident that everything is good for bitcoin and the market structure is going to change these conversations. They're going to change a lot of the things we've been discussing since the inception of multi institution and on ramp are going to come to the forefront. We're going to be doing a lot of things behind the scenes. There's with all that, even before this happened we were already launching a promotion with back to the basics. The whole idea there is we kind of quasi lost our way. Won't go deep into the way we lost our way. But the reality is we realized we needed to make it simpler for individuals to get onboarded with us. Whether it was having 0 fee DCA half cost lump sum buys or reducing the cost for multi institution down to $100 a month for individuals that had smaller stacks or just wanted to try the platform. If you use basics and you include GTS if want to gradually and suddenly book I have a signed Parker Lewis books. Still have a few left. Would appreciate that if you want to use it. And yeah, if for nothing else, if you want to book a consult and then just reach out and talk, we can share what we're seeing, what clients are doing, how they're thinking about risk, et cetera, et cetera. You can also just follow us on social and you'll get up to speed as well. All right. I hope you enjoy the show. We'll be back later this week with more updates on what's going on and hopefully some other positive news that are happening. There's a lot of good also happening, a lot of people coming together to support and help people get their bitcoin safe.
Liam
Thanks for sharing that. Yeah, I mean I think that like a lot of folks were in your type of boat. Like honestly I heard about the news Thursday afternoon and I had some bitcoin in a queue. I think I rolled passphrases. But to your point too, it was, I think I set that up years ago now, so I honestly can't really remember, but I wasn't in the vicinity of it too. So I had my Sparrow like desktop wallet, but I had to have somebody go and get my cold card and use the QR codes to both share the transaction and then they would show me the QR code back and then put that into Sparrow and then ultimately upload and broadcast the transaction. I had to do that multiple times because if you do larger transactions and QR codes it's, it's very hard to actually broadcast them. And I share that, just not because, just because there are likely a number of people who are traveling over the summer and I think that it is a prudent move to have somebody who you trust to honestly go in and do something like that for you before it ultimately gets swept off the platform. There are both black hat and white hat attackers now. But honestly, yeah, feel significantly better with having the assets in multi institution custody. I think that folks should not necessarily take the time to set up like a multi sig themselves at this point, but they can figure out where they want the assets in a pretty quick amount of time and then ultimately if they do want self custody later on, just figure it out themselves when they have a clearer head and aren't necessarily rushing off the platform. But to your point Michael, I think that this is going to be a lot AI is going to be significantly more of an issue for bitcoin over the next 10 years than quantum computing. Full stop. There is a Lot of exploits in the code potentially and having white hat and black hat attackers that are looking at over every single code base and they realize that there are massive bounties now because of like nine of the last 10 largest heists in history have been on either exchanges or self custody at the moment. There are going to be a lot more compute used to try to take Bitcoin off of these types of devices. And I think that the industry really needs to take a step up at this moment and figure out either one how to come to a degree and both do it on exchanges. Collaborative custody, multi institution custody is obviously something that we really believe in here, but pretty much across all of the different spectrums, I think that there needs to be significant improvement and collaboration at this point to ensure that assets are safely and securely guarded. Given the heightened risk right now, yeah, 100%.
