Loading summary
A
You're listening to a brief segment from one of the Bits and BIPS episodes this week. The full show is now only available on its own dedicated Bits and Bits channels, so be sure to go to X, YouTube and your favorite podcast platform and search for bits +bits spelled B I P S and subscribe
B
so Coldcard was a hardware wallet largely marketed in some places as the gold standard in the Bitcoin ecosystem. And it had a deep systemic flow law. So an exploit tied to entropy aka key generation cold card mark 3, mark 4, mark 5 had bitcoin drained from I believe well over a thousand wallets at this point and the reported total has been climbing throughout the week. Up up up up. CZ via Zero Hedge said nothing is 100% warning Bitcoin holders after the exploit exploit. We also have an expert who's been commenting on it extensively here, Alex Thorne, who Alex, I saw in Cointelegraph you said a fourth organized wave is likely in progress. 208 transactions across some specific blocks sweeping about 389 bitcoin from 462 suspected victim addresses in roughly 2.5 hours. Human cost is real here. Good example. The retail bull had said I've had all my bitcoin stolen while away on holiday. It was on a cold card Mark three. I was led to believe this was really secure. The two Bitcoin was supposed to be to give to my two children to give them a good start to life. And the ETF crowd has been speaking up here. Eric Balancunas said some such an intermediary upgrade for bitcoin, safer, more secure and almost always cheaper. Speaking about ETFs 33 year old industry 15 trillion in AUM and never once lost someone's money. So I could go on and on about this but Alex, you've been observing the whole thing. Could you start by telling us like the core of how did people get this wrong? Why was all this money sitting out there in a way that it could be stolen?
C
Yeah, it's been a brutal four days. This sort of started early in the morning Thursday UTC time and is still ongoing. Before I even go. If any viewer or listener has funds on a cold card and a single signature address, as in not part of a multi sig quorum, you should move those coins off as soon as possible. And I by the way I like Eric Balchunas quite a lot but obviously an ETF holding a DTC registered stock inside it is not the same thing as one that holds a digital bearer asset. But we move on the Saddest part is that to your direct question, Austin, these people did nothing wrong. In fact, they did everything right. And the cold card itself is very popular among a cultural demographic in Bitcoin that believes in cold storage, self custody, stacking, sats, working hard. You know, not that anyone deserves to have their money stolen, but this isn't a drain of a defi bridge where you were, you know, bridging between, you know, Ethereum L2s to harvest, you know, altcoin inflation yield, right? This is not people speculating on crypto exchanges on meme coins, right? These are people, by and large, and I can tell you I know this community quite well that are working hard and saving and stacking sats and then putting them away for a long period of time. The average dormancy of coins that has been siphoned like almost four years. So these are not like short term holders. That makes it particularly devastating because they did nothing wrong. To your point, just to underline it a little bit of how this happened, when you generate cryptographic keys, you need entropy. You need a random number generator to seed the key generation with randomness, which is what makes it difficult to brute force attack. And Cold Card had updated their firmware on March 17, 2021 to add their own version of a random number generator. And it's not even that that version wasn't good. They miswired it into the firmware such that it would fail, it would never be routed through that random number generator and it would fail silently and it would backfall to this other crappy random number generator that has way too weak entropy to create secure keys. That means that attackers with compute that know this vulnerability can go and use that random number generator that it did end up using and compute billions of public keys, then go and private keys seeds, seed phrases and then derive the public keys across the whole derivation space and then go and see if any of them have coins and if they do, bam, submit transactions to move those coins to new locations. It's the worst type of attack. These people did not accidentally drop their hardware wallet on the ground or post their private key in a chat. They didn't even click a link, a phishing link that siphoned their metamask, right? Like so many that we see. I think that's what makes it particularly devastating, you know, when compared to other hacks, all of which are devastating. But this is really not supposed to happen.
B
So to unpack this one, the problem here, ironically had nothing to do with Bitcoin specifically. This was a core like cryptography exploit, where you had a poorly generated, at best, pseudo random function to create your seeds. And as a result of that, whatever was secured with that cryptography could have been hacked. So if this had been, for instance, a, I don't know, email provider using encryption instead, you would have been able to get into everybody's email. Correct. Like, this is not a problem unique to blockchains, it is a cryptography problem.
