The Coldcard Disaster: Everything You Need to Know | Lloyd Fournier & Nick Farrow

21 Aug 2026 · 1 h 23 min · 35 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The Coldcard hardware wallet vulnerability (“Mark III” focus) that caused some users’ Bitcoin to be swept after corrupted firmware/entropy handling. Hosts discuss timeline, how the attack worked, why it was missed, affected amounts, and what to do next (move funds, reassess entropy practices, consider multi-device/multi-vendor verification).

Guests

Lloyd Fournier (Frostsnap team; says Frostsnap avoids relying on device entropy by linking randomness differently) and Nick Farrow (analyzes the code/AI-assisted review; discusses RNG/entropy failures and security implications).

Key claims

Attackers exploited weak/non-cryptographic randomness via “Yasmerang RNG” (described as a toy RNG with very small state, ~32–40 bits cited, later corrected to ~20s bits). Multiple safeguards/tests failed. Mark III was “complete catastrophe”; Mark IV was harder to crack and not yet reliably broken, though still not fully trusted. Community response was fast once proof emerged; CoinKite’s earlier disclosures didn’t reach the root cause.

Notable examples

~1,200 affected wallets and ~2,000 BTC (Mark III devices with balances at attack time); attackers came in small bursts (about four attackers). One attacker reportedly swept ~1,000 BTC quickly. Mentioned “Dark Skippy”/malicious firmware research (education) and prior “LibBitcoin” incident where TRNGs were rejected.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Introduction to Bitcoiners and Cold Card Vulnerability

0:00 to 0:45

Learn about the Bitcoin community's commitment and the impact of the Cold Card vulnerability.

“The Bitcoiners, these are people all in on Bitcoin.”

Understanding the Cold Card Issues

0:45 to 3:00

Discuss the recent Cold Card vulnerability and its implications for users.

“Criminals who are focused just on this, their skills are there.”

Personal Experiences with the Vulnerability

3:00 to 5:30

Hear firsthand accounts of discovering and reacting to the Cold Card vulnerability.

“is you don't want to be the person who raised the alarm and then be wrong and then sort of, you know.”

Industry Response and Community Impact

5:30 to 8:00

Explore the quick responses from the Bitcoin community and the emotional toll.

“But it's just some random dude on the internet came up with it, right?”

Deep Dive into the Code Failures

8:00 to 11:00

Examine the flaws in the Cold Card code that led to the vulnerabilities.

“but then it's like randomly mixing with Yassmerang RNG, which why would you do that?”

Technical Discussion on RNG and Security

11:00 to 14:00

Discuss the implications of using MicroPython for security-sensitive applications.

“He replied to a tweet that said like, it was a tweet from years and years ago saying like, I got a cold card, generated a seed, and it looked like a collision.”

Analyzing Attackers' Behavior

14:00 to 15:20

Learn how blockchain behavior can expose attacker identities.

“Yeah, I can, I mean, the initial attacker was, they all did different.”

First Attacker's Strategy

17:25 to 18:20

Understand the tactics used by the first attacker in the incident.

“I guess it doesn't necessarily mean it's the correct KYC information.”

The Timing of Attacks

18:20 to 19:15

Explore how the timing of attacks affected user reactions and movements.

Running the Attack and Vulnerabilities

19:15 to 21:00

Discuss the feasibility and methods of executing the attack.

“The attackers came in small bursts, actually.”
Show all 35 chapters

CoinKite's Oversight and Arrogance

21:00 to 23:00

Analyze CoinKite's missteps and perceived arrogance that led to vulnerabilities.

“Like, I think, I believe one of the issues was that it was going through the potential private keys and if there was a gap, it was then stopping.”

Importance of Code Audits

23:00 to 24:26

Learn why regular code audits are essential for security.

“I think people, there was so much smoke around it, including people getting the wallet of someone else.”

RNG Issues in Coldcard

24:26 to 26:31

Examine issues related to the random number generation in Coldcard hardware.

“And people are sending you things about Yasmerang RNG in your security disclosure and saying, what are you doing with this Yasmerang RNG anywhere near any of this stuff?”

Comparison of Coldcard Versions

26:31 to 28:00

Discuss the differences in entropy improvements across Coldcard versions.

“But that chip, RNG, was not from the chip.”

Exploring the Mark IV Improvements

28:00 to 29:59

The hosts discuss the technical improvements and issues with the Mark IV device compared to its predecessor.

“Like, how the hell does that even happen?”

Challenges with Fund Recovery

30:00 to 31:46

The conversation delves into the difficulties in recovering funds from compromised devices and the communication strategies that might be used.

“But they don't have their data on people.”

Entropy and Key Generation

31:47 to 34:18

The discussion shifts to the importance of entropy in Bitcoin key generation and the potential pitfalls of user-generated entropy.

“I'm not going to dox them, that was at that meetup who had set up a cold card Mark III and done dice rolls, but instead of actually rolling dice, had just pressed random numbers.”

Entropy and Key Generation

40:10 to 40:49

The discussion shifts to the importance of entropy in Bitcoin key generation and the potential pitfalls of user-generated entropy.

“If something happened to me, would my family know what to do?”

Future of Bitcoin Security Practices

40:59 to 42:00

The hosts reflect on the implications of recent security incidents and the need for improved Bitcoin security practices.

“And maybe if you look like if your goal is for like absolute perfect security, maybe they're the right way of doing it.”

Assessing Device Security in Bitcoin

42:00 to 45:20

Understand the implications of device security and randomness in Bitcoin transactions.

“Yeah, so I don't think the security of those other devices, I think everyone's going to be taking a hard look at them.”

The Rise of Multi-Signature Solutions

45:20 to 48:00

Explore the shift towards multi-signature solutions for Bitcoin safety.

“Like, you can't do this to spread Bitcoin.”

Open Source vs. Closed Source in Bitcoin

48:00 to 51:00

Delve into the impact of open-source software on Bitcoin security and audits.

“I think that, listen, it is a black swan sort of thing.”

Simplicity and Security in Bitcoin Custody

51:00 to 54:20

Learn about the balance between simplicity and security in Bitcoin custody solutions.

“It probably also means you should probably centralize more on libraries and things.”

The Aftermath of the ColdCard Incident

54:20 to 56:00

Examine the broader implications of the ColdCard security breach for Bitcoin users.

“Those backups are probably with that device.”

The Coldcard's Impact on Bitcoin Custody

56:00 to 57:11

Learn about the implications of the Coldcard's failure on Bitcoin custody practices.

“And it's with like probably what was perceived as the most sort of hardcore Bitcoin solution.”

Understanding Dark Skippy Attack

57:11 to 59:16

Explore the Dark Skippy attack and its vulnerabilities in signing transactions.

“Years spent stacking on things, and it's gone.”

Risks of Firmware Manipulation

59:16 to 1:02:35

Discuss the risks associated with malicious firmware in hardware wallets.

“trustlessly and make sure everything's correct but if i take your seed signer or call your call and I get the malicious firmware on there, like, that's still a trusted party.”

Introducing FrostSnap Technology

1:02:35 to 1:10:00

Discover how FrostSnap works and its benefits for multi-signature wallets.

“Well, now that, I mean, now the clankers exist, like you can just point it at darkskippy.com and tell it to do it.”

Risks in Self-Custody of Bitcoin

1:10:00 to 1:10:38

Learn about the potential pitfalls of self-custody for Bitcoin and common mistakes people make.

“You got all the money back, you're good.”

Storing Private Keys Safely

1:10:38 to 1:12:02

Discover strategies for securely storing your private keys to avoid theft.

“Although the fuck up fairy may come for you.”

Kidnapping and Bitcoin Ransom Threats

1:12:02 to 1:13:40

Understand the implications of Bitcoin in kidnapping situations and negotiation strategies.

“Even your friend who's in an apartment in a security building, you have to like dial up, you know, to get into the building and go up a lift where you might encounter other people.”

Hostage Negotiation and Insurance

1:13:40 to 1:15:41

Explore the role of insurance in kidnapping scenarios and how to handle negotiations.

“Because in that scenario, you send them all your Bitcoin.”

Preparing for Physical Attacks on Bitcoin Holders

1:15:41 to 1:17:44

Learn how to prepare against physical attacks and home invasions targeting Bitcoin.

“I mean, if we all get on strong multi-sig setups, there'll be no more low-hanging fruit and the attackers will just be like, Oh, we got to go find something else to do.”

Device Compatibility and Future of Bitcoin Security

1:17:44 to 1:18:48

Get insights into the compatibility of Bitcoin security devices with various platforms.

“So with these, this is a bit of a gear shift.”

Security Risks with USB Connections

1:18:48 to 1:22:29

Examine the risks associated with USB connections for Bitcoin devices and coding practices.

“I have no news, but it's the way we're going, surely.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:02The Bitcoiners, these are people all in on Bitcoin. You know, they're people with families. Like, they're saving all their money in Bitcoin and they're doing all the right things. They're self-custodieding it. And then overnight, it's just gone. Like, it is really sad because I look at the chart. I can see when, like, when people are buying Mark 3s with this corrupted firmware, you can see the money starting to go into the insecure wallets. The money keeps going up in the Mark 3s because people are still stacking. They're doing what they've been told, right, to stack sats. and they more than double the amount of Bitcoin in their compromised Mark 3s.

0:34So it's, yeah, that bit is very sad. Years spent stacking on things and it's gone. Like, this has hit a lot of people. Do we know how much Bitcoin is as of right now? 1 ,200-ish people and almost 2 ,000 Bitcoin. Criminals who are focused just on this, their skills are there. They know what they're doing now and they know how to target and they get information and they know how to do it. FrostSnap team, let's go How you doing guys? Very good Danny, good Thanks for having us Here in Sydney I don't know where In fact the first place to start I think is If anyone out there has not heard about this cold card vulnerability somehow Probably time to turn off the show Move your Bitcoin off a cold card I did a video with Rob Hamilton as soon as this dropped I'll put a link in the description Go watch that And do something about it immediately Because we're going to get into the details here But let's start with like, when did you first hear about this?

