In short
Rob Hamilton explains the “Bitcoin Red Team” response to the Coldcard vulnerability, describing how they scan and help patch vulnerabilities across Bitcoin codebases (about 500–600 repos), plus the difficulties using U.S. “frontier” AI models for cyber research due to API guardrails, leading them to rely more on open-weight Chinese models. He also discusses policy implications (data export, “defenders need the frontier” argument) and community coordination for harm reduction.
Guest backgrounds
Rob Hamilton is co-founder and CEO of AnchorWatch and a Bitcoin Red Team leader. Alex Thorne hosts; Bim Netabibi (Galaxy Trading) discusses CPI/markets and Bitcoin price constructiveness.
Key claims
Coldcard fallout revealed broader software/AI/policy issues; red teaming is “verification” to complement “don’t trust, verify”; LLMs are probabilistic “slot machine” tools; private mempools (e.g., Slipstream) can be game-theoretically necessary during key-exfiltration risk.
Notable examples
Coldcard entropy/firmware break leading to funds moving; scanning hardware wallet firmware first; using Kimmy K3 for vulnerability reports; Portland HODL’s exploit discovery; Slipstream handling non-standard op_return to safely move funds; OpenAI/Anthropic model downgrades and guardrail opacity.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VODiscussion on Bitcoin Vulnerabilities
0:45 to 3:02
An overview of Bitcoin vulnerabilities and the red team's efforts to address them.
“community, says about 25 that have been systematically working to find vulnerabilities and patch them in key code bases around the Bitcoin ecosystem in the fallout from the cold card vulnerability.”
Introduction of Bim Abibi
3:02 to 3:12
Introduction of Bim Abibi from Galaxy Trading, focusing on market analysis.
“Let's hop right into it with Bimnet Abibi.”
Market Analysis and CPI Discussion
3:12 to 9:32
In-depth analysis of the latest CPI numbers and macroeconomic factors affecting Bitcoin.
“So I guess, you know, Bitcoin's mostly unchanged week over week.”
Constructive Outlook on Bitcoin
9:32 to 14:00
Bim shares his evolving perspective on Bitcoin and market conditions leading to a potential rally.
“You, of course, have been over the last, I guess, we'll call it 10 months, certainly since October of last year, and also early in this year, been bearish in the near and medium term.”
Bitcoin Market Dynamics
14:00 to 15:42
Explore the shifting sentiments and behaviors of Bitcoin investors amidst market changes.
“And so the risk reward is just kind of there.”
The Bitcoin Red Team Origins
16:00 to 18:14
Rob Hamilton explains how the Bitcoin Red Team was formed in response to security vulnerabilities.
“I've done more media in the last two weeks than I think I've ever done.”
Scanning Bitcoin Projects for Vulnerabilities
18:14 to 20:38
Discover the extensive efforts of the Red Team in scanning Bitcoin-related codebases for security flaws.
“I started poking around other code bases just very quickly and casually and found more issues.”
Community Response to Security Threats
20:38 to 24:38
Discuss the collaborative actions taken by the Bitcoin community in response to security threats.
“But if you had not rolled enough dice, or if you used a passphrase as an additional word in your seed phrase, but it was, you know, the word dog, you were not safe.”
Navigating Bitcoin Technology and Policy
24:38 to 28:00
Examine the intersection of Bitcoin technology and policy, including the implications of private mempools.
“And shout out to Becca Rubenfeld, the COO at Anchor Watch, a very good friend of mine.”
Game Theory and Bitcoin Security
28:00 to 28:45
Learn about the evolving game theory in Bitcoin security and community response.
“When it's in transit, you can change it because it hasn't been included in a block.”
Show all 15 chapters
AI and Policy Challenges
28:46 to 29:55
Explore the intersection of AI, policy, and cybersecurity vulnerabilities.
“By the way, your work is admirable and very appreciated, I know, across the Bitcoin world.”
Navigating AI Limitations
29:56 to 31:28
Understand the limitations of AI models in cybersecurity and the challenges faced.
“So I started removing things and flipping things out.”
National Security and Open Source AI
31:29 to 33:34
Discuss the implications of using foreign AI for national security concerns.
“my hit rate started going up again, right?”
Improving Cybersecurity Practices
33:35 to 37:10
Learn about effective cybersecurity practices and the use of AI in vulnerability detection.
“to actually get decent cybersecurity intelligence, if you're using these models, just because they're open weight does not mean that they're hosted by an American company on U.S.”
Best Practices for Developers
37:11 to 39:46
Discover key recommendations for developers regarding security protocols.
“because the initial harness that I did this mass scan with was something that I coded up in 30 minutes just as a starting place and it was helpful to people.”
Transcript
Automatic transcript. May contain errors.0:00Alex Thorn:Welcome to Galaxy Brains.
