In short
Emergency Bitcoin update explaining a Coldcard firmware bug (early 2021) that reduced entropy when generating seed phrases, enabling attackers to brute-force possible seeds and sweep funds. Host urges immediate action for Coldcard MK3/MK4/MK5/Q users who relied on device-generated seeds without strong dice-rolled entropy or a sufficiently strong 25th-word passphrase.
Guest background
Rob Hamilton, co-founder/CEO of AnchorWatch; discusses incident response, key-generation threat models, and mitigation options. He references industry exchanges and collaborative custody services.
Key claims
If you used Coldcard MK3/MK4/MK5/Q and later chose “give me seed words” (or otherwise didn’t add strong external entropy), your funds are at risk “code red.” One-word passphrases are not sufficient. Attackers scan on-chain patterns (e.g., first-gap UTXO behavior) and are now multiple teams using GPU farms; theft estimates rise into the thousands of BTC.
Notable examples
White-hat hackers reportedly swept dozens of BTC while trying to recover it; multi-sig wallets with two Coldcards are especially vulnerable; River/Bitkey/Ledger are suggested short-term options.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOThe Cold Card Emergency Explained
0:45 to 2:02
Details about the cold card firmware change and its implications.
Understanding the Firmware Bug
2:02 to 4:26
In-depth analysis of the firmware bug affecting cold card devices.
“entropy that gets created and that is when a bug was introduced now uh since i will take a moment to explain the nature of the problem.”
Passphrase Importance in Security
4:26 to 6:27
Discussion on the significance of using strong passphrases for security.
“And so the passphrase is the only thing keeping it secure.”
Impact of Changed Entropy on Security
6:27 to 9:22
Exploration of how changes in entropy affect Bitcoin security.
“That is the universal proverbial needle in a haystack.”
Analysis of the Attack Dynamics
9:22 to 13:55
Insights into the behavior of attackers exploiting the firmware bug.
“somewhere between 45 and 50 bits of entropy, which is more.”
Emergency Self-Custody Measures
14:00 to 16:39
Learn about urgent steps to secure your Bitcoin amidst a cold card vulnerability.
“This is something that is for each individual person to kind of make that judgment call.”
Navigating the Risks of Exposure
16:40 to 18:15
Understand the implications of Bitcoin exposure and the need for immediate actions.
“They've bought what was sort of perceived as the most secure Bitcoin hardware wallet.”
Impact of the Cold Card Attack
18:16 to 19:38
Explore the ramifications of the cold card attack on Bitcoin self-custody practices.
“Do you think this sets back Bitcoin self-custody in a significant way?”
Threat Models and Mitigation Strategies
19:39 to 21:00
Learn about advanced threat models and how to protect your funds effectively.
“There's a couple of more threat models I do want to go over for maybe more advanced users as it relates to ways that your funds could additionally be put at risk.”
Understanding Multi-Signature Risks
21:01 to 22:39
Gain insights into the vulnerabilities of multi-signature wallets and necessary precautions.
“for those that need to know, because I have talked to...”
Show all 18 chapters
Evolving Attack Patterns on Bitcoin Systems
22:40 to 25:10
Examine how attackers evolve their strategies in response to vulnerabilities.
Long-Term Effects on Bitcoin Trust
25:11 to 27:55
Discuss the long-term implications of the cold card incident on trust in Bitcoin self-custody.
“What you'll be able to have an attacker do is they're going to be able to look through the full list and just pop it right out.”
Covenants and Vaults for Self-Custody
28:03 to 29:50
Learn about the importance of covenants and vault-like structures in enhancing Bitcoin self-custody.
“um in some conversations people are talking about we need covenants and vault-like structures things that can improve self-custody.”
Understanding Key Management Risks
29:50 to 31:51
Explore the risks associated with key management and how to improve security in Bitcoin transactions.
“So there is a lot of learning, I think, within the ecosystem about where do we go from here.”
The Evolution of Security in Bitcoin
31:51 to 35:58
Discuss the implications of AI on Bitcoin security and the need for improved vigilance in key generation.
Trust Issues and Hardware Wallets
35:58 to 37:56
Analyze the trust issues surrounding hardware wallets and the consequences of firmware vulnerabilities.
“Do you think we're going to see more and more attacks like this?”
Emergency Response to Coldcard Incident
37:56 to 41:21
Get insights on the immediate actions users should take in response to the Coldcard security incident.