1:28Lloyd, let's start with you. It was in the morning. It was just before a meeting or whatever. And it was good because I was about to make a point about our feature, you know, feature of Frostnap, which means we don't have to rely on the device entropy. It gets linked in the group chat. And I said, yeah, there's something wrong with the cold card. I thought it was a platform that made some fake cold cards or something and gave them out and really know what it was. And then after the meeting, it was in full swing. It was a complete nightmare. And I was transfixed by it. Yeah, luckily I am almost always on Bitcoin Twitter.

1:57So I think I saw it quite early. And the first thing I thought was like, this is probably FUD. Like I imagined that it was being, you know, over exaggerated. Text Rob Hamilton right away being like, is this real? And he was like, because I had some funds on a Mark IV luckily, but I'd like generate the keys on the device. So it's still vulnerable to a degree. And he was like, move them immediately. Don't mess around. This is not a drill. And I was not with the wallet. So I had to do a phone call, managed to get the Bitcoin moved. But like scary times. And I don't think we've still digested everything that's happened as like a Bitcoin industry yet.

2:33I don't think so at all. I think people are sort of grieving in a bunch of different ways without actually sort of having to have time to soak it all in. But one thing I was surprised at was how quick the response was actually from, you know, some of the big names like Kevin from Liana and I think it was Instagibs from, I think he's a Bitcoin Core developer. I think, I could be wrong there. He, you know, they were onto this right away and sort of raising the alarm, which is quite a risky thing to do as well is you don't want to be the person who raised the alarm and then be wrong and then sort of, you know.

3:04But I think Instagibs found some proof that, you know, once he'd seen what he'd seen, he was like ready to pull the trigger and say that something's really messed up here. Yeah, the thing that sort of surprised me with it is it looks like this was found by an AI model. But this is viewable code. I know it's not fully open source code, but it's viewable code. And I know, Lloyd, people like you actually look through this code. I wasn't. Nick was the one looking through it. Oh, really? But like, why was this overlooked? Or not found earlier? I have my theory about it. And I have to put my own hat on, because I didn't look at the code.

3:39I needed Nick, to be fair. Like, this part of the code, Nick didn't look at me. He did point AIs at it. And why didn't the AIs and the humans? Everyone failed. And not only that, but like all the different things failed, you know, like all the safeguards for this kind of thing wouldn't happen. They had several checks in there to make sure this kind of thing wouldn't happen. Tests of the RNG, all the kind of things that those all failed. And then all the extra randomnesses also failed, basically. And so like there's just failure after failure after failure. So it feels like you're on a different timeline.

4:09Like it's cursed, basically, this kind of outcome. So why, but in reality, like it wasn't just bad luck. There was some contributing factors. So what I think is that the code was actually quite bad. Okay, so not just this problem, but the code around it was actually very bad. And I was surprised because I thought cold card, if you're looking at how this generates randomness, the code will just be pristine. You know what I mean? It's like, I'm going to spend 10 hours doing this. every line of code will be perfect and just make total sense to everyone who's reading it. And then I started looking at it and it's like red flags everywhere, you know, smoke and fire everywhere.

4:50And like, no wonder people have been emailing them about it, doing security disclosures without ever getting actually at the thing that caused the problem. We're just pointing out like, man, what are you doing with this randomness? Okay, you get randomness from here, but then you put this Yasmerang RNG thing, which is now like a famous meme RNG, because it's not a cryptographic RNG. It is just a toy RNG, basically. And it's being used in weird ways. Was this the one that the CTO, Peter, it's Peter, right? Yeah. Is this the one that his other alt pseudonym came up with? It didn't come up with it.

5:29It's been around for a while. Okay. But it's just some random dude on the internet came up with it, right? And it's just a toy RNG. and it was in MicroPython. And so I think, like, Peter Doc Hex was probably working with MicroPython and he wanted an RNG over here and so he just sort of copy-pasted what's over there. Now, MicroPython is not meant for secure applications. It's not something, it's like for toys, basically. It's literally what it's for. And so... As someone who knows nothing about, like, actually coding, why is MicroPython not the right thing to use? Well, you can. You can use it.

6:03you just have to be extremely careful. Like the things that micro, I mean, micro, it's like make your own IOT device kind of thing, I would guess, right? It's like for embedded devices, it's not for secure embedded devices. People would usually write in C or type safe language, right? So Python is a hobby, like it has a reputation as a hobbyist language, right? And MicroPython sort of fits in that vein of being a kind of hobbyist toolkit so you can whip up cool applications really quickly, right? So you'd like the beer dispenser at a Bitcoin conference, it probably could be built with MicroPython with communicating with a Lightning wallet or something.

6:39You could also do a hardware wallet with it. Technically, nothing necessarily goes wrong with it, but you have to be super careful because it creates these layers. It's very easy to make mistakes. It's very easy to forget. Actually, there's still these things called linters, which check that you used variables and stuff that you didn't forget anything, but it's still very easy in Python to introduce logic bugs. I think what we saw in cold card was this layer of... You weren't able to trace the program quite seamlessly through the calling. And one of the reasons was that it wasn't just Python. It was Python stacked on top of C, in my understanding.

7:22And so most of the bug exists in the C code. Okay. Okay, but it's not helping that you're trying to finagle it through different layers, right? So the C code just does things that no cryptographer would do. Like I said, it would be pristine. It would be the most cleanest thing, you know, in your code base is how these seeds go from right from the hardware to the seed words. And instead, it's like these weird loops where you're pulling words out and putting into it, like pulling words out of a chip. It seems like it's using the chip. So that's what everyone looks like. It all looks like it's using the chip, but then it's like randomly mixing with Yassmerang RNG, which why would you do that?

8:05There's a very simple in cryptography. What you're going to do is you're going to take a cryptographically secure pseudorandom number generator. You're going to pull randomness out of that true random number generator, out of the hardware, a lot of it. Compress it down to a seed for that pseudorandom number generator and just pull out. Anytime you need randomness, just pull out of that pseudorandom number generator. Okay? That's what you would do as a cryptographer. And what was Coldcard actually doing? They were going to the chip, they were seeding it at the start, but then they were putting it in Yassmerang RNG, and that is not even an RNG.

8:38That RNG pulls out a single word, so it's like 32 bits, integers, and its state is very small. That's the big problem. So the amount of data you can put into that, like your secret key, right? Because a pseudonym RNG, when it's a cryptographically secure one, it has a secret key. And basically it's like some 32 bytes or something of secret data. And you pull out as many secret values as you want from that thing. And the security definition is that no one can distinguish without knowing the seed, the bits that come out of that from a truly random string of bits. That's the actual security theoretical definition of it, right?

9:16And so this thing doesn't even have a space, like the state of it doesn't even have enough input to be secure. It's like a few bits. I think it's one word or like... 32 bits. I think it might be 32 bits. I think it was 40 bits was the entropy that you were getting on a Mark III, I think. And from the analogy for anyone listening that I heard was, that's like a needle in a very, very, very large haystack. But if it's the proper 256 bits, it's like a needle in a million galaxies. Yeah, it doesn't. Every bit doubles it, right? So you keep doubling. But actually, it was much easier than that. It wasn't even 2 to the 40.

9:52It was just like 2 to the 20-something, really, in the 20s of bits. That's because I thought it was also... I initially posted out. I just got Grok or whatever, just told it, like, you know, let's start posting about whatever the hell was going on here and, like, get the actual bits of security. I thought it's like 2 to the 40-ish. I think Blocked said something similar around the exact same time. And then we found out later, now Kevin and the team at Wizard Sardine has actually gone through and figured out what the actual numbers are this incredible article which sort of restores your faith in bitcoin a bit because it's so people really care about bitcoin it shows you of course yeah uh and i've laid out the thing and it's actually only there's only millions of possibilities or tens hundreds of millions of possibilities of um seed words for all these cold cards and actually when you do the maths uh what they've done is it showed that and it seems to be empirically verified and we've seen found people with it is that some cold card users got the same seed words.

10:50So I saw that on Twitter and I don't like, from what I saw at least, you may have seen something else. I don't know if that was true. D. Hoddle, who to be fair, has done a really good job at sticking around and trying to help people. He has. Yeah. He replied to a tweet that said like, it was a tweet from years and years ago saying like, I got a cold card, generated a seed, and it looked like a collision. but it turned out the guy had just pressed six on his dice rolls a hundred times or however many times I've seen a few false flags as well but then I did see one it seemed more legit which was actually a guy he got a cold card and he already had some money on it and then he already put money on it and he's like alright I'll just put my money on that and then someone took it so um it's so unimaginable right it's like you know in both directions like if you're the person who buys a cold card and puts money on it and it disappears.

11:43And if you do all the right things, like no one is going to believe you, even if you're like, and then people even believe you less. Like if you just bought a cold card and like it already had money in it, that's like even more unbelievable. But that's the thing that sucks the most is like the people that have lost money here are like good Bitcoiners who have done everything right. Like they've been completely rugged by CoinKite in this. And I think that's why it's hit everyone so hard. And I think that's also why we've seen people band together in the way that they have and try and help people out.

12:11I've had a lot of DMs about people who've been caught up in this. The only person I know personally, and I'll only say this because he put out publicly that lost money was Madex. But this has hit a lot of people. Do we know how much Bitcoin is as of right now? I know how many people it is. So I even know how many. It's around 1 ,200-ish people. How do you know that? Because I ran the attack just last night. So I finally got my clankers to finally just run it all. Like, put it all together, check, go through, find all the possible seed phrases, go and check if the first address or whatever has ever been used, output the public keys from the net so I can find them all.

12:52And so, yeah, it's about 1 ,200-ish people. And almost 2 ,000 Bitcoin. Damn. Is that 1 ,000 people, 1 ,200 people that have actually had fun sweat or that could have fun sweat? That's wallets. No, that's wallets that got hosed, yeah. I mean, some of them got it away. This is like the total affected Mark III. That ever had a balance. That had a balance at that moment. Okay. It's more, it's more, it's like more than 2000. It's more people. If you go back to the peak Mark III and it's like more, it's like 2 ,400 Bitcoin was stored on these devices insecurely. So it's got, it went down to like 1 ,900 by the time of the attack.

