
Loading summary
A
Foreign. Yo. Welcome back to another episode of the Jack Maller Show. My name is Jack. You are listening to yet another edition of Mailbag Monday. A bit of more somber and emotional show today. Just a devastating time in bitcoiners, especially for bitcoiners in bitcoin, especially for bitcoiner. Excuse me. So excuse my tone. I think it's just. It's organic, it's natural, it's reflective of real emotions. And that's what we're going to be talking about today. So really quick, before I go any further, if you are not aware, the cold card hardware wallet suffered a catastrophic bug that leaves Bitcoin stored by a seed that they have generated Post March of 2021 Vulnerable to theft if your seed may be affected. Move your bitcoins immediately off of your cold card wallet. Move it to a new wallet, move it to multisig. You can even move it to an exchange like Strike. I obviously know not. Not your keys, not your coins. But Strike is plenty trustworthy, geographically distributed multisig cold storage is what we use. Get your coins off of a cold card generated seed immediately. There are still people that had enough entropy or enough protection to survive the first swaths of attack. And there are still ongoing attacks. It is not too late. If your bitcoin is stored on a seed phrase that was generated by a cold card hardware wallet, specifically using the firmware after March of 2021, your bitcoins are seriously at risk. This is not a drill. This is urgent. Move your bitcoin to a new wallet or onto an exchange like Strike. Okay, so with that context, for those that don't know, again, cold card, one of the more popular hardware wallets in the industry, suffered a catastrophic bug which left Bitcoin vulnerable. The attacker doesn't need to know who you are. The attacker doesn't need to have access to your hardware wallet. The attacker doesn't need to know anything. And that is the problem. Just the information that this bug exists and how much entropy these seed phrases used to encrypt and create was enough. So a few things. So that's what today's episode is going to be about. Guys, no straight a horn moves today. No macro stuff, no market stuff. We're gonna talk specifically about this incident and even broader about bitcoin, about custody. I think self custody is far from dead. In fact, probably the opposite. But I'm going to walk us all there. Very logically and hopefully in an informative, educational way. Before I get started, I just want to acknowledge something I've Recommended Coldcard before Cold hey listen, I was not as religious about hardware wallet recommendations as others in the space, which I will explain later on in the episode. I still think BitKey is the hardware wallet to recommend for true beginners that want to dip their toe into self custody and multisig. I stand by that. But nonetheless, there's Unchained, there's Casa, there's Bitkey, there's TREZOR Ledger, there's ColdCard. The point is I recommended Coldcard on this show along with other hardware wallets and I'm sorry, I own that the level of negligence displayed by the coincide team, the developers of Coldcard. I'll explain later in the show exactly what the technical issue was and the mistake they made. The level of negligence for a team of developers in a company producing a product to secure your bitcoins is astounding. Is astounding. And I'm sorry. I'm sorry that it was even within the lexicon of this show and within the lexicon of how I think people should have stored their bitcoins. I mean listen again, I'm not very loyal or religious to a particular custody solution and I'll explain why in this episode. Storing bitcoin solves for a very particular problem. I do think that not enough people truly understand even the basics to give themselves a good reading on what would be best for them. But nonetheless I take ownership where it needs to be owned. The other thing that breaks my heart is the bitcoin stolen is in small tiny amounts. There's not a lot of large sweeps of bitcoin. I think I actually hadn't checked today. I should have before the show but I don't think that there was a sweep of coins from this attack. More than like 100 bitcoin at once. This is all a couple bitcoin. Majority of the coins I believe are less than 1 bitcoin and that's what just breaks my heart the most is these were are good hard working family bitcoiners did everything the right way. Followed the not your keys, not your coins, cold storage, self custody. Spent the 10,000 hours really understanding the asset class. Many of you maybe listen to this show. This is not a giant whale. This was not a hedge fund that got blown out for leverage. This is not risky shitcoin speculation. This was stay humble stack sats, you know, life savings, hopefully passing down inheritance to your kids. I mean we're talking about 0.2 Bitcoin, 0.7 Bitcoin, couple Bitcoin, seven Bitcoin and not to make a judgment on what is and isn't a lot of money. But in the prior hacks we've seen one or two whales go down for tens of thousands of bitcoin or single exchanges and central parties go down for hundreds of thousands of bitcoins. This one is so horrifying. Just because the negligence displayed by a bitcoin only business that claimed and touted otherwise, the lack of verifying that the community did on their product and their business and just who the victims are. The victims don't deserve to be victims. That's the most painful part. And the victims are people that, even if I don't know them personally, I respect, I admire. These are the people that support me, that support this industry. And it's just awful. So I posted as many alerts as I could this last weekend. I was actually at a wedding. I was at my buddy's wedding and I was every hour just taking some time away from the ceremony and going through my DMs. I had the strike support team and the security team on call this whole weekend trying to support as many bitcoiners. Whether you guys are customers or not. I mean, these are my people. These are the people that I want to have wealth when my kids are my age. These are the people that I want to be on the other side of the greatest wealth transfer of all time. And it's just, it's just true horror to watch this unfold and the victims be who the victims are because the victims just don't deserve it. And that's what this, none of this, you know, philosophically makes sense for that reason. So yeah, to the victims, I'm truly sorry. Obviously I will do everything I can. Whether you're a customer, strike or not to help. It's kind of been my life's motto, my life's mission to just be the best bitcoiner I can be. Trying to get in contact with law enforcement, introduce everybody to other companies or the red, the red team, the rob and Kale and everybody that's trying to do the best they can. Just hopefully we can catch the block team. Shout out to the block team, the bitkey team. Hopefully we can catch the attackers. I think that there are multiple, hopefully that we can recover any stolen funds and even if we can raise some money and just try again. These are hard working, real bitcoiners. They didn't take any on any leverage. They didn't do anything ill advised, they didn't break any law. In fact, they did the opposite. These are honorable People, and this is the just a very. This is a very devastating moment for bitcoin. So with all that being said, here's how I'm thinking about the show today and what I did. I could have spent. I could spend a whole year of shows breaking down how bitcoin works, talking about what cryptography is, talking about some of the technical details of entropy of 256 bits. Here's what I did. The title of this is How Bitcoin Custody Works and Breaking down the Cold Card Incident. I picked and chose exactly where I think high level knowledge is relevant. Given the moment we're in today, I'm not so sure how valuable this episode will be in five years from now. Sometimes I try and create content, whether it's a keynote or an essay that's going to be timeless and everlasting. And whether you look at it in a year or in five years or in 10 years, hopefully it's still valuable. I'm not so sure about this one, but I just want you guys to know that I kind of erred on the side of the now because I think right now bitcoin needs leadership, bitcoin needs competency, bitcoin needs education. And I'm not really worried about whether people watch this episode in a year. I just know a lot of people want something to go to and at least learn a thing or two right now. So I'm going to talk about how bitcoin works from a very high level, especially in regards to securing it, spending it. What does it mean to have a wallet? What does it mean to secure a key? And then we can obviously progress towards the different options that you can use to secure bitcoin and why I think self custody and securing bitcoin is far from dead because of this incident. This incident was extreme negligence and one of the worst errors from a bitcoin company I've ever seen. But once you guys truly understand what's going on under the hood, it's. It's actually not only far from dead, but it's arguably never been stronger. And I think as a community, we can learn a lot from this and put our foot forward and keep building. And then also once we understand these very basic concepts, I'll walk you guys through what exactly happened to the cold card firmware, where the bug went wrong and where the exact negligence was like a security engineer should have never ever written the code that was deployed to so many bitcoiners. One last reminder, this is a show for what I call Main Street. It's A show by the common man for the common man. You don't need a computer science degree to listen to this show, okay? This is very basic, bare bones, high level. My goal is to get enough people semi literate just so you can understand the conversation, both so that you can contribute to the conversation and also so that you can make better decisions for yourself. Okay? So with that being said, I will now officially timestamp this episode. I'm talking to you guys. At a bitcoin price of $63,480, Bitcoin's market cap sits at 1.27 trillion. All time high remains the same. 126,160. We're 49.7% off that high, so still about 50% down from all time highs. All time high was October 6th, 2025. Just a milestone. We've crossed 300 days now since all time high. It's officially 301 days. And the last bitcoin block mine was Bitcoin block height 960,928. All right, so let's get into this. As always, guys, please ask questions. I even tweeted and got about 50 questions from you guys earlier. This episode will go as long as it needs to go. I'm going to try and answer as many as I can. And obviously this is not the last show I'll do, so I can always try and dedicate more time now that I'm not at 21 and I have some more time. I've told you guys, I'm really committed to doing more content, more education. I don't really know how much money that will make me or how famous that'll make me, but I kind of made the point, I don't care. It's what I love to do. It's what I care about. It's the work that I think that needs to be done. And so any more educational content, any questions that you guys think I can help uniquely solve, just let me and my team know and hopefully we can do that. Okay, so the first section of this is called Bitcoin and the Ledger. And you know, the core questions that I want to answer for you guys from the high level that anyone can understand is where is the bitcoin and what does ownership mean in bitcoin? The first thing I want you guys to know, and I debated the headline of this slide because it's a little jarring, but the slide reads, your wallet does not contain bitcoin. And hopefully that is a jarring enough headline to get you to pay attention. The point is that there are no, like, literal coins in a bitcoin wallet, okay? And when you transfer coins, the coins don't necessarily leave. Like, literal coins don't leave your phone and enter someone else's phone, okay? The point I'm trying to make is the way that bitcoin works from the very highest level possible is the ledger. The blockchain only shows us what public keys, what addresses, what people have the right to spend what bitcoins. Okay, I'm going to say that again and I'm trying, going to try to. I apologize for the highly technical because I'm going to try to abstract a lot of the technical language, like public keys, like addresses, so that I could hand this episode to a grandparent and they would vaguely understand what the bitcoin blockchain, the ledger tells all of us. It's an open ledger that anybody can download, access and read. It tells you who has the right to spend what amount of bitcoin. Okay? Now, the ability to spend it is to sign a message with a private secret that corresponds to that public information. So, as you see in my slide, it says 0.5 BTC. And what the ledger is telling you is that spendable by a valid signature from X, 0.18 BTC, that's spendable by a valid signature from Y. So you can see 0.5 Bitcoin is spendable as long as you have this secret. 