Loading summary
Jameson Lopp
You've had a dynamic where money's become freer than free. If you talk about a Fed just gone nuts, all, all the central banks going nuts. So it's all acting like safe haven. I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins. In the world of fiat currencies, Bitcoin is the victor. I mean, that's part of the bull case for bit. If you're not paying attention, you probably should be. Probably should be. Probably should be.
Matt Odell
Yeah, I don't, I don't think we can assume everybody's heard. And I know, I think that's a bad assumption just because I've been texting people I know have cold cards and they're completely oblivious to what was going on last night. So, yeah, sad day.
Jameson Lopp
Yeah, we've talked under better circumstances for sure.
Matt Odell
For those who are unaware, there is a massive vulnerability in cold cards produced after 2021. All models, some worse than others. But essentially, the random number generator that creates the entropy for private keys that you produce using the cold card is insufficient. Is that the right word? Yes.
Jameson Lopp
Yeah, it's, you could call it deterministic. So the, the search space required to get the private key to guess the private key basically is highly, highly limited relative to what it should be. So basically, the, you know, funds under the mk2 mk3s with firmware between, you know, 2021 and 2023 are just kind of like dangling in the wind. So luckily, if you used dice rolls, you know, if you used, say over 99 dice rolls to initialize the key, you're, you're safe. And, or if you're using a passphrase, which is basically like the, the 25th word you can specify when you're setting up the wallet. If, if that passphrase is of a sufficient length and complexity, which is longer than most people think, then you may also be safe. But yeah, the MK2 MK3s are affected severely to the point where it's like you need to drive home from work and migrate your funds if you're single sig under one of those, without a passphrase, without dice, or with a weak passphrase. But we're finding, and it's part of an ongoing investigation as to the current state of the cold card firmware, which would affect newer devices like the queue. We're finding that the problem still exists there too, but it's partially mitigated. So estimates right now are that current users of cold card devices are getting about 70 bits of security, whereas you're supposed to be getting 256 bits during key gen. But that 70 bit number is even going down because we're finding that one of the fallback RNGs that is used to paper over the original defect is actually less random than we thought and is specified by the manufacturer. And they may be doing things like zeroing out certain parts of this id and so it might actually be worse than we were thinking last night for current devices. So my headline for everybody at this point is if you're working off of a cold hard Device queue after 2021, you need to migrate your funds pretty expeditiously. If you did all the dice rolls, don't worry, you're probably in good shape. But even so, yeah, I think unfortunately people should be making moves to get off of the post 2021 devices.
Matt Odell
Yeah, I mean we're trying to find some humor in light of this, but cold card. Hey listen, I've been an advocate for Cold Guard for many years. If you listen to the show, I recommend it. I have my queue right here. I move my funds last night, obviously a part managing partner 1031 were invested in Coinkite which produces the cold card. This is very close to home for me personally to many people I know that have felt very confident recommending this in the past and it seems that the confidence was ill gotten. We were joking before. It's like the cold card souped up to secure enclaves. But you mess up one part of it, the random number generator. It's like you got a Ferrari on top of a lawnmower engine. Well, pretty devastating.
Jameson Lopp
I'm in the same boat, man. I mean I'm a single sig passphrase guy on a cold card. I think Mark 2. My firmware is older and unaffected, but I love Coinkite, they make great products. But the unfortunate nature of security and hardware wallets is that you screw up one thing, you screw up the wrong one thing and it's toast. And so that's the reason why people have been sort of paranoid in this department is because you just simply can't trust one manufacturer, one source for your entropy. You know, when you're doing entropy construction, and this is what I do professionally for the last few years, is you have to be utterly paranoid when you're constructing a private key and you can't just click a button and expect that it'll happen, you know, so it's, yeah, it's, it's really, it's really sad to see because I recommended Cold card left and right to people who I thought were savvy enough to use them. And I'd say aside from getting yourself safe, my message to people would be think about who is a sort of more normal person than maybe you are listening to this podcast, who you've recommended cold cards to, who maybe isn't, like following bitcoin. Twitter. Give them a heads up if you got them set up with a cold card. I've got a few such people in my life that I've reached out to.