C
Yeah, absolutely true. And not only not a Bitcoin problem, could have been an ETH or Solana problem, and to your point, could have been an encrypted zip file problem or any type of key generation. And the worst part is it's not even really even the crypto. The software and the firmware just failed to route the keychain through the random number generator. This is not the first time that we've seen random number generator problems even in crypto, to be clear. I think one of the other things that's so astonishing though is how popular this hardware is. It's great hardware, to be clear. They also make the block clock and the open dime extremely popular Bitcoin native hardware. This is a software development failure that somehow went unfound for five years. It probably was found with the help of AI. People have proven now that now that it's known that AI can find it, but it didn't need AI to find, there are simply not enough eyes on this code base. There were obviously issues as well with the code base. It was not fully open source and when you look at the code base, there's hundreds of commits right to the master branch with no comments. So it doesn't seem like it was properly reviewed either. But just for some numbers, I'm not an expert in, I'm not a software developer, I'm not an expert in cryptography, and I'm not an expert in this type of computation to derive these seeds, which is what the attack is. I am an expert in on chain forensic tracing and that's what I've been doing. I've been following the funds here and trying to identify victim and attacker addresses and along with helping victims, if they reach out to me, also submitting those addresses to relevant US federal government, law enforcement, crypto exchanges, crypto ISACs. Right. Seal all of the relevant cyber investigators to try to make sure that these addresses get flagged by chainalysis at TRM Labs and Elliptic and all the exchanges so that if they do appear at a centralized intermediary, there's a chance of recovery. It's quite interesting. This started, you know, We've, I've got three defined waves. We call it wave one, wave two, wave three, any prospective wave four, which is still sort of in the medium to high confidence. I haven't actually promoted into what I'm considering a high confidence part of the attack. That's one reason, by the way, why it's so difficult to trace. Not because it's Bitcoin specifically, but because these are like thousands of previously unconnected cold storage addresses. You know, if a bridge gets hacked, we go and look at the smart contract address and we see all the funds flowing out of it and we see where they go this. To actually gather and find all the examples of people's cold storage addresses being siphoned, we basically have to rely on patterns of attacker transaction patterns and victim reports. And so wave one, which started just after midnight UTC on Friday, on Thursday morning, July 30, was really identified by victim reports around the community. And then the pattern described and identified by engineers at Block Inc. Which Cash App Square, the bitkey. Those guys, brilliant engineers there who have their own hardware wallet, the BitKey, they identified the transaction pattern that then I extrapolated to go find the totality of wave one. I've since talked to dozens of victims who are confirmed part of wave one. And those victim confirmations are sort of how we verify that our pattern analysis is accurate.
D
Alex, can I ask a question? Wave 1 through 4, same attacker, or are people piling in and saying, oh,
C
I found an exploit, yeah, so wave one is like a bunch of obviously seeds broken and funds transferred in bulk into one or two collector addresses and then one or two attacker holding addresses and they're sitting there inert. Wave two is a very similar topography. Again, tons of confirmation from victims in waves one and wave two. So we're very confident in that set. Wave three has a totally different topography. It a very internally consistent one. So we think it's each of these. Wave 1, 2 and 3, we're confident are waves. Wave 3, though, rather than siphoning many users into one big address, which is sort of what 1 and 2 do. Wave 3 has one victim per vault storage by the attacker. So it's like if my 10 addresses all get siphoned in one transaction, they stop at one spot intermediary that's just for me. And then they go into one vault that's just for my funds. And they're all. So there's 293 victims, we think there's 293 vaults. So I don't know if 1, 2 and 3 are the same. If I had to guess, if there is any overlap, I would say 1 and 2 are probably the same. 1 and 2 comprise like 70 plus percent of all the funds we think have been stolen. 3 has a bunch. 