The Honest Money Show is your guide to understanding what money really is, and where Bitcoin fits in. Hosted by Anja Dragovic, Australia's female-led, Bitcoin-only podcast, it cuts through the noise to explore how money shapes our lives, why the current system leaves so many people behind, and what a clearer, fairer future could look like.
Expect honest, accessible conversations with some of the most interesting thinkers in the space, the kind that take you from "I don't really get this" to genuinely curious. No hype, no pressure, just money, made clear.
Whether you're brand new to these questions or already deep in them, you're welcome here.
There was this Swedish guy who actually
cut off people's ears and fed it to them.
And then he started doing Bitcoin wrench attacks
because he heard that was the next thing.
If they even think there's like a 10% chance
you're hiding something.
it's worth trying, right.
It's just economically, it's worth doing
the violence just to see,
because on a, you know, you get a couple of Bitcoin,
but what if this guy's got 20 Bitcoin in multisig, right
Like you've got the decoy wallet or something
So if there's a suspicion there's a decoy wallet
any of those kinds of things, that's when the violence can start.
We cannot have the holders of Bitcoin be so vulnerable.
Joining me today on the Honest Money is
Australian cryptographer Lloyd.
Lloyd is also the founder of FrostSnap.
So today we're going to be talking about
the Coldcard case.
We'll talk a little bit about wrench
attacks in Bitcoin, multi-sig, as well as
the solution that FrostSnap provides.
Welcome to the show, Lloyd.
G'day, Anja. Thanks. Thanks for having me.
I just had a little flashback to the time
that I met you, which was Bitcoin Pizza Day
back in Sydney, I think in 2024. Oh,
very well.
Yep. Do you remember that?
The good old days.
May, where were we? At a pizza joint?
At the Baviano Pizza Place in Sydney.
Yeah, yeah. I think so. I think so.
I think I remember.
I was a newb. I was a newb.
I think I remember you were just like
very freaked out about your
superannuation and you were just
going all in onto Bitcoin.
That's what I remember.
In your super and you were like visibly
afraid.
Yep. Yeah. But speaking of afraid.
But now you're in a bad market and you're
totally relaxed, which is really cool.
Yeah. Yeah.
It helps to have proper Bitcoiners around
you at a time like this.
But I'd love for you to tell my audience
about physical safety in Bitcoin,
because this is something
that has been coming up quite a bit lately.
And they're called Wrench attacks.
Yeah, this is obviously an old kind of thing.
People have been storing their wealth in
their home
for a while or on their person and
violence can happen to them.
People rob them.
I like this favorite factoid of mine that
actually the very first written text that
archaeologists have been able to recover.
It's called The Instructions of Shurupak.
And it has on it, it's basically what it is,
is wisdom literature.
So it's like from father to son
explaining all the ways a man should be.
And one of the first pieces of advice is
he says, don't wish for the money chest.
Don't break into your neighbor's house
and try and steal their money.
And so what it,
what it indicates is that this problem
has been,
is literally as old as civilization.
People have been going,
sneaking into their neighbor's house or
using violence to go and just extract
wealth from others
rather than building wealth themselves.
Because at some point it just becomes
much easier,
more economical to just go into someone
else's property.
And of course,
with the massive increase or wealth
transfer to Bitcoiners,
Bitcoin is often stored in their houses.
So it's not just wealth transfer to
individuals.
It's wealth transfer to a specific
locations and people's houses, right?
Which is very crazy when you think about
it.
And so those locations are highly
desirable.
And what's actually interesting,
maybe in the context,
like in the context in the West is the
crime rate has really been dropping.
This kind of crime has really been
dropping for a long time.
So it's not like we're in a period where
there's lots of robberies and home
invasions and things like that going on.
And then this Bitcoin has come on top.
We're in a period where they've just been
dipping and there's not that many
criminals doing robberies.
Because what are you going to rob?
Like the 60 inch TV that maybe costs a
thousand bucks or whatever.
It's like not, it's no longer attractive.
People don't have that much jewelry or
things going on inside their homes.
Much better like security systems,
webcam sort of things that will catch you.
Much cheaper, right?
Doorbell cams, all these kind of things.
So the crime rate has really,
in that respect, has really been going down.
But then, you know,
eventually the economics of it, right?
Adjust the incentives will kick in.
If you're someone with tens of millions
of dollars sitting on in their house and
somebody knows that.
You are a target.
And it happens sporadically.
It happens in different countries.
But you can see now,
like it has in the last year or so,
it's consolidated around France, right?
So that's where you had like now a
permanent criminal expertise, I guess,
in doing this kind of attack.
Despite the French government trying very
hard to stop them.
Although they do a lot of things to
encourage them as well.
They do a lot of things to encourage it
in terms of KYC data and tax collection
data.
That is one of the main problems is
getting the information because there's
lots of houses out there.
But how many of them actually have
Bitcoin in them?
If you can narrow it down,
then it's just like walking over and
picking up money if you do some of the
basics.
Right.
And so that's where we're at the moment.
We're in a bear market.
Things have cooled down a little bit.
So it's sort of like price leads these
things.
The price lead goes up and then people
start doing them.
And then by the time the bear market is
over, they're really into the swing of it.
And while the price is falling,
they're doing it frequently.
But now the price has been low for a
little while.
So it's cooled down a bit.
But you can imagine how much worse.
If France is, it could be,
if we have another bull market right now
when it goes 5x what it was, the last one,
then France won't be the only country,
I expect,
having this kind of embedded criminal
organized crime syndicates that actually
specialize in doing that kind of attack.