Closing Remarks
42:00 to 42:13
Final thoughts and gratitude expressed by the host.
Transcript
Automatic transcript. May contain errors.0:02Rob Hamilton. Damn man. Crazy, crazy 24 hours. We have a legitimate emergency in Bitcoin. What's been going on? In the spirit of emergency, I'm just going to start this with if you or anyone you know has used a cold card MK3, MK4, MK5, Q, any of those devices with any wallets that were generated from the device. you clicked give me some seed words um you need to immediately stop what you're doing and contact friends this is a canceling of weekend plans this is getting on planes for any ability for you to be able to recover your bitcoin this is uh as about as code red as it can get for bitcoin self-custody as it relates to the urgency in which you need to act um i will go more into the details with that urgency i want to caution um slow is smooth and smooth is fast so you need to act very decisively and you need to be able to act deliberately you should reach out to your friend networks and people that can help you support um any questions you may have but time is of the essence right now so maybe we should just start with what happened um because i first stop your podcast if you have to like you need to stop like you but yeah this is not going now this is not a drill continue um and so i obviously first saw this pop up on twitter yesterday um i actually had a cold card mark four that was using as almost like a spending wallet but the amount in there had got to a point where i was like very uncomfortable as soon as i saw this news i text you being like i've seen this thing with the mark three is overblown or do i need to do something and again you were like this is not a drill you need to do something now i wasn't with my wallet managed to managed to sort that out but this is like a serious product a serious problem that's impacting a ton of people um where did it all start so uh in early of 2021 there was a change to the cold card firmware as it relates to the entropy that gets created and that is when a bug was introduced now uh since i will take a moment to explain the nature of the problem.
2:20If you had an ear-gapped wallet, never talked to the internet, it doesn't matter. The things that would save you if you were using a cold card MK3, MK4, MK5, and Q is if you have a sufficiently strong 25th word passphrase. If you also rolled dice or provided your own entropy from outside of the cold card. The nature of this bug is that when you turn on a cold card and you have a clean device and you say, this is amazing, can you please give me some seed words? Those are not secure. And from that, everything else needs to go down. I just want to be really clear so that we don't miss anyone here.
3:08You obviously said Mark 3, 4, 5, or Q. What about the Mark 1 or 2 if they were on updated firmware and they still generate those keys after 21? To my understanding, the MK2 is not supported in any of the impacted firmware. I'd have to go double check. But if you have an MK1 and MK2, technically the firmware bug that we're talking about has not been introduced because that is long end of life hardware. There aren't updates for that really anymore. And so if you have an MK2 or MK1, you should not be impacted by this. Okay. And then I think we should also be really clear on the passphrase because that's essentially a 25th word.
3:47At this point, that's the only word really keeping your Bitcoin secure. Is that right? If you really only used one word, that is right, which means you are not secure. You have to assume with what we're discussing right now is that many attackers, not just one person, there are many attackers right now who are scanning to get the entire table of all possible seed phrases a cold card could generate, whether it was 12 words or 24 words, and they are sitting on all of those words and they are taking all of the low-hanging fruit of single signature keys. My assumption is they're going to move on to other things, but we'll get to that, yes.
4:26And so the passphrase is the only thing keeping it secure. If you've done that, you should still probably move funds. Would you agree? Absolutely, especially if it's one word. So like a one-word password is not strong. um there are different uh perspectives on exactly how to mitigate this rather than if you're in the zone where you're kind of debating am i safe or not you just need to stop what you're doing and uh recover your bitcoin before it gets stolen um in theory if you had 12 like 12 random words that you added on top of that okay like you're in a better spot but now your entire security model was oh an attacker needs my seed words and my passphrase and the seed phrase is now known by multiple actors at this point or will be imminently over the coming uh couple of days if not like maybe a week but honestly this is something that you need to move as fast as possible so the only way you're secure is if you create your own entropy and doing that obviously comes with its own risk that you have to do that very carefully very consciously um yeah is it kind of to the point where if you're using a cold card device just move off it for now wait and let the dust settle then see what happens um yeah like there there are a couple things so if you have a cold card and you generated your own entropy there is no identified bug in any of the firmware from the operations of anything else besides the generation of the seed now to be very clear the most important thing a hardware wallet can do is give you a secure seed phrase yeah power users will roll dice and do other things to bring their own entropy into it so it exists outside of the cold card tragically exactly for reasons like this of not trusting the cold card and that you're not going to trust it to provide that information reliably um if you have a very strong pass raise or you roll dice for the time being there's no urgent need to move as long as you're very sure like that you you roll those dice um to add to that uh for migrations and things to do that is there's a longer conversation we need to have there um if it's a single signature specifically with the mk3 you need to do that right now um the mk3 is identified to have two to the 32 bits of entropy now if you're familiar with uh seed phrases right like these words is that there's a list of 2048 of them and each time you can pick one you can even have them sometimes be the same word each time you're basically picking 2048 multiplied by 2048 multiplied by 2048 so if you take 2048 times 12 you're close to 128 bits of entropy which is really good and if you do the 24 um you're at 202 to the 256 both of the like we're talking numbers that are in the scope and size of there are more possible seed word combinations than there are atoms in the observable universe.