0.18 spendable as long as you have this secret. Okay? And all a bitcoin wallet is, and it depends on what type of wallet and what the wallet does for you. But broadly speaking, it is your ability to generate that secret and then sign these messages to spend that bitcoin. But when you spend a bitcoin transaction, when you broadcast that to the network, all you're doing is reassigning who gets to sign a new message spending those same bitcoins. So I write here, spending destroys one entry in the ledger and creates another entry in the ledger. The signer holds nothing but authority to spend said bitcoins. Okay? So the point is that Bitcoin does not know who you are. It is not like a Chase bank account where I go to Chase and I say, I'm Jack Mallers. Here's my passport, here's my birth certificate. Here's where I went to school. Here's who my brother is. How much money do I have? That is not how bitcoin works. In fact, Bitcoin has no idea who you are. The only thing that Bitcoin knows is math and cryptography. All it can do is compute. And so all a transaction is, is are you able to provide the secret that corresponds with the bitcoin you're trying to send? That's it. There is no, like, oh, the bitcoins are stuck on my phone or in this wallet or in my house. No, the bitcoins cannot be spent without the valid secret. Now, that secret might be in your house, it might be on your phone, it might be in that wallet. But you have to understand if anybody could obtain that secret, whether it's picking it up at your house, whether it's guessing it, whether it's running through a computing farm to churn through and eventually find it. The point is, as long as you have the secret. You guys understand what I'm trying to articulate here? I can't tell if I'm doing a good enough job. It's not that the bitcoins are stuck in Illinois or stuck in China. It's. They are only a ledger entry, and the ledger entry cannot be moved and reassigned without the secret. So the only thing bitcoin cares about is the secret itself that could spend the bitcoin. Okay, this is why, by the way, this is why a recreated key, like in the cold card incident, works exactly as good as the original. Because bitcoin, the network, it doesn't actually know whether you're the true owner and some other person is a thief. It has no idea. All it's doing is, does two plus two equal four? And so if the thief is able to recreate the secret that you created on the cold card, bitcoin, it doesn't know the difference. It's not like as if your bitcoins are on the cold card itself. That's why people are saying, well, I have my cold card here and I know no one else has touched it. How can anyone get my bitcoins? Bitcoin doesn't care about that. Bitcoin only cares if you have the secret. That's it. It's not actually on the cold card. The cold card generated a secret. And if anyone else is able to recreate that secret, then the bitcoins are as good as theirs as they are yours. Okay, now, what is this secret? How does the secret work? This sounds really terrifying. Can't people just guess other people's secrets? Let's get into that. The secrets are known as public keys and private keys. Now, we're getting into a little bit of cryptography. But hang with me. The only thing that you need to understand about this whole key thing is it's very, very, very, very easy to prove that you have the private secret that corresponds with a public address. Okay? So think of the public address like an email, like a housing address that you could send mail to, like a safety, like a. Like a deposit mailing address or something. Okay? It is very easy for me to prove that I have the secret that corresponds to that public identifier without disclosing the secret itself. I could create a little message with my secret, and I can share the message, and the whole world can be like, wow, Jack has the secret. He has it. Now, I don't know what the secret is, but I know that he has it, and I can mathematically prove that. Now, the opposite is not only more difficult, it is infeasible to do. Meaning you cannot take the public information and reverse engineer the private secret. It is infeasible. Okay? So you can publish the public part and you can say, hey, guys, send your bitcoins here without revealing the private part. You can keep the private part private. You can prove that you are the signer. You are the authoritative owner of whatever bitcoins have been sent to and associated to the public part. But the reverse is not true. The public part cannot be reverse engineered to the private part. And so a bitcoin transaction is only about sharing proof that you have the private part associated with the public key. That's it. Okay, so the private key is this one secret. Okay, this one secret that only the owner of the bitcoin has. The public key is the address where everyone can send bitcoins to. So let's say you buy bitcoin on Strike. You're withdrawing that bitcoin from Strike to an address. That's the public part. Strike knows the address because my infrastructure had to send to it. That address is on the public blockchain, which is verifiable and public for anybody to download, for anybody to scan, for anybody to review. All of that's public. The one part that's not public, that's a secret, is that private key that you have. What a bitcoin transaction is, is you use that private key to create a signature. It's like signing a check. Now, you attach that signature to a transaction and you send it to the network. And what the network is doing is it's. It's actually taking the ledger entry that previously said this bitcoin can be sent by this public address, and it's invalidating it, and it's creating a new ledger entry in the Blockchain that's reassigning those same bitcoins to a new public key, basically stating whoever has a secret associated with this public address can now spend these bitcoins. So you're just constantly publishing these signatures. But the key point is the private secret is never, ever, ever, ever shared with anybody. And this is the beauty of bitcoin, is that everybody can have access to every piece of information. We all know each other's addresses. Well, you know, you guys know what I mean. Not, not OPSEC wise, but every single bitcoin address is public. All of the public keys can be public. We can share. Hey, pay me here or hey, I'm going to auto withdraw via strike to here. All of that. There's so much, much information that is known to the world forever in bitcoin, except for one piece, one critical piece which is this private secret. You broadcast proof and signatures that you own the private piece, but you never publish the private piece itself. Okay, now the, the private key again never has to leave your control. And this is where we get into, well, how should I store my bitcoin? What does it mean to store bitcoin? What does it mean to send a bitcoin transaction? To store and send a bitcoin transaction? It's all about management of this secret, guys. That's it. That's it. To say that bitcoin self custody is dead would be to say that being able to store a secret is dead. And obviously for me, that's a violation of just human coordination and collaboration. If we can't safely and securely store secrets, then society as we know it will deconstruct and fail. Trust me, we are more than capable of being able to safely and securely store information. We got this. We can do it. But I needed to dumb it down. And to that very simple basic understanding, that's all bitcoin is, is when you create a wallet, you're creating one really large and one really random secret. And I'll get into why that's so secure in a second. Don't bail on me yet. But when you talk about what's a hardware wallet, what's the difference between that and this one and that and this one? We'll get into all of this, but it's really about managing these secrets. And when you need to move your bitcoin, it's using the secrets to sign a message that proves that you in fact have the secret. You never give away the secret, you never reveal the secret. Nobody can ever be able to guess your secret. But it's all about managing the privacy of the secret and being able to sign these transactions, proving that you still have the secret. Make sense? So like I said, I need you guys to take into account everything that's public about Bitcoin. So I put the slide here. The consensus rules are public. Addresses are public. Source code, wallet code. Bitcoin core is public. SEC P256K1 is public. Every address balance is public. Every transaction that's ever been made is public. The BIP 39 word list, like what your the words that make up your seed phrases are public. The signature on your last spend is public. The block your coins arrived into your wallet is public. The signature algorithm is public. SHA 256 is public. The transaction graph is public. The mempool is public. Everything is public except one thing. Your root secret. That's it guys. That's all storing Bitcoin is now. I don't, you know, for the technical, I don't want to over over oversimplify it, but just for everyone to understand, that's all storing Bitcoin is. When you generate a wallet, you're generating one root secret. And that one root secret defines whether you can sign and move bitcoins or not. Because that's what ownership of money really is. Not to stare at it on a wall. If you had to, could you spend it? And that's all comes down to this one root secret. So let's get into the secret. Okay. Why one random number can secure a public system? How the hell is that even possible? Okay, again, bear with me on the technical stuff here. If it gets too technical, you guys will leave comments in the YouTube section. You'll ask questions. Dylan's in the live chat and I'll answer. Maybe this episode, maybe next episode. But we will get there, I promise you. Okay, but bear with me when people talk about bits, okay, like a bitcoin private key or cold cards bug. How many bits of entropy? This is going to be really fun to break down because it's actually more simple than you think. One bit is one binary choice. Okay, so one bit zero or one. Okay, that's two possible outcomes. How secure is one bit? It's not very secure because it takes a human to be able to chew through the amount of potential outcomes. There's only two. The outcomes are either 0 or 1. It's very binary. So let's say we increase from 1 bit to 2 bits. Well now there's four possible outcomes because the possible outcomes are now either 0, 0, 0, 1, 10 or 11. Very critical insight that just happened right there. By going from one bit to two bits, we doubled the amount of outcomes. Doubled. Now, what if we went to three bits? We now have eight possible outcomes. And I didn't write them on the slide, but it's 0, 0, 0 or 0, 0, 1, right? And so on and so forth. Now, the point is, each new bit does not just add a possibility. It doubles the entire space of possibilities. Do you guys understand that? So you go one bit a bit. It's very binary, guys. A bit. Either 0 or 1. So if you have one bit of entropy, of security. Well, that's not secure at all, because I can guess it. Is it zero? No. Okay, then it's one.
B
Boom.
A
I have your bitcoins. Okay, let's increase the entropy. Two bits. Well, two bits now is four. So we're doubling the amount of potential possible outcomes. Three bits, eight, so on and so forth, so on and so forth. So every random bit doubles the search space. Okay, so think of it like flipping a coin. That's what I have here on the right. It's either heads or tails. So how secure is flipping once? Well, not very secure. Flipping twice doubles the amount of outcomes, because it could either be heads, heads, tails, tails, heads, tails or tails, Heads. Now, if you flip it three times, there's eight potential outcomes. Four times 16, 5, 32, 6, 64, so on and so forth, so on, so forth, so on and so forth. And so when someone says 260. 256. Excuse me, 256 bits, do you understand what that now means? There's 256, either 0 or ones. And what I have here in the slide is every random bit doubles the search space. Keyword random. Obviously, if I create, you know, 256, 0 or ones, but I say, you know, I'm going to make the first half zero and the second half ones. That's very easy to guess because it's not random. It has to be truly random. And the goal here is to create the largest amount of possible space. Makes sense, because what we need to do is create something with a surface area so large that all of the possible outcomes would be impossible to chew through in this universe to actually arrive and find our secret. Okay, so if I keep going, I want to take a second now, because the number 256 doesn't sound big to the human mind. The human mind's like, well, 256. I mean, that's not that big. And I know the number that comes after that. That's 257. The human brain cannot actually comprehend the size of these numbers.
B
So
A
I want to see. Do you see the 256 down there is 10 to the 77 down there. Okay, so what I did on this slide, that's. So that's 256 bits, okay? What I did on this slide is I said, okay, well, let's take 10 to the 6, 10 to the 9, 10 to the 12th, okay? Which is a million. A billion. A trillion, right. Just to comprehend how big these numbers are. Do you guys know how long ago a million seconds ago was? I'm just trying to humanize, you know, the size of going from 10 to the 6 to 10 to the 9 to 10 to the 12th. Do you guys have any idea? A million seconds ago was about a week and a half ago. Okay, how about a billion seconds ago? How long ago was that? Was that like a month ago or a quarter ago? No, that was 32 years ago. Okay, so the difference between a million and a billion is massive. Okay? It goes from a week and a half to 32 years. That, by the way, I'm 32 years old, so I wasn't alive a billion seconds ago. Now what about a trillion seconds ago? If you just add those three more zeros. A trillion seconds ago, Manhattan, New York City was covered under a thick layer of ice. I'm going to say that again. A million seconds ago was a week and a half ago. A million seconds ago, this cold card vulnerability had not been discovered. A billion seconds ago, I wasn't alive. A trillion seconds ago, New York City was under ice. Now are you guys understanding just the, like, the ungodly size of these numbers? It's, it's actually impossible for our brains to like, truly rack and comprehend. So let's spell out the two to the 256, like the size of the numbers that bitcoin uses. I wrote it out in this slide. I don't even know how to pronounce it. 115 quattro, vegetarian. 792 trevintillion. 89 dwarfs. It's, it's a number that the human brain can't even comprehend. Okay, now I usually don't want to
B
play too much like video on cryptocurrencies. I made two ref.
