Loading summary
A
Hello and welcome. This is Gabriel Custodiet of Watchman Privacy privacy practitioner, consultant, author and frontline fighter in the push for privacy. I know why you're here. Like the rest of us here in the resistance, you're trying to escape the technocratic apparatuses that you see enveloping you and crushing your freedoms. That's why I created all of this, all without sponsors. I hope you enjoy this show, but then when you're ready to take the next steps to secure your privacy and your future, Visit my website, escapethechnocracy.com to start the real journey. Your support alone does not determines the future of the show. See you there. Welcome to a special episode of Torchlight Chats where we discuss things happening in the realm of tyranny and technology. This is a special episode because we're talking about something here on August 3rd, 2026 that is direly urgent for anybody who owns bitcoin in a cold card wallet. So we're going to get into this. We're going to explain what this cold card catastrophe is and why you need to move your funds from your cold card wallet as quickly as you reasonably can. And we're going to, then, after we show you what to do, break down what exactly happened. Urban has been at the cutting edge of all of this. And as usual, this is going to be the only show that discusses bitcoin that's going to cover things from a beginner level, at an expert level, emphasizing privacy and sovereignty and being completely agnostic about the whole thing. The only place on the Internet that you can find this kind of discussion about this topic. That's why I know why you're here. And Urban, welcome to the show. How's it going?
B
Very, very stressful. Four days maybe now. I don't know. I've been sleeping very little between the phone calls and answering people on Twitter and the Twitter space and helping people recover their funds. It has been a disaster since this happened. I think it was on Friday, on early, early morning Friday, very exhausted. And I know you, you yourself, you had some friends affected by this and you also had to. To help them get out.
A
So let's get. Let's get into it then basically explain what happened on. Around July 30, 2026, it became public that the way that the Cold card, this is Cold Card is a big hardware wallet company recommended by a lot of people. They sponsor a ton of the bitcoin community. It's maybe not as popular as Trezor or Ledger, but they have a pretty big AUDIENCE. A lot of people use these, especially people who are really hardcore about their self custody. It became public that the way that they generated their seed phrase on their devices was actually had something of a pattern to it. Before you know it, before you could blink, there was 500 bitcoin worth $38 million that were stolen from cold card wallets. So let me start by reminding people, breaking this down in a very basic way, just from the start, the way that something like Bitcoin works is when you create a wallet, your wallet, unless you're doing it yourself with dice rolls, your Wallet is generating 12 or 24 words for you that are supposed to be random. And these 12 or 24 words are basically the identity of your wallet if you were to lose that device. As long as you back up these words, you can resurrect them from any wallet anywhere in the world. And that's a really cool aspect of, of self custody. But in this case, Coldcard dropped the ball. They had a bad way of generating these seed phrases. It had predictability to it. And now we have up to 1500 bitcoin that have been stolen as of July or, excuse me, August 3, 2026. And there's no reason why every single cold card mark three, these are the worst affected. There's no reason why every one of those funds won't be drained given enough time. And there's no reason why the Mark 4s and then I believe the other models as well, such as the cold card mark 5 and the Q are also not going to get drained over time. Now what is cold card done? Well, they introduced a new firmware to solve this issue. There's problems with that and it doesn't solve anything if you originally generated your seed phrase with a cold card wallet.
B
Now I think it's a good overview. Now there are lots of it. It is a complicated scenario because in certain case you can be in a better position. Like if you use dice and you did a hundred plus and, and so
A
just, just for the audience. And if, you know, if you did this, you know what we're talking about. But instead of having the wallet itself generate the seed phrase, you can do it manually through dice rolls. Most people don't do that. But if you did, that is what you're talking about.
B
Yes. And there's also, if you have a passphrase, then you're also a bit more secure. But the point is, if you're using a cold card, what we recommend that to everybody who called us and wrote us and asked for help Is you just migrate your funds out and you let the dust settle and then you rethink about your setup. But I wouldn't keep for now using it. You have more time, of course than if you just use the default. But I would still consider moving eventually
A
you have more time if you did. If you have a passphrase is what you're saying.
B
Yeah, if you have a passphrase, if you have done all the dice, it should be fine. Many people who actually tried and it seems that in this scenario the seed generation is, is good. But yeah, I mean then you know, there is also your, your own question like do you still trust this wallet or not? And, and that's a separate issue. But I, I would still recommend moving them out, especially if you don't really know what you have done. If you don't really know if your seed phrase, if your sorry passphrase is strong enough. If you have only made a few dice rolls, you need to move them out like you really need to. And this is all the models, like all the newest model, the Mark 4, Mark 3, Mark 4, Mark 5 and model Q, all of them are affected. Mark 4, 5 and Q, they are slightly less at risk, but they are still affected. So you still need to move the funds out. Now how you do that as, and I know this sounds contradictory. So first, do not rush unless you have a Mark 3. If you have a Mark 3 and you're now on vacation and you're somewhere, this is a get on the plane and fly back and do it. Because the Mark 3 they are actively getting drained and with each wave there is more and more wallet that are getting hacked. And by the way the attacker, because it is on the seed itself, the attacker doesn't need access to your call card. This is a completely remote thing that can be done, actually can even be done offline. You can just pre compute the seed and then you know, drain the wallet. So you people do not need access to your call card in order to drain. So if it's Mark three, yeah, take plane, go back home and do it. If you have Mark 4 and 5 and Q, you have a bit more time so you should get a new wallet. If you are in United States and Europe, you can go to electronic stores and you can buy ledger and in some case Trezor. So you can do that. That's totally valid. You can also buy a phone like a Pixel phone and you can install graphene os. That's also totally valid. It's actually not that expensive. If you get one of the cheap Pixel phone compared to a brand new hardware wallet. And if you have an existing hardware wallet that you know how to use, that is not a call card. I would use this one. I would not try any new fancy software. There have been people who have downloaded like oh let me try wasabi and sadly they downloaded the fake wasabi and then their funds got drained as they were trying to save them not from the hack, but from a fake wallet. So don't try anything fancy. Just go for what you know, get a new hardware wallet or get one that you have around. If you have one that is not open, create a new seed and then transfer the funds. I would also consider make sure you have a backup. Do not update the cold card before you transfer the funds.
