Loading summary
Mike
Suddenly your yield goes down to, you know, 20 basis points, which is probably, you know, where it'll end up. Like, okay, so now you're going to have tens of billions of dollars of eth unstaked and, you know, out there in the, in the market. So clearly, like, if you're worried by eth price, which is one of the arguments that this is going to be worse, this is actually going to be much worse. I think the argument, and I would not, again, I would not make the argument to increase issuance, but the argument to increase issuance is in my mind actually stronger than the argument to decrease it. But the strongest thing is just don't with it.
Kane Warrick
Hey, everyone, I'm Kane Warrick and welcome to Uneasy Money. Because what happens on Chain never stays on Chain. Before we begin, here is a word from the sponsors that make this show possible.
Sponsor/Ad Voice
This episode is brought to you by Kape America's Privacy. First mobile carrier. Same premium service you'd expect from any other carrier, but designed so your number, your location and your data at actually stay yours. Get 33% off six months at Cape Co Unchained.
Kane Warrick
All right, hey guys, I'm here with my co host, Taylor Monahan, security expert. And we have a special guest this week, Sonia Kim, co founder of Re F Labs. Welcome. All right, our first segment, let's jump straight into it. The Cold Card tear down. So for those of you who are not aware, I'm going to, I'm going to hand this out over to Tay in a second to give us the full, full debrief here. I guess she's been deep in, in this, but Cold card is, was a hardware wallet, one of the minor hardware wallet players out there, and they had a small issue which basically wrecked everyone. So yeah, Tay, why don't you walk us through the details of exactly what's wrong here?
Taylor Monahan
Yeah, so the most, I guess, basic way I can put this is that one of the critically important jobs of the wallet is to generate a secure private key or seed phrase. And the way that you do that is with a thing called entropy, which is just randomness. It's just. But it has to be like truly random. And this is just like a cryptography math thing. It's not super important you understand exactly what it is. It is important to know that you absolutely need it, like desperately need it. For those who've been around for a while, you, you might have heard of like the profanity bug that was also like an entropy issue. And so basically if you don't do the Math good enough, then everyone gets wrecked.
Kane Warrick
This is not even like profanity was another one. Uh, there's been a ton of them, right? Like, there's been a ton of these, these things. And it's like you.
Taylor Monahan
Yeah, yeah, it happens quite a bit.
Kane Warrick
It used to happen more. It used to happen more when we were still like, you know, rolling our own crypto and doing weird stuff, but.
Taylor Monahan
Exactly.
Kane Warrick
This thing goes back to 2021.
Taylor Monahan
And that's what makes this incident, I think, different and crazier than all the rest. First off, it's cold card is a hardware wallet. So they screwed up this the way that they were getting randomness. They screwed it up in 2021. It got in the, in the code base. It was used for five years before someone just discovered it. Once that first attacker discovered it and started to exploit it, it's basically. That was like six days ago, seven days ago. Now it's been a free for all since because there's basically five years of seeds and private keys that, that the various attackers are. Are basically mining. And so like, how do I explain this? So when you don't have enough randomness, you don't have enough entropy. What happens is they, they, they have to like, mine. They have to like, literally like throw massive amounts of compute out this stuff in order to get it to go. And once they do that, then they take all the funds. But it takes time, it takes energy, it takes compute in order to do this. So that's why we've seen the thing
Kane Warrick
that I think I was like, the last time something big like this happened and maybe profanity, we, you know, I was trying to explain it to my team at the time. Right. And you know when you get a vanity address, right? Yeah, if you say I want, you know, and, and we've talked about the, the like address poisoning attacks where they like make an address that looks like yours or whatever. And you know, the first four, last four might take them like, you know, 10 seconds to. To cook. Right? But if they wanted to have the exact same address as yours, like with just one digit removed, it would take like, you know, a trillion years or whatever. And, and so, you know, if you want 0x whatever dead or some address like that, right, it takes the long. The more you want the, the like more of the address that you're trying to get, right? Yeah, the longer it takes. And, and you can go to like these vanity addresses and be like, hey, hey, I want like 0x. Tay is the best. And it'll be like all Right. That'll take a week, right? Yeah. And then if you're like, tay is the best and the smartest, it's like now it's getting.
Taylor Monahan
Yeah, it's like a century.
Kane Warrick
It's like a century. It's like, oh man, I really wanted that, like vanity address, right? Yeah. And this is, this is kind of the same thing where like they're reverse engineering. You only got zero X tape and like that's not enough because that would take like a minute to. And so they're just like cycling through these things and waiting until they hit something.
Taylor Monahan
Yeah, exactly. And so that's why I always say like entropy issues in wallets are the worst vulnerability, like the absolute worst. One reason is because the attacks play out like this, where we are going to see losses for the coming weeks and even months. Right. The other reason is that these are non custodial. The cold card users specifically are like pretty hardcore bitcoiners. Cold card specifically deleted all of their data. This was like a marketing thing, right? Like they were like, we're not ledger, we don't keep any data. So now they have this five year old bug that's wrecking everyone and they have no way to warn people to like move their money. Right. Like, it's just so painful. We're, I think. Okay, so to talk about numbers really quickly, Galaxy Research has been doing Alex Thorne. He has been doing an amazing job. He's been doing what I usually do. I'm just on looking. This one poor guy, he's been doing so good though. So he's collecting victim reports on the one side and then he's also doing some crazy on chain analysis to find all these different clusters and they're calling them waves. At this point we're looking at like, okay, so last check, I think we have four waves. So a wave is sort of like a set of movements and we're kind of assuming at this point that each wave is like a distinct, it's a distinct cluster of activity. They're probably, they're probably. I won't say probably. It's possible that it's four separate threat actors. Right. But it's also possible that like waves one and two are the same threat actor. And we're not like 100% sure yet. And so he's doing, he's doing like, you get victim reports, you find the pattern, then you find the other things. You combine it, you find all these waves. Total numbers right now are, it's like over $100 million stolen. It's like 1600, 18, hundred Bitcoin. Thousands and thousands of addresses, probably thousands of victims. Uniquely like these are all super hardcore bitcoiners who believe in self custody and cold storage and hardware wallets and safety. And that makes it super painful.
Kane Warrick
Like I, it's, you know, it's funny like I was, I was a bitcoin maxi in, in the old days, right? And like you know, hardware wallets, like of course, like, you know there, there was definitely a segment of like the hardcore bitcoiners that were like, you should have a harder wallet. They were the more pragmatic ones. Like the actual hardcore ones were like, you should you know. Yeah. Get out a deck of cards and like sit there for eight hours like generating your own entropy. Chisel it on a tablet and like, you know, put it in, in a safe or something. Right. Like, and throw away the key. Like anything that was like anything that touched the world or had firmware or whatever was like very much like not acceptable. And, and so you know, like, yeah, like definitely it's bitcoin maxis for sure because they were targeting that, that group. But like, yeah, yeah, it's still, it's still, you're still reliant on someone else's software and, and, and, and, but yeah, the, the, the like bad seed phrase generation stuff is, it's so bad, it's so bad.