Matt Odell
Yeah, that's why I wouldn't. That's why I hit you up last night to record this. And I'm distracted right now because I'm about to send out a newsletter that just covers this as well. And I got to give one more prompt to my client. Care to make something very clear here, but dive into the math. So you mentioned, like later versions, people are saying potentially 70 bits of entropy. You should have 256mk2, mk3, after 20, 21, even less. I think it's like 32 bits.
Jameson Lopp
20, 20 something.
Matt Odell
Yeah. And I mean the nature of the attack, I mean, this is obviously very much centered on Coin Kite and coldcard. However, AI comes into the mix. I mean, this is a new era of security vulnerabilities. And I mean, we've been talking about it for the better part of a couple years now on this show and others that these models, once they get sufficiently intelligent, we'll be able to uncover these. And it seems like that may be exactly what happened yesterday.
Jameson Lopp
It's totally plausible, man. Me and a number of other researchers very quickly, independently reproduced this just by giving the AI kind of a pointer as to, hey, between this window of time between these firmware versions, check for an RNG problem. And Kimmy K3 chewed through it and found it readily. And yeah, look, if you're a sort of unscrupulous attacker and you're willing to just sit there and grind through, take any open source bitcoin software you can and just say, hey, file by file, go through, look at the entire history, find something that's plausibly an exploit. All that stuff's going to get unearthed. So somebody I was talking to yesterday put it this way. He said security by obscurity is going to zero rapidly and everything. The tide's washing out, so it's going to be really wild. A few weeks and months and probably years
Matt Odell
outside of bitcoin. Matt and I discussed it on rhr, but there was a water system in Minneapolis that was attacked. Looks like with some vibe coded. LLM attack. And
Jameson Lopp
what.
Matt Odell
How big of a setback do you think this is?
Jameson Lopp
Well, you know me man, I'm, I, I tend to be somewhat pessimistic in the short to midterm. Um, and my real worry, aside from like the horrible tragedy of a bunch of good people losing their coins, that's obviously horrible. I'm, I'm a bit worried about the second order effect of this being a hit against kind of the most reputable hardware wallet vendor among hardcore bitcoiners. That kind of rippling out into a notion that, well, even the smart guys screwed up self custody and how can we expect that anybody will comfortably self custody after this point? So I don't necessarily agree with that because again if you kind of followed best practices that were recommended, you'd have avoided this pickle purely by obeying that principle that you can't trust a single manufacturer or you have to bring your own entropy to the table somehow. But even so I worry this event's going to get a lot of play and maybe the general public is going to be like oh yeah, that bitcoin thing, that's impossible to keep safe by yourself. So just got to use a custodian.
Matt Odell
I mean the irony of the whole situation is with all the eyes and compute focused on the cold card repository right now, by the end of the week it may be the most secure system in the space. But again the trust is very hard to build, very easy to break.
Jameson Lopp
Yeah, and that's the problem. And in some ways this is a sort of inexcusable error if you are a company making the product that they make. And so I, you know, again the coincide guys are friends of ours, certainly of, of yours and mine. And even so it's like I think,
Matt Odell
huh, what the fuck.
Jameson Lopp
Yeah, it's, it's going to be hard to trust anything that comes out of that brand anymore.
Matt Odell
You know,
Jameson Lopp
so it's, you know, I mean the thing like it feels like every single hardware wallet manufacturer has made some kind of like fatal misstep again because this domain is just very hard. You know, Ledger spilled, you know, all of their clients information essentially back. What was that like 20? Okay, yeah, yeah, probably multiple times. You know, Bitbox had some pretty, pretty obvious physical defects that allowed key exfiltration. I don't know specifically if anything has befallen Trezor or not, but you know, it's just, it's kind of the nature of the game that these things get hit with something and even if they aren't obviously Hit with something. The very fact that it's a security critical bitcoin device means that their whole supply chain is probably targeted. The companies themselves are targeted for intervention. So custody's tough man, it's really tough. And I spent many years hoping we could make it easier with better scripting primitives and covenants and vaults. But I think given the community's more fractured than ever, I'm not sure we're going to get there and certainly not in the next year or two.
Matt Odell
But I don't know, I think this may light a fire in our people's ass to figure that, figure out how to get that stuff through. I mean a lot of the conversation there's back and forth, people on both sides of the aisle, now's not the time to talk about this. And I think Alex B. From from Arc Labs Arcade was making some good points. It's like, hey, don't worry about obscure covenants when we haven't even verified like random number generation on some of these wallet providers.