2 if it, if 3 is the same as 1 and 2, then the attacker demonstrably changed their operational process. Wave 4 is still not totally confirmed. I don't actually have victims yet that I can confirm are in wave four. Wave four I identified solely by a burst pattern. Think about the pattern we're looking for. The addresses have to have been funded and created after the firmware upgrade on March 17, 2021. They likely are dormant for a while in general because again, these are long term holders. They're fully swept. They're swept with a fee that typically. Most of these patterns have dramatically exceeded the median fee rate. Right. Attackers, they'll overpay for fees to get the coins. And they have other transaction fingerprints. I saw all of that at the chain tip last night and in the mempool and that's why I flagged that there definitely are some false positives in there. We need some victim reports to really help us confirm the last thing I'll say, which I haven't yet really reported, but I will on X sometime tonight. There are like 14 other identifiable patterns that we have found that do not appear related to any of those waves, but do have verifiable victims identified because victims have come forth. And then I've looked at the patterns and behavior of their attackers and found several others or at least one other. Right, so more than one instance. You know, those are literally footprints A through L that I'm calling them at the moment, I think N actually now those have crept up the count. While we may not be able to yet extrapolate like a giant amount to each of them, they are confirmed victims. And so, you know, we've been saying, I think the last numbers we put out were near 1400 Bitcoin yesterday at the end of wave three, if you add the amount, you know, we're saying maybe two or three, I think three or 400 in wave four. But I'm not adding that yet. I really do need confirmation and I encourage victims to DM me on X. I've been diligently helping people for several days now. Not just cataloging it for us, but providing back basically fulsome chainalysis style reports that they can use to report to authorities. But I have it now at, you know, if we include wave 4, we're almost at 2000 bitcoin. So we're well over $100 million of self custodied bitcoin. Even without wave 4, we're over $100 million. I would place it more in the 1600 BTC range again for a distributed self custody storage hack. That's unprecedented as far as I'm aware. Quite devastating.
D
That's awful. The thing that jumps out at me is that, you know, we operate in this trustless, permissionless environment. And the problem was is that as trustless and permissionless as you try to be, you have to have trust somewhere. And they trusted cold card to do the right thing. And that's where everything broke down. And so it's really, really hard. Hopefully there's some good things that come out of this which you hate to even emphasize right now because it's so terrible. But Alex, you're very much in the bitcoin world. If a high level of compute allowed people to derive seed phrases. To me this is a precursor to what Quantum could do, not only in bitcoin, but across all of financial services and beyond. So maybe this is a wake up call for the community to really focus on these high compute threats. Yeah, agree with that.
C
I do. I, of course the threats are a little different.
D
Yeah.
C
But you know, they're not, they're really not that different.
B
Right.
C
I mean if you had substantially, you know, industry standard entropy, you're not affected here, but you could be if, you know, because the world's GPUs combined probably couldn't break it. But that, you know, you're talking about multiple step function increases. In the case of Quantum, they might be able to derive seeds across that whole space. That's the fear. I think this, you could call it a trial run perhaps. If Quantum does emerge, it wouldn't look that different. Right. Because the attacker. This is one thing that's going to be tough with the recovery. If it can happen. How does the victim prove their ownership? Right. Like the attackers have their keys. Right. So it can't be solely by a cryptographic proof. That's why we're encouraging people to make, you know, fulsome formal victim response filings and reports to FBI's, IC3, their local police to establish their victimhood and keep the cold card device. Don't use it necessarily, don't use it, but keep it because it could be evidence that shows that you did act, you actually were the one that first had the keys. You know, I think another point worth raising is that it's not just the, the cryptography or the generation of the keys. That's an issue. AI is of course across other domains as well are finding substantial code base issues all over the world right now. There's a red team of Bitcoin security engineers working as we speak and for days unfortunately forced to use like Kimi and GLM and not Frontier US models which won't allow this type of cyber work. Literally going over every hardware, wallet, code base, every open source library that's used in crypto and in Bitcoin, fulsomely to try to patch and fight back against what is becoming an increasingly dangerous threat environment. That work is ongoing.
B
If you like this segment, please like subscribe and tune in every Monday at 4:30pm Eastern Time. I'm Austin Campbell, the host of Bips and Biff, along with my friends Rahm Aliwalia and Chris Perkins and our slate of exceptional guests. Every week we're going to discuss macro, crypto and the collision of worlds, covering topics that move markets and shape the financial landscape.