Taylor Monahan
So if anyone, by the way, let me just say if anyone listening to this, that's a cold card, uses the cold card, knows someone with the cold card, please call them on the telephone like a boomer and make sure there are. Yeah, like don't mess around with this. Take your time doing so. They do not panic and go click the first Google result. But like you know, like do it please, because this is, this is literally an ongoing thing. We are going to see losses from this continue to grow over probably like this week, in this month, but even like far into the future as people like continue to use their, their basically these weak ass hardware wallets at this point. And then I think it's also just worth talking about the other conversation or the other half of this is like who's behind the attack? Is it AI? All of those fun questions. Is it North Korea? All those fun questions. Oh, he's North Korea. It's not actually North Korea this time, guys. This is not North.
Kane Warrick
How do we know?
Taylor Monahan
Yeah, how do we know? Okay, so North Korea just doesn't do these types of attacks. It takes a massive amount of compute and there are guys that have been like cracking and mining these Things for ages. My best guess, based on the sort of distinct waves of activity and what I know about, like prior entropy attacks, I think the first wave was probably someone who found the issue in the code base. Maybe with AI, maybe not. Some people are like saying that AI can find this, but once the. Once the exploits like public. The AI tends to learn from public reporting. So it's not as reliable to say, like, oh, it can find this. Like, there's a big post on Reddit right now that said Claude can find it in two minutes. It's actually not finding it in two minutes, it's finding other Reddit posts. About
Kane Warrick
10 seconds, right?
Taylor Monahan
Yeah, exactly.
Kane Warrick
I saw Haseeb's post though. There was a post saying like, you know.
Taylor Monahan
Yeah, put.
Kane Warrick
Because you can, you can put an agent in sandbox, like run in PI, like strip tools or whatever. Yeah, and, and see, and I think even then when pointed at the code base, someone was like, yeah, like stripped in a sandbox. It took 10 minutes or something like that for it to find it. So I don't know, I haven't tested that. Maybe I'll test it.
Taylor Monahan
Yeah, you should test it and let me know because I would trust you. It's a, it's a weird one because, like, the. Where the exact vulnerab, basically the vulnerability is. God, this code base was a mess. Guys, go look at your code bases that you're relying on.
Kane Warrick
What's it written in? This is an old. This is old code. What's it written in?
Taylor Monahan
Python, I think there's like some.
Kane Warrick
Oh, okay.
Taylor Monahan
Yeah, there's something else though, too. Python and C or go or something. Okay. But it hops. So basically you have, you have basically one repo and it hops to a whole another repo. And so you have to follow this chain. You have to be like, okay, it's getting the randomness from here. It's going to hop over here. And then you're like, oh, what's this? And it's like, okay, this is actually a completely different language and repo library. And you have to hop over to that. You have to then traverse the whole thing. And that's where the, that's where the confusion happens, right? Is like, it's supposed to go. Here it goes. Yeah.
Kane Warrick
This one thing that I saw, right, like, gave, like, gave me like, chills, right? Because I work with agents all the time. And one of the things that I have in all of my repos, like, it's like number three is no fallbacks, right? Because they will make a Chain of pullbacks that makes it impossible to see what's going wrong. It looks like it's fine, but you don't know. Right. Like, even when you're reading the code, it can be hard, right? But if you're not reading the code, it just. You look at the thing and it's like, okay, you know, they're like, ah, we'll show an A here. You know, if something goes wrong, right? And then the thing goes wrong and it's like built a fallback so that, like. Oh, well, actually, you know, we won't show it because we're just going to like hide that thing with. And they'll like, especially Codex. It will put in like five layers of fallbacks.
Taylor Monahan
Right?
Kane Warrick
And it's funny because it's one of those things where I'm like, these, these fucking agents. But they learned from us. This is the first time that I.
Taylor Monahan
Most times. So this is the thing. There is like an old, old quote. I think it's a Matthew green quote from 2015 after the true Crypt audit. They're true, so true. Crypt was like another like super hardcore over a decade ago thing. Encryption, cryptography thing. Right. That ended up having a pretty nasty vulnerability in it that allowed. Because you're like, so this is supposed to be secret. And then the randomness was screwed up. And he has a great quote in there that has always stuck with me where he goes, if your code cannot get the randomness necessary or initialize the process with any amount of confidence, then it should barf and catch fire.
Kane Warrick
Yes. Like the 100% throw an error stop hard.
Taylor Monahan
Exactly. And in this case, and we're going to see it with AI code as well, but humans do it too. That's actually kind of the opposite of what you want with code most of the time. Most of the time you don't. Like error messages are bad. That's a bad ux. You want fallbacks if the API call doesn't work, but a fallback to the other API so that people can get their balances, whatever. But with Cryptography, you do not want that. You want it to be dead simple. It either works or it doesn't. And you want to know when it doesn't work. And in this case, that's definitely one of the things that happened.
Kane Warrick
Yeah. That it fell back to this, like, PI library and nobody noticed.
Taylor Monahan
Like, you know, there's conspiracies that the team did this and they were insiders and they're just on like, I don't know.
Sonia Kim
I. I have a question. So I don't have any background in security or cryptography, but as like a user of a hardware wallet, this really concerns me. And you know, Defi founder, we've gone through like a whole host of attacks this year.
Taylor Monahan
Yes.
Sonia Kim
Off being kind of the new vector. Are you worried at all about hardware wallets being like the new vector? That this is maybe like one of the first that we're seeing, but then there'll be like more and more waves of other providers that might be vulnerable to either this specific attack or like some others that we may not even be aware of.
Taylor Monahan
I'm not too worried. I think this one definitely caught me off guard just because of how long it's existed. I think this is a, it is a bit of a perfect storm type situation. You have a complex code base, you have a small developer team. They seem to have antagonized a lot of security researchers and engineers. But like there are people that are now coming out, very well known bitcoin DS that are coming out and saying like, yeah, I tried to talk to them because I didn't understand the code base. I was trying to understand the code base and they were dicks. So I didn't like keep looking or whatever. But I don't know, like I'm still. In terms of like general broad risk, I would say you're mo. You're more likely, you're more likely to lose money from like an opsec failure phishing social engineering than like this specific bug, this specific one is just scary because you can't, it's very hard for like, it's very hard to give end users any advice. And that's why it is painful.