Jameson Lopp
There's a point there. But again there's a sort of inescapable point which is that even if you supposedly verify all the RNGs, you just can't again you can't trust one manufacturer. Even like look, I'll pick on say bitkey because that's being touted as a migration target and I think the world of that team and I know a lot of the guys who wrote that they're super smart but are you really auditing their whole software stack? BitKey requires on device software that's closed source. I know a lot of it is open source but some of their, the back end services are closed for. So it's like, you know, until you move some of that security into the chain itself, you're not going to be able to like trust one provider. And that until we get, until we solve that, you know, it's like okay, well all right, so I go to two providers, I set up a multi sig for myself. That's, that's kind of a horrible user experience or a worse one for sure. So while, yeah, I mean Alex's point is taken that like there are fish to fry in the auditing department. I think the only categorical fix for a much better UX and multi sig level security is going to be something at the covenant layer. So that's why it's important to kind of keep focus on that.
Matt Odell
I do think focus will be coming back to covenants pretty strongly here. It's my gut feeling and as we've discussed throughout the years. I mean, the Covenants vault conversation has been probably the most consistent continuous thread that we've had on this show. The conversations that you and I have had on the show over the last two or three years. And I think it is time to have that conversation. But bringing this back to LLMs and security, that's another frustrating thing, is, in your mind, as somebody who is a protocol engineer or somebody who's building custody systems for enterprises, what is the importance of fuzz testing your system with the latest models as soon as they're dropped?
Jameson Lopp
Yeah, I'm doing it all the time now, both on the level of analysis as well as generating permanent test fixtures that are really solid, which is. That's a total blessing. It's easier than ever to say, hey, cross test every cryptographic implementation I'm relying on against two or three other alternatives, make sure everything marries up. Oh, and then, by the way, run a full audit of my entire system at both a conceptual level and an implementation level. That's incredible. And those are the same tools, obviously, that enable unearthing these kinds of attacks. And so it's the arms race. If you're not a diligent user of the latest AI models and techniques and you're building this stuff, then you're at a real disadvantage. And it really points you back in the direction of man, this stuff has to be simple and rock solid.
Matt Odell
And it's incredibly frustrating. I mean, in parallel to all this happening, we have like the. The model wars here in the US and the government stepping in and cucking like Fable 5 and ChatGPT 5.6. And so that's. It's like, if you're trying out of these systems, you can't use the American frontier models because you get immediately nerfed and you're forced to figure out a way to get access to communicate. Three, which I think many people are assuming that that is the model that was used to discover and then exploit this particular vulnerability with cold carb. And. What are we doing in the US like, like the, the Operation Glass Wing? Because I know many Bitcoin teams are like, hey, anthropic, like, we have a pretty important system over here in Bitcoin. Can we get access to this to make sure that we're audited and finding any vulnerabilities or bugs that may exist. And I've heard that some teams in the space and maybe even core developers got access to it. But when it comes to something like a system like Bitcoin, we need the ability to audit this immediately now, like just thinking about like, I think people really need to get through their mindset that like the, the landscape of defensive technology has completely shifted and like the, the way in which you secure your systems has changed and it's being proactive and consistently proactive from here on out.
Jameson Lopp
100%. I was using Kimmy exclusively last night to do the triage and investigation and I was working with some colleagues and the US based models were just shutting, locking up, refusing to, you know, go further on certain lines of inquiry. You know, I don't have a lot to say about the policy side. I'm, I'm, I haven't thought much about that. I'm sort of a freedom guy and you know, I bless, I feel, feel blessed that we have VPN technology. But yeah, the, the fact of the matter is if you're not kind of on the bleeding edge and you're doing security stuff, you're at a real disadvantage.
Matt Odell
Yeah. Bringing this back to cold card, walking through many scenarios, like just thinking of the questions that many people who are just becoming aware of this may have in their mind. Let's like walk through the scenarios like going from MK3 past 2021 and like obviously MK4, MK5Q, what's the difference in terms of vulnerability, exposure and urgency to move coins. And then beyond that, you mentioned the dice. So to be clear, if you've set up a cold card and you added, you brought your own entropy by rolling dice. If you did it more than 100 times, you're very confident that you did, you should be good. You basically rolled your own entropy and are not affected by the, the RNG bug that exists on the firmware or existed on the firmware yesterday. Have updated the firmware so you can update that too for MK4, MK5 and Q. If you want to get on, get on something that's more secure than what existed yesterday. But if you do that, if you just update the firmware, that doesn't make you secure. You have to create a new private public key pair and move the bitcoin from your existing wallet to that new wallet that you set up there.