13:32Cause people are moving on to new, newer devices, generating new seeds. So that's roughly the numbers we're talking about here. It's like a thousand-ish people. How many people actually got robbed? I'm in the middle of figuring that out. I think I have a good heuristic on it. Do you know roughly, like, can you say roughly what you think it is? I told my clan to start figuring out that number just before this. Let's see if it's done its job. I'll have a look. So you actually ran the exact attack that the attacker will have done? Yeah, I can, I mean, the initial attacker was, they all did different.

14:07There's a few, I think there's four attackers. That's what I think. It looks, they leave quite like obvious fingerprints on chain, like in the behavior of, you know, do they all sweep all these wallets at once? Do they use, you know, a fixed 30 sat per byte fee rate? And so it's kind of, you can kind of distinguish, oh, that's like not the same person as, you know, that other attack that we saw. If you hold Bitcoin long enough, there's going to come a time when you need some dollars. It might be a tax bill, a business expense, life getting in the way, but whatever it is, it might come at a time when you don't want to sell your Bitcoin.

14:40That's where Ledin comes in. Ledin lets you borrow against your Bitcoin instead, with tiered rates that go as low as 9.25%. So you don't have to sell your stack if you don't want to. Ledin have operated through every market cycle since 2018 and have originated over$11 billion in loans. But the important part for me is the way Ledin handles these loans. Your collateral is held in custody and never lent out to generate interest. And Ledin's more than just loans. Tether Gold is now live alongside your Bitcoin with instant trading across 10 pairs. And later this year, you'll be able to borrow against gold in the same way that you do with Bitcoin.

15:13Ledin really is an awesome company. I've used them multiple times. The applications have taken me less than 15 minutes and you have the dollars in your account within hours. If you want to check out Ledin, go to ledn.io and use the code WBD for 0.25 % off your first loan. that's leaden.io and use the code wbd if you own a bitcoin etf especially if it's gbtc you need to listen up spot bitcoin etfs provide price exposure to bitcoin not direct ownership you can't withdraw it you can't self-custody it and they charge you a management fee every year to hold it well swan recently announced swan real bitcoin exchange and it's ready to use right now rbx is a structured in-kind exchange that converts your spot bitcoin etf shares into real on-chain bitcoin it does that without selling on the open market and it's designed to support a tax efficient outcome.

16:00So for example, if you hold GBTC, you're paying 1.5 % a year in management fees for Bitcoin price exposure. But by swapping GBTC for real Bitcoin with RBX, you can drop that figure as low as 0 % by just holding it in self-custody. This is designed in a way that maintains your cost basis and in a manner that supports the deferral of capital gains tax. So if you own a Bitcoin ETF, especially if it's GBTC, you need to talk to Swan Private about RBX today. Head over to swan.com forward slash WBD and book in a call with one of their team. That's swan.com forward slash WBD. You wouldn't reuse a Bitcoin address, so why does your phone broadcast the same identifier for life?

16:40Every SIM has a static ID and carriers, ad networks and bad actors all use it to track you. The big carriers have been caught selling that data over and over again. Cape is America's privacy first mobile carrier. Their identifier rotation feature changes your ID every 24 hours so you look like a different subscriber every single day. And sim swaps are off the table. Your number can't move without a 24-word phrase that only you hold. There's also no name at sign up, no social security number, and there's no profile to build on you. If you're a Bitcoiner in America, I honestly don't know why you'd use any other network.

17:13You can head over to cape.co forward slash WBD and use the code WBD for 33 % off your first six months. that's c-a-p-e dot co forward slash w-b-d so I know the first attacker was basically moving everything into one like pooled wallet yeah and none of those bitcoin moved so he was he got the vast majority right I think he was over a thousand bitcoin I believe so yeah is the rumor that they think he used some sort of like paid on-chain heuristic website that was KYC is that true do you know oh I've not heard that rumor I've heard the rumor maybe could be It'd be good to figure that out. I guess it doesn't necessarily mean it's the correct KYC information.

17:53Like a blockchain, like, you know, data provider. Yeah, exactly. Yeah. But I mean, he could also just... You really didn't need to. That's what I can tell you. You don't need to do any of that stuff. Especially if it's Bitcoin, you can run your own node. The guy probably didn't... The guy probably... Yeah, he probably wasn't a big investor to run his own node. You know what I mean? Why would he invest that? And also, you're in the time limits. Like, I've made it. You know, I can buy a small island now or whatever. So let me just take what I've got. uh yeah he he took about half of it that's what i see so he's like there's around 2000 there and he took about a thousand yeah on the first and just in like a few blocks well then it's gone and then actually nothing happened for like you know uh 16 hours or something and then uh kevin posted and then nothing still had nothing happened actually people didn't start moving their funds right away it was only when coin kite actually as soon as coin kite put out their advisory thing it all just started happening it's just like yeah that's what that's what the chart shows like i don't know if the time is coincidental or whatever but or like people are getting it was a it was they admitted it at 6 50 uh new york time you mean people are getting home from work or whatever it's all happening at that moment and then like really start things start moving and then like another attacker hits them and then 12 hours later another attack hits them so it's The attackers came in small bursts, actually.

19:16I think there were four of them. Interesting. And so tell me how hard it is to run this attack. Are you assuming you did this with Kimmy K3? No, actually, I did it with Claude. I am in the security, whatever, cyber security program. Maybe not for long. But I did, like, I put safeguards in that I never get the seed words. I only ever get, only outputs me the public descriptors. And so it was willing to go along with that. And Codex went along with it as well. Did any of them still have money in it? Yeah, but like James OB has been like, putting test ones. Yeah. I think no one's going. There's no money there.

19:55So there's no point. There's still this tiny amounts of money. We could probably pay for dinner tonight if we took it all right now. Let's not do that. But tell me how hard it is to actually run this attack. Especially for someone like me who I can't do any coding. Like, could I still have done this? Yeah, you could have. It does look like it was someone who ran Kimi. I do think it was Kimi, so I do not think it was an insider attack. I think it was someone who said, let's just throw it at these hardware wallets and had the gall to go at the cold card, the great most secure hardware wallet of all time, and say, go look at the entropy.

20:30They must have, because they would have, usually you would clone the latest version, right? So in the latest version, it's not as bad, but they probably would have found the problem and said, okay, so how bad is the problem across all these different versions? And then you would have found the Mark III is complete catastrophe. And then you say like, let's write something to find these things and spend them. And the code was, I mean, it got half of it. You could have got too much more. And I think they made mistakes. Like, I think, I believe one of the issues was that it was going through the potential private keys and if there was a gap, it was then stopping.

21:08Yeah. Yeah. But, like, if it was me doing this, I put Kimmy on the case. Could I have spun something up in, like, a few hours and exposed this vulnerability? I don't think so. Lloyd, you're doing a lot of research into, like, asking, like, models prior to Kimmy, whether those models, like, the ones when I was looking for this kind of bug, whether those models at that time could have found it. And you sort of came to a conclusion that not really. Not really, yeah. with Opus and these other models. They were not. Not at the time you were looking, but the time that the attacker was looking, yes. Yes, the new ones.

21:47So, yes. So, I think, I don't know how, like the thing is, you probably want to use the GPU. Okay? You can, but you can, if your laptop has like the special instruction for SHA-512, which is the real time-consuming thing, it needs to be done over the password derivation thing in BIP39, It has like this password derivation algorithm. I think you can do it. I was looking at how long it would take my laptop and it would take the whole day or something. No, it would take a half a year. And my original estimates are two to the 40. But now it's two to the 20, that's a million times easier. So I don't think it would take very long at all, actually.

22:27Now I think about it. So if you're using, yeah, you would be able to do it in a very little time, sweep the space. And that wouldn't get you everything because there's also how many times people click buttons. There's all kinds of little finesse things you have to do. But it's got the real low-hanging fruit. Yeah. And to get the low-hanging fruit, it was like 1 ,000 Bitcoin. Yeah, you can do it on your laptop. Crazy. It's crazy that this was just looked over for so long. This was out in a while for five years. It's nuts. It's absolutely nuts. Yes. And that is a reason. That is a real fault. Whatever you say, that is a fault on behalf of CoinKai because I think it could have been.

23:01I think people, there was so much smoke around it, including people getting the wallet of someone else. It seems to be. Maybe those were all like, you know, people. I mean, still, listen, if you've got a feature that people like get rugged on it, like don't have that feature or like do it. Like, cause you could put in one dice roll, right? So people are coming like, I lost my money. And there's, oh, it's just another, you know, he's coming, comes in and says, oh, I lost all my money. It's like, oh, it's just another guy who put in one dice roll. Yeah. Cause we let, but if you - And I think that gets to like, and many people have said this since, but I think that gets to the sort of arrogance of CoinKite.

23:34that they were widely regarded, I think, as the best Harlow wallet before this happened. And I think they had believed their own hype with that. And maybe they felt they were too, you know, this couldn't happen to them. It must be. Yeah, I think, and maybe a distraction on like all the, you know, away from the fundamentals of what's most important and onto some of the more fancy features. Yeah. You know, that distraction and takes away the time from really like making sure the really... Which is insane. when all you really need from it is three things. You need it to generate good entropy, sign transactions, and store your private key.

24:09That's really all you need to do. And it failed at the most key fundamental one of those three things. Though it is true, if you're a developer, you put in the safeguards, you believe that was correct. You're not going to randomly revisit it. Except when people complain they lost their money. That's when you should be revisiting. And people are sending you things about Yasmerang RNG in your security disclosure and saying, what are you doing with this Yasmerang RNG anywhere near any of this stuff? Like that should have been, let's say you take another look at this. But should they not have been having audits on that code?

24:40Like especially the key parts of the code every like six months or something. I don't know. I don't know how this works. It's a new question. Audits are an interesting one. We probably have a lot to... In retrospect. If I was like, because yeah, but people in the community did order it. Like James OB audited it. And he says like, you can bet that Ledger Donjon, like I bet they looked, you know, through that code, like maybe not through that exact code, but you know, they would have looked through the hardware TRNG, surely. You would have thought so. Maybe you would have thought so, but it is very easy to get fixated on a certain thing, because I had the cold card firmware, and I was planning to do a little attack on it.