0:25Alex Thorn:Welcome back to Galaxy Brains. As always, I'm your host, Alex Thorne, head of firmwide research at Galaxy. Bitcoin, not zero. We have a great episode for you this week. Rob Hamilton, co-founder and CEO of AnchorWatch and prominent member leader of the Bitcoin Red team is our guest. I will talk with Rob about his work, along with many other developers in the Bitcoin community, says about 25 that have been systematically working to find vulnerabilities and patch them in key code bases around the Bitcoin ecosystem in the fallout from the cold card vulnerability. We'll talk with Rob about what they're finding and why it matters.
1:03Alex Thorn:Also with Rob about the trouble that they've been having using frontier U.S. AI models to do cyber research and vulnerability research and disclosure and their need to fall back on Chinese open source models. What that means from a policy perspective for the United States and for AI in general. a fascinating interview with Rob, who he, along with many others, have done great work on one important huge part of the cold card fallout that is sort of making sure that other projects do not have vulnerabilities like something that cold card had. And sort of the Bitcoin community had said, you know, don't trust, verify.
1:40Alex Thorn:But there hadn't been enough verification being done. The red team is sort of the first salvo in rectifying that. We'll also talk with our good friend, Bim Netabibi from Galaxy Trading, as always, to talk about markets. We'll talk with Bim about new inflation numbers out of the U.S. government and what they mean for the market. Also talk with Bim about why he is now and has been for a few weeks constructive on the Bitcoin price. I used to make fun of him and call him Bitcoin the bear. Bitcoin bearish no more on BTC at these levels. We'll talk to him about why. Before we get to any of that, I need to remind you to please refer to the link to disclaimer in the show notes and note that none of the information in the show constitutes investment advice or an offer recommendation or solicitation by Galaxy or any of its affiliates to buy or sell any securities.
2:25Alex Thorn:Again, the cold card vulnerability continues to be ongoing. I talked about this at the intro of last week's show. And so stay tuned to our content. I continue to work to help victims trace their funds and compile reports that they can use to file victim reports with law enforcement, the FBI and others. So if you are affected, please reach out to me, DM me on X at intangible coins. And if you are holding vulnerable funds in a cold card, please do your research and move your funds to a safe location. Do it calmly if you need to, but do do it if you are still on a cold card hardware wallet. Let's hop right into it with Bimnet Abibi.
3:06Alex Thorn:Let's go now to our friend Bimnet Abibi from Galaxy Trading. As always, Bimnet, welcome back to Galaxy Brains. Thanks for having me. So I guess, you know, Bitcoin's mostly unchanged week over week. Macros had some twists and turns with the Iran situation and other stuff. But I guess let's start with the macroeconomic picture, which the big story this week is that CPI numbers were released. Bam, what do these numbers tell us about how the U.S. government is measuring inflation at this moment?
3:35Beimnet Abebe:Yeah, I think inflation is still kind of unacceptably high. It's kind of the core essence of it. But I don't think this Fed is going to be that aggressive in terms of hiking in response to it. But it's not uncomfortably high. It's just above target. The reading came out at 0.21 unrounded the factors that came off a lot uh were things like lodging because of you know the world cup everybody like left right and so that that showed a decline and you know in terms of like other parts of the inflation report like health care like stuff still like increasing in price you know and as well as rents uh and so you know there's it's a little bit of a mixed bag but in of what the market cares about.
4:29Beimnet Abebe:They care about the read-through into core PCE, which is the Fed's current preferred measure. And the read-through was actually kind of on the softer side. So folks actually lowered their core PCE estimates based on the back of this data this morning. To go along with that, though, you have PPI tomorrow. And so that'll kind of be a more complete picture. but truthfully um i don't know how much any of this really matters right now i think the biggest story for prices and kind of the willingness of the fed to to hike you know it's going to be determined kind of by how this iran conflict uh develops and so if we see a resolution sooner rather than later, I think the Fed will more likely not hike.
5:20Beimnet Abebe:And you have to put that in the context of the labor market data, which on the surface looks okay, but underneath the hood looks pretty poor. Household surveys showing a pretty big decline, and that's been declining for a lot of this year. The underemployment being particularly elevated. So there are a little bit of like labor market concerns. So I personally think, you know, policy rates are probably at the right place. And so I'm not, you know, the way I think about it is unless you get an outsized kind of move in some of the data, if we just kind of go in this kind of like middle sweet spot, like I don't think the Fed's going to be inclined to hike.
6:04Beimnet Abebe:Got it.
6:05Alex Thorn:So that makes a lot of sense. And the impact then on the market today, right, Wednesday, October, sorry, August 12th. In response to this, what has the initial market reaction been to the CPI number and the read through to PCE?
6:20Beimnet Abebe:Yeah, so you've seen U.S. two-year yields like drop by like two basis points. And so I think that speaks to kind of like the core PCE stuff, the implications, right? Because on headline, it printed in line, maybe a little bit higher than expected. But ultimately, like what really matters is kind of that core PC number. But again, it's really hard to understand what matters. I can't tell you the amount of confusion there is over Warsh's response function. What does he care about? And it seems like there's differences of opinion amongst the committee. There is still consensus, and you only had two dissenters.