7:26And to explain why this is a problem, the nature of cryptography and Bitcoin security ultimately is that everyone, your Bitcoin address ultimately in one way or another results back to a large number, some number between zero and two to the 256. That is the universe. That is the universal proverbial needle in a haystack. And the idea is not that someone can't know my number, it is for someone who doesn't know the number to be able to guess it they have to basically guess all of the numbers in the universe and the universe will go through a heat death before someone's able to get there with all of our modern computing right the problem with the cold card firmware with this firmware change was with some of the changes i saw it succinctly summarized as there was code that said hey use extra secure entropy um and then continue there was basically a one-line error that just said oh does this function exist somewhere if so you can skip the entropy and rather than is this function true right it was like a true false statement and rather than it being is this true we should invoke that uh you can skip the entropy it was like oh this exists so we can skip the entropy that's the best highest level it is one line of code um of how i can describe this issue but the thing is with the mk3 since you have two to the 32 bits that is trivial for consumer hardware to be able to brute force all of the c phrases the mk4 the mk5 and the q have updates to the firmware the those updates to the firmware are not better in the sense of you don't have to worry about this.
9:18They are extra entropy. What people in the industry are estimating right now, somewhere between 45 and 50 bits of entropy, which is more. That is a significant amount more extra protection. But with someone with a data farm of GPUs, they will get this information. And now that people don't know that money's being stored on it, it will be consumed rapidly and quickly. So if you did not use a passphrase, If you did not use a seed phrase, like if you did not roll dice, you need to right now stop what you're doing. And you have to treat those funds as you're in a race against the clock across many teams of hackers who are going to get your Bitcoin.
9:55So the obvious question is, like, how how is this bug not spotted? Like for me, like this is obviously source viewable software, but I can't read that code. You can like did you ever go through and read the cold card code? Like how was that not spotted earlier? Yeah, I had gone through it previously. I had gone through it with my own eyes, and I'd also had gone it through earlier versions of large language models. And what I have observed, and I think this is an important part of the story, is the latest open source bleeding edge model, Kimi K3, which is from China, it's an open source model, does not have the safety guardrails that OpenAI and Anthropic have.
10:38And so when this incident started happening, myself and many people in the industry started looking exactly at where this would go wrong in the code and Fable would downgrade me. So you can't use the leading model. This is a cybersecurity thing. And then using OpenAI, it would kind of like be coy and generally nudge that something may be going on, but not tell me details. I put it into Kimi K3 and it instantly just read out the entire incident and exactly what went wrong. and so uh there is something to be said that for a long time uh security through obscurity was used in places and that is no longer possible if the code exists and people are able to walk through and see it it will be exploited it's um so when i first saw this i assumed that it was a lazarus north korea type hack very sophisticated but i've read some stuff online that says it's maybe a bit of an amateur doing this doesn't really know exactly what he's doing but still managed to exploit this bug the first the first attacker was i would say an amateur um there's a lot of on-chain heuristics of what you could tell in the movement patterns they only moved bitcoin addresses that were more than 0.15 bitcoin why someone wouldn't run a little extra logic and just get 0.1 bitcoin at six thousand dollars for no extra cost really that's weird they did not that properly scan full addresses.
12:01So people were getting hacked and they still had funds that were sitting in the addresses. Was that, I did see something about that. Was it because it was only looking at like the first 200 UTXOs or something like that? It was looking, what it was doing is looking for the first gap. So if you create an address and you didn't use it, and then you made another address and you use that second address, the moment the bot saw that there was no more addresses, it stopped looking. And this is initially would have kept you safe, but this is going back to the point now, there are multiple attackers now executing this.