Yeah, that is really concerning.
And I'm sure you heard that, you know,
Francis Pouillot from Bull Bitcoin is,
I guess, taking the government,
the French government to court over this,
trying to advocate for not centralizing
that data.
And I believe the same thing is happening
in Australia.
Like it's being rolled out by the CAF
where they're trying to, I guess,
pull this information into one data set,
making it, I guess,
easier for criminals to hack.
And that's just really concerning because
obviously we have Australian Bitcoiners
and yeah,
we wouldn't want that kind of thing
coming here.
Yeah, well,
so far we've done very well in this,
in avoiding these attacks.
There has not been any serious ones in
the last few years.
And so we want to keep it that way.
And so now it looked like the government,
we won't be able to keep it that way if
the government keeps doing this kind of
things.
But unless we actually take action
ourselves to make ourselves unattractive
targets.
So they look down the list and they see
you and they're thinking, no,
I'm not going to bother with that for
some reason.
Right.
And so that's what that's kind of what
our product Frostnap is about.
You saw Trezor just today had leaked like
all the addresses and full name addresses
of all the people they've shipped Trezors
to.
And that includes the people who are
fleeing from the recent coal card thing.
So we're out of the frying pan into the
fire.
And now what we,
we obviously don't want to leak anyone's
address.
We, although it is true.
Like you've got to understand,
like you have to tell a third party who
does shipping where someone's address is
if they deliver it to their home.
Right.
I mean, it's just,
there's no physical way to get it to them
otherwise.
So you have to know their address if you
want to deliver it. Um,
and that's every hardware wallet company
has to deal with that.
The, the saving grace in our case though,
is that we are delivering you a product
that will not exist just in your house.
Right.
So the Trezor you expect is delivered to
this house and it probably stays in that house, right.
So our, we deliver several devices.
So our,
our product is a multi-sig wallet only
pretty much.
And so we're delivering you several
devices and they're going to be in
different locations.
There may be one in your house,
but they'll be in different locations.
You won't be able to spend the money from
your house.
So when you look at, you know, if the,
if you know,
if you're looking down that list and you
know, someone has a frost nap then,
or multi, or multi-sig in general.
Right.
Uh,
you can probably say that I'm going to
skip that name on the list and go down to
the next one. Right.
That's what we're trying to do as
Australians, I guess, or as anyone,
we want to have our names on those lists,
not, not be the ones that are pursued.
And it should be, um,
it's one thing that may be interest,
really interesting about these kinds of
attacks is that they are not really
geographically necessarily co-located as
much as you might think.
France has, uh,
obviously had a huge swath of them.
Uh,
there's French criminals targeting French
people.
But before that,
the really sophisticated attacks that,
that got most of the money and were sort
of repeated were often international.
So people would fly in on a tourist visa.
They have a target.
They, they do set,
like they dress up as an Uber driver or
whatever,
or Uber delivery person or whatever.
And they go and they,
they surveil that target.
They go in, uh, and take the,
do the home invasion attack where they'll,
you know, usually the person,
the reason it's so international is the
person who's coordinating it isn't even
in the same country.
Right.
So the person who's coordinating it has
like an AirPods or whatever in their ear,
and they're just talking to the people on
the actual ground who are cheap and
disposable.
Uh,
and they're the ones who are swiping the
money.
They're the ones who are getting the seed
words.
They're the ones who's take,
providing the address that the money we
transferred to in during the attack.
And so they hold all the money and they
don't have to flee the country.
They're safe wherever they are.
And so you just send a team to that
country or you pick up people who are
already in that country,
which is often the case,
but like lower income people, like, like,
uh, low level criminals.
Just sort of train them a bit, you know,
how to do it.
And then they, they,
the low level criminals often don't even
know who the person is,
who's they're talking to.
Right.
They just hear it through some,
they get recruited through some,
some messaging platform.
Uh, and so that's kind of how it works.
And so you don't really have to have a
homegrown Australian criminal scene for
this to happen in Australia.
That's the, that's the main point though.
You can see that it does help if the,
if like the,
if your country's own criminal scene
starts adopting these.
These attacks,
cause they are wildly profitable.
Um, if you have the data,
there's like incredible one,
one night of your life and you'll never
work again.
And it's very hard to track and catch them.
Uh,
or you have a decent chance of not being
caught.
Right.
Uh, yeah, those, those are, that,
that makes it worse, but you can,
even if it's,
even if you don't have a homegrown scene,
international people can fly over.
Uh, they,
they have their flights booked already
and they just leave on their tourist,
they come in on tourist visa,
leave on the tourist visa.
And it's, and it's done by the time,
by the time you untie yourself, uh,
they have left and call the police.
They've left the country basically.
Yeah.
Yeah.
And that's the ones,
that's the attacks where the person
doesn't get physically hurt.
But from my understanding,
there have been many instances where
someone was physically hurt as part of
this attack.
Yeah.
Uh, there are many, I mean, there, it,
it goes like, there's a whole range, right?
The pro I mean,
the problem is like what I would say the
let, there is less physical harm,
the more professional that they are.
Um, and the more cooperative the victim is,
uh, with it.
So they're, they're often, you know,
criminal organizations,
you don't get the smartest people and you
get violent people who are willing to do
this kind of work.
And often they do the violence is
manifestation.
It's not, it's like part of a strategy.
It's just like, you know,
I'm here to be violent, you know,
that's my job, whatever.
And then, I mean, there's a, there is a,
the craziest example I have of this is
not a guy, you know,
who's not really even trying to get money.
Some, some of the criminals, you know,
just do it for the love of the game.