A
I usually don't want to play too much long form content on a podcast or a video that I do because people get bored. They exit out this YouTube video and the audio is going to work fine. If you're listening on podcasts, does a Phenomenal job at just conceptualizing how large the numbers are that Bitcoin uses. And again, guys, keep in mind the whole point of things being truly random in Bitcoin is you need to be creating the number in a space where there's so many outcomes, like there's so many potential numbers. Okay? Like, if it's not truly random, then the potential outcomes aren't that big. And that's what gives people an opportunity to guess your secret. So it's all about when you're generating a secure Bitcoin wallet. It's, it's all about this randomness idea. Am I being truly random? So that the amount of numbers and the space of potential outcomes is so big that there's nothing known in the universe that has enough time and enough energy to actually chew through all the potential outcomes and guess it. Now, this YouTube video does an unbelievable job at just humanizing this. It's about four minutes. And again, I would never, in another circumstance, want to play a four minute YouTube video, but please trust me on this and just be patient. It does such a good job at giving human comprehension to the size and true scale of these numbers, which then we will come back to and understand exactly what bitcoin custody is and why these numbers are so big and how this is so secure. Okay? So just bear with me. Going to mute my mic and play this. Four minutes. We got it. We got it.
B
In the main video on cryptocurrencies, I made two references to situations where in order to break a given piece of security, you would have to guess a specific string of 256 bits. One of these was in the context of digital signatures, and the other in the context of a cryptographic hash function. For example, if you want to find a message whose SHA256/ is some specific string of 256 bits, you have no better method than to just guess and check random messages. And this would require, on average, two to the 256 guesses. Now, this is a number so far removed from anything that we ever deal with that it can be hard to appreciate its size. But let's give it a try. 2 to the 256 is the same as 2 to the 32 multiplied by itself eight times. Now, what's nice about that split is that 2 to the 32 is 4 billion, which is at least a number we can think about, right? It's the kind of thing you might see in a headline. So all we need to do is appreciate what multiplying 4 billion times itself, eight successive times really feels like as many of you know, the GPU on your computer can let you run a whole bunch of computations in parallel incredibly quickly. So if you were to specially program a GPU to run a cryptographic hash function over and over, a really good one might be able to do a little less than a billion hashes per second. And let's say that you just take a bunch of those and cram your computer full of extra GPUs so that your computer can run 4 billion hashes per second. So the first 4 billion here is going to represent the number of hashes per second per computer. Now picture 4 billion of these GPU packed computers for comparison. Even though Google does not at all make their number of servers public, estimates have it somewhere in the single digit millions. In reality, most of those servers are going to be much less powerful than our imagined GPU packed machine. But let's say that Google replaced all of its millions of servers with a machine like this. Then 4,4 billion machines would mean about 1,000 copies of this souped up Google. Let's call that 1 kilog worth of computing power. There's about 7.3 billion people on Earth. So next imagine giving a little over half of every individual on Earth their own personal kilagougol. Now imagine 4 billion copies of this Earth. For comparison, the Milky Way has somewhere between 100 and 400 billion billion stars. We don't really know, but the estimates tend to be in that range. So this would be akin to a full 1% of every star in the galaxy having a copy of Earth where half the people on that Earth have their own personal Kilokougul. Next, try to imagine 4 billion copies of the Milky Way. And we're going to call this your gigagalactic supercomputer. Running about 2 to the 160 guesses every second. Now, 4 billion seconds, that's about 126.8 years. 4 billion of those, well that's 507 billion years, which is about 37 times the age of the universe. So even if you were to have your GPU packed kilogougol per person multiplanetary gigagalactic computer guessing numbers for 37 times the age of the universe. It would still only have a 1 in 4 billion chance that of finding the correct guess. By the way, the state of bitcoin hashing these days is that all of the miners put together guessing,
A
how valuable was that guys? That goes to show the mere size of these numbers. So when people say, well Jack, are we sure no one can guess my secret? Yeah, I'm sure. Like, again, like that guy just walked through. You would have to have the most powerful computer and then a giga. Amazing Google, like Google times thousands, and each human gets their Google times thousands and then their own copy of Earth and then 1% of the stars in the galaxy. And then you still would need 37 times the amount of time that the known universe has existed. And even then, every single guess is a 1 in 4 billion chance. I mean, again, guys, the size of the space, if, if. Listen, if you do it truly randomly, because again, guys, if you have one bit of entropy, then it's either a zero or a one. It's not secure. So it's all about how random, how effective your randomness is. But if it's truly random, meaning it could be any of the potential outcomes, it is like one of the most, if not the most secure things ever, because the potential space of outcomes is just unfathomably large. Like the human brain cannot possibly comprehend the size of that number. Does that make sense? And so when people say, like, well, just roll a bunch of dice. Well, in this slide, I use a deck of cards because I play cards with Dylan all the time. We play this game called golf, and it's not like poker and I'm not like a card player, but it's just like a fun game when we're out with our fiances and stuff. And sometimes someone will go on a run and get really hot and like, win a bunch of hands in a row and. And I'm usually dealing and people will be like, dude, like, you're not shuffling. Or, you know, I can't believe that the cards ended up in the same order again. And it's funny because as a bitcoiner and someone that's familiar with this math, I don't think people appreciate that if you properly shuffle a deck, it is almost certainly in an order that no one else has ever held in the history of the universe. And again, this goes to show how this math works, you see, because again, guys, if the randomness is true, and so like you shuffle properly the potential outcomes, imagine, you know, how we did. Well, one bit is 0 or 1, and two bits is either 0, 0, 1, 1, 0, 1 or 1 0. So you've gone from two outcomes to four. Now imagine doing that for a deck of cards. Like, the first shuffle could be king, king, queen, queen, right? You've got all the possible cards and you've got the two colors, the four suits, and so every properly shuffled deck is almost certainly in an order that no one else has ever held. And mind you, the key space for Bitcoin is, is still 1.44 billion times larger than that. So when people say roll a bunch of dice, shuffle a bunch of cards, and people are like, what are these crazy people in bitcoin talking about? What do they mean, roll dice? The point is they're trying. People are trying to encourage others to generate sufficient randomness. Sufficient randomness, because just like we're going through in the bits, 01 is 1 bit 0011, 0110 is 2 bits. How can I get sufficient randomness and create enough potential outcomes where the space to guess is far too large? Makes sense. Let's go on. So the point is, your key is somewhere inside of this massive space that like the universe and us humans can't even comprehend the size. And the point is, as long as it's sufficiently generated as random, it's safe. It's as safe as you can keep it. So when people say storing bitcoin is dead, self custody is dead, I disagree. Self guys, self custody's always been the same. And I don't want to make light of this incident and I'll get all the way back to what I think people should be doing and how strike does it. And also, but like for someone that's been in Bitcoin for almost 14 years now, self custody's always been the same one. Did you generate a large enough and random enough secret number, yes or no? And if you did, how can you protect that number? And then on top of that, the bitcoin space, back in my day it was only single sig. And now that nowadays we have multisig, we have key sharding. Okay, but don't let people scare you or over complicate what securing bitcoin is. Securing Bitcoin is, is just generating a secret that lives within a space of a large enough amount of potential outcomes. So it has enough randomness, it has enough entropy and then being able to keep that safe, that's it. Again, I don't want to oversimplify it. I don't want to mislead. This is for educational purposes only. But you know, you guys, that's it, that's how it works. Okay, so this is what a private key looks like. And again, this is for illustration purposes only. Don't ever, ever use that. But this is what it looks like. It's one line. And nothing about the line is particularly special. But everything about it being Unguessable is the point. That's the whole point. Okay, so now if we go back to Bitcoin wallets and how they work and what you guys are accustomed to seeing when you download something on your phone, what is actually happening under the hood is someone is creating this root entropy, this really, really large and really, really random number, okay, that is able to be converted to and consumed as seed words. Those seed words are the root of your wallet. And then from there you can sign messages, you can have addresses, so you can create an address from that, send funds from Stripe to that address, and then if you need to move funds from there, you can sign transactions and publish those transactions to the Bitcoin network. But that's a Bitcoin wallet, guys. Again, I'm not encouraging everyone to make their own Bitcoin wallet. I'm not encouraging everyone to oversimplify all of this technology educationally. Don't let people make this more complicated for you to say like oh, humans are never going to be able to self custody Bitcoin. It's can we generate a sufficiently large and a sufficiently random number, yes or no? And then can we keep that secure and build software around that that makes it usable? That's it guys, that's it. That's what Strike does. That's what Coinbase does. That's what bitkey does. That's it. That's it. Okay, I really hope you guys understand. And let's go back to. Well, when people use the term in Bitcoin secrets or passwords, are these secrets human chosen like the thing I'm using for my Gmail account? No. Right? And now you guys understand why. Because words or quotes or just what the human brain can comprehend and produce itself is way too guessable. And because an attacker searches what people usually pick, right? The whole point is finding a space of numbers that is so unbelievably large, then in order to chew through all the potential outcomes, it's impossible. It's impossible. And again, nothing in life and in security and in Bitcoin is ever like super duper guaranteed, right? Like it's, it's all probabilistic, but it's infeasible, right? This is why dice generated entropy are card shuffled entropy. The point is, how do you find sufficient randomness, which in itself is difficult, right? And different wallets have different ways of doing it, but it's how can you be sufficiently random to generate this really really really large number that's really, really, really, really random, that is infeasible to guess okay, now let's start to dig into cold card. What's going on today and what happened. So I want to show you guys something. At the top, okay, is a 40 bit internal state. So this is what the cold card, what the. The. The level of randomness and security that the cold card, MK3, the one that was the least secure, that's what it was generating. And at the bottom is 256 bits of independent entropy, which is like what you want. Okay? What you notice is they look the exact same. Now these are illustrative values. These are not. This is not the. Again, I'm just trying to make a point here. But the length just tells you how the number is written. Okay? The length just tells us it's 256 bits. The entropy tells us how many possibilities an attacker cannot rule out. So the reason that all of this is happening is because an attacker realized that the cold card was only using a 40 bit internal state. Level of entropy of randomness. That's why all of this is happening. But do you see how when people say, how did this go on for five years and no one noticed? Well, the point isn't. How do I articulate this? The point isn't that a less secure secret looks different. They look the same. But why they're weaker is because the amount of possible outputs is significantly less. So what I have Here is this 40 bit internal state. That's only around a trillion possibilities, which for a normal computer is not that many. You can chew through a trillion possibilities fairly quickly. You know, we're seeing instances of cold car generated seeds being wiped and swept in, you know, minutes, in 10 minutes, versus if the amount of possibilities is generated correctly. We just went over it, like, there's not enough. Even if you had 40 universes and thousands of Googles for every human, and every human had an Earth with 1% of the stars in the galaxy, you still wouldn't come remotely close. That's the difference again from a million seconds versus a billion seconds versus a trillion seconds. Just these exponentially large numbers are way larger than you think, okay? And so here's another way of visualizing this stuff. If there was only ever six possible inputs, the point of this slide is that the randomness has to be solved in generating the secret. And all of the things that you guys saw from the cold card, like seed phrases and the addresses that those seed phrases were able to generate and the messages that they were signing for the bitcoin network, there was no way for anyone to be able to distinctly look at any of the public information and be like, oh my goodness, there's something wrong with Coldcard because all of the public information, again, the format remains the same. The problem with Coldcard is there wasn't enough randomness, meaning there wasn't enough possible outcomes that an attacker would have to sift through. The space that they can start guessing was so small that for some of these seeds, it took them 10 minutes on a MacBook, you see. So, going back to just how bitcoin works in cryptography and why this is so cool and hopefully inspiring if you think about the physical world before bitcoin, if you apply enough force to anything, you can and will open anything, like a door or a gold