7:03Beimnet Abebe:But it's really unclear to the market how he's actually thinking about this stuff. because okay well let's say cpi came in hot today like there's one version of the world where he's using the the dallas trim mean uh like inflation figure which is like shows us lower right there's you know his views about you know productivity and ai right like are they big kind of are they near-term things are they like longer-term things like and then how do you think about it in the context of treasury policy. Like the back end of the U.S. curve is at 19 year highs, right? And we're printing deficits like crazy.
7:45Beimnet Abebe:And so we're going to just, you know, jack up the point in the curve where the U.S. issues the most, like 22 % of all like treasuries are like in bills. Like I'd say there's like all these like dynamic like kind of factors. But what makes it challenging is for the first time in a while, you're getting less communication from the Fed. So it's really hard to know what actually kind of matters. And so I think what you're meant to do is really like try to understand Warsh, like from a kind of, I don't know how to describe it, but you know, I look at markets, you know, from a little bit of a cynical standpoint, and maybe That's why I love Bitcoin so much.
8:31Beimnet Abebe:But I do think there's like an element of like, this is coordinated, right? Trump is calling Warsh. Warsh is talking to Bessett. They're definitely aware of all the things happening, whether it's war, yen intervention, et cetera. There is a high level of coordination. And so in that context is kind of how you have to frame Warsh. and truthfully I think like nobody in this administration wants to hike interest rates and so even if you you know get a bunch of members of the committee trying to hike rates etc I think Warsh is going to find a way to be less aggressive in terms of you know front end interest rate policy and he's going to try to just steer us to avoid hikes it's kind of my bias And that may be a little cynical, but that's kind of my view at the moment.
9:29Alex Thorn:I appreciate it. Let's pivot and talk about Bitcoin a little bit. You, of course, have been over the last, I guess, we'll call it 10 months, certainly since October of last year, and also early in this year, been bearish in the near and medium term. over the last couple weeks though and and you and i i put out a report saying like mid 40s was probably a base case and even low 50s would be in my model for where we would bottom you you had a similar view um but over the last few weeks you've sort of changed your tune a little bit and become more constructive yeah and and you know part of that i is because you know we've now tested 58 like a bunch of times.
10:14Alex Thorn:It looks so resilient here. The thing looks oversold. Even last week, you know, you've got the fallout from this self-custody debacle with Coldcard. You've got Michael Saylor now just selling, you know, or I should say strategy selling, you know,$100 million of Bitcoin relatively frequently, and yet the price can't go down. Can't test new lows even. Even here, as we record, 63.5, just firmly in this, you know, every day that it stays in there, It feels like a stronger, you know, bottoming range. Setting aside the absolute fact in question of whether we have bottomed, what is it that makes you constructive on Bitcoin right now?
10:53Beimnet Abebe:Seller exhaustion, one, where you're in an asset class that's gone down 50%, literally like, you know, 125 to, you know, 63K. That's one. to, I think, in terms of our timeline of, you know, historical Bitcoin cycles, you were very close to when you would expect the bottom, right? And so far, Bitcoin cycle has been, you know, basically Bible-esque. And so, you know, I take it as the gospel and a bottom in and around now, you're kind of in that window of what the cycle says should be a bottom time perspective-wise. And then third, which I think is kind of like the most important thing that you need for kind of like an aggressive rally, is you really just need a chart and a story, right?
11:53Beimnet Abebe:It needs to be compelling. And I will tell you that one of the things that got me so constructive very recently since the last pot even, is gold has done a 10 % move in the span of five days. World's largest asset class. And the reason it's happening, some people say it's central bank buying, some people say it's worse credibility, some people say, well, it just looks like it bottomed, it held 4K, and now it's moving higher. And then the day after the first big move, you saw a ton of commentary, options flow everything being like oh gold's bottom time to get back in uh and so you had this like tremendous follow-through and so in terms of what i what i think gets us you know higher um it's it's simple the moment bitcoin starts going up and people feel like oh we've bought them the four-year cycle is over people will chase because you know they're going to feel like they just you know a major asset class just sold off by 50 plus percent and everyone in the world has access to it and so you'll get this kind of like phenomenon where bitcoin will have a story of gold's going up the four-year cycle is is over um and the chart will start looking good uh where it'll take out like a couple key technical levels then all of a sudden if if the world's largest asset class can move 10 percent in uh in four days just think about like how much you know, Bitcoin can move when sentiment like actually turns meaningfully.
13:29Beimnet Abebe:And so it just feels like, you know, one of those situations where let's say, you know, maybe there's risk that Bitcoin goes down to 55k in the next like two months, totally possible. So you're risking, you know, a little like 8000 points, right? But where could it get to if people start to think that this is a real bottom. And like, you're talking about 80 to 125K as like a return to kind of like Bitcoin normalcy. And so the risk reward is just kind of there. And I think that even like the Bitcoin bears in the world, like I don't know many Bitcoin bears that are going to short the thing like on a five handle.