Right.
So there's, there's,
there was a Swedish guy who actually cut
off people's ears and fed it to them.
And then he joined,
started doing Bitcoin wrench attacks
because he heard, you know,
that was the next thing.
So he was put in jail for four years and
they let him out.
Um,
and he started doing Bitcoin wrench
attacks.
So I don't know what's going on in Sweden
with the criminal justice system.
But, uh, but that's sort of like,
you have these crazy people who are like
psychopaths who get into violent crime
and they just,
they will get into wrench attacks just
because Bitcoin wrench attacks just
because that's the thing that's going.
Um, but that's not likely,
you're like highly unlikely to be
targeted by that person.
You're really going to be more likely in
the future to be targeted by
well-organized people.
Um,
because this is how Darwinian selection
works, right?
It's not guaranteed.
You may be, you may be targeted by,
you may be the one targeted by the idiots
and the, you can't,
the idiots come in and they be violent
and then they all get arrested.
That happens all, it's still,
it's still happening like that.
But I would be thinking more about how to
protect myself against sophisticated
people rather than the like crazy people
who just don't know what they're doing
and they're out for a laugh and they have
no, you know, they have no,
they have no self-worth.
Uh, those, protecting against those people,
um, they may, they may harm you,
but usually it is to extract something
from you, right?
I mean, that's, if they, if you just,
if they go in and you just like hand them
your seed words,
they're not going to do it and then take,
you take all your money and they're like,
they're convinced that that's all your
money.
They're not going to take anything from
you.
The thing that the violence usually comes
in when they don't,
they think you're hiding something, right?
Because,
and if they even think there's like a 10%
chance you're hiding something,
it's worth trying, right?
It's just economically,
it's worth doing the violence just to see,
because on a, you know,
you get a couple of Bitcoin,
but what if this guy's got 20 Bitcoin in
a multi-sig?
Like you've got the decoy wallet or
something.
So if there's a suspicion there's a decoy
wallet, any of those kinds of things,
that's when the violence can start.
Um,
but you think about it from a criminal's
perspective, it's not like criminal,
and I don't want to ever get the
impression that criminals are wrong.
They're not rational, economic actors,
and they just follow incentives.
They denote, they're humans with emotions,
and they're often emotionally not well
managing themselves.
And so, uh,
but if you think about it from their
perspective, uh, and you, and you,
you keep them calm as the victim, you know,
you be cooperative.
There is,
they don't want to be in there for very
long, uh, in your house.
They do not want to be in your house for
very long.
They want to get out of your house.
And so that's,
if you can help them get the money and
help them get out,
they'll probably take that help without
any violence.
That's actually an interesting point
because I did observe in the Coldcard
hack, the, how high the fees were.
And is that because you,
do you believe that was because they were
rushing to extract the Bitcoin as fast as
possible?
They weren't trying to go on the lowest
fee structure.
In this, yeah, I mean, well,
it's just like this,
the guys were still in the Coldcard hack.
I mean,
this is obviously a totally different
criminal, um, different criminal world,
right?
This is the,
the guy in his chair or girl in their, uh,
you know, their chair at home.
And they,
they're using AI and poking it around at
different things.
And they poke it at this repo and they
strict struck gold, right?
Uh, there,
they don't know what's clear is this
person who's attacking the first attacker
on that very first sweep did not know, uh,
Bitcoin too well.
And did not write the software themselves.
And they just wrote very, you know,
hacky sort of software by AI agents sort
of thing that, um, that,
that took the money in a very peculiar way.
And so they didn't want to worry about
what the fee rate should be.
They were not maximizing.
I mean, they're getting, I mean,
they're getting a thousand Bitcoin in a
few minutes.
So do you worry about paying like 10
times the fee?
Do you worry about paying a $20 fee per
transaction?
Cause they actually lost money on several
of their transactions.
If you look at their transactions,
they lost money on several of them.
Because they spent like an,
a UTXO has almost no money in it with a
high fee and just burnt money,
but it didn't really matter in the overall,
right?
It's not worth them spending the next few
minutes to get the software right and to
exclude those things.
Yeah.
So, um, that was not a motion.
That was just,
that's what the AI gave them and they
clicked, went go, right?
Yeah.
But do you want to tell my audience?
I know the story,
but do you want to mention why you know
this?
Like this level of detail?
I think, uh, yeah, there's,
I reproduced the attack.
So I went and, uh,
ran the attack just recently,
just so I could see everything on chain.
Cause I thought it would be interesting.
I think some other people,
there's a guy called Praveen on X,
who's also published a blog post today.
And he's also done something similar.
And so, and so, yeah, you can,
what that lets you do is stop speculating.
You don't do chain houses as much to see
what's going on.
You just get all the wallets and you sort
of roll it up in software into one giant
wallet and you see yourself getting
drained sort of thing.
You just watch it getting drained over,
over the time period and get to see a bit
more detail what's happening.
And you get to see the behavior of those
wallet software that you, that got,
was stealing your money.
Cause that's,
that's how I can sort of see it.
I probably posted on X or something in
the coming, coming days, um,
to search so other people can take a look.
But it's quite an interesting data set.
So it starts off with some,
there's clearly one guy who starts it off.
Uh, and the software is, you know,
it gets only about half the Bitcoin
that's there.
The software behaves very strangely.
Then that's about 9 PM New York time.
And then that carries on until the next
day, about 1 PM New York time, 1. 30.
Uh, Kevin Lake, uh, from,
from Wizard Sardine, uh,
who's been in contact with some of the
victims of this thousand Bitcoin.