Michael
I think there's an important distinction or function worth calling out around that. Like it's something that's been embedded in a lot of the conversations we've shared and it's really been amplified and showed here is the notion that we've been in a hobbyist led industry. It was nothing's really changed because we're so early. The same thing we do in 2012 is the same thing we're doing in 2026 when it comes to custody and management. And ultimately that's what's gotten us into this spot. There is a reality that people can't audit and check these things themselves. And so I think there's a core aspect of all this is you shouldn't just if you're going to park and this is really where it gets sad, is like Bitcoin's the best store value we've ever seen. While it doesn't feel like it empirically, it's been the best performing asset and on a long enough time horizon, you're storing value of a load and time preference. You're looking at a long timeframe. It will continue. But the reality is most people do not park any assets or very few because of this issue that they don't feel with certainty that it'll be there tomorrow. And the sad part is the people that did come to that conclusion are now losing the assets or deciding what am I doing here? Because of its performance coupled with what's recently happened. And the other side of that is without question A, self custody, distributed custody has to exist for Bitcoin to work. But B, the alternative is not conducive to Bitcoin working long term. Like if you believe you need a parking and a centralized custodian. You're ultimately saying, A, you don't really necessarily understand Bitcoin, but B, you might like maybe want to just take a position off because until you fully grok bitcoin because you may lose it there and when you come to the understanding that it shouldn't be on that central custodian for a number of reasons and one of the biggest ones, and this is like the misnomer that you were calling out Liam, is that AI is going to cause so much disruption and Bitcoin is always this canary in the coal mine because it's the easiest first thing to move liquidity, it's a bounty in a digital world. And that it's like this incoherence from a first principles thinking around if I park it all at Coinbase or even Fidelity, that we love them, that this notion that the more successful you are as a single custodian, the more likely you are to fail because all you're doing is putting more users to have to get through their permissioning, you're putting more bitcoin and you're effectively putting the bounty on a greater scale for physical digital attacks, whether it's at the third party custodian layer or just the engineering between them, because they cannot from a compliance services perspective, map and make sure that every single person withdrawing is going to be that person. And so that's where this all just starts to go. Where do we go from here? Because the reality is it's not and it never was going to be treasures and ledgers where bitcoin scales for a number of reasons that we've talked about. But it also can't be Coinbase and fidelity holding 60, 70, 80% of the Bitcoin because that also brings a whole slew of other issues. So I'll pause there if we're going to go in that direction or if you have anything else, Brian, on this.
Brian
Yeah, no, I think that that's a good recap and I think part of the discourse over the weekend was sort of two separate knee jerk reactions. The one was, you know, you should have rolled more dice or you need to now do multi vendor, multisig yourself. Here's how to set it up. And then the other knee jerk reaction was, you know, kind of why, you know, what are we doing here? I'm just going to put it in an ETF or I'm going to move it to an exchange. And there's issue on issues basically on both sides of that knee jerk reaction. But ultimately I Think if we distill what has happened and sort of where we need to go from here, it's thinking about not only single vendor risk, which this, this, you know, incident is a matter of single vendor risk. Like you mentioned, you know, it wasn't just people using a single sig in the sense that if you had a majority quorum with this same vendor, you still had an issue. So it wasn't even that it's single sig versus multisig as sort of the defining line of whether you were safe or not. It was are you too reliant, overly reliant on a single vendor? And the same can be said about single entity risk. So like when we talk about the coinbases of the world, yes, they use multisig to secure client Bitcoin and cold storage, but they manage all the keys. So there is single entity risk there. And so it's the same idea as single vendor risk in that sense. And so we need to get to this place where you know, whether you're doing it yourself or you're trusting counterparties, you need to one be using multisig, but you need to be doing it in a way where there isn't a single point of failure, there isn't single entity risk and there isn't single vendor risk. So that's where we need to go. But what.