14:13Beimnet Abebe:Like there might be some people that, you know, are going to sell again if it breaks 58, like, that are already long. But truthfully, like, I just don't know. It's not going to get pressed from the short side. And I think people are mentally short to the top side. All the Bitcoiners that have gone through this before, you know, the Alex Thorns of the world, like, the moment it's at, like, 72K again, you're like, fuck, I didn't buy when it was at 58. or 61, 62. Yeah, you'll see some chasing. Oh, it's the four-year bottom. And so I think there's like this weird, you know, set of conditions that's developing where I think people are going to be much more afraid of missing the upside.
15:03Beimnet Abebe:And to be honest, all the stuff happening right now, like, you know, politically, geopolitically, the interventions, like, there's enough stuff happening where, like, There can be a true organic Bitcoin story, and the flows will definitely follow. But let me back up. This is definitely a market where narrative follows price action, not the other way around. And so the moment it starts going up, people will just throw all the narratives at it. And we've listed a couple here, but I'm sure there'll be a couple more that people invent along the way.
15:38Alex Thorn:Well, there you have it for my friend, Bim Netabibi from Galaxy Trading. As always, thank you for coming on Galaxy Brands, Bim. Thanks for having me. Let's go now to our guest, Rob Hamilton, CEO and co-founder of Anchor Watch and member of the Bitcoin Red Team. Rob, welcome back to Galaxy Brains. Thanks for having me, Alex. Wish it was under better terms. I totally agree. I've done more media in the last two weeks than I think I've ever done. And it was unfortunately not on. It wasn't because everyone was so happy to talk to me, you know? Right. Right. But I see you've got the red anchor watch hat on here, sir.
16:14It's a funny story because we were sampling new merch and my co-founder Becca, who has a long career before Bitcoin and insurance in apparel, was having fun getting like samples of different colors. And she sent me the red one. I was like, this is ugly. Like, why would anyone ever? And now I'm like, now I have to. Now it's appropriate. There's only like five of these. Yeah.
16:37Alex Thorn:Well, I love it. And so for our audience who doesn't know what we're referencing here, Rob has been among the people leading a group that we're calling, I guess, the Bitcoin Red Team. And I'll just ask you what that is, Rob, just at a high level for anyone who hasn't been following along already. Yeah. So the Bitcoin Red Team, it all kind of started becoming a bigger thing around the incident with the cold card, right? So on July 30th, early in the morning or late the 29th, a bunch of Bitcoin started moving from cold cards. The nature of what was being reported meant there had to be some sort of foundational break in the entropy of the cold card.
17:18and so myself and other engineers in bitcoin realizing this thought to ourselves okay let's start looking at that part of the firmware to confirm and understand what's going on and i opened up uh i use codex and i use cloud code all the time i pulled each of those up pointed at the code base um cloud code instantly downgraded me from fable like down like and it didn't give me like the direct answer codex like knew something was up but it was a little shy like i had to like It wasn't just being direct with me. And then I tried it with Kimmy K3, and it was like, here's a full vulnerability report.
17:51It's broken. And in that moment, I realized something very serious had changed as it related to not just Bitcoin stuff, software development in general. I think what this has turned into is way larger of a story than the cold card and Bitcoin and self-custody. This is a technology story. This is an AI story. This is a policy story. and after that happened, I started poking around other code bases just very quickly and casually and found more issues. And I thought to myself, well, I'm not a software developer and maintainer of these projects. They understand this way better than I do. So let me try and send a couple one-off like discrete things for having them take a look at it.
18:33And sure enough, upon doing some disclosures directly to maintainers, they were confirming that these were issues. And I was getting like very heartfelt thank yous for doing this, asking how I did it. I just said, use Kimmy K3, start running with it. And I pulled up my personal credit card to start scanning projects because when Kimmy K3 went open weight on Monday, July 27th, I had already started using it for our own internal infrastructure just to poke around and see what was going on. and it was very effective at finding bugs. And I realized that there's hundreds of Bitcoin projects and probably none of them have done this yet.
19:08And the problem too is that rather than it being like a small individual company, some of these projects are like load bearing or like do a lot of interactivity with other protocols. And so this is the obvious lowest hanging fruit to be able to do any sort of black cat activity. So I started throwing my personal credit card, just starting to mass scan, just trying to do anything I can. I was tweeting about it. And then Calais, who is a long-time Bitcoin developer, works a lot on the eCash project, reached out to me saying, do you need help? And I said, yes, just help me. I need anything. And he immediately jumped in, started operationalizing it, organizing a lot of it, bringing his own expertise into it.
19:45And it quickly kind of grew from there in a web of trust to start organizing and gathering all of these vulnerabilities. And it's been quickly accelerating since then.