A
Yeah, what you said, Urban, is a great point that there are a number of people asking questions. Oh yeah, but you know, my cold card is air gapped and it's. If you generated at any point in time a cold card seed phrase and you have funds on that cold card or that cold card is part of your multi signature setup, then you need to act now. You need to change none, none of those other details matter. If you generate, if you generated a seed phrase with a cold card wallet and you have funds there, you need to take action. I was talking to some person, one person in the last couple of days who didn't even realize until you know, the next day that actually even though they were using a different wallet, their seed phrase was generated with a cold card. So sit down and think about whether that is the case or not. Now in for the next steps for people, as you're saying, Urban, they need to get a new wallet. They need to do that properly and the proper way to do that. Of course, if you have another hardware wallet lying around, that's a great option. You can use a Pixel phone that you could go and buy. You could go buy a cheap Pixel phone, start it up, don't have to install graphene OS necessarily. Install a trusted Bitcoin wallet on there, the software wallet that you trust, generate the seed phrase on there and just use that phone for having generated that seed phrase. Essentially if you're more advanced, you could also take one of your laptops and do a fresh install of Linux. Install a wallet such as Sparrow, generate your seed phrase from there and then potentially wipe the device after that so that you don't have a always on hot device. That if you have generated a seed phrase on a hot device such as a laptop. This is why we don't advocate that there could be malware on your computer, there could be key loggers that are looking for your seed phrase that could take your seed phrase. That was the whole point of a hardware wallet is that it's not connected to the Internet. You can replicate that functionality in a semi cold way through the Pixel phone. Pixel Phone is the most secure phone out there. That's why we recommend that. Or you know, wipe your computer with Linux if you know how to do that fresh install of Linux, get a wallet like Sparrow Wallet, generate your seed phrase and then wipe it again. So that would be the thing to do, create a new wallet and then urban what you're going to do is you're going to transfer your funds from the cold card wallet to the new wallet. Now I encounter this with some people as well. They don't realize that the cold card wallet, it's not just there's, there's very, there's many different variations of people who have used a cold card wallet. Can you talk about some of those variations? We have multi signature, we have people who forgot or you know, never realized that the cold card is not just for generating your seed phrase, but it's also a signing device. So if their cold card is sitting in a Swiss vault or you know, is at their mom's house, they need to be able to have the cold card in their hands in order to send a transaction out of it.
B
Yes. So I just want to add one precision before wiping out, make sure you can recover the seed. Make sure you do the whole process right, that you wipe out the wallet, then you try to recover from your backup. And then you see that the entire creation of the wallet, destruction of the wallet and recovery of the new wallet is something that is functioning and that is correct. And again, this is a temporary measure. Right. You eventually want to go to a new, better setup. But for now the goal is to safeguard your funds.
A
Right. Don't sit around, order a Trezor wallet and wait seven days for it to come in or two or three weeks depending on what the demand is.
B
Now don't start to go into crazy multisig right away or put very complicated passphrase right away, like safeguard the funds now and then you can think in the next week or two how you want to reorganize this. Okay, so the different way people were using the cold card, so if you used it to generate seeds and it even had a feature where you could do that, where you could generate sub seed from your main one, all of those are considered weak and they are Considered potentially compromised. So all of those you have to migrate if they have funds. If you were using the call card in a multisig, if you have only cold card for the multisig, like you have three device and those three device are cold card, then obviously it's weak. And you should also change this and you should rotate, you can rotate the keys and add a new device. Now we won't explain this into too much details here because multisig is quite advanced. We suspect many people don't have this set up many or listeners simply because it's something that is a bit more rare. Just be aware of one thing. If you have a multisig with multiple cold card, when you broadcast a transaction, it can reveal additional information that can help the attacker to steal your funds. This is why when you are upgrading it, you have to use a silent broadcaster that send your transaction directly to the miner. And there is Mara, the mining company that has a service called I think Slipstream that allows you to simply upload your transaction. You have to pay all the fees and everything like before. But they will not broadcast it to the public. They will mine it. And once it's mine, it's good. So this is just the one caveat. And then for the rest, simply follow a tutorial. How to remove one of the wallets, put a new one and do a rotation of the keys. Be aware that when you do a rotation of the keys, you need to send all your funds because technically you are creating a new wallet. So that is for multisig. If you use to generate the seed, we covered that by the way. If you use to generate the seed and then you load it on a ledger or Trezor or a seed signer, that's entirely fine. As in your device is okay, you don't have to use the call card anymore. You can just generate a new seed on this device that you're using now. Right? So that, that's, that's a scenario that is a bit simpler.