12:37And I'm assuming they're getting more and more sophisticated. So like that's, and that's why you can see different on-chain movements and seeing different wallets being used, different transaction behaviors. You can just tell by some basic fingerprinting that different actors are going about this. That makes sense. So, but this is something you can do trivially. like i could do it on my laptop if i had like the skills yeah uh there are reports of white hat hackers which is people who are trying to do it for the good who started seeing this exploit started running code and came into dozens of bitcoin and they swept them because they were trying to do they'd rather at least try to find a way to give it back to the right owner and then try to uh let an attacker take it so people will be in a panic hearing this if they're if they're using a cold card um i want to talk about some of the other devices because cold card was initially like a fork of treasure and since then um foundation has fought cold card are those other forks from the same thing safe from the same original source code yeah neither treasure nor uh foundation use the library that was compromised with the cold card okay so basically anywhere anywhere is safe apart from cold card right now this isn't like a broader self-custody attack this is a specific cold card.
13:50The use of this library was specific to cold card or realistically mainly cold card. So what should people do if they're panicking right now? Where should they be moving funds?
14:02This is something that is for each individual person to kind of make that judgment call. I am, while I am the co-founder and CEO of AnchorWatch, I want to be fair to everyone and talk about how I would console someone if I did not run this company and I was trying to help a loved one through this. If you had used a Bitcoin exchange and your Bitcoin is, you know, in the system, you give an exchange dollars, you get Bitcoin, you withdraw it to self-custody. Immediately short-term, sending it back to that exchange is not a bad idea if you have no better place to do this. I'm a big fan of River, personally.
14:40I have high confidence in the infrastructure over at River if you're looking for a good Bitcoin exchange. I'm talking to other people in industry. I just know that River runs their own custody. They're not outsourcing it to someone else. And I think that's an important thing to be aware of. And they do proof of reserves. I think really genuinely proof of reserves is kind of table stakes if you're going to leave your funds out in exchange. And River is the main place that does that. As it relates to other options. Now, you could, in theory, go to a Best Buy and pick up a ledger in the States today.
15:17You can get bit keys there as well. You can get bit keys as well. Those are good immediate emergency options to get things set up properly. And to be clear, the whole context of this advice is your funds are imminently going to be hacked if you're on a cold card without the entropy and without the dice and without passphrases. So my advice is not set this up and hang out for the rest of your life. This is you need to do something in the next 24 hours. Now, there are other services like there are Unchained, there's Casa, there's us at Anchor Watch. There's a Swan Vault as well. There are many products across the industry that offer these things in collaborative custody.
16:00I think those are all great measures to be able to provide extra support to people. If you have a friend, we won't say who, but as we were starting this podcast, you and I got a call from a mutual friend who was basically breaking into a friend's house who was on vacation. and getting the pin over the phone to then move the funds before they got hacked they had a reliable self-custody wallet to be able to do that right um the universe and space of this has to be very carefully thought out and this goes back to um something i i believe i said before is that um slow is smooth and smooth is fast so you need to have a decisive plan that is good enough for the trade-offs right now and decisively execute you do not have days to really war game out your optimal option here it's just most important that you take action now there's so many things that are very unfortunate about this um from a user perspective like one of them especially comes down to sort of privacy um because if you're in a panic now you might have a ton of utxos on a cold card some of which may be like non-kyc bitcoin stuff that you don't really want to mix but at this point you kind of just have to move everything together like that's one of the really unfortunate outcomes indeed yeah uh while you could if you are technical enough spend the time building a careful transaction graph i'm going to assume most people aren't and so you have to make a cost benefit analysis for your own position to understand is that with any of these movement options and how you're going to execute about them you are the best person to be able to understand your circumstance and that's why i try to keep the advice very open-ended in general to meet different people depending on where they could be in their self custody journey and their bitcoin journey and their technical competency and then the other side of that is the thing that is very harsh about this situation that's completely unlike a mount gox or an ftx is that the people that have been affected by this have done everything so right Like they've taken the time to learn self-custody.
18:09They've bought what was sort of perceived as the most secure Bitcoin hardware wallet. They've done everything correct. And they've still been fucked in this situation. Do you think this sets back Bitcoin self-custody in a significant way?