vault or a country's border. If someone shows up to your front door with the military and a gun, or a police force or the FBI, they will get in and take over your house. Same thing to your gold vault, same thing to your country. Bitcoin's treasure chest is designed very differently because it's math strong. Cryptography inverts the power balance. This is why it's so cool. It inverts the power balance of the physical world. It doesn't matter how many people show up to my house with a gun or to my gold vault or to my country. Good luck guessing my number. Fuck you think Go through the mental exercise of trying to think of something that's that secure. Because pretty much, if I show up to someone's house with the military, it's now my house. If I show up to someone's country with the military, it's now now my country. If I show up to someone's gold with the military, it's now my gold. But if the military shows up, I say, well, what do you want me to do, guys? You could kill me, you could kill my neighbor, you could take over the land. But you're never going to guess that number ever. That's why cryptography is so cool. Only if it's implemented and done properly. Only guys, it has to be a, a large enough in a random enough number. That's it. That's the most critical part. You cannot that part up because going back to the one bit, if you secure it with one bit, how easy is that to guess? It's either 0 or 1. So when cold card 40 bits, 40 bits isn't nearly enough, not nearly enough potential outcomes. An attacker can guess that number because the potential outcomes, the space of probability just was not big enough. This is why Julian Assange said no amount of coercive force will ever solve a math problem. This is the cypherpunk idea. We finally have technology resistant to force, to weapons, to violence. You can kill me and put a gun to my head, but think about it, guys. If you walk into my house, you put a bullet in my head. Okay, you got my house. Now. Good for you. Okay, you got my gold too. Okay, you got all my hoodies and you got my fridge and you got my workout equipment. Guess what? You can't guess my number. The only way to guarantee you don't get my secret is by killing me. Because you need me alive to figure out what the secret is. That's the power of large numbers and cryptography. You see, that's what's so inspiring about this strength in numbers. That's what bitcoin brings. And by the way, how accessible is math and numbers? Everyone on the planet can use math, use large numbers and share information. That's why bitcoin's the most accessible monetary system in the world. And it's the safest, with the most distilled property rights. Because as long as you have a sufficiently large and sufficiently random number, you are secure. That's it. No military, no state, no corporation, no nobody can guess that. As long as you generated it correctly and you kept it safe, you're good. That's what self custody is, by the way, guys. That's never going to die, ever. And if you are storing your coins with someone else, all you're saying is I trust you in the number that you generated, in the randomness that you used and I trust you to secure these secrets. That's all you're saying. You understand? So now let's get into the cold card. Cold card failure. Because the terminology I used on the slide here is that the lock itself wasn't broken. The key maker failed at making a good enough key is what honestly happened at the end of the day. So let's walk through it. A hardware wallet. Theoretically, now that you guys understand how bitcoin works, which it's really just about safely and securely generating this secret. Again, I don't want to oversimplify it, but if I were to dumb it down for the layman on the street, that's it. And a hardware wallet has really three jobs. If I were to distill it down to three. One, generate. So create a root secret so large and so random that nobody can predict it. And we just went over that. That we can use cryptography and just massive numbers that the human brain can't even comprehend. The second job is to Protect that root secret. So you keep that root secret away from untrusted network systems. So one of the dreams of a hardware wallet is it's not something that persistently lives on the Internet, which is online and within a broad network, a broad public network. So it is something that you can put in a safety deposit box, that you can put under your mattress, you could put in a vault in your house. And then the third job is it has to be able to sign and authorize transactions. Because obviously there's no point in owning bitcoin. That's stuck. Eventually none of us want money for the sake of money itself. Like you don't want dollars for the sake of the paper or bitcoins for the sake of the bytes. You want what money can get you as much as we want to hodl and everything eventually at some point, the whole point is that it gets you a bigger house, it gets your kids a better life, it gets your wife the dream, whatever the fuck backyard. So if you can't sign and authorize a transaction that you actually own the root secret that corresponds with the ledger entries on the blockchain. So these are technically the three jobs in cold card for failed at the first one. So what, what did cold card fuck up now that you guys understand from a high level how bitcoin works? It fucked up at generating that root secret. It did not generate a random enough number that nobody can predict. The one true job of owning bitcoin, it fucked up. Like I hate to be that blunt. Honestly, I take that back. I don't hate to be that blunt. That's what happened. I have to call it how I see it. The one job of a bitcoin wallet, the first job, create a large enough in random enough number. That's it. And they fucked that up. So let's get into some of the technicals of what actually happened because I haven't seen too many people talking about it, at least what I consider to be reasonably accurately. So I'm not. Again, it's interesting decision on my part because I'm not like a highly technical show. This is for the streets. But I think you guys will be interested in this. So what happened is there actually is the. How do I dumb this down? The cold card could have actually generated a large enough and random enough root secret for bitcoiner storing bitcoin. It had the capability on the device. The problem was it was turned off, which I'm not going to spark conspiracy theories because I actually think that this was a genuine software bug. After taking A look at what happened and reading a bit. But the point is, and a very like novice catastrophic. I mean, the level of incompetence here is really difficult. I really think coldcard owes, when the time is right, coin tight owes the community a postmortem here because I'm having a tough time comprehending. Listen, people write bugs all the time. So much of security guys, which we'll get into in a second, is not doing everything perfectly all the time. It's designing systems that inevitably, when shit goes wrong, it's still okay. That's security in a nutshell. Okay, so why was, why was it set to zero? I don't know, but people write bugs all the time like it's. It's okay. The problem is the cold card then fell back. Like, like think of the device going, oh, oh, the, the true. Tried and true and random enough. Entropy is turned off. Well, plan B, I'm going to fall back to this other one, which was awful, not nearly random enough, and inevitably lost a bunch of people, a lot of Bitcoin. But it's the mere fact that the cold card had a fallback in the first place that wasn't nearly random enough, because like I said before, just because it's not nearly random enough doesn't mean it won't generate and it won't actually create valid seed words. And those valid seed words won't be able to actually work on the Bitcoin network because, like I said, the format itself doesn't change. What changed is the amount of potential outcomes and possibilities of the numbers that cold card was generating. Does that make sense? So it had a. It had a plan B. It had a fallback to something extremely weak. And the, and the incompetence is, as a security engineer, how you failed silently, you cannot do that. So let me explain what that means. What happened is the entropy was defined, the secure randomness was defined, but it was not enabled. So check A. So again, this isn't too technical, but just imagine this check A in ColdCard is, is the hardware RNG, which is this again, enough randomness? Is the hardware's randomness flag defined? Does it exist? And the answer is yes. Now, the problem is, is the hardware's randomness flag enabled? And it was no. Okay, so when they were testing the cold card and you'd get a green light, like, is the hardware's randomness defined? Is it there? And it would come, yes, test passed, it's here. And they say, okay, that's good enough. And then it would produce seeds and it would work in the Bitcoin and everything looked normal and no one thought to look for, well, is the hardware randomness enabled? Not just is it there, but is it enabled? And let me tell you guys something. You cannot fail this way as a security engineer, so. Meaning this, a device that generates a weak key, a weak secret in silence, is far more dangerous than a device that refuses to generate one at all. So the problem is not that someone accidentally disabled it. Really. They set the value to zero, it looks like in the code. Okay, again, like I said, people make mistakes. When you're a security engineer, that has to result in a fatal error. What I'm confused by and what I don't understand, and I think what Coinkite is going to have to explain to somebody someday is why there was a fallback to something that was not nearly secure enough. Do you understand What I'm saying? Said in human language, is if the ability to create a large and random enough number fails, then halt, stop, freeze, break. Don't just generate a weak random one instead. That's the thing. Because bugs happen all the time. But this is an idea in security engineering called fail closed, which is, you do not. You do not fail silently like that. Silently meaning, well, we'll just generate one anyway. That's really weak. That's the incompetence that I'm struggling with. It's not the fact that it wasn't enabled because, like, I'm telling you guys, that shit happens. But this is more like best security practice is, is the software has to work a very specific way. And if it doesn't, don't build in fallbacks. Why are you falling back to anything? It either has to work the right way or it shouldn't work at all. Because giving people weak seeds is far more dangerous and catastrophic than just doing nothing. How much better would Bitcoiners be if the fucking device just said, sorry, I'm not working right now. Why the fuck was a fallback implemented? That's the part that I can't understand. It's one thing to write a bug, Fine. You run the thing and it says, I'm not working, I'm not working. And then you dig into it and you realize, oh, shit, there's sufficient randomness on the device. It's defined, but it's not enabled, it's not turned on. Fail, fail, fail, fail. Why it fell back to generate something so weak. And again, part of being secure and part of security and security engineering is being humble and carrying humility. Okay, so it is dangerous to Cast stones, like I said, because everyone makes mistakes. And the goal of building secure systems is actually not training to be perfect, it's training to be secure, despite things going wrong. So I, I am not sitting here, you know, and there are way better. I'm a CEO now. Okay. There are way better security engineers that I would love their opinion on. But my people want to know my personal take on where the incompetence was, Potential incompetence, right. Like, I don't know. I. We haven't heard any of the story. It's not that the secure randomness was disabled. Okay. Again, of course it should have been enabled. I don't understand that. But things. Shit happens. It's this design decision to have implemented a fallback, like you must fail violently in this type of engineering. You cannot, you'd rather fail and break in the, in the software, just crash, than give somebody something so weak. A device that generates a weak key in silence is more dangerous than a device that refuses to generate one at all. And so that's what happened, guys. The one job of a wallet is to create a random enough route. And, and the cold card didn't do that. And so you can see here the MK2 and the MK3, it's estimated. And these things are changing, so don't hold me to this, but the point which you guys will get is, you know, two to the 40th, it's just, it's not nearly large enough number and, and random. It's that combination of big and random, right? Because you're trying to get as many potential outputs as possible. Obviously, if a human were to do it, it wouldn't be as random as rolling dice, shuffling cards, whatever. Like true randomness, true entropy, right? And that's why when you, when you hear people say, well, the MK4 and the MK5 and the Q, these were the later models of the cold card. When you hear people say, well, those were a little bit more secure, but not secure enough because the randomness actually improved, but only by a little bit. So that's why you saw certain devices get wiped immediately. And someone seemingly was able to do it with an AI program, maybe on a laptop. And then the later devices, it took some time because you had to get enough compute, enough like it actually took a decent amount of compute to go through the amount of guesses required to find it and crack it, but it's just not random enough. It had to have more randomness and they failed at that. But I need you guys to understand something. Bitcoin did not Become less secure. Bitcoin did not get hacked. And cold storage self custody for itself did not have like a catastrophic design error. It was one company up at the one job they had. That's why people say, well, is it the same for Trezor at the same for Ledger? Now we'll get into do. Should I be recommending and telling people what to do? I'll get into that in a second. I'm not going to sit here and tell you guys, oh, Trezor's really secure. They're as secure as the how large and how random their number they generated is. And that's why we encourage people to open source as much as they can. It's why we audit code bases. This is why. And we'll get into best practices and what I would recommend and stuff. But back to the point, you know, is what happened to cold card? Mean Ledger is insecure. According to ledger, they say no because our numbers are large enough and random enough. And here's our proof. Trezor said the same. So how is this only a cold card specific issue? It's a cold card specific issue because it comes down to how they were generating that root random large number. That's it. That's all that happened. I'm not belittling what happened. It's fucked up, it's terrifying, it's sad, it's horror, horror for, for bitcoiners. But let's not, let's not misconstrue this to like, oh, it broke self custody. No, no, come on, guys. Can we generate large random numbers and can we secure those? Come on, for the future of money for our kids. Can we do that? Come on. Yeah, we can. Come on. Yeah, we can.