Sonia Kim
Yeah, right.
Taylor Monahan
Because I can tell you like, Sonia, don't get on random zoom calls with North Koreans. Okay. And you can, you know, you can, you can take that advice and improve your life with that advice. With hardware wallets like I, you know, and especially this vulnerability, it's like, go read the code base.
Sponsor/Ad Voice
Right?
Taylor Monahan
Like that's what bitcoiners are saying right now. Read the code base. I'm sorry, that's like completely illogical. Yeah, you lost me there already. Yeah, exactly, exactly. I would say, I guess maybe one piece of advice that's like more realistic is ask your teams about their audits. Right? These guys didn't have a single security audit and then actually read those security audits.
Sonia Kim
Right.
Taylor Monahan
Look at, even non technical people can have discussions and look at code bases and notice things like if it's one person committing directly to main without any peer review, without Any process, usually a very bad sign. There's a lot of like, signals like this, that, that even if you don't see the, the, the, like the literal issue or find the literal issue hidden in the firmware, there's a ton of signals and a ton of red flags. And if you were to go look at Trezor's code base, Ledger's code base, they don't like, they do not operate like this. These are large teams. It's organized. They have processes. They have processes in terms of how they commit code, how they comment their code, how they peer review their code, how the build system works. Right. On and on and on. And they, you know that it's, it's required when you're predicting billions of dollars. Like, that's like bare minimum. And the fact that this team wasn't doing that and nobody noticed is. It sucks. But I think it's also a failure of just like the community for, for trusting that these guys, because they're such hardcore bitcoiners or whatever, that they had it unlock and they clearly did not at all have it unlocked. Like, not at all. Yeah. Oh, and I didn't answer why we know it's not North Korea. North Korea. They do social engineering. That's it. They're very good at it. They make some billions of dollars. They're very happily doing that. The guys that have the major compute and like GPUs to crack these types of things have been doing so for decades. They don't only crack private keys and bad entropy, they crack databases, they crack passwords, they crack like they're just doing this 24 7. They're very good at it. Their scripts are all like super optimized and they're just like sort of like turning knobs on the. They'll like write the exact script for this new type of entry issue, but then it's just a matter of turning the knobs on how much compute. Right. To make sure that they're profitable. So, yeah, so that's in terms of like, like who it is. I would say there's a possibility the first wave is like a normal type dude, like Lone wolf found this with AI. It's possible, also possible that it's, you know, someone that's hunting these for a living and has been for a while. I think the later waves though are definitely more like professional crackers. Like the people that just like brute force these things on and on and on and on and on. So, yeah, not North Korea, but what.
Kane Warrick
The one, the one thing before we, before we go to ads is the dice thing. There was also some thing here where they had some suggestion that on top of the firmware based entropy, you should also roll 50 dice to add some off chain entropy. Just like classical bitcoin, like don't trust. So, so, so what's, what's the deal with that? Like that.
Taylor Monahan
Okay, so basically what they're saying is, okay, so entropy is randomness. It's like the noise in the world, right. Cloudflare famously has a wall of lava lamps in their office. And this is like one way that they generate entropy is they have this camera of on the lava lamps, right? And it's like, and there's mirrors behind the lava lamps too. So basically they get the entropy from this like thing because it'll never be the same and you can't go back and calculate or whatever. That's entropy. So one way to do it is like, you know, you trust the firmware, which in this case was a terrible idea. Another way to do it is you build like a huge massive wall and algorithms of lava lamps and fancy shit like that. Another way to do it is with dice. So basically if you roll, you roll a set of die 50 times and then you take that input and use that input to contribute to like the entropy pool, the randomness pool, then you're going to be more secure. However, I want to caveat this because I think almost all of the early cold card victims, meaning the ones that came forward prior to the last week. So the people that came forward that had their cold card attacked in 2021-2022-2023-2020 24, 2025. Right. They're not a huge number of reports, but there are reports. You can find them on Reddit. I've looked at them on Chain. I've had these victims before. Right. In almost all cases, those people were the dice rollers. Okay. So the problem with the dice rolling, and I'm not actually sure Coldcard might have fixed this problem with the dice rolling is that if you don't roll the dice enough, then you still don't have enough entropy. And it's.
Kane Warrick
Right.
Taylor Monahan
It was triple trivial. Trivial to crack those. And so I think they're saying 50 plus is probably safe. Probably. Like, do you really, like, really? Are you. The advice is to roll the dice
Kane Warrick
50 as a Bitcoin maxi? Yes. Like this is like the type of shit that they want.
Taylor Monahan
I'm sorry, like, yes, this is what they love. So everyone says roll the dice 50 times and then people like, actually some people like Very few people. But some people, like, actually try to do that, and then they didn't roll them 50 times, and then they got hacked before this wave. So, you know, it's. We have to make it easy for users. There are a few insane people. I think there was a tweet about specifically the Korean bitcoin community. This is like.
Kane Warrick
Actually, they're like, we're rolling 500 times. We don't care.
Taylor Monahan
Apparently, they were very good at actually rolling the dice. But as an American over here, and I know my American friends, I'm just saying, if you tell an American to roll, like, dice 50 times, they're not rolling.
Kane Warrick
They're doing it three times, and they're doing out. They're like, this is actually boring. I'm done.
Taylor Monahan
Exactly. So I don't know, maybe, like, I mean, we do know the Koreans are very dedicated and disciplined, so, you know, maybe it's okay. But
Sonia Kim
as you can say, I see from my last name, I'm actually Korean.
Taylor Monahan
So do you agree with this? Probably. Would you?
Kane Warrick
Yeah.
Sonia Kim
Although I'm a bit of a hybrid. I'm a Korean Canadian, so maybe the North American cultures.
Taylor Monahan
Yeah, you're like, you're. 10 times.
Kane Warrick
I'll roll the dice. I'm not gonna. I'm not gonna stop at 3. I'm gonna. I'm gonna go to 10, and then I'll give up. But I mean, this is. This is kind of the. You know, this is exactly what we're talking about with, like, vanity addresses. Right? Three letters. You're like, ah, three letters. That's fine. No, like, that's not fine. That'll take. You know, these things are like exponential curves, right? So three letters takes five minutes. Four letters takes 20, and, you know, 20.
Taylor Monahan
Yeah, it's like a day and. Yeah, exactly. Goes up.
Kane Warrick
You know, it's funny, there's a Neal Stephenson book where they, like, in the book, they describe, like, this way of, like, using deck of cards to create passwords.
Taylor Monahan
Yeah.