Uh, he, he, you know,
he starts saying that something's really,
really wrong.
Um,
I think initially he gets a pushback on
that or whatever,
but nothing really changes after,
until CoinKart makes the,
admits the problem.
Um,
so once CoinKart admits the problem on X,
like that literal minute,
like things go ballistic.
And then the, the, the, the,
the coins just start flowing out of this,
this wall of this, like aggregate wallet.
And then I think like, uh, it's stuck.
I think there's another attack,
which starts at around that.
So CoinKart admits at around almost eight
o'clock, 8 PM.
New York time.
And then the next,
the attack starts again at about 1 48 AM
or around there, New York time.
So it's, you know, eight o'clock to one,
one, two AM.
This is how long it took people to start
reproducing it.
So I think it's a different guy.
So I think it's someone who was like
written new software and is like,
that's how, about how long, uh,
long it takes.
So it's,
it's taking four or five hours just to
make the basic attack.
Once you get notified that there is a
problem on this thing.
And then I think it might be a few people
also,
he sort of looks a bit noisy around there.
It's not just necessarily one person,
but like a few people, you know,
the first guy takes four hours.
The next guy takes, you know,
four and a half.
And, you know, it's kind of like that.
Right.
So it's like,
there's a few new players coming in,
but they don't get that much money that
this scan doesn't find much new money
that hasn't been taken by the previous
guy.
I think they keep iterating and trying to
get a little bit more.
And they seem to go quiet overnight, though.
I'm not 100% sure.
Uh, they,
they may assume that everything's been
taken, but by the next day,
there is definitely, uh, another attacker.
But this is a bit,
this is a bit difficult to know because
obviously I can't,
you can't distinguish between an attacker
and, um,
a normal person sweeping their funds.
Right.
Uh,
it's only because the attackers use weird
software written by AI in a short term
that you can sort of distinguish them.
But, uh, only those attackers,
like there's some attacker who actually
wrote the software properly,
which would also make it easier to hide.
So they have an incentive to sort of
write it properly.
They have an incentive to make their
coins look like a normal sweep.
Um, it, it, yeah, you can, you, you,
that could be happening,
but actually I don't think so.
I think that because of the way the times
look, it's sort of,
everything sort of cools down around 4am.
Right.
So the attackers cool down,
even people withdrawing of like sort of,
they're still doing it, still happening,
but it's, it's a trickle.
Right.
Like it's like a Bitcoin every hour sort
of rate or, you know,
a couple of Bitcoins every hour.
And so that's like a few plebs, you know,
who are up all night, you know,
trying to do their things and, you know,
people in other time zones.
But during that time, the New York time,
it's,
it's really cooling down until you get to
like, you know, a,
until you get to the morning, like 7am.
And then it starts kicking up again.
Right.
So 7am people are waking up to this news
because it came out, you know,
Colcart admitted it around 8pm.
People turned off their screen.
They've done it.
Use their screen time thing to turn off
their social media.
They start getting messages from their
friends and then it's off to the races
again.
And everyone starts withdrawing.
And that's when most, that's when,
that's when a lot of it disappears.
And I think, yeah,
I don't think it would be attackers.
Why would the attacker go to sleep?
You know,
it seems like someone's going to sleep
there.
Um,
and it's probably the honest people who
are trying to get their money out,
go to sleep.
But then, um, I can,
you can definitely see another attack
happening at 5am on the, I know this is 5pm.
On the 31st of July, this is the next day.
Uh,
and there's another little attack that
someone's found an extra bit of Bitcoin
that hasn't been touched.
And then the sort of same thing happens
until the next day.
Uh, 8am the day after that,
which is August 1st,
someone finally takes all the money
that's left.
Uh, and that's, that's, um,
that's done in a more sophisticated way.
Because the person who took all that
money had good quality software.
They just took all the money in one
transaction sort of thing.
I mean,
I don't want to say it's good quality
software.
Because actually,
probably the smart thing to do is to
spend it, you know,
sweep all each wallet individually.
To make yourself look like a normal user.
But they had a more, you know,
they had a more sophisticated approach.
They could index all the wallets
independently and take all the money in
one go.
Which none of the attackers before seemed
to have.
But once again, we're sort of, it's sort of,
um, speculation there.
Without which one is attackers and which
ones are not.
But I'd say there's at least four
different attackers.
That's what I would say.
At least four.
Wow.
And do you think they're US based?
Um, I think.
In terms of, in terms of time,
I think it could be.
I mean, there is only,
there are some attacks going on at 4am.
That's kind of like the 4am after the
news broke.
And so, that seems like that's just people.
Like, they broke at 8pm.
So, people staying up all night.
I mean,
there were many people staying up all
night who were not even affected, right?
That was just so transfixed by this thing.
I can imagine if you're trying to
actually take the money,
you're willing to stay up to 4am.
So that, and then the others, yeah,
were all in, like, sort of normal, uh,
normal hours for the US.
So,
it does seem it might be an
American-based one.
To get in a bit, I mean,
the first attack starts at,
it starts at 9pm.
According to my data, uh, 9pm EDT.
Not, 9, yeah, about 9pm.
So that's, that's probably,
that seems like normal, right?
It could be.
I mean, that's, and that's Eastern time,
right?
Western time.
I don't know what, uh, where things are at.
So that's, uh,
it seems like it could be a New York, uh,
American-based time zone.
It could also be anywhere in the world,
right?
Obviously, but.
Yeah, it's true.
At least the first,
and there's four different attackers,
but none of them you can exclude
from being from America.
Um, but they could also be from Europe, um,
as well.