B
Okay.
A
So anyways, the, the issue was introduced into the cold card firmware In March of 2021 block published technical analysis identifying this RNG. So this randomness fallback issue, it's really this issue about falling back. Like I said, if they shipped a bunch of customers hardware devices and the hardware devices were just like, sorry, I can't do what you bought me for, people would be pissed. But I mean they wouldn't have lost their life savings. So it was this fallback issue that was August 1st. August 2nd, Coin Kite then validated it and we're able to watch the hack go down in real time. This episode's happening on August 3rd and this issue is ongoing. So if you're listening to this fairly real time, please take a look at how you what wallet you're using as. Just check it's not cold card. If it's cold card, get it off. Deposit to strike. Deposit to strike for the time being. Okay, now let's get into. I have this last kind of chapter for what are better practices? Because people should know. What is multisig? What is key sharding? What are ways to ensure randomness and do this the right way? I want to say something real quick here, and I know this is a long episode, guys, but I think it's worth it. And if you're here for macro and markets and stuff, come back next week is what it is, right? Is what it is. But you know, you know, bit. Bitcoiners need bitcoiners right now. Okay, so now that you guys understand how Bitcoin works from a high level, it's just about generating a large enough and random enough root, secret root number and protecting that and being able to use it to sign transactions when you need to. Okay, that's it. Now, advising on what people should use and should do. That's why I've never been big on that. What I've been big on is I've built my own financial service in STRIKE that does all of these things incredibly well. If you want to use a financial service, that means trusting me and us. Now, if you don't and you want to do things your way, which is incredibly valuable. I am not implying that everyone needs to use STRIKE or that's the only way it becomes interesting on what to advise, because it depends on your use case. It depends on what you're optimizing for. Is multisig better than single sig? Well, it depends. Multisig's more complicated. So, yes, it improves certain areas, but it makes it easier to fuck up and fail. Because Bitcoin that's stuck in a contract or in a setup that can't be moved ever again is also lost. So it depends. I think multisig is great. STRIKE uses geographically distributed multisig. But why I've never been religious about recommending things for others is because once you understand it's all. All it's about is generating a large enough and random enough number and securing that. Well, what then? What's best? Well, depends. Depends on what you're trying to do. For example, I'll tell you guys this. If all you're trying to do is store Bitcoin and rarely, if ever, touch it or move it, you could just buy a laptop and run Bitcoin core. Boom. Keep. Keep the laptop offline, never connect it to the Internet. Like spin up a bitcoin core node. By the way, when we talk about code bases that have been reviewed to death, like, clearly not enough eyeballs were on the cold card firmware source code, right? There weren't enough people reviewing the cold card firmware. What's the most reviewed code base in the bitcoin ecosystem? Bitcoin core. That's why oftentimes my advice is like, listen, if you're not trying to do something fancy, because let me say this, ColdCard had a lot of features and the features were great and people geeked out on the features and that's fine. But me, I use Strike if I need to send a lightning payment. If I need a hot wallet for any reason, obviously I trust Strike because I built it. And like, when people say, do I self custody? I mean Strike is technically my custody. I have different custody than Strike. But I also use Strike to custody. So you can get why, you know, I love Strike. And there's a lot of other bitcoiners around the world. There's millions of people that have Strike account and they do the same. So I wasn't on cold card, you know, using all the features and doing all this crazy shit. I have cold storage just to, like store the coins. That's it. They just need to be protected. Bitcoin core. Bitcoin core. Why? One reason is because, like I said, it's the most audited, actively reviewed code base in the entire ecosystem. So this is the problem is like, do you need a hardware wallet even? It depends on what you're doing. It depends. And now that I really am, and this was before the cold card incident went down, I'm so motivated and dedicated to doing more content and trying to be more of a leader and just helping people. It's not even telling people what to do. Because the other thing, Cold card never paid me. Anything you guys want to talk about? I have no sponsors on this show. And this is one of those reasons, like, it's. It's just authentically me. I don't want anyone to be paying me to tell me what to say or tell me what to promote that shit. That you guys can come here and know that I'm just genuinely trying to do my best. And I'm not like, paid from. I'm not paying my mortgage, selling you a product. Okay? So nobody paid me to say anything about anybody. Just it ultimately depends. And I'm very, very committed to not even telling people what to do or getting sponsors and telling people to use my sponsors. It's just education of like, okay, at the end of the day, you need to generate a large enough and a random enough number. Here are the different options to do that. Here's what each option is optimizing for. If you're just looking to store Bitcoin, an offline laptop that you spun up Bitcoin core, you created a bitcoin address, you sent the bitcoin to it. Unplug that shit, keep it offline. That's the most audited and reviewed code base in the whole ecosystem. There's no such thing as not enough eyeballs on Bitcoin core. I mean, there's always a shortage of developers. Come on, come on. Don't misconstrue my. Always a shortage of developers. You guys get it? But it's the most actively reviewed code base. You know, I'm saying now there's definitely a market for hardware, wallets, 100%. And like, is everyone gonna buy a new laptop? Like, is that the mainstream way? No. Is bitkey bitkey the mainstream way? Maybe. Is the mainstream way. Like, you understand what I'm saying? Gotta understand, at the end of the day, the job to be done. The job to be done is a big enough, random enough number. Many, many ways to do it. Many ways to do it. Okay, so let's get into some stuff. Multisig. So here's what you guys need to understand about multisig. Multisig changes the fact that once your. Your secret is compromised, it's over. Whoever's able to recreate that secret or get access to that secret or find your secret, it's over. Because what multisig does, it requires multiple keys. So what is a very frequent solution is what's called a two of three multisig. And what this does is it requires two of the keys to move Bitcoin, not just a single one. So what you guys will hear as you are researching this and you're on Twitter, you'll hear people say, single sig, multisig. Single sig is in reference to one large random number, and it's a single sig. So once it's signal signature. So once you are able to produce a signature, because you have either guessed or stolen or hacked or whatever, that large random number, you're good. It's over. The Bitcoin is whoever is broadcasting that signature. Now, what multisig does, which is fascinating, is it requires two. So if one of them is compromised. So let's say you had a multi sig, where you created one with a cold card, one with a ledger, one with a treasure, you're good because, yes, the cold card's compromised, but that's not two, that's only one. You, you need two. You need the cold card and the ledger or the cold card and the treasure. And so you're okay. And so what this does is it addresses security in a slightly different way. It says, again, guys, remember, security is about humility. It's about being humble. It's about saying, what if something goes wrong? Or am I still going to be okay? And this is why I recommend multisig, and I think it's a great option. And geographically distributed multisig is what Strike uses to secure coins, is it's. Well, you need multiple secrets to move the coins and it could be as many as you want. There's two of three, there's three of five, seven of 11, right? And what this does is it allows a key to be compromised. It allows one of these large random numbers to be stolen, theft, guest, and you're still okay. That's why multi sig is more redundant now. It's also more complicated. So some of the problem now, I have to be honest about the pros and cons. People have tried to set up multi sig themselves and they've accidentally set it up wrong. And all of a sudden your bitcoin is locked away forever because you set up the software in a way that you can never move the bitcoin ever again. So it's more complicated, pros and cons to everything. That's why companies create solutions for this type of stuff. That's why strike exists. Okay? Experts can do it, but that's what multisig is. So again, single sig, one affected key, one signature required, you're toast. Multisig, if one key is affected, you still have the other two. You're good, you can swap that one key out and life goes on. And then obviously, if two keys are affected in a two of three multisig, then the multisig fails. But the point is, you're creating redundancy to failure. Because again, guys, being secure is all about. It's not about being perfect. It's about how can I create an environment where things can go wrong and I'll still be okay? You see, that's what being secure is. That's people. Only the paranoid survive, right? What could possibly go wrong? Skip that, okay? Another thing you'll see is sharding. So sharding is. So you have these keys, so you could have a 2 of 3 multisig, and sharding is distributing the key itself. So it's one signing authority. So one key distributed across people, systems, locations. It changes who can actually reach the key and how hard the key is to assemble, to sign. So not only can you distribute the keys, you could say, I'm not going to have one key. I'm going to have many keys and I'm going to require multiple keys just to move the bitcoin. You could say, I'm not going to have one person own one key. I'm going to have 12 people combine, make up for one key. Where you need at least seven of the 12 people or something like this to make up one key. And then you need another 20 people to make up the second key. And so you can do very fancy things, which again, just implement fail safes, which just implement redundancy. What if something goes wrong? What if one person gets hacked? What if one person gets a gun to their head? So there are many ways to take these really large, really random numbers and protect them. Now, this is not an advertisement for mainstream, I'm not solving mainstream self custody on this episode. Education, education, brutal honors, honesty, leadership. Okay? Just like, hey, this is what's going on. This is how you can understand it. What questions do you have? Here's the information necessary. And let's just take one step further at a time. Maybe this, maybe this episode doesn't get the most views. That's okay. Some people will learn some stuff. You guys will ask questions, you'll give me feedback. We march on. We march on. We march on. Okay, and so lastly, something to, to think about in regards to custody. Custody has two enemies, okay, to think about. One is theft, so someone else gains authority to your secret. Okay? So predictable key generation is what happened at cold card malware. An insider job, some inside compromise, physical extraction of the secret. The other is loss. And that's the other thing that we, you know, we have to be careful of. We have to make these tools easy, we have to make them accessible because if they're too complicated, people are going to lose the bitcoin, which happens. I mean, it doesn't happen as frequently anymore because the space, excuse me, has gotten so much better with tooling and companies and projects. But you know, back in the day it was very easy to lose bitcoins because if you set it up wrong, you're like, oh crap, I set it up in a way where I can't move the bitcoin because I don't have the right secret, you see? So really good bitcoin custody. Both keeps bitcoin inaccessible to attackers. And recoverable by its rightful owner. That's like the way that I would think about storing bitcoins myself, which is, what are we doing to prevent attackers and what are we doing to ensure recoverability by its owners? And that's, well, let's multisig. Well, let's do key sharding. Well, let's do. Let's do. Let's do, let's do. And you're adding, you know, when I say geographically distributed, that's what I'm saying is like, well, what if you're able to keep these things in different places so that it's not all down to one geography? And so this slide custody is a stack, it's not a product. Okay, so you've got recovery operations, key protection like sharding or geography or access. You've got multi sig. And then the generation, and the generation again, just a reminder is where cold card fucked up is just generating like the, the, the severity of this issue in the level of error here again, is hard to comprehend because you're like, well, where. Where did they screw up? Was it in the operations? No, no, it was literally in generating a large enough and random enough number. It was like the very basics. Bitcoin 101 is where they messed up, unfortunately, super sad for everyone involved. So it all comes down to strong enough, random enough number. From there you build up. From there you build up. So in recap, in summary, the bitcoin ledger records the bitcoin, okay? The randomness makes this key undecable. Multi sig makes one key insufficient, and distributed control makes one person, machine or location insufficient. Recovery makes failure survivable. Everything can be public except that one root secret. You gotta get that part right. Okay. All right. In regards to Strike, listen, I. I will say kind of it's a little disheartening that Strike hasn't been mentioned as a place that does custody well, or, you know, I mean, we do. I think I. I think I need to talk about it more. And we as a company need to talk about it more and promote it more. So just to be clear, Strike is unaffected. Incredibly safe, incredibly secure, geographically