Jameson Lopp
Yeah, key point right there is, is it's not the firmware that's currently running on your device, it's what you generated your key with. So I could see that tripping some people up.
Matt Odell
Yeah.
Jameson Lopp
But yeah, we initially thought the red zone was basically cold cards from 21 to 23. That footprint has expanded because we're hearing about MK4s that have been stolen from and we have some Indications of why that might be. But again, to reiterate at this point, you know, if, if you've generated a single sig with no passphrase, no dice roll on a coin kite device, post 21, you know, you got to get off pretty expeditiously.
Matt Odell
Yes, multisig. I've talked to a number of people that are using code cards in a multi sig setup. Some are using two mk3s and a two out of three. Like what are the intricacies there? There's some nuance depending on if you've ever spent from that wallet, if you haven't. So if you have a 2s3 multisig using two MK3s or an MK3 and MK4, this just goes through those different scenarios. What, and you've only sent bitcoin to. You've never spent from, or you've both sent bitcoin to and spent from, what is the exposure there?
Jameson Lopp
Yeah. So multisig is where it gets pretty complicated. I think it'd help to maybe step back and just explain a little bit how multisig works or pay to witness script, hash or taproot scripts in general. In bitcoin, when you spend from a multisig, you actually have to present the script that locked up the coins in the first place, which means you have to present the pub key for each key involved in the multisig. And so what that can mean is if you're using a multisig with all cold cards and you've used say that address before, you've revealed all of your pub keys. And so an attacker could theoretically grind out all the private keys and construct a valid spend and be able to present a valid signature or a valid script. If you have a multisig quorum where you have any device that isn't a cold card or a coin kite product, and that's. That has to be part of the critical spend threshold, then you're in good shape. Basically your coins are protected by that segment of the multisig. So, you know, for example, if you have like a three of five and you have, you know, not that I hope anybody out there as a consumer has a 3 to 5, but a 3 to 5. But that would require signing with a device that isn't a coin kite device affected by this. So you'd be in good shape if, for example, you're like an unchained customer, let's say, and you're doing a two of three and let's say that you yourself used two affected cold cards at home. That's sort of an interesting situation because depending on what unchained does their pub key may or may not be on the chain. I don't know, you know, they'd be able to field this question. If their pub key is available, then you are vulnerable. So I think the safe guidelines there are basically, if in your multisig you have a situation where you could move the coins with only Coin Kite products, I would move to get off of that because there are a lot of subtleties around. Well, you know, are the pub keys out there? Aren't they out there? Don't get too clever by half. And you know, if you have a critical threshold of your multisig that can be provided by coincide products, I would just move. Don't, don't think twice. So that's the long short answer there.
Matt Odell
And what is the we assumed time you like say again? Multi sig 2032 mk3s, maybe the pub keys exposed, but compared to just a single sig mk 3. Bring your own entropy, no passphrase. I've heard that if you have multi sig you probably have a couple days the way these attacks are.
Jameson Lopp
Yeah, that's my inclination to say. But with this stuff you kind of have to assume that now that the vulnerability is out there that the entire Internet is going to be just like grinding on this. And so yeah, a multi sig is harder to scan for for an attacker, but that's just a shallow throw more compute edit type problem. Yeah, and I wouldn't, I wouldn't back up to that. And let me reiterate there when I say, you know, if you have a critical threshold of Coin Kite devices able to sign for your multisig, that is assuming you didn't use dice, you don't have asp rays and so on and so forth. That's just a kind of naive single sig. So if you've used 99 dice rolls on some of your Coin Kite keys, I have verified by hand that that code path is safe. So you're okay, don't worry about those. It's really just. Yeah, if you just trusted the device to give you a good key.
Matt Odell
I'm trying to think of all the scenarios that the one question like have you heard of any white hats going after this? Because it's going to be messy. And there was some discussion. There was a Twitter space this last night. I was listening in on him. It was the moral conundrum a lot of people were discussing, like should we run GPU and just sweep the people who are exposed.