Kane Warrick
And it was actually in Korea. I was in South Korea in, like, 2003 or something, and I was reading the book, and, like, this is, like, even before, like, good password managers and stuff. So. So I basically sat there for, like, I think it was, like, two hours or something. Like, so this is, like, so autistic and, like, dealt the cards out and, like, came up with, like, 10 different passwords and then memorized them so that I could, like, use them interchangeably for. For my passwords from then on. Because I was like, oh, this entropy thing, it's going to get me. So, so can you. I wasn't, I wasn't securing anything today. Yeah, I probably could. Yeah. Yeah, I probably could.
Taylor Monahan
Wow.
Kane Warrick
Yeah, I have, I have like. And so I, I used to have like variants of like, you know, the core password, then like 5, 5 extra characters or whatever. Variants. Yeah, Weaponized autism, so. All right, let's go to Ads. Before we continue, let's a take, take a quick commercial break and we will come back and talk about the. Another Korean thing. Weirdly. Yeah, this is like there's a lot of Korean angles here to this. We're going to find out how Somani's Korean soon. All right, let's, let's go to ads and we'll come back and talk about Trade xyz.
Sponsor/Ad Voice
If you hold crypto on your phone, your biggest vulnerability isn't your wallet, it's your carrier. AT&T. Verizon and T Mobile have been breached again and again and SIM swaps are still one of the easiest ways for attackers to drain accounts. That's where Kape comes in. America's privacy first mobile carrier, same premium service, but Kape rotates the identifier on Your Sim every 24 hours, deletes your call and text metadata after a day and protects against sim swaps with a 24 word recovery phrase that only you control. You also get two middle to end encrypted secondary numbers for banking and signups. So you stop handing your real number to every app that asks. Go to Cape Co unchained and use code unchained for 33% off your first six months.
Kane Warrick
All right, we are back. So there was a perp issue, an Oracle issue. Oracles and perps. One of my favorite topics last week where SK Hynix per on Trade XYZ fell from 1128 to 917, $917 and then almost immediately recovered. So this was like some thin premarket print that happened. It was a real trade. And then a bunch of people got wrecked which again like oracles. Actually we have a special guest, another special guest who's going to just join us, Mike from Etherfi. So let's pull him up on stage. We're gonna, we're gonna talk Ethereum later. Uh, so, so I think let's, let's get this, get this rolling. So welcome. Thanks for, thanks for joining us. So yeah, Trade xyz. I think the, the, the maybe most interesting part about this is that they were like, actually sorry, we're going to make you guys whole. And then they were like, well, but just this one time, like never again. This is not a precedent. Like don't come crying to us if this happens again, which it absolutely will. So yeah, I don't know. Takes on this Oracle problem, but yeah. So I think, you know the other thing that was quite interesting that this was a Kobe post that came out around about the same time as this where he's like Trade XYZ is not raising money. Which is always like a weird like whenever Kobe tweets something randomly like you know that there's some like chaos going on in the background that like some, some crazy shit going on. So, so basically the, the setup here is you have hyper liquid and then you got Trade XYZ and Tradoc. XYZ is a call it ecosystem participant that offers RWA perps, right? And RWA perps are maybe like a little in the gray if that still exists in this day and age in terms of what you can get away with doing. So Hyperliquid has core crypto assets and then they've got all of these other ecosystem partners that offer like different, different other asset classes and, and trade types, you know, options, etc. But again, you know, the, the challenge with RWAs that you don't have to the same extent with like Bitcoin is someone has to tell you what the price of this thing is. And rwas stop trading at random times for random reasons. Like when Synthetics was building this like this took us like a year of dealing with Oracle providers like Chain Link and, and a bunch of people, Chain Links people that they were talking to had. No, they're just not. They're like when the market is shut down, the market is shut down. Like why would we care about the like outside of market times, right? But pre market closed markets, it's, it's a really challenging thing to manage. And, and so like a real trade happened in pre market that someone dumped all of their sk hyex which maybe was a good trade actually in hindsight. And, and you know that's the price, right? Like, and, and so there's you know, even the fact that Trade XYZ was like, okay, we, this probably shouldn't have happened for reasons whatever. Even though it was a real trade is like itself a pretty opinionated take on asset pricing. Right? And you know, whenever I mean this like, you know, to Mike, like what is the price of eth vs rap e is it the same thing? Like what about when it dislocates for some weird reason like is it still that price? Like you know, or like LFT's LRTS, right? Like, you know, this is, this is the thing that you must lose sleep over, right? Like, you know, not all flavors.
Mike
I mean, we're somewhat of a preview. We're gonna make trading a lot better in etherfi over the next couple weeks. And it is something actually right now, you know, we're beta testing and some of this functionality. And yeah, we actually had the exact same situation where a couple of trades went through or, you know, not massive sums of money, but like users lost a bunch of money because they were allowed to do something that I think reasonably, reasonably, we should have not allowed them to do. Now, if somebody goes to Uniswap, right, goes to the ui, picks some low liquidity token, you know, this happened not that long ago, right, with AAVE, someone went to the UI.
Kane Warrick
Yeah, yeah. I want to say 50 million eth for 5 or boss, right.
Mike
It's just madness. Now, on the one hand you could say, look, sorry, bro, this is, you know, permissionless, smart contract like you, you, you press the proof you saw in the ui. But like, I think if you're hosting the UI and you're, you know, I don't want to say facilitating the trade because, you know, we're not facilitating the trade, but you're, you're playing some role. Yeah, you're involved, but you're playing some area, right?
Kane Warrick
Yeah.
Mike
I think ethically, and I do mean ethically, like you have a responsibility, I mean, you have a responsibility to prevent the user from doing something that's just like wildly insane. I think that's how brokerages operate. Again, not that, you know, we're a brokerage, but if I go to interactive brokers and I do try to do some insane thing, it does, you know, and I think, I think Uniswap should do that. I think, you know, we're planning to do that as we roll some of this stuff out and, And I think Trade XYZ should have. Should have done that. Like, this isn't, you know, this isn't rocket science, right? It's actually, it's not that hard to know, hey, somebody tries to do a trade with 70% price impact or some crazy slippage, you probably should just shouldn't let the user do that. Forget warnings and red text. Like, you just shouldn't let them do that. What if they. I don't know.
Kane Warrick
I mean, what if they really need. This is, you know, this is the, the thing, right? Like, what if that guy. Go to Ether Scan.
Mike
Go to Ether Scan?
Kane Warrick
Yeah, like contracts, right?
Taylor Monahan
Yeah. This feels like the same conversation that we've had before with we have it
Kane Warrick
all, we have it like every few weeks.
Taylor Monahan
Oh, okay, so it is, it's not. This is, this is literally the same.