distributed multisig. Now, I can't get. Or, of course I can. I don't want to talk too much about some of the details because at a certain point, you're severely disadvantaging yourself versus providing trust and comfort to customers. So I saw a lot of you guys like, well, what are you guys doing to protect Bitcoin? How do you secure bitcoin? I am working with the Strike team, our technology team, our security team, on the best ways for us to answer these questions without, you know, potentially, I don't know, just carelessly giving away information that we probably, we just shouldn't, to be quite honest. So I'm curious what questions you guys have, if I can answer them today. And we're, we're trying to do a lot more, like I said, content, blogging, promotion and just about our services and the quality of our services. And the other thing I will say is we are taking a look at custody products just based off the back of this event. And people, I mean, so many customers ran to strike in the wake of this event. I mean, we saw hundreds and hundreds and hundreds of millions of dollars of deposits. Again, what was disappointing to me is I saw people showing like, oh, this is how many deposits Coinbase got in the last 24 hours. And no one mentioned strike. And again, I think it's because, I don't know, people don't think of us that way. Or I don't talk about the custody technology that we've built or something, maybe, I'm not sure, but who knows? I mean, I didn't see a lot of people mentioning Cash app necessarily and they've built a lot of amazing things. So maybe it's just a brand thing that I need to work on. But we're going to be blogging a lot more, producing a lot more content, technical stuff just to give customers enough information to know we do things the right way. And we're doing bitcoin custody well. And obviously I want to be able to promote and encourage you guys to do custody yourselves and hopefully just educate you enough to make decisions on your own. And if Strike can build products like, we're taking a look at collaborative custody, we're taking a look at multi sig solutions that we can help provide. I mean, we have all of the infrastructure and all of the licenses and distribution. To be honest, we never really got the demand to do things like proof of reserves or do things like some of the custody products. I mean, people tell us to build things all the time, but there wasn't that much noise about some of this stuff. There is now. We'll see how long it lasts. Obviously we'll see how persistent it is. Obviously this is all happening in real time, but we are taking a look at custody and just the brand and the messaging and how we talk about ourselves just so that people know we're safe, secure, in an amazing place to do all things Bitcoin, not just buy or get. Or get a loan. Another thing I wanted to say regarding Strike, this hack seemingly involved AI a decent amount more than other hacks in the past because AI is so new and prevalent. So I wanted to show you guys. No, not that I wanted to show you guys. I tweeted yesterday that Strike we built. So we've been running this. People are like, oh, did you build this? Yesterday? We built an Agentix system that reviews our code base daily using Frontier AI models, including Kimik 3. We've been doing this for months. So every single day, a bunch of AI models attack our system and try and find vulnerabilities, try and find threats, try and find insecurities. Because it's one thing to do Bitcoin well, I think it's increasingly important to. To do AI well. And doing AI well has grave implications on security too. And so we'll be writing about this and publishing this too, and just not only how we do bitcoin well. And I really want to hear from you guys what type of Custody products Strike can offer you that would grow your trust, make you feel safe, you know, like sleep well at night technology, if, you know, if you don't want to do the hold your own large random number yet, what we can do, whether that's information, blogging, content, videos, actual products like collaborative custody, collaborative institutional, collaborative custody, multisig, all sorts of stuff we can do. And then we're going to do a lot on the AI side of just how we are using AI to actually harden our systems and better our systems, as opposed to people feeling scared that AI exists. So just wanted to shout that out as well. But I'm incredibly proud of the Stripe team. I mean, like I said, we saw. I think we saw a quarter billion dollars of deposits in like 36 hours or something of Bitcoin. And the whole team, whether you guys are a customer or not, was all weekend answering tickets, answering DMs. I mean, I was in and out of this wedding, trying to help the best I can. And our service stayed online, stayed available, stayed secure. We continue to iterate and innovate when it comes to the intersection between Bitcoin and AI. I think I just need to talk about this more and we need to brand it a bit better. But incredibly proud of the team and just all the work that they've done up until this point and that we're doing actively and that we'll do in the future is just really proud moment as a founder. So as much as this sucks, I'm glad that Strike was a beacon of trust for a lot of bitcoiners around the world. And that when times get tough and people get scared that they feel like they can come to me and come to us and come to our services. Okay with that, let's do some Q and A. I know this is already a really long episode. Like I said, apologize if you're not too interested in this stuff, but it felt really necessary. Let me blow up my camera here and pull up Dylan's questions. We've already spent over an hour and a half, so I don't know how much more time we'll do, but I'm gonna just try and chew through as much as I can, guys. I mean, fuck it. Let's see. Okay, let's do it. Jack, I'd love to see someone like you make a YouTube series on self custody. Most importantly written so anyone can understand us. Non power users are now paranoid since the cold card incident. Yeah, man, listen, I get it. I feel so bad for not only the bitcoiners affected, but all bitcoiners because it introduces a level of paranoia and fear that is hard to live with. Especially if you're a big believer in so much of your life savings is in bitcoin and you just can't live with that level of stress. So hopefully this episode was useful in what this is all about. At the end of the day, it just comes down to Cold card failed at the one core job of any bitcoin wallet. Securing any bitcoin which is creating a large enough and random enough number. And they fucked that up in a preposterous way. So that's what happened. If it makes you feel any better, that's all it is. And Trezor and Ledger and everyone in the community is going about proving that they're ability to generate this root number for your wallet is sound and good and open. Sourcing any any software that previously wasn't and battle testing it with these frontier AI models. So it has been encouraging to see the industry rally around this incident and support each other. There's so much time we spend fighting, which I don't think is bad. I think it's necessary and good. But in the moments when where it's needed, we have each other's backs and that's been cool. And so yeah, strike safe and secure. Many other bitcoin exchanges do an incredible job and build incredible technology and they seemingly are safe and secure. And Trezor Ledger, again, I don't want to guarantee anything because unless I've done the work or built it myself. But it's all about doing your own research, trying to verify your, your best. You know, feel free to reach out to the support staff of these companies and say, hey guys, point me to the proof of entropy used to create my root secret. And they should be able to do that. Right? And like I said as well, you know, if this is a question of, well, the cold card firmware code base just didn't have nearly enough review or there just wasn't enough battle testing. Like what is the most Jack, what's the most battle tested Secure software in Bitcoin? Bitcoin core. Bitcoin core, you know. So anyways, I do plan on making more content. So like I said, I'm gonna spend a lot more time on this show, potentially do episodes with guests. I know a lot of you are like, don't do that. I like the Monday just you. The Monday just means not going anywhere. But, but it's can I have interesting guests on? Can I create series tutorials, written content? I wrote a really long essay, but that was more introspective and philosophical. That wasn't educational. So I don't want to like run in a million directions at once because then none of the content will be good at anything. It's all about quality and focus. So I'm just trying to get my bearings a little bit. Like I need a new mic, for example. Got to get that done. But yeah, more content on the way for sure. Single sig question, given this hack, how do you feel about single sig devices such as Trezor? Can we still trust them even if they have good entropy? Is multi sig going to become more important? Yeah. So, you know, hopefully you guys can start to answer these questions on your own. Single sig is as secure as that one large random number. So one, is the number large enough and random enough. Two, can you, can you secure it? Can you keep it safe? And if the answer to that. I know bitcoiners that have hundreds of millions of dollars of bitcoin that have been securing their bitcoin on a really large, really random number for over 10 years. Single sig. It's very simple. It doesn't involve multisig and other software and potentially it up and all this. It's my number was random enough and large enough and I can secure it. So I'm good. I and I know plenty of bitcoiners that are good there now if you want to build redundancy to that. Multi sig has been growing in popularity with every year that's gone by because it builds that redundancy. Well, if one of these goes wrong, well, at least it requires two. So if someone steals one, they can't steal the money. If I fuck up one, if I lose one, if I spill a drink on one, well, I'm good. And there's two of three, three of five, so on and so forth, so on and so forth. So, yeah, and now there's, you know, institutional collaborative custody, where it's like, what if strike holds one, another institution holds one, and another institution holds a third. So not only is it you need two keys, but you need two institutions to sign off and move your money. So not only is one key compromise, but like one institution has to fail. And not only fail, but like get hacked. And there's all sorts of ways to go about it. There's all sorts of companies that provide varying different services. But I don't want to say like, single sig is dead. I know really og really competent bitcoiners that are like, I know how to generate a really large, really random number. And people make fun of rolling dice. Guys. I don't know. Like, I get that it's not a mainstream thing. I get that it's not a mainstream thing. It's not something we can expect millions of people to do. Totally agree. But the question is, are you comfortable doing it? Fuck everyone else for right now. This is your life savings. This is your sovereignty. This is your ability to store the best money yourself. You have to find randomness that you're comfortable entrusting. And so I know a lot of really OG Bitcoiners that rolled dice 10 years ago. And it's single sig. They know how to protect a secret whatever. They've got a safety deposit box, they've got guns, they've got whatever they got. And they're good. They feel super secure. Because by the way, there's no silver bullet for every institution you trust. They could something up for every multi sig, like any. Anything could go wrong. So I don't know if that was helpful, but I know a lot of smart people that store bitcoins in so many different ways. I'm just very. I'm very bullish that the space will continue to build tools, will continue to innovate, will continue. Everything is good for bitcoin as long as we survive. If we survive, we get hardened and we get better for it. People learn more. People like me are going to be pushed to producing educational content. I mean, the level of guilt that I have that I spent so much time talking about the Fed and talking about like the straight of Hormuz and not enough about this stuff. Like I need to get better at this stuff. I need to do more presentations on it. I need to make more short form content on it. Like I just like man, like so we, we all become better for it. If we can just survive, if we can just, no matter how dark it is, just show up tomorrow and keep going. Do we need to have a hardware wallet to make a new seed phrase using dice? Let's say ledger. No. See this is the thing guys. A hardware wallet isn't needed to create this really large, really random number. That's the thing people don't understand. The brand of hardware wallet has just like dominated what we're calling cold storage or self custody. But it's not like these little devices are like uniquely capable of generating all these numbers. Not, not the case at all. You can do it a million different ways. So. But yet like yes, ledger. The question ended like ledger, question mark. Sure, ledger Trezor. But there's a million different ways to do this and you know, I will try and start putting together the different ways and how they work and the trade offs and what they're solving for. And at the end of the day ultimately it's your choice. And so like let's talk about bitkey for example, which I still think for like someone who's fairly beginner, who's in between. I'll just keep the coins on strike for now. I trust Jack to. Oh, I actually want you know, some level of quote unquote self custody and ownership of my coins keys. Great. Why? The key is multi sig. So you know, if one of the key keys fail, gets compromised, so on set and so forth like you're good. Got the other two so there's some redundancy there. And the user experience is a little bit more mainstream. You get this device, it feels like an Apple product. When you open it, you got an app that pairs with it. It's designed by Dorsey. He's got great taste, great design. Always been good at both hardware and software engineering. So different, different trade offs, different products, it just really depends. But do you need a hardware wallet to create like a root secret to participate in the bitcoin network? No, you don't actually. I remember way back in the day. Let's see if this website still exists. Put you guys on. There used to be.