Like,
maybe the final one looks a bit more like
European, because it starts at 8pm.
It's,
it's like right in the morning in New
York time, which you would expect it's more
like in the afternoon, you know,
or middle of the day for the Europeans.
So, yeah.
Um,
but do you believe that any of these
attackers could be white hatters?
Like trying to, you know,
they got ahead of the, the bad guys,
or is that?
I heard some,
I heard some speculation about that.
If, if, if any of them were white hatters,
I think it would definitely be the last
one.
And they took about a hundred Bitcoin.
Um, I don't, yeah, I don't know.
I have no idea.
I had some,
I had some speculation about that.
I heard some people white hatting for
other people, but, um, yeah, I would,
would be keen
to know, keen to know if someone has, um,
admitted to this,
I haven't seen anyone admit
that they took this hundred Bitcoin.
Yeah.
For the purposes of, um, you know,
refunding people.
It is very tricky to refund actually much
harder than I initially thought.
It's, it's, it's, you know,
you're going to have to do a KYC process
basically, uh, with
that person.
Cause the entropy is, is,
is very bad on this cold cards.
And so really even,
even people buying cold card wallets
could get the same wallet.
So there's really no way to prove like,
yeah,
my cold card is the one that generated
this
terrible entropy.
There's a little bit of nuance that you
can prove a little bit, but not much.
It's really not much at all.
Yeah.
Um, and the authorities, have you heard,
are they doing anything?
Uh, no, I don't know about that.
Um, I did not, I've not,
I expect that people have been reporting
it to law enforcement.
Um, I, I, I, I've heard Praveen,
this guy who's done this analysis,
he reckons that they
were using, like,
they may have used paid services to do
the blockchain sort of scanning
for them or something.
Um,
I didn't follow exactly why he thought
that yet, but if that, uh, that, if that's
the case and maybe you have a thing there,
I mean, the, you would imagine, like you,
you
couldn't imagine that it was someone who,
if someone was looking up all these
addresses,
like on a blockchain Explorer before they
got taken,
then that's a good IP fingerprint,
maybe, you know,
like the software is looking it up
because they have to do that.
In order to actually find whether that
thing has money,
there's a certain pattern that they
will reach out to the software,
like the blockchain explorers to check.
Cause this person doesn't have their own
Bitcoin node probably.
Right.
So they're going to reach out on the
internet to find out whether an address
has money or
doesn't have money before they take it.
Um, and so that's the hope, I guess,
is just trying to IP locate or, or,
or maybe they're
signed up to something to get this data,
just try and get that person.
And I hope,
I hope that they do obviously hope this, um,
this money can get returned
somehow.
Yeah.
But what do you think is kind of the
biggest lesson that we've had from this
recent cold
card attack,
like in terms of what we should be doing
with our custody moving forward?
Yeah.
So this is this, you know,
the two ways to answer it is like,
what should I be doing right
now?
Um,
and I don't think that if you're a
Bitcoin user, you need to do anything.
Um, unless you were a cold card user,
which you need to go back in time.
Uh, the,
the thing that you should be aware of,
like the information that you need to know
is that if you should not be confused on
this point, you know,
hardware wallets generally
are trusted third parties,
same way in exchange as a trusted third
party.
Right.
So if you think you're like,
I'm withdrawing from this exchange onto
my hardware wallet.
Oh, great.
I've gotten rid of trusted third parties.
No, because that,
that manufacturer is a trusted third
party of your hardware wallet.
And it's much worse than you think.
Like you might think, Oh, if I,
if I do like,
if I follow these guides and I generate
my own
seed or I do my own dice rolls.
And that's what a lot of people have come
out thinking about this because people
who
did their own dice rolls and had their
own passphrase did not get attacked.
Okay.
They did not lose their money.
I mean,
so people are thinking that that's really
the lesson.
Uh, unfortunately,
that's just the peculiarities of this
particular bug.
It's not actually a fundamental,
fundamentally,
the bug could have been different, right?
So that everyone who did dice rolls lost
all their money, right?
Uh,
because they didn't do the dice roll
entropy correctly and they skipped all
the other entropy
in case of the dice rolls.
I mean,
there have been people who lost all their
money doing dice rolls on cold cards.
They'll let you do a single dice roll.
Yeah.
I did hear there was one instance where
someone did a single dice roll and got
sweeped.
Is that right?
Yeah.
I mean,
I'm saying that people just did a dice
roll and that was the whole wallet.
This is before this attack.
Oh, right.
Yeah.
So I'm like,
like there was some guy on Reddit who
said like, hey, I did a dice roll and
like, well, my money's gone.
What's going on?
He says, yeah, you rolled a six.
Yes.
You know, because he got the,
you just reversed engineered from the
single dice roll.
For some reason,
the interface let you put in a single
dice roll.
So I want to be, you know,
I want to just like point that out,
but okay.
Yes.
You could make the interface correct and
make sure that people actually try to
try and make sure people do the dice
rolls though.
Definitely people just click different
numbers.
Also not real dice rolls.
And so anyway, the point, the point, the,
the,
the real headline is I want you to know,
there's this thing called dark Skippy,
which is the attack we developed a dark
Skippy. com.
You can see the video and it's got
someone who chose their own words totally
outside the
hardware wallet and loaded them in.
And they still lost all their money.
And it's because even though the device
is using those seed words and those seed
words
don't exist at the time that you created
them on anyone, anywhere else, that device,
even though it's fully air gaps,
can send that thing over because they can
send transactions.
I mean, they sent, they send those devices,
assigning devices, they send signatures.