A
What, what some people who just, they don't realize what it takes to use a hardware wallet. So they started their wallet with a cold card and then that's just been sitting there and sure, maybe they've sent some funds in there initially, but what they don't realize is that the way that a hardware wallet works, such as a cold card, is that you have to be using a software wallet. Let's say you're using Sparrow Wallet or something like this. You have to initiate a transaction with your software wallet and then you have to connect Your you have to make that transaction available to the cold card wallet. You could use like a micro SD card or you could connect it to your computer, something like this. And then the cold card has to approve that transaction in order for that those funds to be able to be sent to the hot wallet to, to the actual software wallet and made available to the Bitcoin network. The cold card wallet is offline is what is signing the transaction. It is the thing that has the authority to sign the transaction. But the details of that transaction are actually done in a software wallet. So that's why you need the cold card in your hands. And if you need some details about how to do that sort of thing, there's some tutorials online BTC sessions does great work about that. And by the way, if you're listening to this, go ahead and share this episode, wherever you are with everybody you know. Let's make this show, this episode, the definitive episode on this particular topic. Urban's been the ones, the one on the front lines of this whole thing. We're not the guys who have ever shilled ColdCard. They've not been a sponsor. So, you know, we're the ones you should be supporting now and moving forward when it comes to Bitcoin security. Also our good friend alejandra Guajardo Sada, Ms. Bitcoin has a video that we helped her to make that is more digestible for the average person. So we'll share that link. If you're on Twitter or especially Instagram, you have a family member who needs it broken down just very simply from the beginning. That will be a good resource to share with them as well. So, okay, we have told people that they need to create a new wallet. Be responsible about how they. Let's talk about that for a second, Urban. So creating a new wallet, of course you need the most secure device that you can have. If that's a hardware wallet that you have lying around, great. Otherwise you could get a Google Pixel phone like we said. Or if you're more advanced, you could do the Linux laptop method. But when you create that new wallet, obviously it will generate a seed phrase for you. And in the case of ColdCard, we'll get to the details of why that was not secure. But. But don't get another cold card, obviously. But most other reputable wallets, for example, I just onboarded somebody to Trezor. That should be fine. Okay. And you know, I'm careful what I say now because we need to be careful about just saying things are fine. But you gen you get a new wallet, generate the seed phrase. You're going to write that down. This is Bitcoin 101. You're going to write down that seed phrase on a physical piece of paper. Don't store that anywhere electronically. Write that down on a physical piece of paper. We have an entire kit, by the way, backup kit for seed phrases. I just helped somebody to use that recently. Write it down with a gel pen, which is not going to smear over time. And then in our, in our process, we have special templates that we create that look like everyday things like birthday cards and such. So there's a little bit of obscurity in this process as well. And then you can go the extra mile of folding that and then layer laminating it, if you would like, at home with a cheap laminator that you can buy on Amazon. That's the method that we recommend. Other people will imprint it in steel. It's a little bit too late to be getting steel shipped to your house or something like this. Very basic thing though is you can write it down on a piece of paper and then store that piece of paper with your life, essentially. And make, of course, multiple backups, two or three, and hide those in a place that you also write down so you remember where it is hidden.
B
One of this template we provide for free. So this is part of our product, the underground backup kit. But due to the emergency and so many people that need it, we provide this one template for free. And it has everything you need to back up to get a proper recovery. You know, the software version you use, the type of wallet, the manufacturer, all of those things. And why is this important is because in that template specific instance, the manufacturer and the version of the wallet is important to know if you're vulnerable. And most people don't back up this because they don't think about it. So this is why. And this product, you know, this is not something new we did just for that. This is something we have now since maybe you created Escape the Technocracy back in the day, in the days. So this, we have been sending it on Twitter.
A
We'll have a link for this in the show, right? So, okay, they generate the and protect their nude seed phrase urban. And then after that they're going to make a transaction from their cold card wallet to this new wallet. Now, we've always told you that combining all these UTXOs is a serious privacy risk and that is the case. But if you're an hour away from getting your cold card wallet pwned, stolen from you, then it's going to be what you need to do and then you can sort out the rest later. So to send a transaction to Bitcoin and a lot of people who have their funds in a cold card, maybe they've never done this, but now's the time to educate yourself and then, you know, learn. But the basic process is you will initiate a transaction on your software wallet. If you need to get permission from the cold card, which you will, then you will connect the cold card to the wallet, have the cold card approve of this transaction, you'll be sending the funds to your new wallet. So that's why you need to create the new wallet. First get a receiving address from this new wallet, double and triple check that long string of characters, okay? Starting with the first characters, starting with the last characters. You don't want to send these funds into the ether. So double check that receiving address from the new wallet and then send your funds from the cold card wallet to this new address. And that is the basic process.
B
No, you covered very well. That is good. And I mean if privacy is a concern and you feel like you have the time, then go ahead and send one by one. If you have a Mark 4, this is doable. If you have a Mark 3, just don't. And in the case of the Mark 3, your privacy is already gone because those seed will be eventually hacked. Eventually all of this will be published at some point in the months or years that come. So you don't really gain anything by sending everything at once. In the case of Mark 4, 5 and Q, it's a bit like this could take longer and you might have some more time. And also it's unsure if the hackers will be easily able to hack them or not.
A
Right, but still there have been funds taken out.
B
Yeah, there have been. Yeah, exactly. There have been funds that have been taken. It's just way slower, right?
A
I, I would say cold card, cold card three or after, you need to take urgency, right? If, if, right. We're talking about people maybe, you know, are they spending that $10,000 on a last minute ticket to their Swiss Volts or something? You know, maybe that's when you have a mark iv. You're like, okay, maybe I'll, you know, wait a day or so. But you know, we'll, we'll leave that up to their discretion. So, okay, so just in summary, and then we'll move on to some other interesting topics surrounding this. If you have a cold card, wallet mark 3, and after you have to move your funds out of that wallet, you have to. So you create a new wallet and you move your funds to that new wallet from the cold card. Have to do that. Now, let's, let's get into some of the interesting questions surrounding this. Let's go back to this problem.
B
To begin with, there is one thing. Before, before you transfer anything, do not update the call card. The manufacturer made a release that fixed this bug. Do not update before you send the phones. What? Why? Because this update, and we will discuss about it actually, in certain case, brick and destroy your device. And this means that you won't be able to use it anymore. And then you will be doubly screwed because now you know you cannot send your phones out. And also you don't have a hardware wallet that you can easily do. So don't do that.
A
ColdCard, basically, they're, they're scrambling over there. Obviously, as a company, they created a fix for this which changes how a seed phrase is generated. But that was done in a hurry. And that can lead to anytime you update your firmware and let's say you unplug it while it's updating, that's always a risk of bricking your device entirely when you need it most. But also the update that they did in a rush. You're saying there's people, people have shown that you have an even higher likelihood of bricking your device.
B
Yes. And potentially you have other issues that. Anyway, don't do it. We will explain in the second part of, of this episode what happened. And, and, and I know, Gabriel, you're excited to go this, but this is just for migrating your funds. This is the last thing you need to know. And then after that, I wouldn't even update. I mean, it's debatable, but like, I would just not use it. I would just not use it and wait for the dust to settle. But it's like I cannot trust this device anymore.