B
Yeah.
A
Here, let me share this. There used to be a website and it still exists. Bitaddress.org and so watch this. First of all, I'm going to create a wallet right in front of you guys. Don't use it obviously. Okay, please. So this is how this. So you can see bit address.org or open source JavaScript client side Bitcoin wallet generator. So it's going to generate a bitcoin wallet for us. And you're like, jack, what do you mean? Don't you need a hardware wallet to do that? No, I'm telling you guys, no. That's not how bitcoin works. We got to get back to understanding it's all about generating one really large, one really random number. So how does it do that? What's it say right here? It says, move your mouse around to add, add some extra randomness or type some random characters into this text box. So I'm going to start moving my mouse around and do you see it's creating the really large, really random number. And you're like, what do you mean? Well, it's taking the movement of my mouse on the screen and basically the randomness is derived from, well, what are the odds that someone is going to move to the pixel the exact amount that I've moved my mouse. And if you do the math on the size of the screen and the pixels and the potential ways I could have moved my mouse, it's probably pretty fucking random. And it's at 39%. So what it's saying right now is this isn't quite random enough. Like if we were to stop here, you wouldn't feel comfortable enough with the randomness of this number. So keep going. So I keep going and I'm moving my shit around and then I go in here and I start clacking on my keyboard and it's just random, random, randomness, randomness, randomness. Look at all this randomness. For random. Boom. It hit what it considered enough randomness. Here's the secret that obviously if I were to use this, I shouldn't share with you guys. And here's the public part that I could say, yo, send some bitcoins here. And then as long as I kept this part secret, I just generated a large enough and random enough number to have a bitcoin wallet. Did I need a ledger to do that? No. Back to basics, guys. Self custody is all about can I generate a large enough, random enough number and can I protect it? That's it. I continue to say it. If you want the most auditable, most reviewed code base, just get a machine, plug it in, let Bitcoin core sync to the blockchain. Create an address, unplug the machine, turn that bitch off. Send the bitcoin to the address. You're good. Bitcoin core gets reviewed by like, Bitcoin core is the most. One of the most popular code bases in the world. It's been reviewed by everybody, like all day, every day. But boom. I just created a really large, really random number and I didn't need a hardware wallet. So a hardware wallet is one way to do it. And it's good because you know it's offline and right, like you need to protect the information that it generates from attackers and so you don't want it to be on the Internet and you know it. Hardware wallets are not bad. They have features, but I think people often think too synonymously of like, oh, cold storage and self custody means hardware wallet. No, it doesn't just truly understand. It's about creating a large random number and then protecting it. Hopefully that was useful. Okay. Oh, shit. I just realized my screen was protecting my whole demo. Oh, wow, that was so dumb. Okay, well, I'm not gonna take all the time to hear. Sorry, sorry, guys. Sorry. Hold on. Okay, hold on. It's called bit address.org. do you guys see what it says here? Move your mouse around to add some extra randomness. And so when I move my mouse around, do you see that it's generating this really large, really random number? See that? That's enough randomness. And then I can even click clickety clack on my keyboard. Boom, there's my bitcoin wallet. So sorry, you got the audio version first and the spun sped up. Now, obviously, do not use this bitcoin wallet. Do you guys see that? I'll do it one more time. It doesn't have a wallet yet because I haven't done enough randomness. It says, move your mouse around to generate some extra randomness. Move, move, move, move, move, move, move, move, move, move. Random, random, random. Clickety clack, clickety clack, clickety clack, clickety clack, random, random, random, random, random, random, random. Boom. It does not need to be a hardware wallet. Now, also to be clear, don't use this wallet. I would not Recommend using bit address.org. don't do that. There are way better ways. Like, like I said, I'm a bitcoin core guy. Bitcoin core is really great audit. Like, like I said, Bitcoin core is one of the most reviewed. But then you're going to have to keep the laptop safe, so you shouldn't use Bitcoin Core to store your life savings with the laptop that you're taking through the airport and stuff. But you could buy a machine, download and run bitcoin core on the machine, create an address, take it off the Internet, store it in a vault or something, and then just periodically send bitcoin that you're stacking to that address and there you've got like software that has been audited and reviewed, arguably more than any other code base in the world. I don't recommend bit address.org, but that was just a good way to kind of visualize, you know, I'm saying, you guys get it, I hope. Thanks, Jack, for all that you and your team has done to help during this stressful time. Quick question. How do you suggest calling out blind spots in the bitcoin space and avoiding group think? This is kind of why the meme of like being a toxic bitcoiner is never considered a bad thing. I think bitcoin bear markets are inherently humbling. They're full of humility. Heroes are slayed. And so you have to. Bitcoin is the money of humility. It is. It's the money, you know, where you, where you're like, wait, we're not meant to central plan the universe. We're a child of the universe. And you know, I have to accept what comes with that, that I'm not in control. So it's the money of humility in that respect. And I think these bear markets are all about humility, learning, being secure, planning for the what if scenarios and bitcoiners, remaining vigilant and don't trust verify and taking that to heart. Clearly there was too much trust in Coldcard and not enough verifying. And every single time that we as a community go through tough times, as long as we survive, we're better off for it. And I can't speak obviously for the independent victims. Hopefully we can raise a bunch of money or we can get the, we can catch the, the thief and get the stolen bitcoin back. You know, I can't speak independently to everyone's in independent experience and whether they're better off for it, but as a community and as an asset class, we're better off for it if we can just survive. Thoughts on coincide emailing customers warning them of a security flaw and what to do given that they've always claimed they didn't retain customers info. Yeah, I don't know much about that, to be totally honest. I saw that kind of past my timeline. I didn't look too much into It, I mean, you know, the optimist in me would like to think that they were only able to reach out to recent customers because I think their policy said that they delete customer info after three months. But I didn't look into it and obviously I don't think anyone should be trusting their word. So. So I don't know. Can you confirm that using a dice rolled private pub key pair on a cold card would be fine? Then it would only be a signing device, not using the key generator. Yeah, but it all comes down to like sufficient randomness. So for example, like do you have high quality dice? I'm not kidding. Like obviously if you had dice that only had the number one on it, then you know, it wouldn't be that good. Or if you had dice that had like a chip on it so like it actually ended up falling on one or two numbers more frequently than other, then you'd have less randomness than otherwise but probably still enough randomness to be secure. So it all comes down to the quality of your randomness and you're never really going to know for certain. But and the other thing of like, well, why didn't anyone else attack cold card and catch this earlier? Well, because nobody had found out that they were only using 40 bits worth until recently. And then it took the attacker that. But once the attacker realized like holy shit, like I, they did not use near, near enough randomness. So it's, it's also. Yeah. So Yeah, I think 100 plus dice rolls in theory is plenty entropy. So the answer would be theory. Yes, but I wasn't there while you were rolling the dice and I don't know what dice you used. Right. So just keep that in mind. It's, it's just all about the quality of your randomness. So I can't. The question is, can I confirm? I could tell you that. Yeah, for sure. In theory. Yeah, that like 100 plus dice rolls is, you know, sufficiently random. Yeah. But just keep it in mind, like security doesn't work that way. Can I confirm? Yeah, I sent everything from my Le Pal cold storage back on strike. I think I'm going to leave it on strike. Moving forward without bias. What are your thoughts on this move? Yeah, I mean, listen guys, that's totally fine. Like strike is secure, safe and like I said, you know, we're take, I'm taking a look at our roadmap personally and seeing what we should move up when it comes to security and custody. Should we just start to. I mean there are in some instances, I mean Our I won't again, I won't talk too much about our stack, but we do collaborative custody in some instances. Like we can productize that there's certain features where we can make. Like there's different things we can do. But even as it is today, I mean, strike is extraordinarily secure and safe. I store a lot of bitcoin on strike. If it's meaningful to you guys to know that I have a ton of bitcoin on strike. So it's up to you. There's no right way to do it. Like, should you use single sig? Depends what you want. Should you use multisig? Depends what you want. Should you use strike? If you trust me and us and our ability to generate large random numbers and secure them, then yeah, of course, no problem. Just understand the decision you're making. No. Right answer. Obviously, I think over the long term, people, first of all, it's incredibly important that you can self custody, like obviously making it as accessible as possible and ensuring that people can enact that and that a certain percentage of people do is critically important to the future success of Bitcoin. But you know, if someone I sit on the Natalie Brunel podcast, like, I'm much more personally in interested in the fact that nobody even vaguely understands money. Like when people say, oh, bitcoin has been adopted by 1% of the world. No, it hasn't. That's 80 million people. 1% of 8 billion is 80 million. You think 80 million people have a vague understanding of anything we talk about on this show. You're crazy. I wouldn't even think 8 million people kind of understand that money is an abstracted form of time and energy and that printing money is an affront to human dignity and that bitcoin solves core monetary principles in the most important information system in human history, people don't understand that shit. And so I would much rather someone truly understand what money is and what bitcoin's role in money is. But like, oh, because they're a fund manager, they have to own the etf. For now. I'm much more okay with that, to be honest, than having someone have bitcoin exposure through a proxy, through a proxy, through a proxy, through a securities wrapper. Like in the 0.7% of their 401k is in Bitcoin. Like, what the fuck? That's not adoption. I consider it's much more adoption. Someone like, I get money. I understand the affront to human dignity that fiat currency is and that bitcoin solving that and right now I'm only comfortable or I can only, or my fund mandate is only this IBIT thing or whatever. Or I'm going to keep it on strike for now. But I get it, I get it. And I'm listening to your show, Jack, and I'm looking forward to the products and I'm looking forward to self custody in the future. I'm much more. That's adoption for me. You know what I mean? So no, if you want to use strike, you strike. That's why I built it. That's why I built it, guys. And we'll work on it. We'll produce content people. And by the way, it's not always about strike. People will build more tools. Like it's. What is it? Rising tide lifts all boats. Like, we'll keep building, we'll keep building. We'll do it right. We'll open source everything. Stripe will share how we use AI to test all of these code bases. And it's not just our code base. We're testing all of the open source bitcoin code bases that we use because our security is only as good as, as the other open source code bases we use. Right. Can you please go into some detail about strikes, custody, security, proofs of reserves, audit, etc. Yeah, so I kind of touched on it a little bit before, but we use multisig, geographically distributed, multisig. Our systems are very safe, secure. There's some part of our stack also do collaborative custody, which I think is interesting. That's about as much detail as I'm comfortable to go in for now. But you know, we custody it ourselves. Like we generate, have the keys secure and what else did you write? Yeah, we also get audited. We provide proof of reserves for our lending product. Right now, to be honest, I know some other bitcoin companies have done proof of reserves and you know, not like mad or thrilled about it. I think it's cool. But our customers are like, I know I need to borrow against my bitcoin or I need you guys to get in Europe. And so it actually, you know, despite some, like sometimes on Twitter is a very loud minority. But so despite like a lot of voices on Twitter, it actually wasn't like a really top request until obviously the last 48 hours. People are like, hey, can you take a look at that again? And that's what we were doing. So whether it's proof of reserves, different variants of custody products that we can offer, all of the above, we're taking a closer look. But any other specific questions about Our custody. I could potentially answer audit. We're audited. Yes. And we do provide proof of reserves for our lending book. And taking a closer look at that question for Jack, would Strike ever create your own cold storage wallet? Obviously with the recent loss of trust in what was the best wallets in cold card, could you fill the need?