Jameson Lopp
Yeah, that's an ethically gray area that I haven't sat down and put the right amount of consideration into. I have been contacted by people with prospective plans for that. I don't know if it's actively happening. There's obviously the problem of attribution. If you do sweep those funds as a white hat, how do you then verify back? There's some indication that given the uid,
Matt Odell
if you bring the physical device.
Jameson Lopp
Yeah, exactly. If you can present. But the mechanism for that hasn't been demonstrated to me conclusively. So. So on the one hand it's very difficult and I personally wouldn't be rushing out to white hat this, but on the other hand, the real argument for that kind of thing is that there are a lot of users out there who are affected by this who probably are not listening to podcasts and browsing bitcoin Twitter. And those are the guys that are going to get ground down over the next few weeks if they're not made aware of the situation. And so that's a real tricky one, man. Yeah, there's a big ethical dimension to that one as well as probably like a legal dimension that you need to think through.
Matt Odell
Yeah, yeah. I mean that's like. Does the, does the collapse in confidence of the Coin K code cards lead to like a lack of confidence in other. And like it goes back to the importance like I've been a big believer of multi vendor, multi sig for this exact reason for many years since. It's like there's a bunch of people wondering like, okay, cold card. I don't have a cold card, but I'm looking at my treasure, looking at my ledger like, are these okay? Should I wear like. I think no, you shouldn't be worried as of right now and maybe you won't ever have to be worried. There's the potential that the way they do their entropy and create their private public key pairs is really top notch and gives you enough. It gives you 256 bits of entropy that is secure and very hard and impossible to break. Statistically improbable to break. And so if you're out there in that situation, do not panic. That's what I would say. Yeah, because that's one of the other big mistakes that many people will make. Many people lose coins by panicking and foot gunning themselves in the process of trying to sweep coins or something like that.
Jameson Lopp
Yeah, you always want to be doing test transactions of small amounts whenever you're sending anywhere, you know, and that's Crucial to keep in mind throughout all this if you're migrating your own stuff.
Matt Odell
Yeah. How do we know that exchanges have secure setups?
Jameson Lopp
Well, I know that a few do firsthand, but. Yeah, I am not aware of any exchanges that would be vulnerable to this. And I would like to think that almost every exchange has put more thought into entropy generation than hey, we're going to click a button on a consumer device and hope for the best. But this is a wake up call for everybody, including enterprises, that you really have to put tremendous amount of care and thought into this part of the process. And what I've always tried to emphasize to clients is you need at least one component of your entropy that you can physically reason about and that you understand in terms of how it's being incorporated into the entropy. And so I think probably guys like us, consumers are going to have to start to think about this. How do we take a very simple piece of code that we can reason about or have audited by somebody we trust and say, oh yeah, this is a part of the key now for sure, because yeah, I can see how this event would keep you up at night. You say, well, why couldn't this happen to Ledger? Why couldn't this happen to Trezor? You know, what I will say is that Coinkite is a very lean company. And most other hardware wallet manufacturers, certainly Ledger and Trezor have pretty big teams who are doing a lot of internal auditing. I mean, Ledger's. There are some phenomenal people there. This isn't an advertisement for Ledger or anything. I don't even use Ledger personally. But there are some phenomenal people there who have done some very novel hardware attacks.
Matt Odell
The Don John team, it's like it's. Yeah, joke last night. It's like they figured out a way to use $250,000 lasers to hack a cold car, but all they had to do was.
Jameson Lopp
Yeah, yeah, exactly. So, yeah, I mean, I still think a multi manufacturer approach for guys like us is a really solid approach. But as Nick Szabo said, it just echoes all the time. Trusted third parties are security holes. And for something like this, there's a certain level you can't delegate to, to a packaged product. Not easy, man. It's really not easy. Especially at the enterprise level. Thinking about this stuff and designing it, it's a tough thing.
Matt Odell
Well, trying to find the silver lining in all this, I mean, it is horrible, disastrous. But something that bitcoiners have said for a while, bitcoin creates this honeypot to surface these vulnerabilities because the ability to send the bearer asset and actually have control of it with no clawbacks creates that incentive to find these vulnerabilities. And now with the AI tools, obviously that is accelerating. So I'd be interested to get your thoughts. Is there a silver lining where we're going to find these vulnerabilities? And obviously there's already been collateral damage. There's likely going to be more collateral damage in the weeks to come. But on the other side, it's darkest before the, before the dawn. On the other side, could you see Bitcoin actually being significantly more secure and the products around it being more secure a year from now because of the wake up call that we just got in the last 24 hours?