18:30i think it would be naive to say that in the short term that there's going to be a massive re-evaluation of this many people lost their life savings because of this um I think it's important for Bitcoin as a technology, as people who send and receive Bitcoin regularly, to be thinking about where to go from here. The capturing of Bitcoin as a decentralized network is accelerated if the only place you can hold it is at a specific exchange. that is inevitably Bitcoin as freedom money cannot work if you're not able to freely be able to call your money and own it and touch it yourself.
19:24Now, I think this is so pressing and breaking. It is difficult for me to come out with my prescriptive list of these are the things we should be thinking about and doing. I think most important right now, what we should be doing is informing people, letting them know that this is happening. giving them ideas for contingencies. There's a couple of more threat models I do want to go over for maybe more advanced users as it relates to ways that your funds could additionally be put at risk. And I'm going to start there because I think that's actually more important than like the bigger question is if you have a multi-signature wallet and they are only using cold cards and those cold cards are only generated using this entropy, your funds are at risk and you need to immediately make whatever moves you need to do to get that fixed.
20:16If you have, let's say, a two of three and you have two cold cards in a ledger and you did not do the passphrase, you did not do the dice rolling, your funds are at risk and you need to make moves immediately to rectify that. Now, to explain, I feel fairly confident this is what's going to happen. Can I ask you a question on that part first? So you said if you have a two of three and say one device is a ledger, one device is a trezor, one device is a cold card Mark III, even in that situation, your funds are at risk? No. So if you have a trezor, a ledger, a cold card, your funds are not at risk.
20:52If you have two cold cards and a ledger, your funds are at risk. Yeah, because those two can... Yes. And this is to get a little bit for those that need to know, because I have talked to... I've probably talked to at least a half dozen people specifically in the situation, if not more, where they have two cold cards and a ledger or two cold cards and a treasure or two cold cards and a jade or two cold cards and a foundation device, whatever, two cold cards and a seed signer, right? the necessary thing to understand is that when you go to spend bitcoin in the bitcoin network let me actually just take a half step back here what is going to very likely happen across multiple hackers is they are going to build an entire list of every single seed phrase combination that the cold card would do without entropy what they are going to do from there is they are going to start realizing, wait, if I have all these seed phrases, I can actually see if my wallet's being used on chain.
21:52And they're going to say, okay, out of this, you know, billions, we're going to say that we have this many that could be in use at the moment. They're going to look at those and they're going to see what are they doing with it. And to be clear, if you use your cold card in a multi-seg, they can see, wait a second, that person spent from this address and that public key is tied to my list of seed phrases here. They're going to be able to basically monitor your wallets. Here's what happens. If you have reused addresses, those reused addresses have the raw public keys of how you spend that Bitcoin sitting on chain.
22:30And if it's a two of three and the attacker says, oh, I have key A and key B, they'll just take the funds. They don't need to wait for you to do anything. If you have not reused addresses, you are in a very delicate position and this is a little bit advanced and i want to be clear this is a very specific circumstance if you have a multi-signature wallet and that multi-signature wallet is a majority for the threshold uh cold card signers that are impacted by this issue you should look into using something like mara slipstream and the reason why is when i go and broadcast a transaction to the bitcoin network anyone on the network can see the transaction data before it gets confirmed but it's not in a block yet which means an attack by flea exactly so an attacker will be able to replace by fee and change the address from your address to an attacker's address if you use something like mara slipstream you will be able to have it broadcasted to a mining pool that has over five percent network cash rate they find multiple blocks a day and it will just appear confirmed on chain which will mean the attackers will not be able to do anything and so i know it's a very specific circumstance but i've talked to easily a half dozen people who are in this exact position and you can reach out to mark like there are ways for you to be able to do that um if you only have cold cards if you have a three of three if you have three cold cards and it's a two of three they will find your funds they will look at all the seed phrases and once they have all the possible seed phrases they're going to run through all of the common metrics of different multi-sig thresholds among those keys if they haven't already been spent on chain if you've spent from your multi-sig address once on chain they will be able to trivially scan and see that it's there and be able to attack you um and know that yeah so in that situation slipstream doesn't help you so what do you do you just have to set an incredibly high fee rate and hope you just have to go you just have to rip it you you don't have a yeah so if you've and to explain this let's say you have a two of three multi-sig and they're all cold cards you and you've spent from it before attackers will be able to see oh key a key b key c that matches seed one two and three boom boom home connected i'll be able to move my fund so if you have a an n of n two of two three of three whatever multi-sig wallet that is only cold cards that are impacted by this issue you need to move funds right now like you you are marginally safer than a single sig and the reason why is because you need to have an attacker know all of the seeds in the universe to be able to attack it but that is a ticking time that you're racing against the clock you need to immediately make moves if that is the position you're in oh it's such a terrible situation to be in um do we know how much bitcoin's been stolen from this attack so far i saw yesterday it was like 600 but i'm sure it's increasing it's over 1100 at this point and there's probably more clusters going on all the time um i occasionally was poking around the men pool to see if i can find more things it's going to be thousands of bitcoin before this is done and it's going to happen in waves what i'm describing right now this race against the clock the lowest hanging fruit were hit and that was probably one attacker the starting gun has been fired off the everyone has declared the emergency every black cat hacker on the internet with an llm is going to be able to start poking around seeing what they can find they and because there are multiple attackers now there's a an inevitable outcome where well capitalized ones are going to come in spend millions and millions of dollars on graphics GPU computing because they know that they can pop one vault.
