
Loading summary
A
Rob Hamilton. Damn, man. Crazy, crazy. 24 hours we have a legitimate emergency in bitcoin. What's been going on?
B
In the spirit of emergency, I'm just going to start this with if you or anyone you know has used a cold card, MK3, MK4, MK5, Q, any of those devices with any wallets that were generated from the device you clicked, give me some seed words. You need to immediately stop what you're doing and contact friends. This is a canceling of weekend plans. This is getting on planes. For any ability for you to be able to recover your bitcoin. This is as about as code red as it can get for bitcoin self custody. As it relates to the urgency in which you need to act. I will go more into the details with that urgency. I want to caution slow is smooth and smooth is fast. So you need to act very decisively and you need to be able to act deliberately. You should reach out to your friend networks and people that can help you support any questions you may have. But time is of the essence right
A
now, so maybe we should just start with what happened.
B
Stop your podcast if you have to. Like you need to stop. But yeah, this is not a drill. Keep on going now. This is not a drill. Continue.
A
And so I obviously first saw this pop up on Twitter yesterday. I actually had a cold card mark 4 that I was using as almost like a spending wallet. But the amount in there had got to a point where I was like very uncomfortable. As soon as I saw this news I text you being like, I've seen this thing with the Mark 3. Is it overblown or do I need to do something? And again you were like this is not a drill, you need to do something. Now I wasn't with my wallet, managed to, managed to sort that out. But this is like a serious product, a serious problem that's impacting a ton of people. Where did it all start?
B
So in early of 2021 there was a change to the cold card firmware as it relates to the entropy that gets created and that is when a bug was introduced. Now since I will take a moment to explain the nature of the problem. If you had an air gapped wallet, never talked to the Internet, it doesn't matter the things that would save you if you were using a cold card mk3, mk4, mk5 and q is if you have a sufficiently strong 25th word passphrase, if you also rolled dice or provided your own entropy from outside of the cold card. The nature of this bug is that when you turn on a cold card and you have a clean device and you say, this is amazing. Can you please give me some seed words? Those are not secure. Everything else needs to go down.
A
Yeah, I just want to be really clear so that we don't miss anyone here. You obviously said Mark 3, 4, 5 or Q. What about the Mark 1 or 2? If they were on updated firmware and they still generate Those keys after 21,
B
to my understanding, the mk2 is not supported in any of the impacted firmware. Okay, I'd have to go double check. But the MK, if you have an MK1 and MK2, technically, the firmware bug that we're talking about has not been introduced because that is long end of life hardware. There aren't updates for that really anymore. And so if you have an MK2 or MK1, you should not be impacted by this.
A
Okay. And then I think we should also be really clear on the passphrase, because that's essentially a 25th word at this point. That's the only word really keeping your Bitcoin secure. Is that right?
B
If you really only used one word that is right, which means you are not secure, you have to assume with what we're discussing right now is that many attackers, not just one person, there are many attackers right now who are scanning to get the entire table of all possible seed phrases a cult card could generate, whether it was 12 words or 24 words. And they are sitting on all of those words and they are taking all of the low hanging fruit of single signature keys. My assumption is they're going to move on to other things, but we'll get to that. Yes.
A
And so the passphrase is, is the only thing keeping it secure. If you've done that, you should still probably move funds. Would you agree?
B
Absolutely. Especially if it's one word. So like a one word password is not strong. There are different perspectives on exactly how to mitigate this. Rather than if you're in the zone where you're kind of debating, am I safe or not, you just need to stop what you're doing and recover your Bitcoin before it gets stolen. In theory, if you had 12, like 12 random words that you added on top of that, okay, like, you're in a better spot. But now your entire security model was, oh, an attacker needs my seed words and my passphrase. And the seed phrase is now known by multiple actors at this point or will be imminently over the coming couple of days. If not like maybe a week. But honestly, this is something that you need to move as fast as possible.
A
So the only way you're secure is if you create your own entropy. And doing that obviously comes with its own risk. Like you have to do that very carefully, very consciously.
B
Yeah.
A
Is it kind of to the point where if you're using a cold card device, just move off it for now, wait and let the dust settle, then see what happens?