Kane Warrick
This is like what is. There's like a philosophical epistemological question of like what is the price of something thing, right? Yeah, like there is no price. The price of SK Hyex was like, was it the closing price like 12 hours before? Is that the real price or is that like what some idiot on a Saturday wants to sell? Because they're like getting liquidated on something else and they need to, you know,
Taylor Monahan
like they need to.
Kane Warrick
There is no such thing as the price of an asset, right? It is like a, some kind of a construct. So you need to have a set of rules that says, and you know, the, the like if someone is willing to sell enough SK Hynix at $1, like is that the price for that 5 minute period where they're like just dumping into the market, right? And, and like these are, these are like non trivial problems. You can't solve it because markets just do weird shit, right? And so you know, I think Trade xyz, like part of the UX is like if something goes wrong as the venue and you know, NASDAQ does this, right? Like we were supposed to have you know like stop triggered on this and it didn't or it happened three times and we're just going to roll back the trades or like this thing happened, someone fat fingered a thing. It's not the real price. We decide what the real price is. The, the challenge for, for defi is like you're not even supposed to be involved this right? Like it's supposed to be contracts and stuff and all of a sudden you're like making post hoc judgments about what the real price was. It's okay for the NASDAQ to do it. I don't know about, about like Trade xyz. That's.
Mike
Well, what could say like if you're operating a wallet, right, like whether it's let's say metamask or phantom and a user tries to interact with a known malicious contract. Like it's the same kind of argument. You could say, well listen, it's permissionless man. Like just the user should be able to do whatever they want. But the fact is, look, you're operating an app, you have a list of malicious contracts. At minimum there should be a multi stage thing that tells you if you do this you're just absolutely going to get destroyed. And then in the end I think it's a discretionary call to say, no, we're just not going to let you do this. No matter what. Someone steals your phone, tries to do something, we're just not going to let you do that. And I think either decision is right, but sort of throwing one's hands up in the air and saying, like, hey, listen, it's. It's not our responsibility. Like, look, just objectively, to some extent it is. You're running the site. You're providing some responsibility.
Kane Warrick
Exactly.
Taylor Monahan
Yeah.
Kane Warrick
I mean, you know, let's not, let's, let's be realistic, though. Like, part of the reason that people were like, I'm. I have no responsibility, or like, I can't do things or whatever, like, we've talked about this a lot is like, you know, if you said, yes, I'm going to stop people from doing something. There was a guy called Gary Gensler who would show up at your house and blow your brains out.
Taylor Monahan
And so everyone love some bitcoin maxis
Kane Warrick
who are going to, like, yeah, there are like two. Two groups of people that would come.
Taylor Monahan
Philanthropers are going to come and come and get you.
Kane Warrick
But, yeah, so, all right, let's, let's.
Sonia Kim
Let's go add one thing. So this actually reminds me of when, when I was at Steakhous implemented this thing called meta Oracle. Mike, you might be familiar with this. In lending protocols, when you integrate an asset, there's a question of do you use the fair market value, which can whiplash around, like we've seen here, or do you use the primary redemption value, or do you use both and try and figure out when there are deviations? So it's, it's a real. I mean, you know, in different lending protocols, Stablecoins. Stablecoins have been hard coded at $1. Is that right? You know, there's so much different opinions around this, and I think it's quite prudent to have, you know, like a meta oracle like the one that Steakhouse had implemented on Morpho, where you actually get notified and there's a deviation when there's a great enough deviation that you can kind of switch off between the two.
Kane Warrick
So the challenge is, right, with Oracles, everything you do creates, like, downstream consequences, right? Like, you make that design decision, right? And it's like, oh, that's going to, you know, okay, we don't want people to get wrecked in this case, which is like, let's call it, you know, the, like, two Sigma case, right? But then you switch that thing on and then in The Three Sigma case, Everyone dies, right? Like, there's just, you know, like, like, it's like, ah, okay, I see why that was a mistake now, right? Like, it's. It's really, really hard to fuck with oracles and not have layers of consequences that are, like, built into all those decisions that, like, as you get further out into the tail of, like, you know, possibilities, like, increasingly bad things happen. Right? Like, you know, we. We used to talk about this all the time of, like, what happens if everyone tries to get out and the, you know, exit queue meanwhile. It was actually. The problem is like, the entry queue was the. Was going to be the, like, limiting factor, right? You're like, oh, like, people are going to want to get out of staking right now. We're. We will talk about this in a second. Right now we're like, actually, what if we stop this entry queue? This entry queue is actually, like, really annoying. There's too many people trying to get in, right? And so oftentimes the thing that you're trying to prevent ends up not actually being the real thing. It's some other thing that you didn't think about, and then the consequences of that are, like, significantly worse than the thing that you were worried about and trying to prevent. So, yeah, mechanism design is hard, I guess.
Sonia Kim
Right?
Kane Warrick
So let's. Let's go to. Let's go to this next topic.
Taylor Monahan
Hey, Kane. Super. I gotta. I gotta hop off because real life. Real life is hitting me.
Kane Warrick
Oh, okay.
Taylor Monahan
But I want to say thank you to both the guests for. For being here, obviously, and definitely, like, keep talking about this. Crazy. I'll be listening. I just have to go deal with some life really quick.
Kane Warrick
No worries. All good.
Taylor Monahan
But I'll see you next week. Thank you, guys.
Kane Warrick
See ya. Usually it's like some horrible hack is going on, right when Tay gets dragged off stage. It's like, usually someone's lost a lot of money.
Sonia Kim
Maybe we'll hear about it on ct. Yeah, yeah.
Kane Warrick
Hopefully it's not. Hopefully it's not that. So let's talk about these two topics here that are both kind of tied to Danny from a. So A has started to pull back from the, you know, be everywhere play that they. That they were running one of. I think the first projects, and I think it helped them, right, that like, they were kind of operationally capable enough and. And organizationally capable enough to, like, very rapidly roll out to new chains in a way that, like, a lot of other protocols struggle with, and they were able to kind of be everywhere. The full core Press mode that they had where every L2 random L1s that you never heard of and you go there for the first time and Sandy's like hey, welcome. And you're like what the hell? What are you doing here? So they've now I think gotten to the point where they're like okay, this is negative ev to be everywhere. There's a bunch of like risks that we're taking by being on these chains and you know the, the trade off is not worth it. Right. And starting to pull back. But I think there's maybe the more interesting Stani related story was him pushing back on EIP8361. So Mike, maybe you can, you can walk us through what is ERP8361. Why, why should we care about it? What, what's, what's going on here?