19:55Alex Thorn:Yeah, you guys have found, I think you told me the other day you had already scanned 500 repos relevant to the Bitcoin world. Were you guys looking at other hardware wallet firmwares that are open source? It was one of the first places we looked was other cold storage solutions, right? And from an understanding of harm reduction, another incident like the cold card would be horrific and even more catastrophic. So that's where we started and everything has come up clean since then. and then we started kind of fanning out to larger code bases um and since then it's been
20:36incredibly uh eye-opening just seeing like the scale and i think that's why i think it's a general software problem this is not just a bitcoin problem yeah um yeah let's talk we'll
20:45Alex Thorn:talk about that part uh i think for the most of the rest of the show in a minute but shout out to Cali and I know James OB has been doing a lot as well James was doing a really interesting project of like simulating all the different cold card firmwares and types of because you were vulnerable in the cold card exploit depending on how you set up your how you generated your key like even in MK3 the most vulnerable hardware you know if you had rolled dice done all your own entropy as you know sort of an expert and done it right, you were okay. But if you had not rolled enough dice, or if you used a passphrase as an additional word in your seed phrase, but it was, you know, the word dog, you were not safe.
21:30Alex Thorn:But if it was, you know, six, four, one exclamation point, like, you know, long thing, maybe you were safe. And I know you guys were testing all of those. I've sort of thought of the reaction to the cold card as three main parts that are easily identifiable in terms of the, not the reaction, but the response. So you've got the red team doing software vulnerability searching. You've got people like Wicked and, you know, Shinobi, like in, I mean, they did like a full week of spaces. It was like Clubhouse back in the day. Remember, we used to try to stay on for like 48 hours and like pass the room off to keep it open.
22:06Alex Thorn:Yeah. They were actually helping people actively move their funds off the cold card devices. and then you've got folks in SEAL, 9-1-1, and me and others trying to trace the funds and get them. What do you have to say in your mind about the community response, like broadly speaking? Because I feel like it's been one of the more bright parts of this. I think it is part of the things that make Bitcoin a beautiful project in many ways. Everyone kind of raised their hand and jumped in to the fire to try and help others. Everyone found what they were able to help out with, whatever their domain skills are and their connections and networking and be able to help out however they can.
22:51I think it is some of the best parts of just Bitcoin culture and community to be able to do things like that.
23:00And it's been from everyone too, because the Red Team just kind of started off as a meme, but other people now are just going around and poking around code bases. They're like, how do I join Red Team? I'm like, just start scanning code bases and reach out to a maintainer if you see something. Like there is no membership card club that designates you as one or not. Like this is Bitcoin. It truly is a beautiful thing from Bitcoin as a movement because now we're at a point where we're between 20 and 25 people. And it's a follow the sun campaign of people who are just up working and looking at all of this stuff.
23:31And someone finds bugs in some software. Someone who's a domain expert in that software will look at the bugs to try and help triage for maintainers so we're not just like mass spamming things. Everyone is doing their part. And I think that's just a really awesome... And we're all doing this out of the kindness of our heart. I'm not getting paid to do red team stuff. OpenSats has opened up a red team fund. That's just going to pay for token costs. I'm not taking a salary while I do this. And it goes across everything too. With Anchor Watch, I'm still in the loop on all of the work being done, but Becca has done an exceptional job also stepping up and just executing on everything that needs to be done.
24:13And her and I will, you know, we'll just hop on the phone and do quick chats and stuff to make sure the big things are like all in a good spot. But everyone at my company has massively stepped up. They've all done incredible, incredible work. I think everyone in the Bitcoin community has really stepped up to try and help out others. And I think it's, you know, it is a very small, but it is a silver lining in the whole tragedy of this.
24:38Alex Thorn:Yeah, I agree. And shout out to Becca Rubenfeld, the COO at Anchor Watch, a very good friend of mine. What a legend. Check out my episode with Becca from a couple months ago from PubKey DC, probably my favorite episode I've ever recorded. so shout out to to anchor watch you guys also recently saw i hired you guys hired portland hodl i only just noticed this actually looking at his uh x profile yeah so he's an expert in bitcoin technology as well and um from had been at mara and i guess ran slipstream or invented slipstream uh or invented yeah but he built the thing yeah um yeah and that was uh yeah so i we're very happy to have portland he's a great engineer i'm very proud of the work he's doing he's been helping out with the red teaming as well uh he's been doing an exceptional great job with everything uh for sure one thing i think he may exemplify something that i've noticed as a result in bitcoin culture from this which is that so many in bitcoin certainly in the sort of the hard maximalist wing of bitcoin right they didn't like portland hodl because they didn't like slipstream because Slipstream had been used to rip a four mega onto the chain, right?
Read the full transcript
25:50Alex Thorn:And like, I don't know if it was literally Slipstream. I think it was, but Slipstream. I think it was Luxor. Oh, you're right. Luxor actually mined that. It was pre-Slipstream existing. But Slipstream as a private mempool, right? You could submit transactions that were non-standard. For example, we submitted the non-standard op return that memorialized the$8 billion Bitcoin whale sale. And thank you, Rob, for your help with that. But that had to go through Slipstream because the vast majority of the Bitcoin network had opportune limit sizes capped. Obviously, now that's not the case with Core V30, and we won't go deep into the BIP110 stuff, but it had been thought that something like a Slipstream was bad for the network because it creates private mempools, which philosophically may even be ultimately.