B
Yeah, like there, there are a couple things. So if you have a cold card and you generated your own entropy, there is no identified bug in any of the firmware from the operations of anything else besides the generation of the seed. Now, to be very clear, the most important thing a hardware wallet can do is give you a secure seat phrase. Yeah. Power users will roll dice and do other things to bring their own entropy into it. So it exists outside of the cold card, tragically. Exactly. For reasons like this, of not trusting the cold card and that you're not going to trust it to provide that information reliably. If you have a very strong passphrase or you roll dice for the time being, there's no urgent need to move as long as you're very sure like that you, you roll those dice to add to that for migrations and things to do that is there's a longer conversation we need to have there. If it's a single signature, specifically with the MK3, you need to do that. Right now, the MK3 is identified to have 2 to the 32 bits of entropy. Now, if you're familiar with seed phrases, right, like these words is that there's a list of 2048 of them. And each time you can pick one, you can even have them sometimes be the same word each time. You're basically picking 2048 multiplied by 2048 multiplied by 2048. So if you take 2048 times 12, you're close to 128 bits of entropy, which is really good. And if you do the 24, you're at 202 to the 256. Both of the like, we're talking numbers that are in the scope and size of. There are more possible seed word combinations than there are atoms in the observable universe. And to explain why this is a problem, the nature of cryptography and Bitcoin security ultimately is that everyone your Bitcoin address, ultimately, in one way or another, results back to a large number, some number between 0 and 2 to the 256. That is the universe. That is the. The universal proverbial needle in a haystack. And the idea is not that someone can't know my number. It is for someone who doesn't know the number to be able to guess it. They have to basically guess all of the numbers in the universe and the universe will go through a heat death before someone's able to get there. With all of our modern computing, right? The problem with the cold card firmware, with this firmware change was with some of the changes, I saw it succinctly summarized as there was code that said, hey, use extra secure entropy and then continue. There was basically a one line error that just said, oh, does this function exist somewhere? If so, you can skip the entropy. And rather than is this function true? Right? It was like a true false statement. And rather than it being is this true, we should invoke that you can skip the entropy. It was like, oh, this exists so we can skip the entropy. That's the best, highest level. It is one line of code of how I can describe this issue. But the thing is with the mk3, since you have two to the 32 bits, that is trivial for consumer hardware to be able to brute force all of the c phrases. The mk4, the mk5 and the q have updates to the firmware. Those updates to the firmware are not better in the sense of you don't have to worry about this, they are extra entropy. What people in the industry are estimating right now somewhere between 45 and 50 bits of entropy, which is more, that is a significant amount more extra protection. But with someone with a data farm of GPUs, they will get this information. And now that people that know that money's being stored on it, it will be consumed rapidly and quickly. So if you did not use a passphrase, if you did not use a seed phrase, like if you did not roll dice, you need to right now stop what you're doing and you have to treat those funds as you're in a race against the clock across many teams of hackers who are going to get your Bitcoin.
A
So the obvious question is like, how, how is this bug not spotted? Like for me, like, this is obviously source viewable software, but I can't read that code. You can, like, did you ever go through and read the cold card code? Like, how was that not spotted earlier?
B
Yeah, I had gone through it previously. Um, I had gone through it with my own eyes and I'd also had gone it through earlier versions of large language models. And what I have observed, and I think this is an important part of the story, is the latest open source bleeding edge model, Kimik3 which is from China. It's an open source model, does not have the safety guardrails that OpenAI and Anthropic have. And so when this, this incident started happening, myself and many people in the industry started looking exactly at where this would go wrong in the code and Fable would downgrade me. So you can't use the leading model. This is a cyber security thing. And then using OpenAI it would kind of like be coy and generally nudge that something may be going on, but not tell me details. I put it into kimik3 and it instantly just read out the entire incident and exactly what went wrong. And so there is something to be said that for a long time security through obscurity was used in places and that is no longer possible. If the code exists and people are able to walk through and see it, it will be exploited.
A
It's. So when I first saw this, I assumed that it was a Lazarus North Korea type hack. Very sophisticated. But I've read some stuff online that says it's maybe a bit of an amateur doing this, doesn't really know exactly what he's doing, but has still managed to exploit this bug.
B
The first attacker was, I would say, an amateur. There's a lot of on chain heuristics of what you could tell in the movement patterns. They only moved bitcoin addresses that were more than 0.15 bitcoin. Why someone wouldn't run a little extra logic and just get 0.1 bitcoin at $6,000 for no extra cost? Really? That's weird. They did not properly scan full addresses. So people were getting hacked and they still had funds that were sitting in the addresses.