Mike
Yeah, so I mean just every aspect of this was this terrible. There's this, so there's this eip. So let me actually, let me start with this. There's been a lot of discussion over a long period of time, I don't know, years really about ETH issuance. And is this a problem? Like in other words in particular on stakers who deposit their ETH to help secure the network and the reward they get on that is about I guess like 2 1/2% these days. That's a blended rate of NBV and actual staking rewards. But whatever, let's call them about two and a half percent. Two and a half percent.
Kane Warrick
Risk free rate is two and a half percent?
Mike
Yeah, I mean I wouldn't call it risk free but objectively the risk is quite low.
Kane Warrick
Sorry, sorry. Okay, that was a joke. That was a joke.
Mike
People get very sensitive when you call it the risk free rate. But look, objectively it is low risk.
Kane Warrick
That's why I do it, because it's fun.
Mike
You know, very low risk rate is you know, two and a half percent. And you know, I guess for some people this is just a burning issue. Like this is the big problem of Ethereum. It's not that there's no privacy or the interop is non existent or block times are ridiculous. You know, 12 seconds. Or gas prices are still probably 10 times higher than they. No, these are. No, the main problem is that there's like an extra like 1% of issuance. So anyway, so there's the CIP that's been proposed with the 48 hours to provide comments before it basically goes into consideration or vote for inclusion and the next or the upcoming hard fork of Ethereum, which in itself was just. I don't know, I want to say offensive, you know, like, I'm. Whatever, I'm, you know, I'm a random guy, but hey, I'm like, you know, myself, my team are builders in Ethereum or one of the more important protocols. I would stay in the. In the space. But not just us, but nobody was consultant on this. Like, not, like, not a single, you know, DM message. Nobody was asked, like, hey, do you think this is a good idea? What are some consequences that might happen here? But just 48 hours notice, this thing goes up? And so that rubbed people the wrong way. A lot of people were just flabbergasted, like, hey, if you gave us a month's notice, okay, fine, that might be reasonable. But this is just madness. And it also speaks to a level of, frankly, just immaturity. This is a $500 billion network, you know, not trillions, but many billions of dollars of assets are secured on this thing. And like, this kind of behavior, I mean, can you imagine any serious institution, financial or otherwise, just with this level of, you know, whatever.
Kane Warrick
Soviet Russia is the good. Like, hey, here's the new plan, guys. What do you think?
Mike
Yeah, that's an app comparison. Sorry. Yeah, go ahead.
Sonia Kim
For what it's worth, my former colleagues at Steakhouse and I had been weighing in on this issue since 2024. So I don't know if you guys remember, but there was a whole debate about, at that point, it was called mvi Minimum Viable Issuance. And at the time, Steakhouse was contributing to Lido. So we were very privy to the potential negative downstream impact of, you know, issuance being reduced. I think, you know, Lido would be very much impacted. And the price action today really shows. Shows that, you know, etherfi LFTs would be. Lending protocols would be impacted because eth looping would be, you know, killed overnight. And ethoop does, in many cases, you know, make up a big part of the DAP revenues. So the fact that, you know, we've been weighing on this, weighing in on this over two years ago, and then there was no consultation last two years. And then I woke up to just a, you know, a. Like a tag on Twitter from who said, thank, thank you for weighing in on this issue. So it really did feel like it came out of nowhere. And this is worse than. At least FOMC has right structure and process and signaling that makes the whole system much more reliable. Kane, as you say, this is just. I don't know what you said.
Kane Warrick
I make the joke about Soviet Russia, right? But correct me if I'm wrong, this is what we asked for, right? Everyone was like the EF too concentrated, et cetera, et cetera. Everyone leaves. The ef, starts their own organizations. And those organizations are supposed to be like more commercial thinking about things, whatever their mandates were. And one of the first things that one of those new orgs does is say, let's slash issuance, right? So again, I would file this in like the be careful what you wish for. And, and you know, like to your point, Mike, like, why do they not care about other things? Because they're allowed to care what about whatever they want? Because they formed their own org, right? Like this is no longer the EF where they have a mandate to care about all of things in Ethereum, which effectively means caring about nothing. But, but now you have people that are like opinionated, caring about specific things, that have their own orgs that can like, you know, make proposals and, and drive things through. Which means, I think, you know, from a, from an Ethereum perspective, which is good. Like the fact that people are up in arms talking about this stuff like, you know, agitating. There was a, there was a kind of apathy of governance that had crept in through the last couple of years of the EF being both more active but also like setting the narrative as well, I think where it didn't feel like if you, you know, if you're outside of the ef, you really felt like you had no chance, but now it feels like anyone can say things, right? And so there, there is now more of a debate that's, that's open and whether this like proposal is, is good or bad or accurate or dumb or whatever. People can just say things now. So we are in a new era, right? You can write your own proposal and be like, actually let's jack issuance up to 5%. Like, you know, treasuries are 4.5. That's the real risk free rate. We need to be above that, right? You know, there's, there's, there's an argument that 2.5% is too low to justify the risks of. Let's not forget you have to hold Ether. Which is why I make the joke, right? Like the risk for like you, you
Mike
can hedge it, I guess, which is actually a very important point. I mean there's, there's, there are two sides of this where there's an argument and I wouldn't make this argument, but there is an argument to be made that issuance should be higher and there's a credible, you know, you can say a number of things that it'll actually improve defi. It'll make ETH staking more attractive which actually is helpful to ETH price because ETH stakers don't sell eth. Like that's, this is the, the brain, the particularly brain damaged aspect of this proposal that somehow reducing the issue to
Kane Warrick
that eve that gets on.
Taylor Monahan
Yeah.
Mike
Like suddenly your, your is. Your yield goes down to you know, 20 basis points which is probably, you know, where it'll end up like okay, so now you're gonna have tens of billions of dollars of ETH unstaked and you know, out there in the, in the market. So clearly if you're worried about ETH price, which is one of the arguments that this is going to be worse. This is actually going to be much worse. I think the argument, and again I would not make the argument to increase issuance, but the argument to increase issuance is in my mind actually stronger than the argument to decrease it. But the strongest thing is just don't fuck with it. This is just not frankly the most important thing by a long shot.
Kane Warrick
Unintended consequences. You know, there, there's a reason why the status quo was the status quo. Which is not to say you shouldn't try things of course. Right. But given the smorgasbord of trying things opportunities that we have in Ethereum land, trying things with the like monetary policy feels not smart. So.
Mike
Right. So when there's nothing obviously broken, it's like fine.
Kane Warrick
Yeah, yeah.
Sonia Kim
I mean to your point, grow out of this issue. Right. We can achieve effectively the same effect by generating fees because the fees get burned. So that's a subtraction on the number of shares. I actually come from Tradfi, so it's instructive to think about it.
Kane Warrick
I mean, but we had this, let's not forget we had this narrative, right? Like the ERP1559 burn narrative, like ultrasound money. We had that for a while.