25:16I was planning to do dark skippy on the cold card, because we'd done it first on… For education purposes. Yes, of course. Yeah, and I was going to tell NVK about it and all that stuff, you know, to tell him it's coming, to demonstrate for educational purposes, to show that it doesn't matter how many secure elements you have on the thing. If it's got malicious firmware on the main chip, it doesn't matter what the secure elements do. Because when we did it on the seed signer, what we found is people like, oh yeah, luckily I use secure elements. Nothing to do with that, actually. And so I had the firmware there and I was fixated on how to deploy my malicious firmware onto the cold card, which I managed to do thanks to the charlatan, a Bitcoin Core developer, who also pointed out problems in cold card security.

Read the full transcript

25:59not this problem, but other problems, and was dismissed. And he pointed out this one. And I thought, oh, I can use that to do Dark Skippy. So I was like, I had the code there and, you know, whatever. And I didn't look at anything to do with RNGs. Of course I did. Because I was too, I was, of course, that's not going to, that's going to be correct, right? I also don't want to look at a bunch of Python either. And see, and then how it all links together. It's like, and people looked at it and they didn't catch the most basic thing. Like all this mess of pseudorandomness was a mess. And it was bad.

26:28and it should not have been in the cold card itself. But that chip, RNG, was not from the chip. That was the whole real, you know. It was bypassing the actual chip, the RNG. It was not even used. It was all a circle jerk of cryptography, like all these different operations done on no randomness at all, just going round and round of nothing, right? So no one expected that. I mean, it's so hard to think that that would be real if you were a reviewer, right? Yeah. Yeah, I mean, for someone like me, I just assumed that like randomness on the cold car would be elite. Like that's just... So I do want to come back to the dark skippy thing.

27:03But before we do, on the Mark 4s, 5s and Qs, there was better entropy, but not great entropy. Yeah. I've not seen any reliable source that any of those have been cracked yet. Do you know where that's at? Yeah. I think that Kevin's analysis here is good. So, I mean, not Kevin, Wiz and Sardine, because he has a whole team there and they're really good. and their analysis shows that actually it's really hard to do the Mark IV. I was initially, that's what I thought. But then I started seeing that the people were saying that the timer, they also add entropy from the timer. And I started seeing that that wasn't done at all correctly.

27:37And in fact, on the Mark III, there is nothing from the timer. Actually, the timer value get read in, but it's basically irrelevant because one of the timers was not set up. So on the Mark IV, it was set up. and so you get some entry from the timer. And so that plus the actual, and this is a massive red flag, how do you improve it in the Mark IV and not just totally fix it? Like, how the hell does that even happen? Say it again. How do they improve the Mark IV without fixing it? You know what I mean? How do you just get 132 bits in there instead of fixing the whole thing? It's slightly better.

28:12How do you make it slightly better? Is that easily explained in the sense that, I think, is it right that the Mark IV had an extra secure element? Does that do something? It was from, so the randomness from secure elements is not used in the Mark III in this pathway. The randomness from the secure elements was used in the Mark IV. Yeah. In this, but once again, for some reason, this randomness is taken from it and passed through this thing called Yasmerang RNG, which doesn't allow much data into it because it's not a cryptographic segura. And so you only got 32 bits in there, which is like, what the heck?

28:44And so that's why you got 32 bits. it reseeded from these secure elements, but they have much more randomness than that in them. And you just pull out like this tiny, a little bit, and then it improves it. But it actually, in the end, like it is much harder to do the Mark IVs. You can do it though. And presumably those will happen. Like there's plenty of compute out there in the world right now. Yeah, if it keeps going, like you would think... I guess maybe everyone's moving their funds quicker. I think that's the thing. Because there are people moving it too fast. Maybe if someone's lost their pin and they didn't write down their passphrase, like something will be there for a while.

29:19In 10 years, when GPUs are just falling out of our ears, we'll be able to find those funds. But it's not economical. I thought it was, because only the Mark III is economic to all attack. I don't believe the Mark IVs are actually profitable to attack right now. Unless Sailor's putting all his money on one of them and then it changes the average. I don't think he is. One of the things that's so messed up about this situation is even if they'd have found the vulnerability or someone else in the community had, there was really nothing they could do. Like, they would have had to put out a blog post, I imagine.

29:50I can't think of another way around it saying, these are not secure, you need to move your funds. And then it's basically a race against an attacker then. To find it, yeah. I think you have to just literally call up every single person that you know. But they don't have their data on people. I mean, it turns out they managed to keep emails. Every Bitcoiner knows another Bitcoiner and you just do word of mouth it. Yeah, you word of mouth it for a while and don't tell anyone shady about it. That's the only way. I was originally thinking, and other people were thinking, that because there was this weird thing with the serial number from the individual device got mixed into the randomness, that when you recover, you can sort of see part of the serial number, but you actually can't.

30:29So that was an initial thing that many of us thought we could keep these serial numbers and then you could actually get people to make a video. Like, I've got this cold card and show the serial number and you could actually give it back to them. Prove that you owned that. Yeah, but in the end - So that's why people are telling people not to actually destroy them. Yeah, that's the reason why. It doesn't really work. Kevin has convinced me that this was crap. His article destroys the idea. So you can burn the cold cards. There were lots of duplicates, right? Lots of cold cards have the same damn thing, the same damn number.

30:56I mean, that's a red flag on his own. I don't understand. It's called a serial number. Why is it? It's not serial. Serial means one after the other. Anyway. It's such a mess. And one of the things, I was at the Bitcoin meetup in Brisbane last week. and obviously entropy was the topic of the day and we're talking about it. And before this attack, I would imagine the vast majority of at least like, I guess, part-time Bitcoin. People who just store their money in Bitcoin, they don't care about it, they're not listening to every Bitcoin podcast, probably never even heard of entropy when it comes to like generating a private key.

31:28And everyone at that meetup was convinced that everyone rolling dice is the only way forward. And I just can't accept that. Like, I think it's great. I think people should be able to generate their own entropy. I would never want to take that away from people. But you also can't expect this to scale to millions and millions and millions of people if everyone's doing 100 dice rolls. And I think there's also the problem that I know there was at least one person, I'm not going to dox them, that was at that meetup who had set up a cold card Mark III and done dice rolls, but instead of actually rolling dice, had just pressed random numbers.

31:57And so people are going to accidentally generate less secure private keys if they don't do this properly. And so I don't know how we're meant to address this as Bitcoiners now, where it's like, generating your own entropy is great. People should be able to do it. But we also need to accept that that's not going to be the case. Like, how good are actual proper random number generators on the Trezors, the Ledges, the BitKey, like all the other hardware wallets that are out there right now? I'd say they're fantastic. Actually, one of the things humans are good at is actually making these high-precision microcontrollers and these instrumentations.

32:29You know, we're not good at politics, economics, or any of these other things right now. We can damn cut a little silicon thing and make these little microelectronics. So the randomness is good. You have to read the manual a bit on them still. But yeah, you can, I don't want to say you can trust them, they function with overwhelming probability in your particular device. Now, does that mean what people are thinking is like, they're right. Why would I just trust? Like I've just got this device, right? I've taken my funds off the exchange. So because I don't want to have a trusted third party have custody of my money and then i put on this device but then what's to stop those seed words i get from that device like living in an excel spreadsheet on some guy's computer like how do i fundamentally know that that's not the case and the point is you do not and that they're so hardware wallets are trusted third parties unless you're dice rolling oh well yeah i mean that's that's there's the nuance right and if they're doing it properly which is the yeah this is one the things we're very concerned about is that um because of the sort of uh how this one bug manifested the sort of the lesson that most people have learned is that if you add your own entropy then you're good if you if you roll dice you're good or add passphrase you're good yeah um but like it could have very well been the case that this there could have been you know a very similar bug that it just so happens that if you add dice rolls maybe that you know sets your entropy to just being like, you know, maybe a few dice rolls or something.

34:03It could have made it worse, right? Rolling dice could have made it worse. Some people suspect that Doc Hex was doing a malicious rug pull, right? I do not think so. Mainly because of how, if I was to do that, you know, I wouldn't make the code so bad around the RNG. It's like, it's a weird strategy to like draw all this attention to how terrible that thing is, just so they sort of notice the main, don't notice the main problem, right? And I think I've met the guy also, and it's like had a little conversation. It doesn't seem like it at the time. I found that whole theory hard to believe, although I'm not at the point where I'm willing to write anything off.

34:38Yeah, we should be sort of paranoid. Like, what if a psycho... This is one guy, right? He could have been a more psychopathic version of himself, right? And done this. And so all the dice rolling and all the thingies doesn't actually do anything in that situation, right? Choosing your own seed words and giving them to the device, how do you know then that the public keys and the addresses are actually from those seed words? Yep. Right? It's more steps. And like you said, like Bitcoin spreads mimetically, right? We give it to our friends. We see people we respect and they like Bitcoin and we want to be like them.

35:15And if you start saying now, this person I respect like breaks the illusion and say, now get out your dice and we start doing all this wacky stuff. And we need a second device to verify the dice. It ruins the process of spreading Bitcoin. So you cannot actually be doing this. so in our product we really thought about this we had to think about a lot of things from the ground up because we used totally new cryptography and one of the things we said is like listen we're not going to trust the device to generate randomness it does generate randomness it does have a TRNG on it it does get the randomness but it's not the only randomness that goes into the public key every other architecture is just let's just take what that device says and we say, okay, and there's the addresses and we just take what the device says.

35:59We don't take what the device says. The device says, here's my public key that I want to use sort of thing. We say, okay, that's a cool story and we're going to use it. We're going to randomize that before it goes on the chain, right? That's the phone or like the app, right? It is doing that. So that was our solution and it was very comfortable for us in this situation because we did, I did have a panic. I'm like, how deeply did I look at the TRNG actually? Because I just trusted the manufacturer, you know, the APIs that they gave us and like what how does it actually work and i did some analysis and turns out we're okay not totally not it's a little bit less than i thought it was actually but with still way more than you need from the uh the trng but i was not panicking while investigating because i know it was never it was never a single point of failure it was never exactly so we we when you plug your devices into your phone the phone is also mixing in randomness verifiably to that public key in it The device cannot escape it.