A
Was that. I did see something about that. Was it because it was only looking at like the. The first 200 UTXOs or something like that?
B
It was looking what it was doing. It was looking for the first gap. So if you create an address and you didn't use it and then you made another address and you use that second address, the moment the bot saw that there was no more addresses, it stopped looking. And this is initially would have kept you safe. But this is going back to the point now there are multiple attackers now executing this and I'm assuming they're getting more and more sophisticated. So like that's. And that's why you can see different on chain movements and seeing different wallets being used, different transaction behaviors. You can just tell by some basic fingerprinting that different actors are going about this.
A
That makes sense. So but this is something you can do trivially. Like I could do it on my laptop if I had like the skills.
B
Yeah. There are reports of white hat hackers, which is people who are trying to do it for the good, who started seeing this exploit, started running code and, and came into dozens of bitcoin and they swept them because they were trying to do. They'd rather at least try to find a way to give it back to the right owner and then try to let an attacker take it.
A
So people will be in a panic hearing this if they're using a cold card. I want to talk about some of the other devices because ColdCard was initially like a fork of Trezor and since then foundation has forked ColdCard. Are those other forks from the same thing safe from the same original source code? Yeah.
B
Neither Trezor nor Foundation use the library that was compromised with the cold card.
A
Okay. So basically anywhere, anywhere is safe apart from cold card right now. This isn't like a broader self custody attack. This is a specific cold card.
B
The use of this library was specific to cold card or realistically mainly cold card.
A
So what should people do if they're panicking right now? Where should they be moving funds?
B
This is something that is for each individual person to kind of make that judgment call. I am, while I am the co founder and CEO of Anchor Watch, I want to be fair to everyone and talk about how I would console someone if I did not run this company and I was trying to help a loved one through this. If you had used a bitcoin exchange and your bitcoin is, you know, in the system, you, you give an exchange dollars, you get bitcoin, you withdraw it to self custody immediately. Short term, sending it back to that exchange is not a bad idea if you have no better place to do this. I'm a big fan of river personally. I have high confidence in the infrastructure over at river, if you're looking for a good bitcoin exchange, I'm talking to other people in industry. I just know that river runs their own custody. They're not outsourcing it to someone else. And I think that's an important thing to be aware of. And they do Proof of reserves. I think really genuinely proof of reserves is kind of table stakes if you're going to leave your funds out in exchange. And river is the main place that
A
does that
B
as it relates to other options. Now you could in theory go to a Best Buy and pick up a ledger. In the States today you can get
A
bit keys there as well.
B
You can get bit keys as well, those are good immediate emergency options to get things set up properly. And to be clear, the whole context of this advice is your funds are imminently going to be hacked if you're on a cold card without the entropy and without the dice and without passphrases. So my advice is not set this up and hang out for the rest of your life. This is you need to do something in the next 24 hours. Now there are other services like there are Unchained, there's casa, there's us, an anchor watch, there's a Swan Vault as well. There are many products across the industry that offer these things in collaborative custody. I think those are all great measures to be able to provide extra support to people. If you have a friend, we won't say who, but as we were starting this podcast, you and I got a call from a mutual friend who was basically breaking into a friend's house who was on vacation and getting this pin over the phone to then move the funds before they got hacked. They had a reliable self custody wallet. To be able to do that right, the universe and space of this has to be very carefully thought out. And this goes back to something I believe I said before is that slow is smooth and smooth is fast. So you need to have a decisive plan that is good enough for the trade offs right now and decisively execute. You do not have days to really war game out your optimal option here. It's just most important that you take action now.
A
There's so many things that are very unfortunate about this from a user perspective. Like one of them especially comes down to sort of privacy because if you're in a panic now, you might have a ton of UTXOs on a cold card, some of which may be like non kyc bitcoin stuff that you don't really want to mix. But at this point you kind of just have to move everything together. Like that's one of the really unfortunate outcomes indeed.
B
Yeah. While you could, if you are technical enough, spend the time building a careful transaction graph, I'm going to assume most people aren't. And so you have to make a cost benefit analysis for your own position to understand is that with any of these movement options and how you're going to execute about them, you are the best person to be able to understand your circumstance. And that's why I try to keep the advice very open ended in general to meet different people depending on where they could be in their self custody journey and their bitcoin journey and their
A
technical competency and then the Other side of that is the thing that is very harsh about this situation that's completely unlike a Mt. Gox or an FTX is that the people that have been affected by this have done everything so right. Like they've taken the time to learn self custody, they've bought what was sort of perceived as the most secure bitcoin hardware wallet, they've done everything correct and they've still been fucked in this situation. Do you think this sets back Bitcoin self custody in a significant way? But.