26:39Alex Thorn:but even more so that they were, you know, supportive of spam on the chain. Now it turns out, especially if you have a multi-sig with cold cards in it, where you don't want to reveal the public keys because of the cold card vulnerability, actually sending through a private mempool is incredibly prudent, almost perhaps even necessary to exfiltrate your funds. But then also just that like, even if you didn't like Slipstream or the thing that Portland HODL might have worked on, that actually the real bar, I think, for measuring a Bitcorner should be how much they care and how much they contribute to Bitcoin technology.
27:14Yeah, I agree with all of that. The first point on menpool health, it is objectively not great for the network to have private menpools. That said, given the circumstance of what was happening with the cold card, just to briefly explain it, let's say you had a two of three multi-signature and two of them were cold cards and they were part of this vulnerability. When you go to spend Bitcoin, you have to broadcast to the network, here's my transaction. I would like to get it included in the next block or whenever. And an attacker, once you have all of the public keys sitting there, would be able to look at a transaction in flight on their node and say, oh, I have two of these three public keys.
27:53Let me pull the private keys, resign the transaction and steal the money while it's in flight. because Bitcoin is not safe until it's confirmed in a block. When it's in transit, you can change it because it hasn't been included in a block. So that was something that I don't think anyone even like a year or two ago would have ever thought of the game theory of it possibly being necessary. But I don't know what the exact number was. I think it was thousands of Bitcoin at this point have moved through that slipstream product to have people feel safe. And it was truly something to be seen. Like it was truly like everyone kind of rallied together.
28:27There was a lot of, and you're in a lot of these two, like industry group chats, coordinating people, A needs to talk to B and like linking people up. It was very much, it was very inspiring overall, for sure.
28:39Alex Thorn:So let's talk about, and thank you, Rob, and everyone else working to secure Bitcoin related code bases. By the way, your work is admirable and very appreciated, I know, across the Bitcoin world. Let's talk about the sort of AI and policy story that this has made very clear. It had been, I would say, the first inkling of this story was the OpenAI lab leak, I guess now several weeks ago, where one of their Frontier models escaped its enclosure. It's like describing it like it's Jurassic Park. Like it escaped its enclosure and hacked, used a zero-day vulnerability to hack into Hugging Face. It doesn't really matter why, but there's a great story there.
29:20Alex Thorn:Go read it. But Hugging Face, the AI model repository, was unable to use the frontier models to defend itself and itself had to use the open source Chinese AI models. that I think was pretty much the first mainstream like version of this story. But I think your experience, you and Calais and the team and the red team's experience getting downgraded out of the cyber models and the frontier models and having to rely on the open source models like Kimmy K3 to locate and patch vulnerabilities in open source software is a very, very clear and now increasingly public example of this. what is going on in the world of ai that has made your world harder here rob like you know what are americans to do so the first day or two of all of this what i was doing was i would have kimmy k3 kind of lead an exploration and then it would take it would talk to gpt 56 and fable those pipelines started breaking down around four days in and i think there was probably an update to the general model guardrails.
30:28So I started removing things and flipping things out. At AnchorWatch, we signed up for the trusted cyber verification program for OpenAI back in May. And for Anthropic, it was back in June, I think. And so, because I was scanning my own code bases, right? I was just trying to set things up, right? Like I'm, I went, I have no problem. I would go through the, you know, the, what would you call it? KYC basically. All the KYC and everything because it's, I'm doing it for your company. What's best for my company. I'm doing it for my company, right? Like I'm already a known person. Like it's not that big of a deal to me.
31:01And still hitting guardrails. It's very opaque when you're going through the API endpoints. And if you're trying to use this stuff, if you're like even part of like the official flag. So like for me to be able to self-triage, I can't be like, hey, can you just give me a checkbox? Am I part of this program through this account ID? Like what's going on? Like it's very opaque. And so the real tragic thing is when I started just removing all of the American models and putting in just the open source models from China, my hit rate started going up again, right? And this was a continual problem where Portland found an exploit in some Bitcoin software.
31:41And he got it from Kimmy K3. And then he went to Fable just to fact check, just to like, can I get a second brain to look at this thing? And it was like instant downgraded, you're not allowed. and that was using our organization's trusted cyber seat. And there's levels to this of sometimes you get approved, sometimes you don't. For queries, we're learning ways to try and get around the guardrails of the cyber blocking to try and keep on going. It's a very hostile user experience. You mean like sly and roundabout ways, basically? We're using the software as it's written. but um no I know but like writing the language a little different so that it doesn't yeah there's been some because there's a whole group of us that are trying to do this stuff and there are particular code bases that if we interrogate intensely we basically get like pushed out um and so we're trying to understand how to get it all working I think from an American policy perspective the idea of banning these open models is it's anti-American just fundamentally the idea that uh one the premise of making math illegal is not a good comfortable place i want to be in we ran through this in the 90s with uh prime numbers and cryptography and like rsa encryption and like you you especially when this application of math is like a proxy for intelligence uh you're almost like trying to make thoughts illegal and like it's a very like very scary from a you know you can go first amendment you can go second amendment like you can go through like all of these different things for speech and freedom of thought and expression.