Michael
And just one quick thing, this is, this is part of like the founding of this business was I realizing there's a lot of people listening to this that I know this will resonate with and it's up to them if they want to take action. Was that collaborative custody was a great stopgap specifically around the client holding majority of the key set. As we navigated from post ICOs to ultimately I would say like multi institution as an example cause these products didn't exist. But the reason why I say that is because it leaves a lot to be delivered. When it comes to like to start at the very base, it's ultimately that most people, in the same way they trust a single hardware device or the vendor or the code, trust the process of how do I reconstitute and reconfigure this thing? Because the whole reason to use a collaborative custody provider is to technically understand the risk associated with if you're in a minimum of a two of three, you have roughly six pieces of information you need to secure. You need the seed phrases, the hardware devices, and then you need offline and online wallet configuration file. That wallet configuration file is how you rebuild the wallet outside of the Third party. And I saw firsthand that a. A lot of people just, even if they onboard it, they wouldn't get comfortable because they couldn't grok all of that. And a lot of people don't park their money in things they don't grok. So they just left it on the blockfi of the world. They lost the assets. But then even worse, I don't know which one's worse, because on blockfi, you lost the assets. But people have set up collaborative custody without knowing all of those things and left everything under one house, one roof. And sometimes it's right there underneath their desk. And that opens up like 10 to 100 issues. One being just centralization of if a house fire, the problem, if somebody breaks in, or just the notion of as more and more of this data is out there. We've talked about it, like when wives find out that, like, oh my God, imagine somebody comes to the house or whatever, it's like, what are you doing playing with these magic Internet beans and putting all this money. Like, nobody else operates like this on the planet Earth when it comes to their equities, their gold, their dollars. Nobody puts all their duffel bag full of dollars underneath their mattress. But for some reason, there was people explaining that's what you should do with Bitcoin. And so as you just go down that, it's the same aspect of, well, how do I redo it? And then ultimately, well, what are the right keys to do it? And so, like the thing we talked about earlier, the answer is it is actually more dice rolls, more hardware devices, if you're technical enough. The problem is that it's the further you go out on that curve of, like, requirements to protect yourself against AI. And by the way, that curve is going to continue. AI is just only accelerating. It's a moving target on the risk factor. And so how many people on the planet Earth are going to be able to do that? And so that's just the basis of all these things and really where the business has come from. And I think a lot of people listening here, I had the tweet that I think you were referencing is our clients easily are the most sophisticated. We have people that, you know, are large institutions, allow us to use our name here. But the point being is inclined to have thousands of bitcoin with us, is that they went through all of these issues and they ultimately realized, oh, God, I need a partner in this. And like, in a world where I'm bullish on humanity and trust and my family can recoup this is, I need either all or a portion of my stack in this format. And so I think that this is just going to be a very eye opening thing. We have a lot of conversations going out across the industry because I think there's going to be a huge opportunity to step up and help firms across tradfi existing Bitcoin to implement levels of multi institution custody that will really be beneficial to their business. Because the beauty of Bitcoin and game theory is it only flows one way and that these assets, even if worst case scenario, I don't think it's going to happen, go into centralized custodians, I can promise you there will be losses on centralized custodians that will be much larger than whatever this coincide deal looks like. And then everyone's going to re pivot back the other way. And when they do that, whether it's today, tomorrow or a year from now, or a couple years from now, the whole game is to have the tooling available and the on ramp available, no pun intended, to be able to secure those assets. And that's how you build a safety base that can grow. And then that's how market standards form. Because people won't go to third party ETFs or self or you know, for a single individual unless they adopt a solution where no single entity, because of entropy, because of social, because of North Koreans, physical social engineering can manipulate how that private key is used because it doesn't matter, those assets won't be lost. Which funny enough changes the logic of violence. Because when you know that an individual cannot or any entity cannot be manipulated to lose the assets, it fundamentally changes the attack vector. And so even an ETF 2 of 3 nearly becomes impossible. We've run statistical analysis on this and then eventually When Bitcoin is 10 to $100 trillion, you can naturally move an ETF to a 3 or 5 and you can imagine that world. There's Morgan Stanley, Charles Schwab, Fidelity, et cetera. So long way of saying if you're listening to us, hopefully there's some knowledge that's been shared and also credibility because this is stuff we've been building around for a while. This is not something that blindsided us. The thing that blindsided me personally, I think us is that it was cold card and coin kite because that was supposed to be the most vigilant, but this was bound to happen no matter what and is only going to continue.