36:54And so that's one other solution. But the thing is, that solution is only our product, and it's sort of a niche thing. It's very different. We're in a position where we're rethinking everything, and we're having a lot of fun doing that. Not everyone is in a position where they want to go and join the next revolution, right? And so the problem is taking something like this is BIP39, those seed words, the actual specification for those makes it very difficult for you to mix in randomness from multiple different sources. Verifiably. So it's like one device produces that seed words thing, and no one can really get in the way of that and inspect it.

37:33Because otherwise they'll know the secret, right? So when we mix... So there's no way of actually proving your randomness. Yeah. It's like, here's... I mean, you can get the randomness yourself and say, here's the seed words, right? You can do that. You can choose your own seed words. But that doesn't mean that the XPUB you give is those seed words either, right? So this is the difficulty thing. When you have a malicious device, it can say, here's the public key, let's receive money to it. And you can say, no, I'm going to mix into something that public key is the public key is actually algebraic.

38:01You can add public keys together. You cannot add BIP39 entropies together sort of thing. That's the issue. And so what people will suggest is either like, yeah, you have to verify to multiple devices. You take the same seed words, you look at the XPUBs and multiple devices. Okay, that will work. You have to expose your seeds to multiple devices then, but if you're very careful about it, and it's a one-time thing, it can be done. I think the people who say just get a Linux laptop and forget about hardware wallets are not totally wrong in this kind of situation, right? Do you want to pay less in taxes and stack more Bitcoin?

38:35Of course you do. Well, by mining Bitcoin with Blockware, you can. Under section 168k of the US tax code, Bitcoin mining servers qualify for 100 % bonus depreciation. This means every dollar you spend on miners can directly offset your income in a single year. And it's true for both business owners and W2 earners. So if you have$100 ,000 in ordinary income, you can purchase$100 ,000 in miners and potentially offset your tax liability entirely. Blockware's mining as a service does all the heavy lifting. They secure the rigs, they source the low-cost power, and they handle all the day-to-day maintenance.

39:06So you get to stack Bitcoin every single day while drastically shrinking your tax bill. Get started today at blockwaresolutions.com forward slash WBD and use code WBD for$100 off your first miner. That's blockwaresolutions.com forward slash WBD. If you're already self-custody Bitcoin, you know the deal with hardware wallets. Complex setups, clumsy interfaces, and a seed phrase that can be lost, stolen, or forgotten. BitKey fixes that. BitKey is self-custody built for real life. It gives you an intuitive, easy-to-use wallet with no seed phrase to sweat over. and it has a strong recovery system and built-in inheritance for long-term peace of mind.

39:42And BitKey's just had a massive upgrade. The new device now has a screen, so before you approve something, you can check it on the BitKey itself. The transaction, the address, or any account changes. It's a big difference. You're not just trusting what's on your phone, you're seeing it for yourself on the device. It's simple, secure self-custody without the stress. Go to bitkey.world today and use the code WBD to get 10 % off the new BitKey. That's bitkey.world and use the code WBD Every Bitcoiner eventually has to answer one question If something happened to me, would my family know what to do?

40:13Could my wife or parents recover my Bitcoin? And would my children inherit the Bitcoin that I spent years stacking? That's where AnchorWatch builds Bitcoin custody models to protect you and your family against real life accidents, errors, kidnappings, and even your own death Every AnchorWatch custody solution includes their inheritance protocol designed so when the unthinkable happens your bitcoin reaches the people you intended it for whether you're a self-custody expert or want multi-institutional support your bitcoin estate plan shouldn't be an afterthought bitcoin is only generational wealth if it can actually be passed down through the generations so make sure they can access in the future what you've built today anchor watch is your custody your way visit anchorwatch.com to get started that's anchorwatch.com It's hard though, because I do understand those approaches.

41:00And maybe if you look like if your goal is for like absolute perfect security, maybe they're the right way of doing it. But you also have to think about everyone in this, like every Bitcoiner, and not everyone's going to do these things. So like, obviously, there'll be going to be people freaked out about everything that's happened over the last few weeks. In terms of the other major hardware wallets, do you think there's any sort of huge red flags with any of them? Cool. Well, we've been focused on ourselves. We've not been focused on other people. I don't think this is a once in a lifetime one.

41:31Where the actual entry, the thing on chain, all the addresses on chain can just be discovered from a guy's laptop in his jack-off chair. That's like totally, it's totally unbelievable that this happened. It's like, I still don't almost believe that it happened. So this will not happen again, ever. Except we already had this happen in Bitcoin, LibBitcoin. They actually did this on purpose, but that was another. That's another rabbit hole. They said the TRNGs are not good enough, so we're not going to use them at all. And so people generated wallets that were totally not random at all. And so, yeah.

42:05Yeah, so I don't think the security of those other devices, I think everyone's going to be taking a hard look at them. I think that the key point that I would make at this point is like, are we going to just fix this one outlier or just treat it as like a black swan event? We're going to say, yeah, actually, we should not just get this device in the mail and put our life savings on some words it gave out. You know what I mean? But we also should not roll dice and do all sorts of wacky stuff. You know, we should just like say, hey, you cryptography, like mixing randomness is actually one of the oldest problems in cryptography.

42:38There's this old, very old paper called Coin Flipping by Telephone by Manuel Blum. It's like in the 1970s. It's like explaining how you can have a phone conversation and flip a random coin. Like collaboratively. Yeah, collaboratively. without and both of you agree that the coin is random at the end right so you and so there's a trick there's a trick today it's going to commitment schemes use hash functions things like that um it's very much a solved problem okay but we don't do it in bitcoin we just don't do it in bitcoin so there's two things like you're gonna do all this dice rolling and interrogation of the device right it's like i'm gonna interrogate this thing uh so much make it air gapped and all this stuff.

43:18But the other thing is, I'm just gonna get multiple devices, right? So even if I don't really need multi-sig, I'm just gonna get do multi-vendor multi-sig. And so now, I don't have to interrogate each device as much because one of the devices or at least two, the majority of the devices will be okay. And these are two solutions, right? I think they are solutions. If I were to choose either one of them, if I really didn't have a reason to use single, you know, multi-sig, like multi-sig i think is very important that's my whole company does that right we could we do it because we shouldn't have your money in your house not for randomness randomness is actually a very easy one to do so i would if i was like an everyday person i would actually consider doing the cutting out of the seed words getting into getting a laptop yeah pulling them out of a hat getting a laptop checking the xpub is correct taking like some other device and putting it on there checking they have the same addresses clearing it off the laptop and that's sort of like but it's obviously unacceptable like it kind of you cannot spread bitcoin that way yeah and the other thing we haven't even mentioned is like if you really want to have this system work where you don't trust the device to generate randomness you have to do this dice if you really want to do it properly you have to do this dice rolling every time you sign a transaction because the device also gets to choose a random number um as a nonce It's like a one-time throwaway random number.

44:41And it's in this nonce that if it's weak or malicious, it can leak your seed phrase. And so people don't actually dice roll to generate these nonces. If they really want to do it properly, they check what's called deterministic nonces, that with the same private key and the same message, the transaction signatures will be the same. So they essentially, they get the transaction on two different devices, sign the same thing, and then compare the transaction signatures and check that, oh, actually, these devices are being honest, which is just crazy again. Like, you can't do this to spread Bitcoin.

45:22Totally. It might be the perfect solution if you're only worried about security. But if you're expecting 100 dice rolls to generate your seed and then 100 dice rolls every transaction, the vast majority of people are never, ever going to do that. And the thing that I'm nervous about is like, this has been a real hit to single SIG. And I really like the simplicity of a single SIG wallet. And I know, obviously, if you generate your own entropy, then it doesn't really affect it anyway. But I do think the sort of just social blowback of this is going to be, everyone's going to move to multi-SIG, collaborative custody, which are great.

45:56And people should use those if they're storing their life savings in Bitcoin. But the simplicity of single SIG is awesome. I don't want to see it go away. Sovereignty of it. I agree. So I used to be a single SIG person, but then I realized that my entire life is saying it's my house. At some point, it gets a bit scary. At some point, you're like, my children are here and all my money is just over there or something. And it's like... Traveling. It's too much. But yeah, if you're a digital nomad or whatever and you reckon you can do it, you're in a safe environment. There's something very simple about this USB device or whatever that has a PIN number and it's just all my money is there.

46:33and no one can get it without physically getting to me. I think it is right for some people. And yes, we have to somehow make it work. It's just not what our company does, but I'm hoping that maybe we can try and do it. I don't know. But I think that like, listen, like I said, whenever someone, I always said, listen, our device, we don't let them generate their own randomness, even using one device, right? Our devices do not generate their own randomness by themselves, they mix it in. And you can use a single FrostSnap device and it will work. It just doesn't have a pin number. It's designed for geographic distribution, right?

47:11And I always said, listen, I mean, this is what we say and this is important. We think this is really important. This means we don't have to worry about our TRNGs being broken or any of that stuff because we know that your phone is also mixing in there. So it's very unlikely attacker can control your phone and everything else is broken, right? It's a really hard gate to get through as Claude always says. But all these companies are fine. You know, like luckily we have some great companies in Bitcoin and you can pretty much just trust them to generate the thing for you. It irritates me that we do that because we have so many easy ways to do that in cryptography.

47:41We don't have to do it. But you can just let them do it. And now I gave this advice to so many people when they're asking me about our product and how important this fact is. And now I look at it, it's like obviously a crucial fact. The last now feels like bare minimum. It feels like a bare minimum. Like why would you not be doing this? So that's where I'm at with that. I think that, listen, it is a black swan sort of thing. All these other devices are probably okay. And I think the silver lining of this, it'd be easy to hear this conversation and be totally freaked out about the state of self-custody.

48:12But the silver lining is it's going to get much better on the back of this, I think. There's going to be more eyes on code. Maybe this wasn't an issue for any of the other companies, but it's only going to make it stronger, I think. Yeah, the open source is important. Because now open source... The longer it's been alive, the harder that thing is to kill. Before, now ColdCard existed in this state of terrible code for a while, and now it cannot, it's just killed one of them, right? And so the longer these companies stay alive and keep their code open source, the more surety you have in each of their products.