B
I think it would be naive to say that in the short term that there's going to be a massive reevaluation of this. Many people lost their life savings because of this. I think it's important for Bitcoin as a technology, as people who send and receive Bitcoin regularly, to be thinking about where to go from here. The capturing of Bitcoin as a decentralized network is accelerated if the only place you can hold it is at a quality like a specific exchange, that is inevitably Bitcoin as freedom. Money cannot work if you're not able to freely be able to call your money and own it and touch it yourself. Now I think there's a. This is so pressing and breaking it is difficult for me to come out with my prescriptive list of these are the things we should be thinking about and doing. I think most important right now what we should be doing is informing people, letting them know that this is happening, giving them ideas for contingencies. There's a couple of more threat models I do want to go over if for maybe more advanced users as it relates to ways that your funds could additionally be put at risk. And I'm going to start there because I think that's actually more important than like the bigger question is if you have a multi signature wallet and they are only using cold cards and those cold cards are only generated using this entropy, your funds are at risk and you need to immediately make whatever moves you need to do to get that fixed. If you have, let's say a two of three and you have two cold cards and a ledger and you did not do the passphrase and you did not do the dice rolling, your funds are at risk and you need to make moves immediately to rectify that. Now to explain, I feel fairly confident this is what's going to happen.
A
Can I pose a question on that part first? So you said if you do it, if you have a two of three and say one, one device, a ledger, one device, a Trezor, one device is a cold car MK3 even in that situation, your funds are at risk.
B
No. So if you have a trezor, a ledger, a cold card, your funds are not at risk. If you have two cold cards and a ledger, your funds are at risk.
A
Yeah. Because those two can.
B
Yes. And this is to get a little bit for those that need to know, because you, I have talked to, I've probably talked to at least a half dozen people specifically in this situation, if not more, where they have two cold cards and a ledger or two cold cards and a treasure or two cold cards and a jade or two cold cards and a foundation device, whatever. Two cold cards and a seat signer. Right. The necessary thing to understand is that when you go to spend bitcoin in the bitcoin network. Let me actually just take a half step back here. What is going to very likely happen across multiple hackers is they are going to build an entire list of every single seed phrase combination that the cold card would do without entropy. What they are going to do from there is they are going to start realizing, wait, if I have all these seed phrases, I can actually see if my wallet's being used on chain and they're going to say, okay, out of this, you know, billions, we're going to say that we have this many that could be in use at the moment. They're going to look at those and they're going to see what are they doing with it. And to be clear, if you use your cold card in a multisig, they can see, wait a second, that person spent from this address and that public key is tied to my list of seed phrases here. They're going to be able to basically monitor your wallets. Here's what happens. If you have reused addresses, those reuse addresses have the raw public keys of how you spend that bitcoin sitting on chain. And if it's a two of three and the attacker says, oh, I have, I have key A and key battle, they'll just take the funds. They don't need to wait for you to do anything. If you have not reused addresses, you are in a very delicate position. And this is a little bit advanced. And I want to be clear, this is a very specific circumstance. If you have a multi signature wallet and that multi signature wallet is a majority for the threshold cold card signers that are impacted by this issue, you should look into using something like Mara slipstream. And the reason why is when I go and broadcast a transaction to the bitcoin network, anyone on the network can see the transaction data before it gets confirmed. But it's not in a block yet.
A
Which means an attacker replaced by fee.
B
Exactly. So an attacker will be able to replace by fee and change the address from your address to an attacker's address. If you use something like MARA Slipstream, you will be able to to have it broadcasted to a mining pool that has over 5% network hash rate. They find multiple blocks a day and it will just appear confirmed on chain, which will mean the attackers will not be able to do anything. And so I know it's a very specific circumstance, but I've talked to easily a half dozen people who are in this exact position and you can reach out to mark like there are ways for you to be able to do that. If you only have cold cards, if you have a three of, if you have three cold cards and it's a two of three, they will find your funds. They will look at all of the seed phrases, and once they have all of the possible seed phrases, they're going to run through all of the combinatrics of different multisig thresholds among those keys. If they haven't already been spent on chain. If you've spent from your multisig address, once on chain, they will be able to trivially scan and see that it's there and be able to attack you and know that. Yeah.