A
Right. I don't see any reason to trust Cold Card ever again, necessarily, and certainly not for a long time. So, you know, we're not even going to be talking about this company for the foreseeable future, except to condemn them, which they deserve condemnation entirely. So now let's get into a little bit of the details here. Urban, let's go back to this problem in the code of Cold Card. And before we get to how this got in there, can you explain at a little bit of a deeper level, what exactly was this problem in the code where the generation of seed phrases was weak, had a pattern, and led to people being able to guess them.
B
Okay, the easiest way to understand this is you cannot easily generate randomness. I know it sounds like stupid, but it's true. Randomness is very, very hard to do. And for that you need a physical device that is specialized in generating random. So imagine that you have a tiny slot machine, like in a casino, that is inside your cold card or inside any hardware wallet, and that this is what you use to create your seed phrase. Right? Now, in the case of cold card, there is this tiny machine. It's there, but it's just unplugged. And we are going to explain why it was unplugged. But then because it's unplugged, the device when generating, goes back to the software generator, which we know is weak. And the software generator used the serial number of the CPU of your device. Use some other values, and if you read the documentation of, you know, the manufacturer of those cpu, you can know their serial number. You can know a lot of information and therefore you can predict it because it's not using the tiny slot machine that is meant for that. So it goes from being extremely secure and hard to predict to something that a laptop, in the case of the Mark 4, a laptop can break. And in the case of the newer device, a small GPU farm, well, maybe a big GPU farm, but like you can still crack it. We go from 128 bits of randomness to between 40 and 70, which is very, very bad. So that is the very high level thing. It had the hardware to generate randomness, but it never used because it was just not powered, not plugged.
A
And we don't know anything about the attackers at this point in time. What are the details about the wallets that have seized these funds?
B
Okay, so there were like numerous waves. Like the first wave actually was almost not seen in the first evening. And then every day, every roughly 24 hours, there was a new wave of swept. And it looks like it was made by AI because it did very stupid quote unquote mistakes. It only took certain amounts of the wallets. Like if it was below a certain size of Bitcoin, it would not touch. It would only take maybe the first 20 UTXO that you have in your wallet. It had all those weird things. So this was the first attacker. There is between three to four, maybe five waves that are attributed to them because they used similar fees, similar hours of the day, similar everything as, but, but as soon as this was public, everybody then tried, right? Well, everybody, all the bad guys tried to get their crack at it. And now we have multiple, in some case we have even people competing to try to steal from the same wallet. And you can see this on the mempool because they are replacing the transaction of each other. And of course you can do that with, you know, AIRBF replaced by fee. So now it's a bit of a mess. And those new attacker, they, they have, some of them have, you know, sent the money to an online casino, others have changed it to other cryptocurrency like this is more alive. The original attacker that got most of it, which is, you know, the thousand plus Bitcoin, they have not moved as of, you know, third of August. But of course this can change any time. But as of today, which is the 3rd of August when we record this, they haven't moved.
A
And I'll just insert another note here for the real beginners here. The way that the seed phrase works in Bitcoin is that you have 12 or 24 words that are as randomly generated as possible. And these random words, that is essentially your security. Now there are enough combinations with those 12 words and the word list is 2048 words. There's enough randomness that that is an incredibly huge number. Impossible to guess essentially. Unless as the case with this, you can predict a pattern, well then suddenly it's a lot easier to guess. So that's what was happening. And like we said, if you have a passphrase for your wallet, that reduces the likelihood of this happening significantly. So a passphrase is definitely a solution moving forward. So more details about what happens. Urban, some people, you'll see some, some people out there saying, yeah, this is why I, this is why I trust Coinbase with my Bitcoin. What would you say to them?
B
Oh yeah, how do you think Coinbase is storing their Bitcoin? If self custody is not possible to do, then, you know, nobody can do it because at the end of the day there is someone at Coinbase that you know, has the key. Maybe it's a team of people, but like they probably use a combination of, you know, hardware, wallet, maybe some software, maybe custom made stuff. No, it's, it's not the solution for two reasons. The number one is the one I said the number two is as painful as this hack is in terms of Bitcoin lost, it is nothing compared to like an exchange blowing up. Like I think people have such, yeah, ftx, FTX is so much more money. Like, and, and I don't want to go into comparison like, oh, who suffered the most? But like as much as this One sucks. Montgox alone had more bitcoins. Now they were valued less of course, so it's not a one to one comparison. But like just in general you had so much more money. I mean Terra Luna alone is way more than this hack of value that was lost by people. So no, no, no, it is not better to move them to Coinbase or any other custodian. You would be foolish. You might want to store some of them there. If you're doing trading and investment and stuff, I mean that's on you. But if you store them there for security, I don't think you have more security. And then you also ignore that all those centralized exchange, they will not hesitate to freeze your funds. Like if there is anything like new president is elected in USA and then the entire world change instead of anti woke, now it's pro woke or pro this or on TV this or that. And then suddenly, you know, you find yourself on the other side of the fence and guess what, your account gets frozen.
A
Right? This is the, this is the other side of sovereignty, is that responsibility. And you know, honestly, every person who trusted Coldcard, they were trusting them. They didn't do the work to audit that this wallet was generating stuff randomly. So in a small certain sense it is on us. But let's talk about the responsibility of the sermon because this is, this is a big question of, of pointing fingers and such. So there's, there's a lot to discuss here. I'll just say for starters that one of one of the big problems that we're going to discuss is how litigious Cold card or coin kite the company is. That is one of the themes is going to be that this was actually a problem in all this. So even us, we're going to be slightly careful about how we describe this. And this is a shame, honestly. Let me just start with an inflammatory statement and you can go whichever direction you want, Urban, is the fact that coldcard went from being free and open source software, changing their license to being now their source, viewable. So we can look at the code, but it's no longer in the FOSS ecosystem. How much is that to blame for what happened? And where do you put the blame for this? Obviously Cold Card, they're the ones who did the code, they're to blame for this. But what led to that being bad generation in the software?