Brian
Yeah, maybe one, one element to just sort of mention is I think, you know, if you're looking for Positive spins or silver linings of all of this. On one hand it's, you know, people using AI to better secure their own software and not waiting for the bad actors to find it first. I think that's sort of the first order of business. But I also think that there's a more meta silver lining to all of this. In that, and this is something we've talked about over the years is like, you know, for a while there was this effective purity test around owning bitcoin, a dogmatic nature around it that if you weren't doing these specific things, you know, you weren't you, you weren't a real bitcoiner or you weren't doing it the right way. And I think that, you know, for better or worse, like this incident flies in the face of that dogmatic nature. And so I think not only do we need to build better solutions, but we just need to be more open minded to solutions in the sense that what people thought was the gold standard, what people thought was verified to an extent that they could trust, it just wasn't the case. And so I think we need to just, just, you know, have that in mind as we move forward. And then the other side of it is what Fernando Nicola tweeted here is like, you know, he's talking a bit about bitcoin culture, but also like, you know, the ability to actually make sure things are secure. You know, it's very difficult to have a bitcoin only business in the sense that there's only so much revenue to be generated, whether it's from trade, custody fees, et cetera. And so the idea that, that companies need to basically expand their product suite I think is something that on the on ramp side we've internalized. Whether it's adding stablecoin support, dollar support or even gold exposure access, like there's things that, you know, it doesn't mean you have to go add altcoins and be the next coinbase. I think there's, there's different levels to this. But the idea here is that, and it relates to the AI point that as this stuff accelerates, like you also need to accelerate your defenses against it. And this was a tweet from Mike Belshi over the weekend that he basically put a bounty out there for Anthropic. And the way he phrases this is either Anthropic is terrible at building sandboxes or excellent at marketing or both. But enough with the we created a hacking monster. Games do it for real. And so he put 100 BTC in a bitgo wallet.
Michael
Yeah, that was interesting because it seemed like it was Apple's the oranges of what they're hacking versus the bitcoin, a bitcoin private key. But either way it is interesting. Cool to see Bill, she put that out. I think everything you said is super relevant and valid for people just to think about and to have humility on our side or my side personally. It's like we don't know the future, we just truly don't. And I think the things that we know, you can build on them. And one of them is from a long term perspective, if bitcoin was going to succeed, like me personally running a business, you don't necessarily want to have unilateral control of those assets because and you're already seeing these narrative forums where there's been bitcoin companies where assets have flee to and they're great firms and there's nothing against them. But the problem is that on what scale does that end up being a liability and an issue? And when do people start saying oh this is too much and this is too much centralization. And that can come from internal collusion, that can come from external bad actors, that can come from state bad actors because those are effectively honeypots, they're just honey pots in a different form. Parker had a good tweet out and we don't necessarily always see eye to eye on like the self custody side, but he had a good tweet out of like, like you know, people saying just park it all with like a third party custodian. Don't really forget about the debt problem and that bail ins could be an answer when it comes to this. Like that's real. And so point being is that we don't all necessarily know the future, but we can start to bake in assumptions on do you want to be in positions that can move or lose client assets? And that seems like a very pragmatic thing. If you're building in this ecosystem and knowing for 17 years where this industry is going, do you want a single point of failure attached to you? The other side to that and a part of all of this is what we've been sharing on. We really have to do soul searching and rethinking. You gained benefit and knowledge from a lot of people that were early to bitcoin and they wrote really good about it, they talk good about it, but that does not necessarily mean from game theory, from business building, from risk profile that they should be explaining or should be at least questioned in what they tell you to do. And this goes across the spectrum and we've talked about this, whether it's the digital asset, treasury company stuff or the coal car stuff, because at the end of the day, a lot of these individuals, to your point, have not worked with other people. They have not got the emails, they've not onboarded physically to these devices. They've not seen like the market reaction to how they adopted. And if you just extrapolate those small incidences at a smaller prices, what did they think was going to happen as the price rose, as more risk comes on? And the AI is like this black swan that came out of, I don't say nowhere, but it's just this thing that's like ravishing anybody paying attention to it across the world right now. And so I just think that like that's something we've been talking about to your point, when you brought up stable coins and other exposure, that was just a rational place that this area was going to go to and the winners were going to go because we've been in this barbell, which the joke, if anybody's listening has heard me say this multiple times, it's like tradfi read the forward to the bitcoin standard and never opened up the book. And then on the other side, on the bitcoin side, it's like one way, only one way to do it with no realistic discussion or even vision of, okay, so everyone holds their keys in a cold card and then now what does everyone defend themselves from? Bad actors coming to their friends or their family? How do you coordinate economic activity? Like all of these different things were just never logically coherent. And so I think that's one of the biggest things that we're going to have to be loud and really work constructively with others to discuss what is a future that's realistic in bitcoin adoption, That a doesn't have DATs because that's just natural we needed to do that. But then the other side of it is what's the logical way that bitcoin scales that's sufficiently decentralized, that doesn't tell everyone that they have to hold this hardware device and get a seed phrase and roll dice. And so that's just going to be important. It's going to be an ongoing thing we'll be talking about here?