A
If you hold crypto on your phone, your biggest vulnerability isn't your wallet, it's your carrier. AT&T Verizon and T Mobile have been breached again and again, and SIM swaps are still one of the easiest ways for attackers to drain accounts. That's where Cape comes in. America's privacy first mobile carrier, same premium service, but Kape rotates the identifier on Your Sim every 24 hours, deletes your call and text metadata after a day, and protects against SIM swaps with a 24 word recovery phrase that only you control. You also get two middle to end encrypted secondary numbers for banking and signups, so you stop handing your real number to every app that asks. Go to Cape Co Unchained and use code UNCHAINED for 33% off your first six months.
Host: Laura Shin
Guest Experts: Alex Thorne, Austin Campbell, others
Date: August 4, 2026
This episode dissects a major breach of the Coldcard hardware wallet – once considered the “gold standard” for Bitcoin cold storage. Laura Shin and her expert guests explore the technical details of the exploit, its impact on self-custody and trust within the crypto community, and the broader implications for cryptographic security, including future threats from quantum computing. The conversation draws on forensic insights and the human stories of individual victims whose long-term Bitcoin savings were drained.
Summary of the Breach
Notable quote:
“The cold card itself is very popular among a cultural demographic in Bitcoin that believes in cold storage, self custody, stacking, sats, working hard… The average dormancy of coins that has been siphoned [was] almost four years. So these are not like short term holders. That makes it particularly devastating because they did nothing wrong.”
— Alex Thorne [03:10]
Entropy Failure
Notable quote:
“They miswired it into the firmware such that it would fail, it would never be routed through that random number generator… it would backfall to this other crappy random number generator that has way too weak entropy to create secure keys.”
— Alex Thorne [04:13]
Broader context:
Waves Structure
Attacks occurred in “waves,” each with distinct transaction and victim patterns.
| Wave | Pattern | Description | Victims | Total BTC Stolen | |------|--------------------------------------|------------------------------------------------------------------|---------|------------------| | 1 | Bulk transfer | Many seeds broken, funds sent to one or two collector addresses | Confirmed | Large | | 2 | Similar to Wave 1 | Bulk sweeping, same general approach as Wave 1 | Confirmed | Large | | 3 | Vaulted per victim | Each victim’s funds swept into an individualized vault address | 293 | Substantial | | 4 | Burst pattern (unconfirmed victims) | Potential new attack burst, requires victim reports to confirm | ? | Estimated 300–400|
Additional 14+ attacker patterns (“footprints A–N”) identified; some not linked to main waves but have confirmed victims.
Notable quote:
“Wave three has a totally different topography… One victim per vault storage by the attacker… If my ten addresses all get siphoned, they stop at one spot intermediary that’s just for me. Then they go into one vault that’s just for my funds. So there’s 293 victims, we think there’s 293 vaults.”
— Alex Thorne [10:52]
DEX Investigations, Reporting, and Regulatory Challenges
Advice:
Security Model Breakdown
Notable quote:
“You have to have trust somewhere. And they trusted Coldcard to do the right thing. And that’s where everything broke down.”
— Chris Perkins [14:24]
Future Threats
Notable quote:
“If Quantum does emerge, it wouldn’t look that different [from this exploit]. …If it can happen, how does the victim prove their ownership? …That’s why we’re encouraging people to make fulsome formal victim response filings…”
— Alex Thorne [15:32]
On the Victims:
“I’ve had all my bitcoin stolen while away on holiday. It was on a cold card Mark three. I was led to believe this was really secure. The two bitcoin was supposed to be to give to my two children to give them a good start to life.” (Reported victim, paraphrased by Austin Campbell) [01:46]
On Industry Reaction:
“CZ via Zero Hedge said nothing is 100% warning Bitcoin holders after the exploit exploit.” [00:58]
On ETF Debate:
“Eric Balchunas said some such an intermediary upgrade for bitcoin, safer, more secure and almost always cheaper. Speaking about ETFs 33 year old industry 15 trillion in AUM and never once lost someone’s money.” [01:57]
The episode strikes a serious and analytical tone — reflecting on the tragedy for victims, the technical nature of the breach, and the uncomfortable realities of trust even in “trustless” systems. It closes with a forward-looking warning: as compute power (AI, quantum) accelerates, the only robust defense is rigorous, ongoing scrutiny and transparency of cryptographic systems and wallet software.