B
I mean, look Gabriel, ultimately it's a company and they are free to change the license of their code and you know, they choose. But in hindsight it was probably not the Best move technically and politically. So let's start with, you know, the political aspect, which is when you create a company and you advertise yourself doing free and open source software, in other words, FOSS going out and becoming proprietary, or changing the license to just. You can view the source but you cannot use it, is generally seen as a bad move and it generally antagonize people in various way. It is actually much easier to do the other way around, you know, to start proprietary and then slowly go open source.
A
Because the idea of free and open source software is that, because everybody can contribute to this, because not only you see the code on GitHub, but you can actually contribute to it. It builds a collaborative mindset. It encourages people to go and look over the code and maybe make a suggested change. Maybe, you know, they, this problem would have been found by somebody who was going in there, maybe trying to make a name for themselves, maybe just trying to build up some, you know, credibility on, on GitHub, maybe just out of curiosity. But that kind of collaborative environment was not at all encouraged by Coin Kite.
B
So by changing the license, politically, no, it's not encouraging. And then there is a technical aspect, which is if you change a license, you need to sometimes rewrite a lot of things. And rewrite is always dangerous because you build a product that uses certain type of, you know, that has a philosophy. And then you, you need to write a new firmware that is different, but does the same thing. But like, it's a complicated. It's. It's not an easy thing. Like, it takes a lot of resource and time and all of this art, all of this is time and resource that you are not spending making the product more secure. And at the same time, as we have said, it is antagonizing for the community, for the people. And this combination is quite bad. I will just say, and this is a personal story. I read the code of wallets sometime for fun. I'm not trying to audit them, although sometime I am, but not professionally. I just like to see how they solve certain issues. And back in the day, When I found ColdCard, I was thinking, oh, it's a cool wallet. But I didn't read their code because, you know, they had the reputation of going after people who build things that are too close to what they do. So for me, if I read their code and then I create, let's say, my own wallet, I don't want to create my own Bitcoin wallet. But let's imagine I want, I don't want to have the risk that they come after me and they say, oh, you know what? You got inspiration from this code that looks like the same. And then I would be in trouble. It's pointless. And this has reached a point where there are researchers that were apparently, and I have to say, allegedly, because I didn't check too much, we're avoiding them because they just didn't want their troubles, which is ridiculous because you want people, you want the expert to say what they think is if it's secure, if it's not. So you have the worst possible combination. As we said, you are antagonizing the community, plus you're rewriting everything. And when I said that in a Twitter space, actually I was shot out and, you know, someone started to yell at me and, and then I decided, you know, to leave because I, I don't want to be yelled at. But this is the exact point. It is this type of, like, if you allow this type of behavior, it doesn't foster, you know, a good, what to say, good feedback that can be
A
used to improve the product now, and ColdCard has been not fully free and open source software, as you and I would understand that term, for a while now. That is when I stopped recommending it to people. That's when I stopped encouraging it. That's when I stopped respecting the company entirely. But there have been plenty of people, plenty of, plenty of channels that have continued after that anti FOSS and I would say anti Bitcoin stance to recommend cold card wallets. Should we condemn these people who have shilled the cold card wallet?
B
It's a good question. Look, Gabriel, there is an alternative timeline where you're a company, you make a sourceable code and you're nice to the user and the community, and it's a quasi open source project. There are many open source, well, not open source, but like sourceable project that are like this. The license itself is not everything.
A
Right. If it's open source, anybody can still look at it.
B
Yeah, sourceable, anybody can look at it.
A
Yeah. We shouldn't. Yeah, we need to stop using this word open source if it's not free and open source. That's the whole, that's the statement.
B
I'm not expecting like a big influencer to know all the details about, you know, how randomness is generated, which license and things like this. But what would have been nice is
A
more of a, more of an outrage from some of these people. When the cold card became source viewable, that itself could have put some pressure on the company, could have changed things up a Little bit, no, you didn't see a lot of it. You saw that a little bit. Especially let's say from the people in the samurai wallet Venn diagram of things. But and of course, you know, foundation passports whose AI or cold card received during this time. They have been talking about this. But in general, people have just been keeping recommending cold card. That's the thing to do and not calling them out on some of this very disagreeable behavior.
B
What's in this case is you and I, Gabriel, have to be careful about what we say because they were known to be litigious, which is sad, right? But if you are making a product and then half of the people you sponsor tell you, hey, you know what, we love open source and you're not really doing open source stuff anymore. We don't like this. Guess what? This is feedback. And the company can say yes or no. They can decide. And you as a sponsor, as sorry, as someone who is sponsored by them. And again, it's an hypothetical company, you can choose to go to the proper open source project and say, you know what? I will not accept money from it. And I guess like what happened is all of this put together gives a sense that everybody is recommending this specific wallet, all the influencer, all the bitcoin podcasts, even ourselves. If we were never sponsored by them, we never got any money. It gives a false sense of consensus. And then all the engineers and the coders and the dev, they are kind of sidestep because they don't have a voice. They are not on podcast every day. They, you know, sometimes they just shut up because they are afraid of something. And if you are someone who makes critical software that is not a good idea, like that leads to disaster, you know, when you cannot speak up about things. Is it exactly what happened in this case? I mean, you know, people will debate endlessly, but at the end of the day, I think we have to recognize that, you know, we shouldn't tolerate behavior that is, you know, antagonistic against other open source projects. That is just not something that is good. And I'll say for people, you can search foundation device on Twitter and Zach, that is their CEO, he has great post. There have been tweets that have been deleted. I cannot even, you know, read them to you, but some of them have been screenshot and when you read them,
A
deleted tweets from ColdCard and.
B
Yeah, from Cold Card. Yeah, yes, yes, specifically. Yeah. And I think you can make your own conclusions about if this is a good thing or not for the ecosystem, right?