48:48Is that a double-edged sword? I think there's an interesting thing, actually, that also, like, it's not so much that it's the length of time that it's sort of, you know, withstood, you know, survived for, but you know we saw this new model gets released and then all of a sudden overnight it's it's no longer secure um it's very interesting for us because we haven't had these paid audits done but we've had a you know an equivalent level audit done to cold card with kimmy k3 now and these other um the audits are just out in the open now yeah which is interesting and you know i don't think it uh says that there's no value in human audits i think you know having a good human auditor that guide that LLM audit would be probably optimal.

49:31But it's very interesting. Yeah, it is. And it's like, it's the open source thing. Can that be a double-edged sword? Because if your source code is closed source, then the LLMs can't pass through in the same way and they can't necessarily find those vulnerabilities. Yeah, I mean, though, I think we all agree that the level of trust you put in a closed source thing is like, it's a bit the rug pull could be at any moment like i said like if doc x or whatever he's malicious and he's working at ledger or whatever like it's not really acceptable it doesn't solve the problem but does it make it harder to exploit the vulnerability yes i think so yeah yeah it does it does make it a bit harder because you're gonna unless you can get you have to dump because at some point you can be maybe a dump like the firmware or something you know that's on a ledger because you have the firmware updates and all that stuff like i don't know that would be interesting right because some people are taking it and going to the machine code and decompiling things right taking old you know playstation games they always loved and like decompiling putting new things in it because the lms are so good at that and what i wonder i wonder if ledger that would be a technical question can ledger does it ledger fully encrypt their firmware because i mean is maybe like compiled binaries that you can't see the source code of is the same as or open source in the end.

50:52So that's the question. But you think open source is still the way to be doing all of this? Yes, I think so. I think that the Darwinian selection process now is probably the right one. It probably also means you should probably centralize more on libraries and things. One of the interesting things about multi-vendor, multi-sig and people saying, yeah, you know, but the thing is, do you really want everyone to be using a different software stack and like bugs over here, bugs over there? So it would be like, everyone agrees. I think everyone agrees that libsec P266k1 is really good and that everyone should be using that.

51:26In fact, moving over to that was part of what Coldcard was doing when they messed everything up. And that was, so if we agree that like well-audited single libraries are good, then probably people should just use those, right? So having all these different implementations and different, you know, things is maybe not so good. I think the seed sign of people are not totally wrong, right? in creating like a sort of a standard thing that you can create yourself. It's all open source. I don't agree with the fact that you can just swap out an SD card and steal everyone's money with, you know, with Dark Skippy, but, you know, you can see the idea there, right?

52:06The idea is correct. It just so happens that unfortunately, due to the way, you know, signatures work and stuff like that, you're trusting that device. So I think that probably more of that, I think standardization on how the hardware should be more open hardware and more that those kind of things is probably the way things are going and to be fair like the companies in the space are pretty good with that stuff that's open source hardware you can some people can you can create your own jades i think you can create your own treasures as well if you really want to and so you have companies that let you just create their thing but it's pretty difficult so you can probably just buy it from them it's sort of the business model and it's probably not like a huge business also like we're in the business and we don't never thought really it was going to be an amazing business because the number of UTX owners is not going to grow incredibly.

52:512x, 3x, 5x or something. Maybe even 10x, but that's not exponential growth. No one's looking at that saying, I need to invest in that. So probably consolidates and gets a bit more boring around more homogenous software packages and things that are more well audited. I want my hardware wants to be boring. That's everything I need. I did a show with the C-Signer guy maybe, I don't know, over a year ago probably. That has aged like fine wine. One of the things he was calling out was RNG on things like cold card. And it wasn't because he had inside knowledge on it or anything. He was just saying, these are the problems you have.

53:26And seed signer has always been one that I've... I've never really used a seed signer. I've played around with a seed signer. The thing I don't like is having to have my private key always there to actually sign a transaction. But I don't know, this makes me rethink a lot of things. Yeah, I mean, I think a lot of people forget though when they analyze it, like, I want my PIN number. And then they have the piece of words there without any pin. Yeah, yeah. And then, or they put a passphrase on the words then because they're thinking about it and then they lose the passphrase and they lose all their money.

53:54Back it up. It's just like, oh, this, the trade, I think you really, like, Simplicity and boring sounds great. Yeah, with FrostNet, we go, we'd really take it to the most boring extent. Our devices do not even have pin numbers. Your only way of getting security is to put them in different locations. So it's multi-sig pretty much only. And there's no pin numbers. There's no passphrase on the thing. There's no descriptor backups either. so that's most multi-sig solutions you actually have to back up some funny digital file and if you don't have that you lose all your money we don't have that so you just need two out of the three backups or whatever threshold and number you choose and you'll get all the money back and it's all super boring it's very like it is a risk the user has a serious job to do right to make sure their devices and those backups are not obtained by anyone else it usually is a job you have to do anyway but it is a serious job There is no pin numbers in those devices.

54:45Those backups are probably with that device. But for me, once you do that job, it's like really comfy. Because there's nothing I need to remember. I know my wife can get them because there's nothing she needs to remember. She just knows… She has to figure out where… Locations or people. She knows the people who have them. She knows how to contact them. Anything should happen to me. There's nothing really that can go wrong in this kind of setup. It's really… I struggle to think about the things that can go wrong. wrong right that's the the thing the main thing to go wrong is that someone you know goes around and finds them right and so it's really just my job to make sure that how well dispersed they are exactly that's i have one job maybe back on the community like the ecosystem damage for a minute i think it's i you know i've seen some people compare it to say they're comparing like the magnitude of the theft they're saying oh you know it's only a thousand bitcoin look at mount gox or look at ftx yeah i think you know these are completely different populations of people like the FDX people, you know, it's like people in their 20s, like degenerate long, like, you know, gambling shit.

55:48You know, they go from 1K to like 100K and then they lose it, okay. The Bitcoiners, these are people all in on Bitcoin. You know, they're people with families. Like they're saving all their money in Bitcoin and they're doing all the right things. They're self-custodieding it. And then overnight, it's just gone. And it's with like probably what was perceived as the most sort of hardcore Bitcoin solution. Like this was the gold standard. and that being rugged I think is going to have ramifications for quite a long time and I just the thing that I'm really nervous about is this is going to push people to use custodians which it will already have done there's certainly been people that have moved Bitcoin off cold cards to you know a river, a swan, a coinbase whoever and even if those companies are like reasonable solutions it's not what we want Bitcoin to be and that's the problem on that point like it is really sad because i look at the chart because i can see when like when people are buying mark threes with this corrupted form firmware yeah and you can see the money starting to go into the insecure wallets and then you can see the mark four come out yeah the money keeps going up in the mark threes because people are still stacking they're doing what they've been told right to stack sats and they like more than like double the amount of Bitcoin in their compromised Mark 3s, even after the Mark 4 is out.

57:08So it's, yeah, that bit is very sad. Years spent stacking on things, and it's gone. Probably the only thing that saved me, because I had a Mark 3 before I had the Mark 4, is that I'm a nerd for light devices. So I bought the new one. That's the only thing that really saved me. Otherwise, I would have been one of those people. It could have been the other way around. It could have been the Mark 4 had the problem. It's just so random, right? Before we go on to the Frostnap devices, can we talk a little bit about Dark Skippy? Yeah. Because I remember this coming up, but I'd never followed it very closely.

57:43Tell me what that attack was. It was an improvement on an existing class of attacks where a malicious device can choose these random nonces it uses during signing. And previously, it was thought in the literature, you know maybe a malicious device can leak its seed phrase over like maybe 50 transactions like maybe each each signature has like one or two bytes and if you if you're the attacker you can look on chain and you can sort of grab all these two bytes and if you get enough of them you get the the seed phrase um but in a sort of a game of i guess cryptographer sort of code golf uh lloyd and robin linus were going back and forth on on twitter um a few years ago and uh together they essentially figured out you can do it in just uh two signatures so so one transaction is enough for a malicious device to leak your seed phrase inside the the signature itself and this is any device any device yeah that's allowed to choose its own random number for its nonce and that isn't you know um that it's acting maliciously and you don't you don't check that it's doing deterministic nonces or you don't or it's not doing an anti-exfill protocol like jade bitbox or frost snap yeah so this is why nick is saying you know you probably need to run roll random numbers during signatures as well there's no api to do that this is me it would be totally insane to roll random numbers but that's that's the issue uh is you can do everything make sure your seed is set up totally trustlessly and make sure everything's correct but if i take your seed signer or call your call and I get the malicious firmware on there, like, that's still a trusted party.

59:29How would you get the malicious firmware on there? On a seed signer, you literally just take the SD card out and you put a different... You flash it and you put the SD card in. You have to have physical access to the seed signer. Yeah, so it's like you get physical access to the seed signer. Or a much better retirement attack would be to do Dark Skippy, probably. If you were a malicious manufacturer, it'd be a much better... Rather than making weak randomness for the seed phrase, it might be a better attack just to say on... okay, if this transaction is spending over one Bitcoin, just fiddle with the nonce a little bit and exfiltrate the whole seed phrase.

1:00:03And it's completely covert, pretty much, unless they're signing on a second device. As the manufacturer is very trivial to do it. I guess if you, you know, like you want to try and hide it a bit, you want to ship it with them if they update firmware, maybe you want to, you know, you can still do it. Like even if they try and update firmware, there's nothing really you can do. Trusted, like hardware is just a trusted party. It's a black box. You can't really penetrate without x-rays or something to figure out what it really, really is doing. But yeah, so the problem is it doesn't matter what you do.

1:00:36It ends up being this trusted third party. And it doesn't matter how many secure elements there are, right? Because what I can do is if I can change the firmware, and even if I'm not the company, I'm an attacker, I don't have to go through all these very secure chips. I can just go through the main chip, right? The main chip is enough to change, if I can change the firmware. And this actually, Ledger demonstrated this for what it's worth on Trezor. They went and they changed, was able to change the firmware of the Trezor with the secure element on it. And so now, the secure element doesn't do anything.