Liam
I think. Yeah, I think that's a great point. And just to drive it home even further, like if you know yourself and you don't think that you're going to be comfortable with holding your own assets, like don't be shamed into doing that just because somebody told you to do that on Twitter. They don't always have your best interest in mind and you should really be thinking for yourself what makes the most sense for you from and it doesn't need to be necessarily one size fits all for 100% of your assets. And so you can think about different places to hold different amounts of money too. But yeah, I think that to your point, I think multi institution custody or I think that's right now what we've found is the best solutions on both sides of the spectrum so they can scale to very significant amounts of people. That doesn't put one target right on anybody's back that somebody will continue to use AI to go and try to, you know, be able to easily or not easily, but just that will put additional fault tolerance for getting assets out of a platform. There, there necessarily is two of three signatures at the moment and will scale to three of five and continually along there as the size of bitcoin grows. And on the other side of things, I think that increasingly just we've seen it initially with the defi hacks that came out and now this cold card one like this is we're probably going to see more, you know, coming this later this month I would imagine, just based on how many open source and closed source new models are coming out on a daily basis. OpenAI essentially solved what, 10 math problems over the weekend that hadn't been solved by over decades. I think this is a model that hasn't even been released yet. And then on the other side of that, Flash was able to solve tokens like 100x at less cost than some of the latest Claude code models. So at the same time AI is getting both like exponentially better and exponentially less expensive. And that's just going to allow for both a hardening of security models to ensure that there will not be breaks on existing code bases. But for some instances like yeah, there, there also will be some additional hacks from here because it's going to be both good and bad guys looking at everything at once and trying to find both the vulnerabilities and patch them as quickly as possible or just go and take the funds. And so I think over a longer period of time it definitely makes sense to upgrade to a better standard. And that's what we've been doing at early riders too. Both incubating and standing up businesses that are building on multi institution custody, creating a growing network of global keys around the world in order to allow for not just One size fits all solution and allow bitcoin we think to scale to pretty much everybody out there.
Michael
Yeah, it's well said and I think it's probably for a different conversation but I have a pretty direct or at least directional vision of like there's this notion of by leveraging multi institution in the networks you can actually make bitcoin more robust because you'll end up with different implementations on signing and then how the client participates. And so it's like almost this version of you'll naturally come inward and then you naturally can go back outward. You can imagine institution participates in the 304. There's just different formats but reality it's like the iPhone. I've always thought about business building in multi institution like the iPhone versus Android. It's like you want a nice unified experience that just works for the MacBook. You don't want somebody having to paint by numbers and like it's your way and you can figure it out because people just don't necessarily know and if from a financial service partner they're looking for that trust and that kind of like continuity. And that's why we've just been solely focused multi institution expanding the key network. And the analogy that I've always thought about is if you looked at Steve Jobs when the iPhone came out, it took him about a year but he came around to effectively opening up a fund and then setting up for the App Store and you can almost look at like multi for the Apple App Store and you know, everyone knows where that went. Is that multi institution is this application layer for bitcoin robustness because custody is the base layer but then other financial services start. And so whether it's REO in Latin America on Ramina in the central, the GCC Arch on the lending side, Argo on the gold side, you can just naturally see that we're investing and building out. And why I'm mainly calling this out is because if you're trying to break into the space and you want to figure out like what's the firm that's not going to go belly up because it made one mistake. There's a lot of companies that are building on these primitives and premise. There's firm early writers being bitcoin denominated that people come in, they're able to get involved on that respect. But then also on the on ramp side that this is all we've been focused on since the genesis. Like you know, Microsoft was pioneered by us because ultimately we looked at the problems and the reality is nobody was Building anything separate than what we talked about today, either I have to trust myself or I have to trust the third party. That's effectively what it comes down to. And the sad part is you're still trusting somebody. Like this is what I was going back and forth with in a good way. And please, anybody that's listening, ping us, email us. If you have questions, you have rebuttals, we'll answer them on the show. But part of the deal was like, I'd rather trust myself. And I was like, that's fine, but realize you're trusting multiple things. You're trusting the vendor, you're trusting yourself, you're trusting a family member from an inheritance perspective. And yes, that's rational. If it's 1025, you can pick your profile of your bitcoin stack, but is it really worth a hundred percent of it? And can you go to sleep at night like that? And I think for most people, once they like understand all of this, it just becomes untenable to park all those eggs in like one basket. Especially with what we saw this past couple days.