26:06What you'll be able to have an attacker do is they're going to be able to look through the full list and just pop it right out. And you are just marginally safer because it's not the lowest hanging fruit, but you are not safe, period. So this started as obviously like an amateur attack, as we spoke about a little earlier, but this is now you have to assume the best attacks in the world are now having a go at this uh yeah this is everyone it's uh it is a real mess um so when you compare this to like a mount gox or a ftx like the number of coins is going to be far lower but is the damage going to be greater because it kind of arose people's trust in self-custody essentially like coal card was the golden child of bitcoin self-custody essentially I like I said earlier it would be naive to say that in the short term that this is not going to be a a very negative downward pressure on self custody and for I know multiple people who've lost either some money or their life savings.
27:14uh i have spent the past 24 hours i have talked to directly on a one-on-one context dozens of people um in a larger platform i've talked to now thousands of people trying to raise the alarm bell about this and the stories keep on coming in this this will have a downward trend on self-custody i think that doesn't have to be the end of the story but i think there needs to be as the post mortems wrap up and we do a full debrief of this the entire ecosystem has an opportunity to build from here and find improvements um we are now almost 30 minutes into the podcast so um in some conversations people are talking about we need covenants and vault-like structures things that can improve self-custody.
28:11My biggest concern for the health of Bitcoin as a network is that the default option being holding it at a custodian or an ETF wrapper, I am not opposed to those instruments existing. I think those are inevitable structures that happen with hyper-Bitcoinization. But the value proposition of Bitcoin itself will be diminished greatly if those are the only real options. And being able to explain this, the way Bitcoin works today, if you have the requisite amount of signatures you can send any amount of bitcoin anywhere within reason there's weird corner cases but let's just say for the sake of conversation that's true things like covenants would allow you to be able to have things like i only want to be able to send these addresses i only want to send this much bitcoin this is something at anchor watch we are able to offer as a product level service right it is an application that sits on top of bitcoin where we say anchor watch is a required co-signer to move funds but we will in exchange for like us being able to help you out we'll say okay well you only can send to the addresses you give us so addresses a b and c otherwise we at anchor watch won't sign it's effectively a covenant as us acting as a co-signer gives that feature or i only want to send one bitcoin a month that's something we can do at anchor watch it's something you can't do on the bitcoin blockchain level if it were to be democratized to the bitcoin blockchain level anyone in their basement would be able to have orders of magnitude better security than any of the enterprise leading custodians today and that's an important point because when bitcoin is in flight once it gets confirmed in a block it's over whereas with covenants and in general vaulting you would be able to send to like a staging address so you'd be like wait a second why did my funds move it's sitting in my staging address and then you can pull the emergency rip cord to like pull the funds out now it doesn't solve the key management problem right i think it's an important thing to call out that it is a mitigation it is necessary but not sufficient to be able to improve these things but the ultimately you need to send bitcoin to an address somewhere and those addresses have to ultimately be tied to keys.