A
Now I, you know, I do condemn the people who were shilling cold card and not calling them out on this anti false behavior that we saw that was very obvious to people such as us. We've talked about this on the show many times. On the other hand, the problem in the code was right there sitting in front of everybody's eyes for years and people didn't do the work. They did not look at this software that they were supporting, that people were supporting and buying and using. So you know that, that is another aspect of this. But is this something that we should be concerned about? The random generation of other Bitcoin wallets? Is this there, there's, there's no other issues that I'm aware of that people have found in some of the more reputable companies. But is this a, a concern moving forward? And let me ask another question. Is AI a problem in all this?
B
Okay, so first question. Yes, it is a concern like the random generation is crucial and it's not just about Bitcoin. Like randomness is hard. Debian learned a very, very hard and harsh way. There is always things going on with randomness. And famously Cloudflare to secure the Internet, use the webcam in front of a lava lamp. They use literally a lava lamp and then they would take picture of the blobs of wax rising and falling to generate randomness. Yeah, because it's a hard problem. It's a very, very hard problem to solve.
A
Yeah, but does that lava lamp have proper entropy? I'm joking. Let's continue.
B
Of course. Yeah, but yeah, I mean you also, you can, you know, just go on YouTube and search, you know, people who have scammed, quote unquote, casino, casino, spend, you know, billions of dollars to make sure the dice are weighted properly, that all the slot machine have a correct random generator and all of those things. So it is a hard thing. The wallets, I think like with a plane crash. Everybody is now reviewing the code of the random generator to make sure it works. I will just add a bit of credit to call card. In their newer model, after the first random generator which was failing, they added more entropy, more randomness. It was still not enough, but now this makes the mk4,5 and q slightly better. That, you know, you can wait a few days to transfer the fund versus you know, instant drainage. So combining randomness is hard, but in this case it helped. And actually the backup provided enough entropy. Well, not enough entropy, but enough to protect a bit longer. Yeah, I mean foundation, they use I think two or maybe three different source of entropy. So if one of them fails, because another thing nobody discusses, what if suddenly on, on the chip the physical hardware fails? Right? What happens? And it's silent. Like you know, suddenly just generate once or zero or you know, some or capital A forever. How do you detect this? It's hard. This also was a bug that affected other wallets. As in they got, you know, there was a bad random generator in Android and then while it's on Android, we're hacked this way. This is why Samurai, by the way, forced you to put a passphrase. This is one of the reason why. Because then if you add a passphrase, you have another layer on top of it. And when you were creating a new wallet, they would force you to put a passphrase about AI. AI is a blessing and a curse. So I think what's crazy about this discussion with AI is that first of all, all the American based model like Claude and GPT refuse outright to answer you. Like if you copy paste the lines of code that had the issue, even if you ask simple entropy questions about encryption and password to cloud fable and the new frontier models, they will not answer you.
A
You're talking about, you're using AI to troubleshoot. Yeah. So I was also asking some AI, some questions about this gold card situation and it, you know, was, was saying you shouldn't, you shouldn't be, you shouldn't be talking about this stuff with AI. Yeah, yeah.
B
Which means now people need to use Chinese model QIMI3 to do this and to be able to debug and to troubleshoot things. It's really ridiculous to think that the Chinese model have less censorship than the American one. At the same time, in defense of anthropic and OpenAI, the current cybersecurity landscape is a minefield. Even companies like Google are struggling to keep up with the amount of bugs and exploits that are found by those models. I know this because Graphino has posted recently that Google for the time being decided to just stop talking about all the vulnerability and just fix them because they, they had to do it. It was just too much, they didn't have the bandwidth. And we talk about the how many people work at Google in cybersecurity? It's like hundred if not thousands of people there. And the problem is those models just find too many bugs and then you need time, the human needs time to sort them out, triage, is it really a problem? And then fix them. And all of this takes tremendous time. However, the bad guys do not care about this. They will have access to all of the newest model at this point. I think you and I agree that censoring the model on cybersecurity is hurting like it was actively hurting us when we had question to help people recover their funds, which is ridiculous. Or it was preventing me from analyzing some of the code to try to understand it, which is ridiculous. I think those models, we should have access to non censored model just to be able to audit the code and see. And Coldcard to their credit did an AI review of their code and it didn't find this specific bug. But you know, this was like a month ago and before they released their new improved the Frontier Class, you know, the latest groundbreaking models that they released.
A
Okay, so you were retweeted by Coldcard. How dare you. What happened?
B
I'm fair. I think it's because I explain how things are and I'm not insulting people.
A
Right. What specifically did they retweet? What's, what's that all about?
B
It was about them destroying the hardware that was in the assembly line and not yet shipped to the client. And people were saying, oh, how dare you. You're destroying proof. And you know, and all of this, first of all, the proof is in the code. Yeah, it's like man, like, it's like, are you stupid? The proof is in the code. Anyone can download this code and see by yourself. The second thing is why destroying those hardware wallets. So put yourself in their shoes. They have their worst time in their life. Several hundreds thousand plus thousand bitcoin have been lost because of this bug. All their support line is swamped by people having question. They need to triage, they need to help, they need to do everything. We have been doing times, you know, 2000 because they are basically the company that everybody goes to when they have a question.
A
And even then there's, there's going to be people who don't see this. It was an original sin problem and the amount of bitcoin that are going to be taken as a result of this is just going to be mind boggling. Most likely. It's, it's not a, it's not a solvable problem because it requires people to take action and people are not going to take action.