And unfortunately the way Bitcoin
signatures work,
they can have little messages in them
that no one else can see,
which is a big surprise to many people,
right?
No,
no one thinks if you think about a
signature, when you write on paper, you,
it's very hard
to leave a little cryptic message inside
there.
Right.
But unfortunately the digital signatures
we use in Bitcoin and,
but not all digital signatures
do leave.
You have a little space to put messages
in there.
And so you can, um,
you can send those messages out,
unfortunately.
And so no matter what dice rolling you do,
whatever,
the thing is still a trusted party.
Uh, it's still possible to do this attack.
It's pretty practical.
And now you've got AI and stuff.
Like you can see that the main thing
stopping people from finding and doing
this attack is
just simply that the effort was required
to find it and then effort required to do
it.
Right.
It's like, even if I find such a thing,
I'm going to have to spend a week writing
code and
stuff and to get this whole thing started.
And I have to like probably hire,
maybe hire some GPUs from the cloud.
And so, and that's another thing,
like you were mentioning,
what could we find this person?
Maybe the people like started using GPUs.
Uh, maybe they didn't, maybe they used the,
like a remote GPU to do it.
Uh, they wouldn't necessarily need to,
they could have done it on their laptop
or their
laptop's GPU.
Uh, but you know, the stuff like that.
So the effort has just gone to zero, right?
So if you look at attacks,
like even if sophisticated attacks,
like dark Skippy, the effort is going
to zero to do this.
Right.
And so if you think that this,
if you're worried about this hardware
wallet company being malicious
and taking your money, well, I mean,
just don't use it because they're, they,
you can,
you can do this.
Now there is some hardware wallets that
do not allow you to do these attacks.
Um,
I'd say the most comprehensive in this is
our hardware wallet, where we do not allow
the devices to generate your seed by
themselves.
We don't allow them to sign the rent, the,
the, they,
we do not allow them to either put
any messages inside the signature because
we randomize them.
Uh, and so we,
we have like comprehensive protection
against both those things.
There are some hardware wallets that do
protect against the signature thing.
If you use them with the companion
software, um, yeah.
So those would be the bit box and the Jade.
If you use them with the companion
software and you plug them in via USB,
like not using
PSPTs,
they will do this protocol and make sure
that the signatures don't have messages
in them,
but neither of those two do it for the
key generation.
So for the key generation,
you will have to go and roll dice and do,
you know, or choose
seed words or something, uh,
to get it and then verify that those
things were actually
loaded correctly.
It's not,
it's not just enough to just generate the
seed words.
You have to load them in and trust them.
The device is using those seed words and
not using some other seed words already
held by
an attack.
And so you have to, you have to verify that,
that the addresses you actually receive
money
to are actually from that, um,
from those seed words you gave it.
So that's the other, that's the other trick.
And so I just want to, the, what I want,
the thing you have to know really,
unless you,
unless you really want to take those
steps to buy a Jade or buy a bit box or
buy our product
and, you know, do, do the,
what's necessary to remove the trust from
the device.
Uh,
you are just going to have to acknowledge
that this is,
these devices are trusted third
parties and they may be very good trusted
part third parties.
I would have said that until this thing
happened.
I would have said, Hey, cold card, you know,
or bit box or any of these things,
you don't
have to,
you don't have to worry at all really
about these guys attacking you.
Um, you know,
luckily we have great companies,
the Bitcoin space,
they have proof of work in
their brands, but yes, in theory you are,
they are trusted third parties and they
can
take all your money if they ship you a
bad device.
And there's almost no way for you to
check that.
Um, and people don't like that news,
but I always try to temper it,
like try to say, no,
you don't have to really worry because
they're good companies, right?
So they're better companies in exchange
and they have a one off window to attack
you, right?
Exchange can fail at any day in the,
you know, in the last five years,
you lose all your
money, right?
Because as soon as that, that,
if they have a millisecond or whatever it
takes time to,
where their security fails,
then all the money's gone.
Uh,
as long as they shipped you a good device
initially,
then your money will stay secure for
the whole time,
unless you upgrade it to a malicious heart,
which some people did in this
case, right?
So it's, um, that's the, that's the thing.
The window for the attack is much worse
on a hardware wallet.
Uh,
so you should be in theory and they
should be a good company and they should
not be trying
to attack you because they're in Bitcoin
for a long time.
Like why would they want to steal
people's Bitcoin?
Um, in this case,
they probably were not trying to steal it.
I definitely don't think that this was a
malicious attack.
I think it was just a mistake,
a completely insane mistake.
Um, and so, but you know,
if you want to protect yourself against
malicious hardware wallet manufacturers,
you do not do, you do, you have to be,
it's very hard.
That's basically the, the, the,
the headline, our product, we make,
we do a really good job
on this, I think, but, uh, it's still not,
like still not perfect.
So our product cannot leak the seed words
to Intaka, um, in any way, but they can all,
they cannot,
you can always have this problem where the,
the, the wallet can just say it's
a signing device.
So what we reduce it to a sign device,
like if you put all these protections in
the wallet
just becomes a sign device.
So it becomes like a pen that can just
sign the transaction, right?
Um, there's still things it can do in that,
in that scenario.
What, like, what was,
what it can do is just, I refuse to sign,
you know, I've run, I've
magically run out of ink to sign this
message now, uh,
unless the transaction sends this
guy, you know, a bunch of money, right?
So, and then you,
then you get coerced sort of by the
device itself to put an address of
some attacker in there and then it will
sign the funds away.
I'll take 10% or something, right?