Jameson Lopp
Yeah, it's possible this could be like a step along the antifragile path to essentially discovering the final form of individual level Bitcoin security. Because it's possible that we could get to some kind of deterministic endpoint where there's a system or a set of software or an arrangement where humans, machines have done all the analysis and have said, yeah, if you do it this way with this binary on this platform, if it's simple enough, we could get to a point where ultimately this event has catalyzed a bunch of people to put the effort in and create something where you truly can't be hacked unless you get some physical component. And then even then, you know, if something like this motivates a reinterest involved. Well, even if you do get hacked, then you have a six hour window to clot into it, you know, a trusted counterparty, like an exchange. So yeah, I think conceivably this, this could be the kind of kick in the. But that the industry needed to start thinking about some of that stuff. I, you know, there's a long timeline on that and right now the community is pretty fractured. So I don't know.
Matt Odell
Yeah, I will say, I mean in terms of like protocol development, it certainly is fractured. But another silver lining. I mean it was encouraging to see people come together publicly behind the scenes. I mean, I think it was, I mean I was in D.C. at an event at Pubkey and like at the beginning of it it was like, oh, what's going on? Then it became clear what's going on. It was just like in the corner on my phone the whole night, like, all right, all hands on deck. And I think there was. It's weird too because Bitcoin, there is no CEO to call. So it's like people like Rob Hamilton Yourself, Portland huddle others hopping on spaces to try to educate people about all this. And I know behind the scenes many people reaching out, one node to many, like, hey, I wound up texting a friend, being like, hey, are you aware of this? He's like, no, I've been heads down all day. And his brother is a coiner too and was on vacation and he was able to go over to his house, he just sit on a Bear Single Sig MK3 with no dice, entropy or passphrase and was able to move it. And so that was like, okay. And I think there was much of that going on and I think that's the spirit that we need to lean into heavily, particularly as this is unfolding is obviously there's going to be a lot of justifiably angry, angry people very, very much justified. But I don't think this is the time to sling shit and throw people under the bus. It's like, okay, this is happening while it's happening, let's just make sure we get as many people into it, out of harm's way as possible.
Jameson Lopp
Totally agree. And this thing is still ongoing, so it's still critical to give people heads up and just be racking your brain for anybody who may not be listening to podcasts, you know, who has a cold card. Because I think probably we're going to continue to see, you know, funds flow around. So, yeah, I mean, it's hard to. The sentiment thing is difficult because like, there is a kind of like excitement and camaraderie that comes out of an event like this, but that we can only experience that because we didn't lose our life savings, you know, and there are people that happen to. And that's horrible. That's really horrible. It's not, it's not the worst thing, you know, if you're one of those people, God has a plan and you need to keep that in mind.
Podcast Host
But
Jameson Lopp
yeah, it's. It is good to see the community kind of reorient in certain ways and come back to, you know, the real stuff of bitcoin rather than shattering about 110 or whatever.
Matt Odell
Yeah, I think we keep the shorts or anything we missed, we should be getting out there. I mean, it's probably. We should keep it short so we can get out there to people as quickly as possible.
Jameson Lopp
No, I mean, I think we hit the headlines. There's obviously tons of technical detail you go into, but the investigation is still ongoing. So, you know, again, my headline is if you have a coin kite device, post 2021 and you didn't use dice rolls. Don't have a super strong passphrase that you know is cryptographically strong. You know, you need to expedite getting your funds. You know, my recommendation for a lot of people would be find an exchange that you trust and just if you don't mind doxing yourself, park, park your funds there while you figure out what the long term is and just kind of get out of dodge. Do a small test transaction. You know, don't, don't panic, don't, don't rush anything. But, you know, Steady is smooth, smooth is fast.
Matt Odell
Yeah. Then just to clarify, if you're sitting there like, did I roll the dice enough? Is my passphrase strong enough? If you have 99 or more dice rolls and you did it correctly, you're confident in that, you should be fine. Passphrase. If you have 6 or more bip 39 words as a passphrase, you should be good. Is that the sort of thresholds that are correct there in my mind?
Jameson Lopp
Sorry. Repeat passphrase criteria.