Sonia Kim
But if you think about who the marginal buyers are, it's going to have to be Tradfi. And Tradfi loves yield. Tradfi love the growth story of like where do revenues come from? Tradfi loves buybacks. So these things are all achievable, not through an austerity measure like reducing issuance and potentially risking the security budget of Ethereum. But we can solve it by having a growth mindset of how are we going to onboard new users. Do the block fees need to be revisited? I was actually going back
Taylor Monahan
to
Sonia Kim
Ribbit Capital did a Ethereum thesis at the Son Investment Conference 2024. This was before proto dank sharding. So Ethereum was RIP they called it owner's earnings. Right? It's how much the network is making net of the reinvestment it has to make to sustain itself. Owner earnings was like north of 7 billion. What is 7 billion over the current ETH Market app?
Kane Warrick
It's like, like 3% or something.
Sonia Kim
Yeah, 3%, exactly. So if all of that is used to burn eth, then we can achieve the same effect without rugging solo stakers and kind of the downstream implications of this austerity measure, which is centralization and compromise security budget. So I think.
Mike
Yeah, sorry. I would also argue that there's not a lot of economists out there, hardly any that would argue that a 0% increase in the money supply per year is a good idea. That's a bitcoin brain worm. That's not sound economic policy.
Kane Warrick
I've got some bitcoin friends who.
Mike
The money supply should expand with the growth of the economy. That's how money supply works. As more goods and services are produced, you need more money to account for for them. Otherwise you get deflation and deflation is bad. Like this ultrasound money thing is not, I guess it's not in line with any economics, Austrian or otherwise. So, so the whole thing just makes no sense.
Kane Warrick
So like, let's just talk about like the, the practicalities, you know, like staking ratios I think are something that people, it's really hard to reason about, right? Like how much eats should be staked. And, and you know, we're just about to like Lido is about to like collapse all their validators to like five valid, you know, making it easier to not have to run one validator for every 32e. Like, you know, we are making it easier to stake. But there is a question of like how much eats should be staked. Is it, you know, 20%? Is it 50%? Is it 80%? You know, the more, the more eth you have staked, the less there is to sell to your point, Mike. Right. So, you know, and, and the fact that I, I would argue a significant majority even today of E stakers are not financially motivated. They are, they're eth maxis that like my validators, like I, I, I made this joke on, on X last night. Like I think my yield has been like 0.5% over, over the last because my validators have gone offline and then they go back upline. I've been slashed Whatever, right? So, like, my yield has not been the, like 5% or whatever that, that, you know, but it hasn't stopped me from staking because I'm like, yeah, whatever. What else am I going to do with that?
Mike
Eat.
Kane Warrick
Right. Like, I might as well stake. I don't, I don't think that your marginal E staker is sitting there going, the, the yield is, is like the primary driver. Right. Obviously at the, at the margins, you know, there's going to be a bunch of people that if you lower yield, will unstake or if you increase yield, they'll probably come in and stake. But, but it, it is like a really strong question of, like, should we have 50% staked? Like 60, 80?
Mike
Like, I mean, most crypto economic networks would kill to have more people stake their token. Like, they view that as a positive. I don't understand this argument. Again, if you view, and some of this seems to be driven by this frankly, bizarre dislike of liquid staking assets, if you view those as just intrinsically evil for some reason. Okay, fine, I don't understand. I think there's a lot of value that's actually created by these assets. Putting aside my position, and frankly, staking isn't even a material part of our business anymore. But putting that aside, if you view those as intrinsically bad, okay, then I can see. Okay, let's just really crunch this down. I don't even think it's going to have that impact. Yeah, you might kill the LSTs, but at the cost of centralizing the network much more dramatically than before. So I don't see the argument there. But as I said, most crypto economic networks would want, like, it's a representation of people actually buying into the asset, buying to the network. If it goes to 80% staked, what is the problem with that? Why is that a bad thing? How many dollars, Imperfect analogy, but how many dollars are just sitting there passively as physical cash or in checking accounts? Like, not that many. Most dollars are put to work. They're either invested or they're in T bills or they're in bonds or something.
Kane Warrick
Like what?
Mike
Having eth put to work, so to speak, securing the network and getting some small share of the fees of that network just seems like a pretty reasonable, you know, system to have in place. I don't, like, I'm not, I don't understand the.
Kane Warrick
I think there's like, part of this comes from again, you know, like most, like Justin Drake, like the, you know, Jerome, these guys came from like, you know, EF land, right? Like, and, and you know, what's interesting to me is you see what the internal tensions must have been like at the EF when they're inside there. You know, there's a group of people that's like agitating for like, we should be more efficient. Like, and, and I, I genuinely think this is like an argument for efficiency, right? Like, Ethereum should have the absolute minimum amount of eat staked that is required to secure the network. Like, genuinely, like, I, I, like that's the philosophical direction of where this is coming from, right? That like, we shouldn't leak value, we shouldn't be paying more for security, you know, and, and like this, like, what's the security budget, right? Like, what is the cost to secure the network? How much are we paying? And a lot of people have this view, right? Like, you know, Bitcoin pays like a billion dollars a day to secure the network for, you know, $100 million of transaction. Or like some, some like, very distorted number, right? And people look at that and go, that's doesn't make sense. You know, there's not enough economic activity to justify the security budget. But, but I think that the, the efficiency kind of argument, I see how you get yourself there, but it ignores so many other considerations in the real world of like, incentives and why people do things. And like, you know, the directionality of incentives that it just, it's a bit nonsensical,
Mike
I think, going back. No, I hope not.
Kane Warrick
No. No way. So, like, I do think, I think that like, again, this speaks to. Here's what happens if you fragment what was. The unified front is now fragmented. You've split out all these people, you've ejected them out. They're now out in the world doing things, agitating for things, whatever. You will get more chaos, you'll get more dissension, you'll get more, you know, of these things where everyone's like, whoa, what the fuck are you guys talking about? Right? And you know, like, there's no way that these guys weren't in the EF being like, we should do this, right? And you know, whoever it was, like, you know, IO or, or someone being like, we should do nothing. And they're like, ah, it. Fine, whatever, we'll do nothing. We'll keep doing that. But now they're like, oh no, no one can stop us from doing things. Let's go and do some stuff.