Because there's no way to stop that kind
of thing.
The best you can do is make it a signing
device,
which is actually what you think about it
as,
but they are not actually that because
they generate seed words for you and they
can leak
messages in the signatures usually, right?
And so they're not really signed devices.
The best you can do is make them signing
devices.
And then once they are signing devices,
they still have that thing where they can
just refuse
to sign a thing that doesn't give some
guy attacker money.
Of course, if that ever happens to you,
you should not do it.
You should just say,
just sit on your laurels there and say,
uh-huh, wait, wait until, wait
until, um,
technology progressive progresses further
so we can circumvent this device.
Uh, you know, what I would like,
of course in the, do this attack,
then they have to say
like, they have to give you bad backups,
right?
So you have to have,
there would be bad backups and you try to
back up, you use your backup
for something else and it doesn't work.
Okay.
So you can't restore.
Uh, and so that's, you'd find out like this,
this is a ransom attack and you,
you basically
should not pay the ransom at this point
and just wait until, you know,
everything has,
as, uh,
everything has developed on the technical
side of people studying what has happened.
And then they can go, okay, listen,
this is actually how we're going to trick
this device
into thinking it's being paid, uh,
or something like that.
Right.
Uh,
or is that we're going to actually
extract the key, you know,
bypass this hardware security.
Uh, so this is, this attack,
this ransoming attack is very,
I think very unlikely to actually
happen because it's very, uh,
imagine if I was to try and do this to
you on hardware
wallets, I sold you like it's, it's, it's,
um, absolutely, uh, unacceptable.
Like I'll be going to prison and you,
I'll probably not get any money, uh, either.
Um,
I'll just really piss off a lot of people
and ruin my life, you know, sort of thing.
Unless people do the pay the ransom.
So you've got to just,
as long as people don't pay the ransom in
this situation, then reducing
this to a single sign device that can,
the best attack can do is just refuse to
sign is
probably good enough for the industry.
But right now we're not there.
Like our device, our product is there,
our product is new, you know, there,
there are
many, you can be, I don't, I don't, uh,
shame people or be cautious about our new
way of
doing things.
But I think that what we're doing is
setting a sort of standard by which the
next generation
will, will, you know,
we'll have to live up to, uh, because yeah,
like there, it's actually
pretty easy to get rid of this trust in
the device.
It's not, it's not difficult technically,
like it's not risky technically, like this
cryptography needed to randomize the
signatures so that they do not leak
messages.
The technology needed to make sure the
device is choosing the seed words or the
secret it's
using, uh, randomly is very simple.
It's been known out for a long time.
So it's,
it's just not been integrated into the
Bitcoin systems.
Okay.
So the Bitcoin systems is like the,
it initially started,
like you just don't want your money
on your laptop, right?
So get your money off your laptop.
So this other thing will generate the
seed words and keep the seed words.
It never goes onto an internet connected
device.
So no one was thinking at that time, like,
okay,
but that device now is a trusted third
party and like it could generate bad
entropy or just malicious entropy.
And so, so it's not,
it's just not integrated into the Bitcoin
tech stack.
And there's a lot of money on that tech
stack and it's very,
not going to be easy to move
it, right?
Uh, incrementally, right?
BIP 39 is one of the things that gets in
the way.
These are the seed word format itself.
This is one of the things that gets in
the way of actually making those seed
words verifiably
random, uh,
for another device to contribute
randomness to it.
So, so BIP 39 is probably not going away.
We had to do away with BIP 39 for our
product.
We, we have our own format, which can,
which where the,
your phone or your laptop can mix
in randomness to it without seeing the
secret can mix in randomness to it and
make sure that
nothing like what happened to cold car
can happen.
So it's a big bandaid to pull off, right?
Um, you know,
hopefully we get some momentum to move
and fix these things fundamentally
through
the whole stack.
Uh, at least we believe,
we believe we should,
that's what we're doing.
That's what we're doing.
Yeah.
Um, well, you know,
there's the saying that every tragic
plane crash makes air travel safer
for everyone.
So that's the silver lining.
But like,
if I'm completely honest with what's
coming up for me during this conversation,
um,
as much as I'm an advocate of not your
keys, not your coins and that, you know,
everyone
should and can learn self custody.
Obviously it is a huge learning curve if
you're coming in.
Um, but you know,
you are able to do it if you just put
your mind to it.
Um,
it still sounds to me that most people
don't have the skillset.
Like there's so many different attack
vectors from retirement attacks,
wrench attacks, supply
chain attacks, nonce attacks.
You just can't learn all that stuff.
So do you,
do you almost think that self custody is
a lot harder than, than we make it out to
be?
Well, I, yeah, to,
to eliminate the device being a trusted
party, like without the tools
that we use to do that,
cause like our product is designed around
that principle.
Um, if you design,
if you don't design it from the ground up
for that, you won't get
it.
And yes,
you will be left with telling the user to
load the seed words onto different
devices and check to have the same
address and all that kind of stuff.
Um, you know, you get this advice,
which is not bad advice.
Just use a Linux laptop, actually, you know,
just take a laptop, install Linux on it and
just have like Sparrow on there and,
you know,
connect to the wifi just to do a
transaction
and then,
then lock and it's fully encrypted and
whatever.
And that's about the bar you can do.
If, I mean, if,
if you can then verify the signatures on
the software and all that kind
of stuff, right.
That's it.
It's maybe the easiest way to eliminate
the trusted party, uh, aspect of it.
Um, yeah,
I think that it is too much to ask people
not to have this, these devices
and to actually interrogate the devices
so that they're not trusted parties.