1:01:09I remember them extracting keys from Trezor. Is this how they did it? This is a more recent one. They didn't extract keys, they just changed the firmware. So they got rid of the secure boot thing and they just were able to change the firmware. And so what this means is, yeah, you can, you, what, what this attack looks like is someone, crazy person from Ledger comes in. They take your, your Trezor while you're on holiday or whatever. And they go into the lab a bit and then they put it right back where it was. They still don't know the secret key at this point, right? They don't know anything secret on it.

1:01:35And then you, but you put your pin number and you sign something and then that gets posted to blockchain and that signature has the data in it. Right. So this is the kind of thing is very, very difficult. stop it but this is way further out on the risk curve that people should be thinking about because they have to have actual access to your device with the devices that you plug into your computer could it be loaded by like malicious firmware on the computer no no you need malicious firmware on the device but what I'm saying is like if it's not an air gap device and you're plugging it in could it then be transferred to the device some device like most devices they like I'm talking about not our device most devices need a pin number before you can do a firmware upgrade So it's kind of like you're in the security model where you kind of just do it by itself.

1:02:20But yeah, I mean, if it can be exploited and it's not signed firmware and you really don't know what you're doing, yes. So like same with SeedSign. Like you could just put an SD card from your computer and think it's all good and then bam, it's gone. But this is like, this isn't actually gonna, we're not gonna see this in the wild in the large scale. We hope not, yeah. Well, now that, I mean, now the clankers exist, like you can just point it at darkskippy.com and tell it to do it. But then you could have your actual device. Or they could release maybe a firmware of, you know, a device that doesn't check, you know, that it's signed by a manufacturer.

1:02:54They make a fake website or a fake GitHub and say, here, download the latest release. I see, okay. People download that. And then they're trusting the device to generate that randomness. Yeah. Cold card included, they will check this. They will not be able to just install random firmware. Yeah. There's no FUD there. Like, they check the secure boot. Although on Cold Cold Mark III, you could because it's a bug. but other ones you can't. And so you would really be, it's really more the point about this is, you're trusting the manufacturer. Doesn't matter if you do all this stuff yourself, you're trusting the manufacturer, just deal with that reality, right?

1:03:25I'm trying not to totally freak people out here. Yeah, yeah, yeah. I don't think you're doing a good job of that. Some people think Docs Hex was like a malicious guy and he was playing. So this, he could have done Dark Skippy, right? It would have been much better to do Dark Skippy in some ways than what he did, which was like, I mean, if he was, It was like incredible galaxy brain, you know, attack. Because it is so messy. And so it doesn't look at all like someone was doing it maliciously. It looks totally like a mistake. And so I guess if you're very clever, you can make everything look totally like a mistake.

1:03:56But yeah. Okay, let's talk about FrostSnap. Can I see the device? Yeah, of course. I don't think I've ever actually seen these in person. So tell me how these work. Let me... Yeah, open a few up. Yeah, so... the camera how they these ones i'm not the first person to make the joke but it's uh it's the human centipede of hardware wallets yes right you love it or you hate it yeah you can daisy chain them together yeah you daisy chain them tell me how they work yeah so you just um you want to make a multi-signature wallet you just connect a few into them like that and then download the app um on your phone or your laptop click create a wallet you know give each device a name and then it'll interactively generate a group private key that never lives on any one device.

1:04:45So this is that the phone actually contributes entropy during this step, which is what Lloyd was talking about before. And at the end of this, what's called a distributed key generation, you have each device has sort of a share of this or a key to this wallet and you need, say, two out of three to spend the money. And so from there, you would leave them in different secure locations. Each device has its own backup. So underneath those tins is a backup recovery card. And then, yeah, you would leave them in secure locations. And when you want to sign, you visit them one at a time. Oh, so you don't need them all together at the same time.

1:05:27Yeah. Oh, that's cool. Yeah, you would make your transaction on your phone or your laptop and then pick which devices you're going to go and sign on and visit them and get those signatures. The really cool thing is it's using threshold signatures. It's not using script multi-sig. This has a bunch of downstream benefits. It looks like a single-sig on-chain, which is really nice. No one can tell you're using a multi-sig. What's the benefit of that? Well, it's a very strange feeling when you pay someone in Bitcoin from a multi-signature and you reveal that they can look your transaction up on-chain and say, oh, Nick's using a four out of five or he's using a three out of five.

1:06:11And you shouldn't have to reveal this information when you're spending. Because you're just giving away something about your setup. It's your security setup. Yeah, it's a bit crazy. That's just one of many, many issues with it. The privacy heuristics on-chain are much more easier to do when this script is very easy to follow. And this uses Frost, which I don't really know what it is. Can you tell me about Frost? Yeah. Some people heard Shamir's Secret Sharing. It would be like one in three people listening to that show. Shamir's Secret Sharing. Which is essentially where you break a private key up into three pieces and spread them.

1:06:47Yeah. And two out of three of them can spend or whatever you choose. Right? Trezor, for example, does this for backups. You can do that. I don't think many people do do it, but it's a cool feature. I think Ledger can do that as well, right? There was a... That was the backdoor thing that everyone was upset with them about. Which I don't think was actually a backdoor, but... No, but it wasn't a real backdoor. It was opted in, right? So it wasn't like instant backdoor. But yeah, they would split it up across different places. Yeah. And so same tech. I mean, it's the same tech that is used in Coinbase custody to secure Michael Saylor's funds.

1:07:20So different computers have different shares of the key. Yep. And you need three, you need to corrupt like three out of five of them or whatever to actually steal the money, right? So one location is not going to be enough. And so the way it works is, yeah, you mathematically split up the secret key. And then our devices, when they sign, they don't give a signature, actually. They give a Shamir secret share of a signature. Okay. And then the phone is actually taking those Shamir secret shares of the signature and turning them back into an actual signature. And that goes on chain. That's why there's one public key and one signature.

1:07:53Now, the real... Like Nick mentioned several of the benefits, but the real killer benefit for me, like the life-changing benefit, is there is no descriptor backup. So you take that foot gun out of the equation. Yes. That's what scared me off doing script multi-sig. When I learned about... I was fully ready to go script multi-sig for my own setup. And then I learned about this descriptor backup thing on a Bitcoin stack exchange. like you know post and i'm like in no way am i doing this like this is like i'd never heard about it before it scared me senseless it was terrifying yeah so i i i just couldn't imagine my wife with this thing right like this this extra bit of information like frost snap what it really is is what multi-sig you think multi-sig is right it's got multiple keys and any two out of three of them can spend the money or three out of five whatever you choose and there is no ifs or but that's basically it, right?

1:08:48So that's the key feature of it. Multi-sig and when you have different hardware wallets, multi-manufactured, it's complicated because of that. There's different hardware walls you have to learn, but that thing where you have this possible, like people want to move to that because of the cold card thing, right? And yes, now it does do that. So it does get rid of this entropy, buggy entropy on the device problem in the sense that two out of three devices would have to be buggy, right? But it adds this thing, this other way of losing money. So you've got to, when you're thinking about attackers, you always have to think about what does the attacker want you to do, right?

1:09:28And there's one attacker that, Tim, you know, Wizard of Oz, he, or BTC Shelling Point, no, BTC Shelling Point, right? He calls it the fuck-up fairy, right? You've always got to think about the fuck-up fairy and you've got to think about the actual attackers. And so we, in Frostnap, we think the fuck-up fairy is not super happy that you're going on to the Frostnap because although it's a new company, it's new technology, and the fuck-up fairy might find something in there. At least the backup situation is totally pristine. It's like, you got two out of three, and that's it. You got all the money back, you're good.

1:10:02There's nothing else that needs to be backed up. And the thing that I always said about self-custody, which is not aged well, is that the most likely way you're going to lose funds is by your own fuck up. And at the same time, I would have told anyone that asked me if Cold Car was good, I would have said, yes, it's good. So like, clearly that didn't age very well. And no one fucked up who, like those people didn't fuck up. That's what I mean. Yeah, exactly. They did everything right. But I still think that's probably the way that most people will lose Bitcoin. It's not like a nation state attack.

1:10:29That's not what's going to get most people. It is the fuck up. So taking that away is awesome. Yeah, but also, also, if you have all your life savings in Bitcoin, don't leave it all in your house. Yes. It's been in five minutes. Although the fuck up fairy may come for you. Like there are actual people doing this now. Like people who are focused, criminals who are focused just on this. It's come down a bit since the price has gone down. Yeah. But their skills are there. They know what they're doing now and they know how to target and they get information and they know how to do it. I think this is a good time to do a little bit of a one-on-one because I'm sure there's someone listening to this that's like, my life savings is in my house.

1:11:06Yeah. Like what would be your sort of, I know it's different for everyone, but what would be a ideal situation for someone to actually, like where should people be storing their private keys? Oh, interesting. You want... Yeah, go ahead. A good, like having, if you start, if you're thinking about multi-sig, having one key, at least one key, in a place where you have to speak to someone, or if there's like office hours, that's a really good one. Because like if someone comes to you in the middle of the night, and you say, well, you're going to have to take me to this person between nine to five, Like that really throws them out of their, you know, their comfort zone in carrying off the attack.

1:11:44Yeah. But some much more risky situation. Like Nick said, I think like you can have a, what we found, okay, is that when we study the data is that the criminals in, when people have this thing where it's far away, okay, multiple, if it's in multiple flights, you're rock solid, but of course, COVID or whatever, you know, world war three, then you're really in trouble. So if you're trying to predict things that people think like putting it far away one common one common one is the holiday home right wealthy person has lots of bitcoin they put it in their holiday home it's a couple hours away that is in practice not worked they actually will just drive you yeah to the holiday home yeah um it's much better to have it with your accountant lawyer or whatever down the street who's only open nine to five and is very you know uh eins zwei drei with with how they operate things uh have you know security have a safe or whatever and have it with them.

1:12:34Even your friend who's in an apartment in a security building, you have to like dial up, you know, to get into the building and go up a lift where you might encounter other people. Lots of cameras. The attackers don't want to do that stuff, usually. The thing that scares me about it is like, as someone who's like somewhat known in Bitcoin, like if one of these attacks happened, someone could grab me off the street and say, give me the Bitcoin. And I could be like, I can't. And you still might get fucking killed. Like, it's a really horrible situation. Yes. Though it doesn't like... People say that, but when I look at the data, it doesn't happen that.