B
And I will shout out to D, I think who is from Colecal Support because he's left and right on Twitter answering people doing all of this and I think he's doing an amazing job. So they decided to destroy the device. Why? Because you have all of this and then you have, you know, an assembly line that is creating Cold card that you know have a bug. Well, why, why having now to figure out about new customer that don't have yet the device that can wait, that could put their funds there and then get lost. Then it's a liability because you shipped a known defective product. So even if you say okay, you keep them, what if someone steals them? Then send them to people and use them as a way to for supply chain attack. Which software should you use? What should you ask your quality and tester team to test? Too complicated, you just destroy them. Problem solved. We don't have this anymore. And when you start again producing, if ever, then you can start, okay, we start from scratch. This is how we do the new software. This is how we install it. This is what we test and you start. But in this instance, it's trying the hardware again. It's not about proof of what all of the, I mean all of the code is on GitHub. Had they taken down the GitHub then you could say the structure of proof. But no, in this case it's just an empty electronic device that has no software in it. It was absolutely the right choice. Yeah, I think there they did a good thing.
A
Yeah, let's return to this. The code. Okay, so the code was changed at a certain point to introduce this bad random generator. This is rife for conspiracy theories. I don't use that term in a negative way, by the way. We've seen in the case of the XZ software for example, that there was a very profound conspiracy of somebody trying to hijack a popular software. So basically, what have you discovered because you've been again on the front lines of all this? What have you discovered about the. The commit that changed the generation to what it is today, that entity being, well, responsible for all this, essentially.
B
Okay, so around the time when they want to change the license, they were also going away. They were. It was not just about the license change. You know, they were doing big change and they just put two and two together and did those change plus the license change. And around this time they introduced libngu, which is kind of like an unfortunate name in retrospective, which was made by nobody really knows. It's actually a library that no one else use to our knowledge, if anyone, by the way, just let us know, I would be interested. And this is the microcode that is responsible for the management of the device. And then on top of that you put your own system and you rely on this microcode. And this was written by someone who has since disappeared from Internet. I couldn't Find much activity on GitHub. There is a Twitter account that has not posted since 2022. It is just not very used. And again we go back to this problem. If you are doing something super special that no one else is using, you have less eyeballs, less audit, less security overall. And the license of libngu which is this core thing. So up until this time they were using the Trezor based foundation, the core. When they moved to Libngu they made their own. So they moved from this decade old battle, tested every bug you can imagine fixed. Well, not every, but like lots of them to this untested thing made by someone that seems, I mean, I don't know. Again you can read the tweet, but let's say maybe not world class cryptographer as one might expect. Again, read and come to your own conclusions. And the license of it again we go back to license is the Bitcoin license. Now you might ask what is an open source Bitcoin license? Well, it's a made up license. I don't know any other software that use it that says that you can only use this for Bitcoin. Now of course, if you're Bitcoin maximalist, this sounds amazing, but actually it's not. I mean if I want to use it for a video game because I need, you know, whatever I'm doing a gamble like device and I need microcode for my, my device. I cannot use it, I cannot, you know, I cannot debug it, I cannot improve it, I cannot submit bug report. And I see this license, I'm like, okay, it's not open source, let's just move on. Let's say you have the worst shitcoin you could imagine that uses it and then they get hacked in a big way because of this. But now you learn, oh shoot, we used this, right? Let's go back and let's fix our own. Or maybe even the shitcoin company writes you and say hey, you know what, we found this bug and you need to fix it. So again we see this license used to. How can I say that it doesn't foster a good community work around it. Because anyone who read this license, why would you use and is lightning part of Bitcoin is ecash part of Bitcoin? Can I use this if I do a ecash wallet? Can I use this if I do a Whirlpool wallet? A Wasabi client is BTC pay server allowed. I mean they also enable Altcoin and you can pay with Ethereum and Monero on it so now you have this extremely important foundation core microcode that is the base of the wallet that this entire responsibility sit on this new thing, this brand new thing. And there is someone on telegram that said, you know what guys, there is a lot of change that happened recently. Are we sure the security assumptions are still the same? Are we sure that you know like this is wild, right? And of course the bug was in this likely what happened. And this is not me saying there is a guy who made. We can include this in the description. But what probably happened and there is a bit of speculation is they got this new thing, they were trying to make it work and they then it was not compiling and they were you know, scrambling around and you know you have the pressure and all of those things and they were trying different configuration and in one of them there was you know, a way to disable the built in random generator. And they said oh yeah, let's do it because we have our own random generator that is secure. And they did it and it worked. What they didn't know and didn't realize is that well it didn't disable the built in one. It actually went into the fallback and actually it's the fancy one, the proper one that was disabled. I don't think it was malicious. I mean we know who coded this or at least who committed it. I mean only the company can know exactly what happened if this was malicious. I could see like a weird intern that creates this and then you know like one of the developer merged this code. But this is speculation that I won't go into because we don't know and I have no reason to believe this happened. I also don't think Coldcard is like the company is actively evil trying to steal people people's phone. Right? I think they are. I, I think they are a victim that. It's unfortunate. I don't have much sympathy for, for, for what happened to them after you know, some of the stuff you have seen. But I don't think they are evil. And at the end of the day they are in a horrible position. You know, I mean I'm just.
A
No, I mean yeah, no, they're in a horrible position. They deserve everything that they're getting and that they will get. So I, I don't have sympathy for them. Let me just.
B
But, but just saying if we learn in the future that a new, you know, remote employee made those change.
A
Yeah, but the changes have been there for a while and, and yeah, yeah,
B
yeah, of course, of course.
A
Now I just want to End with one comment for people. Because this is also interesting, the privacy problem of all this. So as we said, every cold card wallet mark three, definitely mark four, most likely five and the Q series, those seed phrases are going to get guest eventually because they were all bad seed phrases and now you have a small army of people trying to guess them. It's only a matter of time before all of those are taken. So this is going to be huge. This is going to be a huge loss for everybody because not everybody's going to hear this message and take action. But there's also another problem, Urban, because let's say that you do what we say. You create a new wallet, you send your funds from the cold card wallet to your new wallet and now you just abandon that old wallet. Well, that old wallet still has a history. That seed phrase still has a history of transactions. Now the people who crack this seed phrase and that will happen for the rest of eternity, every agency will be doing a similar thing potentially. They're going to see all of your transactions and that is going to be a very invasive privacy loss as well for everybody who even if they did the right thing and moved away from coldcard.