A
So in that situation, slipstream doesn't help you. So what do you do? You just have to set an incredibly high fee rate and hope it.
B
You just have to go, you just have to rip it. You, you don't have a. Yeah. So if you've, and to explain this, let's say you have a two of three multisig and they're all cold cards. You and you've spent from it before. Attackers will be able to see, oh, key A, key B, key C that matches seed one, two and three. Boom, boom, connected. I'll be able to move my fund. So if you have a, an n of n, 2 of 2, 3 of 3, whatever multi sig wallet that is only cold cards that are impacted by this issue, you need to move funds right now, like you, you are marginally safer than a single sig. And the reason why is because you need to have an attacker know all of the seeds in the universe to be able to attack it. But that is a ticking time that you're, you're, you're racing against the clock. You need to immediately make moves if that is the position you're in.
A
It's such a terrible situation to be in. Do we know how much bitcoin's been stolen from this attack so far? I saw yesterday it was like 600, but I'm sure it's increasing.
B
It's over 1100 at this point and there's probably more clusters going on all the time. I occasionally was poking around the mempool to see if I can find more things. It's going to be thousands of bitcoin before this is done and it's going to happen in waves. What I'm describing right now, this race against the clock, the lowest hanging fruit were hit and that was probably one attacker. The starting gun has been fired off the everyone has declared the emergency. Every black cat hacker on the Internet with an LLM is going to be able to start poking around seeing what they can find. They and because there are multiple attackers now, there's a, an inevitable outcome where well capitalized ones are going to come in, spend millions and millions of dollars on graphics, GPU computing because they know that they can pop one vault. What you'll be able to have an attacker do is they're going to be able to look through the full list and just pop it right out. And you are just marginally safer because it's not the lowest hanging fruit, but you are not safe, period.
A
So this started as obviously like an amateur attack as we spoke about a little earlier, but this is now. You have to assume the best attacks in the world are now having a go at this.
B
Yeah, this is everyone,
A
it's, it is a real mess. So when you compare this to like a Mt. Gox or a FTX, the number of coins is going to be far lower. But is the damage going to be greater because it kind of erodes people's trust in self custody essentially like Coldcard was the golden child of bitcoin. Self custody, essentially.
B
Like I said earlier, it would be naive to say that in the short term that this is not going to be a very negative downward pressure on self custody. And for I know multiple people who've lost either some money or their life savings, I have spent the past 24 hours, I have talked to directly on a one, on one context, dozens of people in a larger platform I've talked to now, thousands of people trying to raise the alarm bell about this. And the stories keep on coming in this, this will have a downward trend on self custody. I think that doesn't have to be the end of the story, but I think there needs to be as the post mortems wrap up and we do a full debrief of this, the entire ecosystem has an opportunity to build from here and find improvements. We are now almost 30 minutes into the podcast, so in some conversations people are talking about we need covenants and vault like structures.
A
Yep.
B
Things that can improve self custody. My biggest concern for the health of bitcoin as a network is that the default option being holding it at a custodian or an ETF wrapper. I am not opposed to those instruments existing. I think that those are inevitable structures that happen with hybrid bitcoinization. But the value proposition of bitcoin itself will be diminished greatly if those are the only real options. And being able to to explain this the way bitcoin works today, if you have the requisite amount of signatures, you can send any amount of bitcoin anywhere. Within reason. There's weird corner cases, but let's just say for the sake of conversation that's true. Things like covenants would allow you to be able to have things like I only want to be able to send to these addresses, I only want to send this much Bitcoin. This is something at Anchor Watch we are able to offer as a product level service. Right. It is an application that sits on top of bitcoin where we say, Anchor Watch is a required cosigner to move funds. But we will, in exchange for like us being able to help you out, we'll say, okay, well you only can send to the addresses you give us. So addresses A, B and C. Otherwise we at Anchor Watch won't sign. It's effectively a covenant. Us acting as a cosigner gives that feature. Or I only want to send one bitcoin a month. That's something we can do at Anchor Watch. It's something you can't do on the bitcoin blockchain level. If it were to be democratized to the bitcoin blockchain level, anyone in their basement would be able to have orders of magnitude better security than any of the enterprise leading custodians today. And that's an important point because when bitcoin is in flight, once it gets confirmed in a block, it's over. Whereas with covenants and general vaulting, you would be able to send to like a staging address. So you'd be like, wait a second, why did my funds move? It's sitting in my staging address. And then you can pull the emergency rip cord to like pull the funds out. Now it doesn't solve the key management problem. Right. I think it's an important thing to call out that. It is a mitigation it is necessary but not sufficient to be able to improve these things. But the ultimately you need to send Bitcoin to an address somewhere and those addresses have to ultimately be tied to keys. So there is a lot of learning, I think, within the ecosystem about where do we go from here. And I think there'll be plenty of time to discuss that in the coming weeks after the initial incident response. And everything can be done as much as possible to keep people safe. Right now I think the main focus is just letting everyone know this is happening and they need to immediately remedy this if they're impacted.