1:13:11Like, people randomly killing people because they had Bitcoin. Or like their finger chopped off. That one, yeah. So that does happen in the kidnapping case, right? In the kidnapping cases, kidnapping is a separate situation. And it's a really interesting situation, and I've been reading about it, and I super want to come up with a solution with it. And I want to get a... Let's be fully honest. Frostnap doesn't help you with kidnapping. If someone... Nothing does. Yeah. Well, maybe Ancortge Insurance. That's a spicy... Ancortge Insurance does. That is a spicy... Does it? Yes. Okay, does it? Okay.

1:13:44I think it does. Because in that scenario, you send them all your Bitcoin. And sure, you have price risk before you get paid out by your insurance policy. This is why when I was reading a book on kidnapping, written by a guy who does lots of kidnapping stuff, It's to teach negotiators. Like one of the risk factors, one of the biggest risk factors in these kind of kidnappings that happen in Middle East or whatever, like a guy working in an oil rig or whatever, they want to take the guy who has the insurance, right? Ah, okay. And so if they know you have insurance, you become the number one target because yeah, there's no reason.

1:14:19They just got to pay it out. And so actually the insurance, probably with Anchor Watch, but I'm not, I would double check with WAP, you can't disclose that you have that plan. Probably not. I don't know. Well, you can't get outside the US, so that's my disclosure. I do not have it. Don't kidnap me. Oh, you can't get outside the US. Okay. I wonder if it protects you if you go abroad. But the key thing is, yeah, you can't disclose it. But the really good thing about it, the insurance, is it not the bit where they pay you back, but the bit where they do the negotiation for you. That's a thing you can't technically solve.

1:14:53That is a real skill. When you're like, I don't know where you get the message on WhatsApp, app or whatever yeah how you say things is just so critically important and how you use whatever leverage you have is just so critically important for the safety of the person and for not giving them all your money uh that's that's what i'd say so that that's what i'm really interested in is how can you how can you provide that expertise to people uh without putting them in a situation where they say yeah i got insurance i'll just because then then the attackers get more money and Bitcoin keep doing it.

1:15:25That's the other thing. You want to make sure they get as little money as possible, but you can't really do it yourself. You can't roll your own hostage negotiation system, unfortunately. It's not DIY. This has been a bit of a black pill, this episode. I mean, if we all get on strong multi-sig setups, there'll be no more low-hanging fruit and the attackers will just be like, Oh, we got to go find something else to do. So right now, the low-hanging fruit is just people have all their money in the house. If you're doing physical attacks, it's just in the house. And you just figure that out. You figure out where they live and you do a home invasion style thing.

1:16:04And it works very often. It works very often, especially if they're prepared. Often the guy who's actually handling the money is remote, right? And they're talking to them on the AirPods or whatever and telling them everything. They're looking up everything. You have to give them your phone first thing and get all the passwords for everything. they're in your email, looking at all the exchanges you signed up to, logging into them, you know, just like doing a quick audit on you. So keep that in mind. That is the situation that the most experienced crews do, put you in and you will not be able to like pretend like you have some, oh, these are my decoy C words or whatever.

1:16:39That kind of stuff is not going to work. That's always been my problem with decoy wallets is like, again, none of this stops you getting your fingers chopped off and your teeth pulled out. And like, it's - Might make it worse. Oh, it can make it. It can encourage them to do it because now you've started deceiving them, right? You want them to think you're super cooperative. That's my only advice. Just be like, just be cooperative. And the best thing to do is not have it in your house so you can be like, yes, let's go see my accountant tomorrow at 9 a.m. sharp, you know, about this problem. Or let's call him now and let's hope that he doesn't call the police.

1:17:11One thing is that they don't want the police called on them when they're in your house. That's the difference between kidnapping. In kidnapping, they're going to pretend, like they're gonna they're gonna expect that you're gonna call someone right but when they're in your house like any little trigger or whatever someone's suspicious of something they're doing they're practically doing a kidnapping but they're in your house and that's not where they want to be they're in an environment they're in control and they could just get surrounded and go to jail for a very long time of getting no money so anything that can trigger uh someone coming to check on you is is good in that situation well i'm terrified um but it's not a problem to the next bull market actually.

1:17:46So it's a good problem. This is the benefit of the air market. So with these, this is a bit of a gear shift. With these devices, I can't use them on my iPhone, right? Not yet. Not yet. Is that coming? We're working on it. It doesn't... It can't use the same hardware. Okay. We're gonna... We're working on a new edition at some point in the future. And that's just because Apple locked down the USB-T. If they even let us get it into the App Store and stuff. Yes, we believe that they will. You know, you never know. They might ban all Bitcoin wallets by the time that we get there. I will not put that out of the equation.

1:18:21Exactly. So, yeah. But like, I could use these like with my MacBook. Yeah. Mac, Android, Windows, and Linux. And Android, so Android phones you can do with, just not the iPhone. Okay, cool. And is that because you can sideload apps? We're in the Play Store as well. It's just using the USB port is a lot less restricted on Android. And what about when they all get rid of the USB port? What should you do then? Oh, are they going to get rid of the USB port? At some point, I'm sure. I will have to do NFC or something. We'll figure it out. This is the first I'm hearing of this. I have no news, but it's the way we're going, surely.

1:18:58And so, like, obviously, everyone cares about air gap devices, and these are not air gap. You plug these in. Is there any risk in that? We don't think so. And I'll be one to admit that I was, before I got into these deep conversations with Lloyd, I was sort of an air gapping proponent. Like to me, it felt like something that was, you know, it felt like it was adding security, right? There's the communication has to like go through this sort of this hop before it gets to the device. But Dark Skippy was one of the good examples that like it doesn't actually matter so much. Like the communication, the information has to flow regardless.

1:19:34Whether it's through a SD card, a QR code, a USB serial, there's always got to be some communication that flows. And what really matters is, does the firmware under the device, like, does it handle that communication securely? And we think we've done a really good job at that by using, you know, solid programming languages and taking the time to do things really carefully. But you totally understand the intuition, right? You don't want to delve into all these topics. So you're like, if it's not connected to the thing, then it can't hack that thing, can't hack that other thing. Yeah. And actually, in practice, that has been true.

1:20:15People who've plugged in had USB protocols. I can think of Trezor, Bitbox, I think, maybe even Jade. Like, they all had some kind of thing where they rolled their own decoder in C. And when they're reading stuff off the wire, it had a buffer overflow or something. It didn't do the code quite correctly. And you could execute code on the device. And so the theory is that this is actually harder to do via images, QR codes. Which I think is not true. Which is a bit weird. This is actually why I was looking at the cold card firmware in actually the first place. Like my initial prompts, it was like eight weeks ago now, was the reason I started looking into it was I wanted to find like a memory bug in animated QR codes.

1:21:02I wanted to find something that sort of demonstrated that actually, you know, this air gapping with animated QR codes is really no different to doing communication over serial, like over the USB. No one is like, you know, inspecting these animated QR codes and like, you know, checking it all. And even if you did, you know, there could be stuff covertly going through that anyway. Yes, but in practice, we couldn't find anything. In practice, like these companies have been owned by the USB, but it's actually, it's a street, it's not a technical phenomenon. It's a strange social phenomenon. An engineer gets the job.

1:21:34Okay, we have to talk over USB. there's so many different ways to do it. You can make a mistake. With QR codes, it's like very one way to do it. And one guy has written that code correctly, right? Yeah. And so it's like, and everyone uses that thing. And so that for some reason actually works. So the much simpler thing is just to talk over a wire, but everyone goofs that up. And so, but the main, it's really a social engineering thing, not really a technical thing. And so when we're looking at it, we use the Rust programming language. so this means you you would not be able to do that kind of thing where you send crazy bits over and it like starts taking control over the thing which can happen if you see and in c is what the cold card was trying to fiddle together with python we think that you should not use python and c mangle together just use rust and then you get rid of all these these possible errors with memory and corruption and so this idea that you're going to plug your device in and it's going to become corrupted by the laptop or something sort of goes out the window just at that level.

1:22:35That's what we bank on at least. So we're all fucked and we should buy the ETF. Yes, the ETF will hopefully be custody by Frostnap. I love it. This has been awesome. This has been a real deep dive. I think there's a lot of value in that. Thank you guys. We're off to the Bitcoin meetup in Sydney. Let's go. Yes, let's go a lot of fun. You've got to do the same thing all over again. All right. Thank you, guys. Thanks very much, Danny. Thanks very much. Appreciate it.

From the publisher

“They’re saving all their money in Bitcoin and they’re doing all the right things. They’re self-custodying it. And then overnight, it’s just gone.”

Frostsnap’s Lloyd Fournier and Nick Farrow join me to break down the catastrophic Coldcard vulnerability that made supposedly secure Bitcoin keys guessable and allowed attackers to drain more than 1,700 BTC without ever touching the devices.

We discuss how a five-year failure in Coldcard’s randomness generation went undetected, why every safeguard failed and the role AI played in discovering and exploiting the bug. Nick also explains how he reproduced the attack himself, what the on-chain evidence reveals about the attackers and why this has shaken trust in Bitcoin self-custody.

We also get into whether hardware wallets are really trusted third parties, the limitations of dice rolls and air gaps, how Dark Skippy can leak a seed through a single transaction and why single-signature custody may need to change.

Finally, Lloyd and Nick explain how Frostsnap uses distributed key generation and threshold signatures to remove single points of failure, simplify recovery and secure Bitcoin across multiple locations.

THANKS TO OUR SPONSORS:

LEDN

SWAN

ANCHORWATCH

BLOCKWARE

BITKEY

CAPE

FOLLOW:

Danny Knowles: https://x.com/_DannyKnowles

Lloyd Fournier: https://x.com/LLFOURN

Nick Farrow: https://x.com/utxoclub

More from What Bitcoin Did

All 145 episodes
The Coldcard Disaster: Everything You Need to KnowWhat Bitcoin Did · 1 h 23 min
Listen in VO