B
Yeah, this is the one thing that, yeah, people don't realize. The entire history. If you use the cold card wallet or a cold call generated seed, eventually the entire history of your transaction and how much money you received and how much money you sent will be visible. And if you had, you know, your precious UTXO and you know, you have your non KYC or KYC bitcoin and all of this, all of this will be, you know, eventually figured out and analyzed. So it is a huge privacy loss. I mean the simple thing to know is let's say you have your 10 bitcoins and you never use the address and at some point you paid for a coffee in one of the bitcoin community around the world and the merchant only saw that you have 0.000 anyway the price for coffee. And then there is this hack and this data ends up on the dark web. What happens is that now suddenly they see all your UTXO and they see that oh, you have 10 bitcoins and then they can come at your place and do horrible stuff to you to try to get this money even if you sold it or lost it or something else happened. And that is something I've never seen discuss really is the privacy loss, the massive privacy loss if someone used whirlpool, if someone use wasabi or whatever with cold card. Well, guess what? Now all of those will be, you know, it's a huge data set that can be basically be used to remove some of the obfuscation that happen in coinjoin and just naturally by not reusing addresses. My prediction is that eventually we will see a data set with all the cold card keys that were found and that this will first stay in the like probably in the darknet and that people will be able to buy basically like a file that contain all the seed that were found. Now all those seeds are empty, but you get the history. Another example is let's say you know, two years ago you had a call card, you send your 10 bitcoins there and then you remove them. Never use the wallet again. Well guess what? This is again known. It is a mess. It is a mess like this goes beyond just and not only it degrade your privacy, but it degrades the one of everybody around because now suddenly we have all those address linked together.
A
We will be. We will continue to report on this. Make sure every one of you is following us on Twitter, especially urban. In this case he's at real urban hacker. Retweet his stuff, comment on his stuff. He should be getting thousands of followers as a result of his coverage of this. We will talk to you more about this no doubt in upcoming bit of time. And for now, fuse cold card. Time to change your funds. Move your funds to a new wallet. That is not a cold card. And that is the message at the end of the day. As always, stay tuned for the most important bitcoin news by people us who are not sponsored by bitcoin companies. And then therefore can speak their mind. We will see you next time. Hey, thanks for listening. I could really use your help. Real quick if you could share this episode with someone, engage with me, leave a review anywhere. This helps me to break the technocratic shadow banning that is happening with my brand. And of course if you really want to escape the technocracy, go to escapethetechnocracy.com privacy tutorial series, books, newsletters, consulting and and of course you can leave a donation. Thank you very much.
B
It.
Escape the Technocracy - Episode 229: Coldcard: The Devastation Begins
August 3, 2026
Host: Gabriel Custodiet
Guest: Urban (bitcoin security & privacy expert)
This urgent, content-rich episode covers the devastating security failure of the Coldcard hardware wallet, which led to one of the largest ongoing thefts in Bitcoin self-custody history. Host Gabriel Custodiet and guest Urban break down what happened, what users need to do immediately, technical causes, rescue steps, and broader privacy and trust implications for the self-custody Bitcoin ecosystem. The tone is one of somber urgency; the advice is actionable and honest, stripped of sponsorship bias.
Immediate Steps (Mark 3 especially urgent):
How to Migrate:
Obtain a new hardware wallet (Trezor, Ledger, etc.) or use a secure phone (Pixel + Graphene OS recommended) or freshly wiped Linux laptop.
Do not use new, untested wallets or unfamiliar software—some users lost funds to fake apps while attempting rescue.
Make sure to create and safely back up your new seed phrase, preferably with a physical record and backups in several secure locations.
Double-check the receiving address when moving funds.
Do not update your Coldcard firmware before transferring funds—updates risk bricking your device and leaving you unable to access funds. (24:25)
"Before you transfer anything, do not update the call card. ...it can brick and destroy your device."
—Urban, [24:25]
“Randomness is very, very hard to do. ...it goes from being extremely secure and hard to predict to something that a laptop... can break.”
—Urban, [26:43]
"Write down that seed phrase on a physical piece of paper....store that piece of paper with your life, essentially."
—Gabriel, [19:34]
Massive privacy loss: abandoned Coldcard seeds, once cracked, reveal complete transaction histories—affecting privacy for years to come.
"Eventually, the entire history of your transaction and how much money you received and how much money you sent will be visible."
—Urban, [64:29]
This event exposes a core lesson: self-custody brings both sovereignty and responsibility. Many Bitcoiners “trusted” Coldcard rather than truly verifying open-source code or seed generation.
Coldcard’s shift from true Free and Open Source Software (FOSS) to source-viewable, litigious business practices discouraged audits and community review—possibly allowing the flaw to go unnoticed for years.
"That kind of collaborative environment was not at all encouraged by Coin Kite."
—Gabriel, [36:27]
Other wallet random generation could be a risk—randomness is “always hard” and must be scrutinized.
Urban on the urgency:
"If you have a Mark 3 and you're now on vacation and you're somewhere, this is a get on the plane and fly back and do it."
—[06:36]
Gabriel on trust lost:
"I don't see any reason to trust Cold Card ever again, necessarily, and certainly not for a long time. ...we're not even going to be talking about this company for the foreseeable future, except to condemn them..."
—[26:06]
On privacy impact:
"If you use the cold card wallet or a cold card generated seed, eventually the entire history of your transaction and how much money you received and how much money you sent will be visible."
—Urban, [64:29]
On source openness:
"We need to stop using this word open source if it's not free and open source."
—Gabriel, [41:02]
Move your funds off Coldcard wallets now.
Create a new wallet (not Coldcard), migrate your funds, do not update Coldcard firmware before doing so, and securely back up your new seed phrase—on paper, with backups.
Privacy and sovereignty also mean personal responsibility:
“We will continue to report on this. ...Move your funds to a new wallet. That is not a Coldcard. And that is the message at the end of the day.”
—Gabriel, [67:20]
Resources & Further Reading
Stay vigilant. Stay sovereign. Stay private.