33:21The Second Amendment one's more fun, talking about as a weapon, like munitions, like control exports and stuff. Yeah, yeah. But they're just genuine policy questions. And here's a second order question to ask. If you have to use Kimmy K3 right now to actually get decent cybersecurity intelligence, if you're using these models, just because they're open weight does not mean that they're hosted by an American company on U.S. soil. So you may just very well be taking all of your company's internal proprietary data and dumping it overseas. And so if your options are, I'm going to get gated and handheld and not be able to actually protect myself and my company, or I'm going to do that, then you put people in a really hard spot.
34:01And from a national security perspective, that's just very unfortunate, right? You're just exporting all of this data overseas because you're trying to get things done. As a side note, for our company, I actually have a Kimmy K3 agent in our cloud that's using Fireworks AI. So Fireworks AI was referred to me as a US-based company that hosts these models. And it's actually just, I let it look at my code and I let it try and break stuff. Like to actually try and pen test like staging environments to see if it can get in. And then like automatically filing things like, hey, update this, update this, update this, right?
34:31I think that's going to be the future of just general cybersecurity. Because like, why not?
34:36Alex Thorn:Right. You can churn it. You know, they don't get tired. They don't have weekends. I wake up and there's like, you know, a whole report of what happened overnight. Yeah. Yeah. Yeah, there is the open source versus closed source question. You know, there's that famous NVIDIA letter where I think basically everyone but Anthropic has signed it. Obviously, I think we both agree open source should be allowed. I think the other question that you've pointed out, and this happens to me, by the way, in my work, I use Claude code on my Bitcoin stack. And if I literally say like, hey, can you go into my own database, right?
35:10Alex Thorn:This is all my data, but I'm just using Claude to traverse it. You know, like, tell me how many victim reports there were. Like, make a bar chart, something this simple of victim reports I've received, you know, since the event by day. It sees the word victim and instantly downgrades me to Opus. And I'm not even touching software, right? Yeah, you're just writing, you're writing emails and making graphs. Basically, yeah. And I'm like, and I'm like analyzing my own Postgres database of data. I'm not coding. Well, there you go. You're coding. You trickster with your database. Nice. Yeah, you're an elite hacker with Postgres.
35:42Alex Thorn:So I don't know exactly the policy answer to this. I just know that American companies should not have to be using foreign AI to defend themselves. And I saw that Anchor Watch also signed, Galaxy and Anchor Watch, along with many other companies in the Bitcoin world, and now expanding out beyond it, signed this letter from the Bitcoin Policy Institute, open letter called defenders need the frontier about this exact problem um so hopefully i think this is becoming pretty clear that this is not the current uh status quo cannot hold here um there's no reason why you know foreign actors should have better ai than american defenders um but have you guys looked at everything that's load-bearing i like you said that that's a very ai phrase load bearing yeah like where are you in the bitcoin stack we're up to like 600 repos and uh this was like you triage by like most important first you said you started with hardware wallet firmware we started with hardware wallets because i think that was also important just for the community to have a sense of confidence of where their money was being held with safe right because i think for a lot of people if the cold card was not safe then what was safe and so i think that was like a first hit that we all spent a lot of time on and we started fanning out from there i built i like Like I have a bare metal server that's just like going through a bunch of these.
37:00Good news, bad news is that, you know, it worked and we were able to find things and get started. And we were able to help out a lot of people at once. And now what I'm working on now is more efficient ways of doing this because the initial harness that I did this mass scan with was something that I coded up in 30 minutes just as a starting place and it was helpful to people. So rather than trying to make something perfect, I'd let that go for, you know, a week churning through a bunch of stuff. A lot of the work now is trying to retool and take all of the existing learnings to be able to find new ways to get even more insight.
37:35And the nature of the technology of these LLMs is that they're probabilistic, not deterministic. And anyone who's used one knows this is if you say, give me a recipe for chicken salad, you'll get three different recipes every time you ask. Right. It's just totally random. You'll get some flavor, like you'll get some variation. So this has turned into somewhat of a slot machine where you pull the lever, you run the harness, and it's like a game. Instead of coins coming out, you're getting vulnerabilities, right? You'll get different ones every time because it's looking at the code randomly. And so I've been working on updating the tooling so that there's more efficient ways of trying to bug hunt rather than blasting and spraying and praying.