A
How do these the like an Unchained or a Casa. Let's say you have a two of three with one of those. If I have. So one key will be on your phone. Generally one key will be held by the company. One key is held by you. If I'm holding my key, let's say on a coal card, how do I know that the counterparty, the unchained or
B
the CASA is not the unchaineder? The CASA counterparty is not what like
A
holding one of their key on a. On a call card? Because that would then put the multi.
B
You can't prove that. You can't with any wallet. Well, in a very tragic sense of irony, very soon people will be able to prove if they were using the cold card keys because attackers will have them. Right. The ideal structure though is that it's not something that can be an issue because if you have sufficient randomness, there's no. You should not be able to fingerprint and say, oh, that that X pub came from a ledger and that one came from a jade. That would be a breaking in the underlying cryptography assumptions. That is a truly random number that is seeding all of your secrets.
A
So I guess the point I'm trying to make, I'm trying to make people feel comfortable here if they are using a Castro on Unchained. Like, have either of those made a statement about how they're generating their keys? Like, because I'm like, I'm convinced that neither of those companies are using the on dev random number generator. But have they made.
B
To my understanding, to my understanding, Unchained has made a statement. I believe CASA has made a statement as well. And we at Anchor Watch have also made a statement. This does not impact us. Right. And so I think it's an important thing to look in your vendors to see if this is an issue. I think that's a very reasonable concern. But I think everyone at this point has made some public statement to the effect of that I'm not aware of any bitcoin business, even through like hushed private circles who are impacted by this. I haven't heard anything yet. They may, they may exist, but I have not heard anything.
A
I definitely don't want my words to be twisted there. Like I think Acaster and Unchained, like Ankorwatch. I'm sure all those companies are set up brilliantly. I just, I just want to try and make people comfortable with moving funds to those places if they need to. Understood.
B
Understood.
A
Anchor Watch. How do you set up your multisig?
B
Yeah, so the nature of what we do that's somewhat different is we use what's called miniscript and that allows us to do more advanced scripting functionality. Rather than just a two of three, we are able to say we have a two of three. You have a two of three. We all have to get together and sign and move. Things we could do is we have a two of three and you have a single key. Right. And we act as that cosigner still. Right. The nature of how anyone generates keys is an extremely sensitive thing because you just need to keep that on a. Need to know the exact mechanics. But our process has been peer reviewed. There are many. I think most actors in the industry have their own very rigorous key generation ceremonies of what they go about for. For being able to evaluate that.
A
So when like I really like single sig self custody, like I think, I think you should have different trade offs for different amounts of bitcoin that you're holding. Like if maybe you have a one sort of deep cold storage which is geographically dispersed multisig. And that's great. But the simplicity of single sig is really important too. I think I would definitely still use that occasionally. How do people think about that going forward? Because I've always said that like the most likely you are to lose bitcoin is through your own complexity and your own setup. Like complexity being the enemy of security. Security. Do you think people are going to make the mistake now of jumping too far into multisig because they're scared of this attack and actually add too much complexity to their own setups?
B
I think multisig is no longer that complicated. I think this is not 2017 anymore. Additionally, if for whatever reason you want to do a single signature, you could do single signature with a passphrase that effectively is a two of two multisig because you have to have both pieces to be able to constitute a spend. If you were doing that with a reasonably strong passphrase going into today, you're still safe. I would still make a new wallet because if you fell under this and your initial 12 or 24 words were actually part of this hit of known possible seed phrases, all that's keeping you safe now is your passphrase. But I think there's a lot of opportunity for everyone to grow and learn from this to even further improve the user experience because this will be in the front mind of anyone who discusses self custody for a very long time.