30:29So there is a lot of learning, I think, within the ecosystem about where do we go from here. And I think there'll be plenty of time to discuss that in the coming weeks after the initial incident response and everything can be done as much as possible to keep people safe. Right now, I think the main focus is just letting everyone know this is happening and they need to immediately uh remedy this if they're impacted how do these um there's a thing like an unchained or a casser let's say you have a two of three with one of those um if i have so one key will be on your phone generally one key will be held by the company one key is held by you if i'm holding my key let's say on a cold card how do i know that the counterparty the unchained or the casa is not the unchained or the casa counterparty is not what like holding one of their key on it on a cold card because that would then put the you can't you can't prove that you can't with any wallet um well in a very tragic sense of irony um very soon people will be able to prove if they were using the cold card keys because attackers will have them right um the ideal structure though is that it's not something that can be an issue um because if you have sufficient randomness there's no you should not be able to fingerprint and say oh that that x pub came from a ledger and that one came from a jade that would be a breaking in the underlying cryptography assumptions that is a truly random number that is seeding all of your secrets so i guess the point i'm trying to make i'm trying to make people feel comfortable here if they are using a cash or an unchained like have either of those made a statement about how they're generating their keys like because i'm like i'm convinced that neither of those companies are using the on-device random number generator um but have my understanding to my understanding uh unchained has made a statement i believe casa has made a statement as well and we at anchor watch have also made a statement this does not impact us right and so uh i think it's an important thing to look in your vendors to see if this is an issue i think it's a very reasonable concern but i think everyone at this point has made some public statement to the effect of that i'm not aware of any i'm not aware of any bitcoin business even through like hushed private circles who are impacted by this i haven't heard anything yet they may exist but i have not heard anything i i definitely don't want my words to be twisted there like i think a casa and unchained like anchor watch i'm sure all those companies are set up brilliantly um i just i just want to try and make people comfortable with moving funds to those places if they need to understand um anchor watch how do you set up your uh multi-sig uh yeah so the nature of what we do it's somewhat different is we use what's called mini script and that allows us to do more advanced scripting functionality uh rather than just a two of three we were able to say we have a two of three you have a two of three we all have to get together and sign and move things we could do is we have a two of three and you have a single key right and we act as that cosigner still right um the nature of how anyone generates keys is an extremely sensitive thing uh because you just need to keep that on a need to know the exact mechanics but our process has been peer-reviewed um there are many i think most actors in the industry have their own very rigorous key generation ceremonies of what they go about for for being able to uh evaluate that so when like i really like single sig self-custody like i think i think you should have different trade-offs for different amounts of bitcoin that you're holding like if maybe you have a one sort of deep cold storage which is geographically dispersed multi-sig and that's great but the simplicity of single sig is really important too i think i i would definitely still use that occasionally um how do people think about that going forward because i've always i've always said that like the most likely you are to lose bitcoin is through your own complexity in your own setup like complexity being the enemy of security and do you think people are going to make the mistake now of jumping too far into multi-sig because they're scared of this attack and actually add too much complexity to their own setups i think multi-sig is no longer that complicated.
34:56I think this is not 2017 anymore. Additionally, if for whatever reason you want to do a single signature, you could do single signature with a pass phrase. That effectively is a two of two multi-sig because you have to have both pieces to be able to constitute a spend. If you were doing that with a reasonably strong pass phrase going into today, you're still safe. I would still make a new wallet because if you fell under this and your initial 12 or 24 words were actually part of this hit of known possible seed phrases all that's keeping you safe now is your passphrase but uh i think there's a lot of opportunity for everyone to grow and learn from this to even further improve the user experience because this will this will be in the front mind of anyone who discusses self-custody for a very long time so this is the first like in the wild case that we've seen of AI essentially hacking and taking down a Bitcoin self-custody solution.