Sonia Kim
So, yeah, I would really encourage those involved to get out there. If, if the overall goal is to get Eth Price to go to the moon, I think Some consultation from the, you know, the people who are already bought in, as well as some consultation with the people who are likely to be the marginal buyers would be very helpful. I think it's not okay for academics to hide behind their computers, run some numbers and have a theoretical answer to influence the downstream applications. You know, I'm reminded of the saying by either Charlie Munger or Warren Buffett, which is, it's, you know, better to be roughly right than precisely wrong. And I think issuance is not correct. Like, there is no such thing as correct, but I feel like it's just roughly right. And to try and be precisely, you know, like the knob and be precisely right could result in it being precisely wrong. And then, so what if we do this upgrade and then realize that there's not enough security or, you know, we don't like the, the second, the change that we made, then what? Right, then you have to keep updating. And what does that.
Kane Warrick
I mean, again, like 155. Yeah, like, let's not forget 1559 was not supposed to be about ultrasound money. It was a really good idea to make the fee market more stable in Vitalik's idea. Right. By the way, you know, and, and it took like two years. Like the people who were agitating for this, including me, you know, I helped raise money for like the, the audits that, that we ran on, on 1559 when we were all poor back in like 2018, 2019. And you know, the goal of it was the UX of a fee market that oscillates wildly is terrible. We need to stabilize it. And then we launched it and this burn mechanism that was not the primary thing became the primary narrative. Again, if you touch something, be prepared for it to touch you back is basically the thing that I would say. And so, you know, again, I, I think it's very unlikely that, that this passes just given. But my, my, my other hot take is, I think like more chaos in Ethereum and, and less kind of, you know, this monoculture is probably good because people are talking about eth. They're talking about Ethereum, they're talking about things like, even to your point, Mike, like, okay, you guys care about this. This is dumb. There's like 10 other things we could care about. Let's go. You probably wouldn't have that conversation today if it wasn't for this to be like, hang on a second, like, why don't we focus on something that's actually going to be impactful for Ethereum, the network, you know, and so I think all of this is, is probably a good thing in the end.
Mike
It's a positive, positive way to look at it. I agree.
Kane Warrick
Yeah, yeah, yeah.
Mike
My hope, I mean, it would be pretty crazy if they, if this ends up getting jammed through, but I do think it'll keep coming back because, I mean, bottom there's clearly people, people that care about this and they're just going to keep pushing it. Yeah.
Sonia Kim
I don't know.
Kane Warrick
All right, thank you very much, guys. I think we can wrap it up here. Appreciate you both joining the show and we will see you guys next week. Thanks for joining us on this episode of Uneasy Money. Remember, what happens on Chain never stays on Chain. We will be back with Tay. Hopefully nothing too horrible went wrong, although I'm sure something horrible go wrong in the intervening seven days. It always does. But until then, do your own research before aping in. See you guys next week. Nothing you hear on Uneasy Money is financial advice. We're just three builders talking about what's happening on Chain and we want you to always do your own research before aping it. You can find all our disclosures@unchained crypto.com uneasy money it.
Taylor Monahan
Sam.
Date: August 7, 2026
Host: Laura Shin
Co-Hosts/Guests:
In this wide-ranging episode, the panel dives deep into the devastating Coldcard hardware wallet exploit that drained over $100 million in Bitcoin from hardcore holders. The discussion branches out to touch on broad security lessons, the perennial issues around randomness ("entropy") in cryptography, and DeFi protocol risk. Later, the hosts debate the ethics and mechanics of protocol-level interventions after Oracle failures, as well as the volatility and politics of ETH issuance. The tone is sharp, occasionally irreverent but always highly technical and insightful, offering valuable guidance for developers, DeFi users, and crypto skeptics alike.
Timestamps: [01:02]–[17:37]
"Once that first attacker discovered it and started to exploit it... it's been a free for all since because there's basically five years of seeds and private keys that attackers are mining." – Taylor Monahan [03:00]
“If you don't do the math good enough, then everyone gets wrecked.” – Taylor Monahan [01:51]
"Even non technical people can...notice things like if it's one person committing directly to main without any peer review...usually a very bad sign." – Taylor Monahan [18:03]
"North Korea just doesn't do these types of attacks...they do social engineering. They’re very good at it. The guys that have the major compute to crack these things have been doing so for decades." – Taylor Monahan [18:03–19:00]
Timestamps: [09:24]–[18:03]
"If you don't roll the dice enough, then you still don't have enough entropy." – Taylor Monahan [23:17]
Timestamps: [28:07]–[41:28]
"If you're hosting the UI...ethically you have a responsibility to prevent the user from doing something that's just, like, wildly insane... You just shouldn't let them do that." – Mike [34:14]
"Everything you do [in oracle design] creates downstream consequences..." – Kane [39:52]
Timestamps: [44:00]–[65:19]
"Not just us, but nobody was consulted on this. Not a single DM message. Nobody was asked, 'Do you think this is a good idea?'" – Mike [45:00]
"There are two sides…[some] argue that issuance should be higher… it'll actually improve DeFi, make ETH staking more attractive, which actually is helpful to ETH price because ETH stakers don't sell ETH..." – Mike [51:13] "You can write your own proposal: actually, let's jack issuance up to 5%. Like, treasuries are 4.5%—that's the real risk-free rate..." – Kane [48:51]
Entropy Catastrophe:
“If your code cannot get the randomness necessary or initialize the process with any amount of confidence, then it should barf and catch fire.” – Taylor Monahan quoting Matthew Green [13:54]
On Oracle/Perp Risk:
"If you're running the site...it's not our responsibility — but objectively, to some extent it is. You're running the site. You're providing some responsibility." – Mike [38:04]
On ETH Issuance Governance:
"This is a $500 billion network...this kind of behavior, can you imagine any serious institution, financial or otherwise, with this level of [immaturity]?" – Mike [45:00] "This is not the EF where they have a mandate to care about all things in Ethereum...now you have people that are opinionated, caring about specific things, that have their own orgs that can...drive things through." – Kane [48:51]
On Security Culture:
"Ask your teams about their audits...look for red flags, even if you don't see the literal issue hidden in the firmware, there's a ton of red flags." – Taylor Monahan [18:03]
| Segment | Key Topics | Speakers | Timestamp | |---|---|---|---| | Coldcard Tear Down | Entropy, scope of the hack, randomness failures, victim audit | Kane, Taylor, Sonia | [01:02] – [17:37] | | Security Culture | Audit/process advice, codebase red flags, communication | Taylor, Sonia | [17:37] – [27:14] | | Oracle Failures | Trade XYZ perp crash, platform liability, meta-oracles | Kane, Mike, Taylor, Sonia | [28:07] – [41:28] | | ETH Issuance Debate | Proposed EIP-8361, process, economic impact, philosophy | Kane, Mike, Sonia, Taylor | [44:00] – [65:19] |
Security is only as strong as the weakest random number generator — and the weakest process.
The stakes are high, and the community must remain vigilant, proactive, and collaborative to safeguard both assets and the principles of the ecosystem.