B
Maybe.
A
And I. So here's the thing. When you say cold storage, I think you're using that synonymously with hardware, which I'm trying to explain to you guys is not the case. So can Strike build cold storage product like a multi sig product or a multi institutional collaborative custody product? Yeah, 100% we could do that. In fact, we've built so much of that for ourselves internally that we can expose it and productize it. We're gonna take a closer look at that for sure. But do we want to get in the business of hardware? I'm not sure about that. I'm not so sure about that. And I'm not so sure that a hardware wallet is gonna solve everyone's problem. I'm trying to tell you guys, a hardware wallet does some stuff, but it, it's like it isn't the solution for everybody. I, I just generated a bitcoin wallet in front of you guys in my browser. You don't need a hardware wallet. I think that the branding for hardware wallet has been so successful in many respects that people don't understand what is going on under the hood. It's really simple. Big, large, random number. There's a lot of ways for us to ensure and help people create those or create multi sig that people can use between different institutions. There's like all sorts of stuff I'm thinking about. Hey, Jack, when will Strike make its way to Canada and what's the holdup? We will be in Canada in. My best guess is early 2027. We're actually, we've been working on Canada this whole year. The holdup is all the licensing and regulatory approvals that are required. So we're just chewing through that. It takes, it's a 12 to 18 month process to go from hey, I, I think I want to do Canada to paying money, hiring people, filling out all the paperwork, working with the regulators actually like changing our software to what the regulators say, like, hey, we need you guys to display this this way. So it just. Unfortunately it's not that easy or else everyone would do it. But we've already started, we're well into the process and hopefully we are months away. Oh my God. I just realized I'm not even remotely close to finished to get through all of these. Wow. And we're over two hours. Wow, I thought that was the last question. There's at least 50 to 100 more. Yeah. So I'm just going to summarize these. I see a lot of you guys want strike custody products. You want multi sig, a vault, some type of self custody product feature. And we're taking a close look at it. I swear we are. I actually was working on it this weekend, so we're taking a look at it and I'll get back to you guys with any concrete plans. Obviously, it's all happening so fast, so it's nothing like in the super immediate. And I do want to see where the demand normalizes, like what people actually want, what type of vision I actually have, how important certain features are. But I'm all ears. And I want your guys feedback. Just tell it. Tell me. Tell me what you need to feel safe. I'm trying to summarize here. Yeah, I think I'm gonna call it here. I think I'm gonna call it here and, and try and summarize. Oh yeah, this one from Liberty Mugs, who I, who I love. How does code review on Bitcoin Core compare to any given wallet and how does that affect security? Hopefully I made that pretty clear. I mean, one of the takeaways is that there just wasn't a lot of eyeballs on cold cards, firmware, at least enough. No one was able to catch this. And again, I think one of Bitcoin Core's strongest selling points is it's the most reviewed code base, like in the world maybe. I mean, I don't want to make that claim repeatedly. I don't know if that's true or not, but it's up there.
B
So.
A
Okay, I'm. I've got these documented. I just think any longer of a show is just unreasonable. Like my throat's starting to hurt. So I'm going to work with Dylan to load these up for the next episode. We'll try. And if there's. Because I don't know how many of these are repeated. How many of these can be answered with the same answer? So I'll stop for now and. And I'll try if these are all on Twitter or DMS and stuff while I'm eating dinner tonight, I'll just try and chew through these and maybe it won't be answered on the show. Maybe it'll be answered via DMS and stuff. And if there's, like I said, repeated themes or Consistent questions. Then hopefully next episode I can answer it. But yeah, with that, hopefully you guys learned something this episode. Obviously a new one. A little bit dark of a time for bitcoin. I'm so sorry for anyone impacted and affected by this and I'm really sorry. That cold card was, was within my lexicon of wallets that I thought was reasonable at generating these large random numbers. Hopefully you guys understand what it means to secure bitcoin from a very high level. At the end of the day, you got to just create a really large, really random number and take care of it. And you can build redundancies with multisig and key sharding. You can engage with companies whether you trust them outright and use something like strike or you want some type of collaborative custody or multisig. There's so many different ways to do it. Please give me feedback, ask questions, direct me towards content that would be valuable to you guys or valuable for you to share with others. I'm going to think long and hard. Obviously a lot of this is raw. I got home from the wedding really late last night and I mean, I didn't have too much time to put together this presentation. I hope it was valuable. This was all just off the top of my head here. So with time and feedback, I'm really interested in making some high quality content for you guys to just grow education, understanding, and ultimately adoption while building products. That's the one unique thing, is I'm going to both try and educate and build at the same time. Okay, well, I love you guys, man. Yeah, chin up. It's. It's all just large random numbers. We'll be okay. We can generate those, we can secure those. 99 of achieving anything is just showing up, just showing up. No matter how hard the day was, or the last month was, or the last year was, just show up, show up tomorrow and keep going. I promise you that's 99% of the job is just keep your chin up and show up. And so as long as we all keep showing up and bitcoin is an idea that's just far too strong for us to give up on. It's the idea that has reached enough adoption to have a pulse of its own. And I'm never going to give up on this idea, and I know so many of you aren't either. So we wake up tomorrow, we show up and we keep pounding pavement and chopping wood for this idea. It doesn't matter how long it takes us and it doesn't matter how we get there. But you know, the idea that Satoshi instilled and propagated is strong enough to have a life of its own. And that's the one job we all share is just keep showing up. Show up for the bitcoiners beside you. Show up for the people that are hurt. Show for the people that don't know. Show up for up. Just show up. That's the culture. So I'll keep showing up for you guys, man. I really will. And I appreciate you guys. Leave all the feedback. Tell me what content to make. Tell me what features to build one team. Whether you're a customer or not, Just let me know how I can help. Talk to you guys later.
Episode: How Bitcoin Custody Works & Breaking Down The Coldcard Incident
Host: Jack Mallers
Date: August 4, 2026
This somber and urgent episode responds to a catastrophic vulnerability found in the Coldcard hardware wallet, threatening the security of many Bitcoin holders’ funds. Jack Mallers explains the Coldcard incident in detail, educates listeners on how Bitcoin custody fundamentally works, and discusses best practices for keeping Bitcoin secure. The tone is emotional, direct, and focused on clear, actionable information for “Main Street” Bitcoiners affected by the bug, as well as the broader community.
[00:01–03:51]
“This is not a drill. This is urgent.” — Jack Mallers [02:10]
[03:51–09:15]
“These are hard-working, real bitcoiners. They didn’t take on any leverage... They did the opposite. These are honorable people.” — Jack Mallers [07:15]
[09:15–13:38]
[13:38–20:58]
“Your wallet does not contain bitcoin. The blockchain only shows us what public keys have the right to spend what bitcoins. That’s it.” — Jack Mallers [15:27]
Private and Public Keys:
Security Principle:
“Bitcoin doesn’t care who’s the true owner and who’s a thief—it only knows, does two plus two equal four?” — Jack Mallers [18:17]
[20:59–37:02]
“You would need a galaxy-sized computer running for 37 times the age of the universe to even have a 1 in 4 billion chance.” — [YouTube clip paraphrased and discussed by Jack, 35:05–41:10]
[41:10–47:55]
The Process:
Key Takeaway: If the random number (secret) is good, you’re secure; if not, you’re at risk—regardless of the device or software.
[47:55–63:45]
“The lock itself wasn’t broken. The key maker failed at making a good enough key.” — Jack Mallers [58:00]
[63:46–70:15]
“A device that generates a weak key in silence is more dangerous than a device that refuses to generate one at all.” — Jack Mallers [66:58]
[70:16–75:12]
“Bitcoin did not become less secure. Bitcoin did not get hacked. Cold storage self-custody did not have a catastrophic design error. It was one company up at the one job they had.” — Jack Mallers [72:00]
[78:10–86:12]
Multisig (“Multi-Signature”):
Key Sharding:
Trade-offs:
[86:12–95:12]
Hardware Wallets:
Open Source & Audits:
[95:12–100:44]
[100:45–115:00]
[115:01–122:18]
“Do you need a hardware wallet even? It depends. Depends on what you’re doing.” — Jack Mallers [80:51]
[122:19–125:45]
[125:46–128:07]
On the gravity of the Coldcard incident:
“I’m sorry that it was even within the lexicon of this show and within the lexicon of how I think people should have stored their bitcoins.” — Jack Mallers [04:43]
On the resilience of self-custody:
“To say that bitcoin self-custody is dead would be to say that being able to store a secret is dead… if we can’t, society as we know it will deconstruct and fail. Trust me, we are more than capable.” — Jack Mallers [22:54]
Explaining cryptographic strength:
“If I show up to someone’s house with the military, it’s now my house… but, you’re never going to guess that number. Ever. That’s why cryptography is so cool.” — Jack Mallers [57:13]
On best security practice:
“A device that generates a weak key in silence is more dangerous than a device that refuses to generate one at all.” — Jack Mallers [66:58]
On how to move forward:
“99% of achieving anything is just showing up… As long as we all keep showing up… we keep pounding pavement and chopping wood for this idea.” — Jack Mallers [130:34]
“It’s all just large random numbers. We’ll be okay. We can generate those, we can secure those.” — Jack Mallers [130:33]