Matt Odell
6 bip 39 words or more.
Jameson Lopp
Maybe I wouldn't john that per se, because there are things like, are you mixing case for that? Each bit 39 word is drawn from a set of 2048. So 2048 times 6 is in a big search space. That's why passphrases are tough, because something you might think is pretty strong given enough GPUs, is not. Unless you're a specialist and you know your passphrase is like, crazy and strong, I would not rely on that. I'll be moving my small number of fractional bitcoin around, even though I have, you know, I'm not affected by the firmware version and I have a strong passphrase, but even so, out of an abundance of caution, I'm just moving.
Matt Odell
All right, well, I hate that we had to meet here under these circumstances, but I really appreciate that you hopped on to walk through this. We'll get this out and warn people about all this.
Jameson Lopp
Of course, man. Yeah. Good to see you.
Matt Odell
Good to see you too. Peace and love, freaks.
Podcast Host
Thank you for listening to this episode of tftc. If you've made it this far, I imagine you got some value out of the episode. If so, please share it far and wide with your friends and family. We're looking to get the word out there also, wherever you're listening, whether that's YouTube, Apple, Spotify, make sure you like and subscribe to the show. And if you can, leave a rating on the podcasting platforms, that goes a long way. Last but not least, if you want to get these episodes a day early and ad free, make sure you download the Fountain podcasting app. You can go to Fountain FM to find that $5 a month get you every episode a day early ad free helps. The show gives you incredible value, so please consider subscribing via Fountain as well. Thank you for your time and until next time.
Guest: Jameson Lopp
Date: July 31, 2026
Host: Marty Bent (with Matt Odell guest co-hosting)
This urgent episode addresses a devastating vulnerability discovered in Coldcard hardware wallets—one of the most trusted Bitcoin storage devices—impacting models produced after 2021. Jameson Lopp and Matt Odell break down the technical details of the random number generator (RNG) flaw, the implications for single signature and multisig setups, the role of AI in uncovering the vulnerability, and the future of Bitcoin self-custody security. They also discuss practical steps users should take immediately, larger philosophical takeaways, and the broader effects this event may have on the Bitcoin ecosystem.
Who Needs to Act?
Upgrading Firmware is NOT Sufficient: Making the device firmware up-to-date does not fix a compromised seed. You MUST generate a new wallet/seed and transfer coins.
Passphrase Security: Six BIP-39 words may be enough, but unless you’re sure your passphrase is extremely strong/designed for cryptographic strength, err on the side of caution.
On the nature of hardware wallet security:
"You screw up one thing, you screw up the wrong one thing and it's toast." – Jameson Lopp [05:25]
On AI and security:
"Security by obscurity is going to zero rapidly and everything. The tide's washing out..." – Jameson Lopp [08:46]
On the need for community outreach:
"Think about who is a sort of more normal person than maybe you are...who you've recommended cold cards to...Give them a heads up..." – Jameson Lopp [06:28]
On the potential benefits of this painful discovery:
"It's possible this could be like a step along the antifragile path to essentially discovering the final form of individual level Bitcoin security." – Jameson Lopp [36:22]
On trusted third parties:
“Trusted third parties are security holes.” – Paraphrasing Nick Szabo, via Jameson Lopp [34:46]
| Timestamp | Content | |-----------|---------| | 00:59–03:50 | Vulnerability description & urgency for affected users | | 07:45–08:46 | AI’s role in discovering the vulnerability; security paradigm shift | | 10:24–12:24 | Impact on self-custody confidence and trust in wallet vendors | | 21:33–22:01 | Why updating firmware isn't enough; must migrate keys | | 23:13–26:44 | Multisig setups: risks vs. mitigations | | 27:56–29:51 | White hat sweep: ethical and practical considerations | | 35:17–36:44 | The silver lining: Bitcoin’s incentives and antifragility | | 41:38–44:16 | Final urgent advice: criteria for safe passphrases/dice, practical advice |
This episode stands as a critical alert and teach-in for the Bitcoin community amid an ongoing security crisis. It not only delivers blunt, actionable advice for Coldcard users but also opens a broader conversation on the future of self-custody, the growing role of AI in infosec, and the urgent need for new technical and social tools to safeguard decentralization. The tone is candid, urgent, and focused on empowering users to act—while refusing to foster panic or point fingers.