A
So this is the first like in the wild case that we've seen of AI essentially hacking and taking down a bitcoin self custody solution. Do you think this is the start of that era? Do you think we're going to see more and more attacks like this?
B
I think in general across the whole web there are going to be more and more attacks like this. The trivial ability for me to be able to open up to open router and use Kimmy K3 and point at the cold card firmware and it instantly read out everything everyone needs to be. And we regularly do this at Anchor Watch. I know most companies that I know of in the bitcoin industry are regularly doing this and kind of defensively trying to deploy these tools to find things. We've always found, we've never found anything that was a money losing bug. Nothing in the universe of bad of what we're seeing here with the cold card. But you find bugs. The software has bugs, it always will have bugs, right? Like there's some emerging research around things like formal verification, so you can actually do formal mathematical proofs as to how code executes. That's an emerging field of research that I think may get more important over the coming decade. But software is written by humans and humans inevitably have bugs and even LLMs sometimes have bugs, right? You don't want to be blindly passing everything you've built to just have it go get figured out later by the LLM. And the LLM may not be complete, right? The rapid development of these models, there's a kind of a funny software motif. If you like vibe code a website and you launch it in three months, the new model comes out and it says, wow, this code base is a mess, let me fix this for you. And that's just been happening continually for two years now, right? So like we're at a place in a time where you need to be hyper vigilant with your own individual judgment, with your ability to understand the nitty gritty details of risk and however it emerges to be able to keep you and people you work with safe.
A
All right, awkward question time because I know you're friends with mvk, but like the blame obviously ends with them. But how incompetent was this? Because this has been five years that this firmware issue has been there.
B
Not acceptable as a starting place. Like, not like there is no. Yes, I've, I've known NVK for a long time. There is no excusable, there's no set of circumstances that excuses this. The, the, the one job a hardware wallet has, if it were to have a single job, more important than all of the other jobs, is that it can securely generate a sufficiently large random number with sufficient entropy, that is the entire game in which everything else gets derived from. There are bugs that have happened in hardware wallets in the past where maybe how they signed a transaction wasn't secure. And then basically if you reused addresses, you could lose your funds or maybe you would have bugs where it wasn't checking the change address. So if I sent you Bitcoin, if I have 10 bitcoin, I send you one bitcoin, I have to send myself nine back in change. There were bugs in software and hardware wallets that didn't check the change which was the most important part of the transaction. That sense, right? This bug is so foundational to the actual security of Bitcoin that it is, it is a nuclear event. Right? This is, this is the most catastrophic thing. That is why someone could be entirely air gapped, never have talked to the Internet and someone's able to peer through the vast space of randomness and get your Bitcoin, which should never happen.
A
Do you think it's the end of Coldcard? Do you think they'll be able to recover this? Because trust is everything when it comes to these devices.
B
It. It is. I, I think it's too early to say. I don't know. I'm not a lawyer. I don't understand any of the liabilities or fallouts or all of these things. It's hard for me to say truly, I don't know.
A
All right, Rob, I appreciate you doing this so last minute. I wanted basically just to get this out there. If one person listens to this show, they're not permanently on Bitcoin Twitter like you and I, and they haven't seen this news that makes it 100% worth it. Any closing words for everyone who's listening?
B
Closing words again. If you or someone you know has used an MK3, MK4, MK5Q, any of those cold card products with out either rolling Your own dice or having a sufficiently strong passphrase. And if your question is, is my passphrase strong enough? It means you don't understand the entropy, which means you need to go fix this immediately, even if it is right. You just, you. If you don't. If you don't know for a fact, oh, yes, I have this many bits of entropy in my passphrase. Because you are super in the details. Your passphrase is not strong enough at the moment. You need to immediately make any moves and plans. You need to cancel your weekend plans. You need to get on a plane if you have to. You need to call a loved one who may be able to help you out. Remot, this is a. This is a full five alarm fire. This is all hands on deck. I think everyone in the bitcoin community has been trying to help through back channels and through direct messages, through being able to have people call, you, find people, get connected to people. My DMs are open on Twitter. Like I said, I've talked to dozens of people across the whole ecosystem, none of them even Anchor Watch customers, because Anchor Watch customers don't have an issue at the moment. Like this is. This is not related to anything of how your funds are being kept safe at Anchor Watch. So all of that to be said, like, reach out to those you may know, people you've ever referred to using a cold card, and do what you can to try and help them out. And I think there's going to be an opportunity in the coming week, two weeks to when the initial race is over, we can focus on triage. We can focus on. Well, once we move beyond triage, we can start focusing on where does the industry go from here.