Brian
Yeah, 100%. I mean, I think when I, when I think about sort of the evolution of custody and bitcoin infrastructure, to me, what it always comes back down to is like, and I think the incident of the past week is a catalyst in this direction. If we again want to take positives out of this, it's that you have to get to a place where one mistake can't knock you out of the game. Because what we just talked about on the AI side in terms of vulnerabilities and the ability to cheaply brute force things and find vulnerabilities and exploits and bugs. Like, you basically have to work under the assumption that something will go wrong. And so you have to get to a place where something going wrong doesn't end up in a permanent total loss of funds. That's really the ethos and the whole value prop of the architecture of multi institution custody. And we always knew that we wouldn't be the first ones to do this because that was our thesis, that that's the place we need to get to. It's a more robust, fault tolerant, redundant architecture that like you said, Michael, it's not just custody. That's how you sort of build the future of financial services around that more resilient architecture. So we knew we wouldn't be the first. And I think this is a We
Michael
wouldn't be the only. You said would it be the first? You meant would it be the only. Yeah, yeah, you said the first real quick. You guys should finish up. We've. It's been a blessing and truly appreciative of all the inbound that's come in. I have a consult I have to jump to. We've had hundreds of clients sign up. Hundreds close to. I don't know, I got to check recent thousand bitcoin come on the platform. If you just want to talk to us, you can go through self onboarding. It takes a few minutes. You can sign up for finance, there's no cost associated, but encourage you to reach out, book a consult, reach out to the team, we'll walk through, help you move assets over. But I'm going to jump to this call with the client. I'll let you guys wrap and then we'll see you guys. We got SVN this week, multiple times last trade. So we'll be sharing the latest with everyone.
Brian
Yeah, thanks, Mike. The only other thing I was going to say was, you know, a brief call to action like Michael sort of alluded to. You can get set up with on ramp in a matter of minutes. We have a self sign up flow or you can just book time with anybody on the team to ask questions, ask about the process, what it looks like. And we also have a free tier so if you're not ready for a multi institution custody vault, but you want to get yourself in the platform into Onramp's orbit, you can sign up for Onramp Finance, get an account, you can buy and sell bitcoin there. The on ramp finance tier uses Bitgo as its custodian, which is insured, qualified custodian. And then when you're ready to upgrade to mic, you can do that very easily in a few clicks. And so yeah, reach out to us if you want to learn more about it. But Liam, what else you got before we, before we wrap, I was just
Liam
going to say, yeah, reach out to us if you want any help either through on ramp or just figuring out what you need to do from your personal perspective. Happy to, you know, help any way we can, even if it's not with us. Be vigilant out there. Don't put your seed phrase into any Internet connected device, any website, really. Be vigilant if there are people reaching out to you who you shouldn't trust, you know, double check everything. But yeah, as we said at the top of the show, please move your assets out of the any cold card devices fairly swiftly. I think time is of the essence but you know, make sure that you go smoothly, you know, not not too quickly that you will lose assets. And yeah, hope everybody stays safe out there. And yeah, this just reach out to us if you need anything.
Brian
Yeah, well said. Maybe the last silver lining to end on. As I was thinking through this over the weekend, in terms of bitcoin's price reaction to all of this, it's been pretty minimal. We're still pretty much in the same range that we were prior to this happening. To me, that's a telltale sign of a price bottom when bad news doesn't cause the price to fall materially. And so while earlier what I said is in terms of the actual amount of bitcoin that this is impacting, it's not not as big as some other incidents we've seen. But I think in terms of sentiment, it's certainly a hit. And so we haven't really seen the price react. So maybe positive on the bitcoin price side that we've sort of bottomed around here hopefully. So yeah.