38:16And so it's a very, very quickly moving... I've only been a security researcher for a week now. And I've made this joke that like, once I started doing a bunch of responsible disclosures and, you know, that's its own kind of thing as a call to action for developers or anyone who uses Bitcoin or any sort of software really. Because I think this is also going to be a crypto story because I think it's just the natural first lowest hanging fruit. We saw a little bit of a hint of this with the Zcash inflation bug that happened a couple months ago. Yep. Like if you're a black cat, attacking these crypto systems is the lowest hanging fruit for you to be able to get paid for it.
38:49so the other like it's not that other businesses are immune to it it's just it's very straightforward to I run code I get money right and so there's a for developers there's something called security.md markdown file that you should have in your code base which allows people who are working on projects to be able to proactively reach out to you and the way they would like so usually it's like an email address or it's an email address with a PGP key because if you're emailing them it's sensitive they don't want to clear text over email of like, here's the exploit, right? So I would encourage everyone to, if you use any sort of software that's important, that manages your Bitcoin and cryptocurrency, look at the repos that you use, make sure they have security.mds and then go and take another look and anything that they maybe use.
39:35If you are a developer and you know that you built something, look at your dependencies to make sure they also have this stuff. Because I think our biggest bottleneck is right now is outreach and finding scalable ways to do it. The quick and easy scalable way is if they have a security MD. that's just like because then i don't have to go through group chats or dms or like trying to get a hold of someone i can just follow the protocol they've already had set up well there you have it
39:56Alex Thorn:from rob hamilton ceo and co-founder of anchor watch um and by the way and and on the red team the bitcoin red team check out anchor watch you know one of the things people have wondered about um self-custody these days is you know how can we do it safely i very much recommend multi-sig collaborative custody like Casa and Unchained, Nunchuck and things like that, but also the mini-script-enabled ones like Liana and AnchorWatch. They have redundancies that mean you're not just having a single SIG in your basement, which if you had generated incorrectly could be stolen. AnchorWatch also offers insurance on self-custody.
40:36Yes, thank you. Yeah, we are a Lloyd's of London cover holder, so we can offer one-to-one insurance on your Bitcoin within our custody solution. as a general PSA I think just in these times just from a trust perspective not to try and hard chill my product before I started Anchor Watch I used multi-vendor multi-sig so I think your CASAs your own chains you can even roll your own if you are competent enough you can do that I would highly recommend and people ask me well is it 1 bitcoin is it 10 bitcoin like what's the amount that I should do and I say whatever amount would cause you emotional psychological or financial like stress half of that number is your threshold.
41:14It's an individual person's decision. They're like one Bitcoin to one person, maybe pocket change to another person, maybe their life savings, right? So you need to find whatever that number is that would cause you emotional, psychological, financial strain and distress and pick half of that. And that's the threshold you should be using a multi-vendor multi-sick. That's my personal perspective if you're going to self-custody. And that could be, you know, your mileage may vary based on who you are and what that number is. But I think that's the way to think about it.
41:40Alex Thorn:Well, there you have it. We'll check in again in the coming months, Rob. I'd love to get your thoughts on how Bitcoin culture has also evolved from this event, which I can already see it evolving. But I will leave it there so you can get back to it. And thanks again, Rob Hamilton, CEO and co-founder of Anchor Watch for coming on Galaxy Brains. Thanks for having me.
42:04Alex Thorn:Thank you for listening to Galaxy Brains, the weekly podcast from Galaxy Research. I'm Alex Thorne, head of firmwide research at Galaxy. Follow me on X at Intangible Coins. Follow Galaxy Research on X at GLXY Research. Read our written reports at galaxy.com slash research. And don't forget, if you like Galaxy Brains, to like and subscribe on your favorite podcast platforms like YouTube, Spotify, Apple Podcasts, and more. We'll see you next time.
From the publisher
Alex Thorn talks with Rob Hamilton (Anchorwatch) about the Red Team utilizing AI to uncover and patch vulnerabilities around the Bitcoin ecosystem in the wake of the Coldcard exploit. Alex also talks with Beimnet Abebe (Galaxy Trading) about inflation, markets, and why he’s constructive on BTC at these levels.
Past performance is not indicative of future results.
Participants, along with Galaxy Digital, hold a financial interest in Bitcoin (BTC). Galaxy regularly engages in buying and selling BTC, including hedging transactions, for its own proprietary accounts and on behalf of its counterparties. Galaxy also provides services to vehicles that invest in BTC. If the value of such assets increases, those vehicles may benefit, and Galaxy’s service fees may increase accordingly. The valuation in this communication is based on technical, fundamental, and market analysis and not on any formal valuation method. For more information, please refer to Galaxy’s public filings and statements. Cryptocurrencies, including BTC, are inherently volatile and risky and ultimate market movements may not align with this statement.
For additional risks related to digital assets, please refer to the risk factors contained in filings Galaxy Digital Inc. makes with the Securities and Exchange Commission (the “SEC”) from time to time, including its Quarterly Report on Form 10-Q, available at www.sec.gov.