A
All right, Rob, I appreciate you, man. Thank you for all the work helping people out on this terrible, terrible event. But bitcoin will get through it, man.
B
Thank you, thank you.
Host: Danny Knowles
Guest: Rob Hamilton
Date: July 31, 2026
In this urgent episode, Danny Knowles and Rob Hamilton tackle a catastrophic security crisis impacting the Coldcard line of Bitcoin hardware wallets. They break down the origins of the bug, how it affects users, the immediate risks to Bitcoin self-custody, and actionable steps to secure funds. The conversation is focused, technical, and urgent, aimed at quickly disseminating crucial information to anyone potentially affected.
Severe Emergency:
Rob opens with a direct warning for Coldcard users—those with MK3, MK4, MK5, or Q models who used device-generated seed phrases must take action immediately. This is described as a “code red” self-custody emergency.
“You need to immediately stop what you’re doing and contact friends. This is a canceling of weekend plans. This is getting on planes.” — Rob (00:12)
Who is at Risk:
Anyone who generated wallets (12 or 24-word seeds) from an affected Coldcard device and did NOT add sufficient personal entropy (e.g., dice rolls) or a truly strong passphrase.
Origin:
The critical bug was introduced in early 2021 in a Coldcard firmware update related to entropy (randomness) generation for wallet creation. A logical error in the code allowed faulty entropy, drastically reducing the security of the generated seed phrases.
“There was basically a one line error that just said … you can skip the entropy. It was like, oh, this exists so we can skip the entropy.” — Rob (08:09)
Impact by Model:
What Saves You:
Scope of Attack:
Initial Exploitation:
White-hat Efforts:
Scale of Loss:
If You’re Affected:
“My advice is not set this up and hang out for the rest of your life. This is you need to do something in the next 24 hours.” — Rob (15:19)
Collaborative Custody:
If in Doubt:
Mixed Wallets:
Attack Vectors:
Advanced Mitigation:
User Disillusionment:
“Many people lost their life savings because of this… the capturing of Bitcoin as a decentralized network is accelerated if the only place you can hold it is at a specific exchange.” — Rob (18:30)
Software Complexity & Simplicity:
Potential for Future Safeguards:
Responsibility:
“Not acceptable as a starting place. … the one job a hardware wallet has … is that it can securely generate a sufficiently large random number… This bug is so foundational… it is a nuclear event.” — Rob (38:01)
Will Coldcard Survive?
On Immediate Action:
“This is as about as code red as it can get for bitcoin self custody… You need to act very decisively.” — Rob (00:12)
On Security Model:
“If you really only used one word that is right, which means you are not secure… many attackers … are scanning to get the entire table of all possible seed phrases a cold card could generate.” — Rob (03:51)
On Vulnerability’s Origin:
“There was basically a one line error… if this function exist[s] somewhere… you can skip the entropy. … It is one line of code of how I can describe this issue.” — Rob (08:09)
On User Responsibility:
"Slow is smooth and smooth is fast … you need to have a decisive plan that is good enough for the trade offs right now and decisively execute. You do not have days to really war game out your optimal option here. It's just most important that you take action now." — Rob (16:22)
On the Severity:
“This bug is so foundational… it is a nuclear event.” — Rob (38:01)
Act Now:
If you or anyone you know has used Coldcard devices to generate wallet seeds without personalized entropy or a strong passphrase, move your funds immediately. Don’t hesitate—speed is critical.
Community Support:
Leverage networks and Bitcoin communities for technical help; almost all Bitcoin luminaries are mobilized to help.
Look Ahead:
As the initial panic subsides, expect major industry introspection, calls for technical reform, and discussions about how to build more robust and user-friendly self-custody infrastructure.
Bitcoin Will Endure:
The underlying message—this is a severe blow, but not the end for Bitcoin or self-custody.
“But bitcoin will get through it, man.” — Danny (41:51)
For ongoing updates and assistance, Rob Hamilton’s DMs are open. Act quickly, share information, and help others before pondering the broader lessons and future fixes.