Liam
Thanks Brian.
Brian
Thank you Liam. Thanks everybody for listening. Reach out if you want to learn more. Thanks. Thanks for listening to this week's episode of the show. If you found the information valuable, please share the episode with a friend or leave a rating on your favorite podcast appreciate app. All the links we discussed in today's show will be in the show Notes inside your podcast app. Before we finish, a quick reminder that On Ramp Media is for informational and entertainment purposes only and nothing should be construed as investment or legal advice. Regardless of where you are on your Bitcoin journey, we'd love to hear from you. Visit onrampbitcoin.com contact to schedule a consultation with one of our private client advisors.
Episode: Coldcard Was Supposed to Be the Safest. What Now?
Date: August 4, 2026
Host: Onramp Bitcoin (Michael, Brian, Liam)
Podcast: Onramp Bitcoin Media – Final Settlement
This high-stakes episode focuses on the recently disclosed Coldcard hardware wallet vulnerability—a topic rocking the Bitcoin community. Once considered the "gold star" of self-custody, Coldcard devices have been found to contain a critical flaw in their random number generator, leading to over 2,000 Bitcoin being stolen. The conversation moves from urgent action steps and technical details, to broader implications for self-custody, business trust, multisig, and the role of AI in Bitcoin’s future. With practical anecdotes and candid takes, the hosts emphasize the need for new, more robust custody models.
Timestamps: [01:28], [03:48], [04:43], [06:36]
Notable Quote
"If you have funds on any cold card device, move funds immediately, as fast as you can."
— Brian [01:28]
Timestamps: [06:36], [11:44]
Notable Quote
"What that means in layman terms is ... if you were able to recognize that this vulnerability existed, you could ultimately come up with a window ... maybe an hour depending, give or take how much power you're using to be able to back in and find out the number of words out of the BIP39 seed phrase that fit in that window."
— Michael [06:36]
Timestamps: [19:53], [21:25], [24:02]
Notable Quotes
"This is happening—the call is coming from inside the house ... the people affected by this thought they were doing everything right to avoid these types of incidents."
— Brian [24:02]
"How can we come back from somebody storing their life savings on a device that is made from another vendor? You don't know what's there ... in this AI world, as newer and newer models are coming out, vulnerabilities will continue to be found."
— Michael [19:53]
Timestamps: [27:07], [34:31]
Notable Quote
"It was meaningful wealth. But on the other side of it, I'm just looking at this, ‘well, that's me rolling the dice.’... It's heartbreaking to hear people that just lost their wealth, or even lost a little of it and are now, like, gun shy—because they're like, what do I do? Who do I trust?"
— Michael [27:07]
Timestamps: [37:31], [40:47], [42:34]
Notable Quotes
"We've been in a hobbyist-led industry. The same thing we do in 2012 is the same thing we're doing in 2026 when it comes to custody and management. And that's what's gotten us into this spot."
— Michael [37:31]
"There isn’t a single point of failure ... you need to be doing [multisig] in a way where there isn’t single entity risk, there isn’t single vendor risk."
— Brian [40:47]
Timestamps: [42:34], [48:08], [54:29], [57:35], [60:20]
Notable Quotes
“We need to just be more open minded to solutions in the sense that what people thought was the gold standard, what people thought was verified to an extent that they could trust, it just wasn’t the case.”
— Brian [48:08]
“If you know yourself and you don’t think that you’re going to be comfortable with holding your own assets, don’t be shamed into doing that just because somebody told you to do that on Twitter.”
— Liam [54:29]
“You have to get to a place where one mistake can’t knock you out of the game ... you basically have to work under the assumption something will go wrong.”
— Brian [60:20]
This episode captures a high-stress inflection point for Bitcoin’s evolution—a moment demanding both technical vigilance and honest cultural introspection. The Coldcard vulnerability is a wakeup call: the entire Bitcoin custody landscape, from DIY “gold standard” devices to large institutions, must adapt to new attack surfaces, new technologies (especially AI), and the practical reality of a maturing, global userbase. Trust, diversification, and a willingness to challenge dogmas are now requirements for anyone serious about long-term Bitcoin security.