35:57Do you think this is the start of that era? Do you think we're going to see more and more attacks like this? I think in general, across the whole web, there are going to be more and more attacks like this. The trivial ability for me to be able to open up to open router and use Kimmy K3 and point at the cold card firmware and instantly read out everything. Everyone needs to be, and we regularly do this at anchor watch i know most companies that i know of in the bitcoin industry are regularly doing this and kind of defensively trying to deploy these tools to find things um we've always found we've never found anything that was a money losing bug nothing in the universe of bad of what we're seeing here with the cold card um but you find bugs the software has bugs it always will have bugs right like there um there is some emerging research around things like formal verification so you can actually do formal mathematical proofs as to how code executes that's an emerging field of research that i think may get more important over the coming decade but software is written by humans and humans inevitably have bugs and even llm sometimes have bugs right you don't want to be blindly passing everything you've built to just have go get figured out later by the llm and the llm may not be complete right um the rapid development of these models there's a kind of a funny software motif if you write if you like vibe code a website and you launch it in three months the new model comes out and it says wow this code base is a mess let me fix this for you and that just that's just been happening continually for two years now right so like we're at a place in a time where you need to be hyper vigilant with your own individual judgment with your ability to understand the nitty gritty details of risk and however it emerges to be able to keep you and people you work with safe all right awkward question time because i know you're friends with mvk but like the blame obviously ends with them but how incompetent was this because this has been five years that this firmware issue has been there uh not acceptable as a starting place like not like there is no yes i've i've known nbk for a long time um there is no excusable there's no set of circumstances that excuses this the the one job a hardware wallet has if it were to have a single job more important than all of the other jobs is that it can securely generate a sufficiently large random number with sufficient entropy that is the entire game in which everything else gets derived from there are bugs that have happened in hardware wallets in the past where maybe how they signed a transaction wasn't secure and then basically if you reused addresses you could lose your funds or maybe you would have bugs where it wasn't checking the change address so if i sent you bitcoin if i if i have 10 bitcoin i send you one bitcoin i have to send myself nine back in change there were bugs in software and hardware wallets that didn't check the change which was the most important part of the transaction that sense right this bug is so foundational to the actual security of bitcoin that uh it is it is a nuclear event right this is this is the most catastrophic thing that is why someone could be entirely air gapped never have talked to the internet and someone's able to peer through the vast space of randomness and get your bitcoin which should never happen do you think it's uh the end of cold card do you think they'll be able to recover this because trust is everything when it comes to these devices it it is i i think it's too early to say i don't know i'm not a lawyer i don't understand any of the liabilities or fallouts or all of these things um it's hard for me to say yeah truly i don't know all right rob i appreciate you doing this so last minute i wanted basically just to get this out there if one person listens to this show they're not they're not permanently on bitcoin twitter like you and i and they haven't seen this news like that that makes it 100 worth it um any closing words for everyone who's listening uh closing words again um if you or someone you know has used an mk3 mk4 mk5 q any of those cold card products uh without either rolling your own dice or having a sufficiently strong passphrase and if your question is, is my passphrase strong enough?
40:22It means you don't understand the entropy, which means you need to go fix this immediately, even if it is, right? You just, if you don't know for a fact, oh yes, I have this many bits of entropy in my passphrase because you are super in the details. Your passphrase is not strong enough at the moment. You need to immediately make any moves and plans. You need to cancel your weekend plans. You need to get on a plane if you have to. You need to call a loved one who may be able to help you out remotely. this is a this is a full five alarm fire this is all hands on deck i think everyone in the bitcoin community has been trying to help through back channels and through direct messages through being able to have people call you find people get connected to people my dms are open on twitter like i said i've talked to dozens of people across the whole ecosystem none of them even anchor watch customers because anchor watch customers don't have an issue at the moment like this is this is not related to anything of how your funds are being kept safe at anchor watch so um all of that to be said like reach out to those you may know people you've ever referred to using a cold card and uh do what you can to uh try and help them out and i think there's going to be an opportunity in the coming week, two weeks to when the initial race is over, we can focus on triage.
41:45We can focus on, well, once we move beyond triage, we can start focusing on where does the industry go from here. All right, Rob, I appreciate you, man. Thank you for all the work, helping people out on this terrible, terrible event, but Bitcoin will get through it, man. Thank you. Thank you.
42:11Thank you.
From the publisher
“This is as code red as it can get for Bitcoin self-custody.”
Rob Hamilton joins me for an emergency episode on the catastrophic Coldcard entropy bug that has exposed Bitcoin held in wallets generated on affected firmware.
A firmware change introduced in 2021 prevented Coldcard devices from generating the level of randomness users believed they were getting. The result is that attackers may be able to reconstruct seed phrases and drain wallets, even when the device was air-gapped and the seed words never touched the internet. Rob explains which Coldcard models and setups are at risk, why updating the firmware does not repair an existing vulnerable seed, and what affected users need to do now.
We also get into the risks facing single-signature and multisig wallets, whether passphrases and independently generated entropy provide protection, how attackers are finding and sweeping vulnerable wallets, and the role AI may have played in discovering the bug.
THANKS TO OUR SPONSORS:
FOLLOW:
Danny Knowles: https://x.com/_DannyKnowles
Rob Hamilton: https://x.com/Rob1Ham