Um, for the most people.
And even like the thing is,
I could say most people,
it's almost everyone.
Like, I mean, people,
even people who are DIYing this seed
signer, like you see our attack
on that, you know,
all I need is access to your seed signer.
If I find your seed sign, anyway,
I can swap out the SD card and then your,
your money's
gone.
Now there are some, there are some models,
right?
So there are some models that you can do,
um, with seed signer or with the open,
the existing
Bitcoin stack, uh, which is like you make,
you want to do out of two out of three
multi
SIG or something like that.
And you put different seed signers in
different locations and the seed times to
stay with the
seeds and you keep them super secret, right?
So you're just using your ability to hide
stuff.
Your ability, if you, you can't,
you can actually just get it down to your
ability to hide things.
And then you remove the trust from the,
the devices sort of thing.
If you just multi SIG and you,
you have multi vendor, multi SIG,
but that actually has, that's
actually like all those,
the problem with this multi SIG solution,
uh, in the, in the traditional
stack is that it leads these backups.
And if you lose the backups,
you actually lost all the money.
So this is, this is like another thing.
It's like another non solution to this
problem is just like have all one
hardware wallet, you
can lose all your money.
So you have many hardware wallets.
So it doesn't,
it doesn't really solve the problem.
And so what, I mean,
we think it is easy though, actually,
if you take the, if you just take
the science and you build everything from
the ground up again, and you don't,
you just don't
hold any, burn any incense before the, the,
the gods of Bitcoin, you know,
traditional security
thought,
and you just redesign everything up from
the ground up, you actually can make it
super easy.
I mean, it's not totally trivial.
Like we have this, when you use our product.
You're going to have several devices.
So it is multi-sig, but it's true,
even if it was a single SIG, right?
So if you can,
and you can use it as a single SIG,
it's just a bit, it's a bit odd to do
it because it doesn't have a pin number.
There are no pin numbers on the devices.
If you just have a single one,
even if you just have a single one,
you plug it in, right?
And you generate a key.
Uh, then you, you do this check.
Like there's a check.
You have to check like eight digits are
the same on the screens.
So it's like the phone has an eight digits.
The device has eight digits and you check
that the same.
If you check that the same, you're,
you're good.
Okay.
And you do the address verification, those,
those tasks, right?
We try to make that easy on the devices.
Then, then you're good.
Okay.
So that's how, that's how difficult it is.
It's just checking these eight characters
are the same.
And so I think most people can handle that,
but not everyone, you know, not everyone is
going to be looking, looking at this, uh,
you know, and checking little codes,
like eight
characters of hex codes and like making
sure they're the same.
It's some, it's not the iPhone experience,
right?
Um,
so you cannot make self custody like this
iPhone experience.
That's for everyone.
Uh,
it's without removing the trusted parties
in it.
Okay.
So if you don't have trusted party, you can,
but if you don't want any trusted parties,
you got to, it's going to be, uh, tricky.
It's going to be a little bit tricky.
We've made it as easy as you can do it.
And that means like, okay,
I don't want to say no trusted by, I mean,
you've got to verify
the phone app and software yourself.
Somehow you can like with AI,
it's getting easier, right?
The integrity of this software should be
getting better because of the way that AI
is, we can,
we can interrogate all this software.
Yeah.
You know,
like a sovereign way without having to be
software engineers with a million hours.
Right.
And so I think in practice,
you can sort of get rid of the trusted
parties to a reasonable
degree and then actually make it easy.
It's never going to be just like the
thing you'll give to your grandma
necessarily.
Right.
Um, I don't know.
I think that that's the, that's the,
it doesn't have to be as hard as it is,
but it cannot
ever be so easy.
Right.
Well,
that's one of the questions I was going
to ask you.
Do you think it's only a matter of time
until self-custody does become an iPhone
experience?
Or do you think it's never going to get
there?
I want to say it can be an iPhone
experience,
but like the self-custody and there's a
lot of being your own bank, you know,
how much money are we talking about?
You know, that's the,
that's sort of the question.
Um, you can have, you know,
just an old Android phone and own the
keys on it and you're doing
self-custody and you're probably going to
be all good.
You gotta, you gotta do the backup.
But like, once again,
like we're talking about a lot of
technical things.
Once again,
like people can just come to your house.
And so what are you going to do about
people coming to your house?
Right.
And so if you need to geographically
distribute things and ensure they're
secure from physical
attackers, I mean, that's not,
that's not an everyday task for an iPhone
user, right?
iPhone users just get happy notifications
or whatever.
Then I have to think about like physical
locations and the security of those
physical locations that often.
So you've got to have like,
put an adversary mindset,
like where do I want to put these devices?
How do I want to authorize transactions?
It's not like some super smooth
experience thing that can be made super
smooth.
I think you can see like evidence of that.
If you look at like the BitKey thing,
I mean,
you end up with systems that are
attackable from,
from reduced risk,
self-custody reduced risk,
but they're attackable from the company
itself.
They,
they are risky in terms of physical
security.
If you're ever with the BitKey thing,
you know, then you can send all your money.
So that's a, you know,
that's not acceptable.
You know, we don't,
we don't find that acceptable.
We don't have all your money in one place
for the Frostnap ever.
That's sort of our thing.
Get your money out of your house.
And so that,
but having your money in your house is
super convenient, right?
So if you can't have your money,
you're driving, right?
You're going to do a drive or you're
contacting someone.
Can you please sign this?
You can have no, you can make it,
you can make it as easy as possible,
but like it's,
you have to think carefully about it and
you're, you're a, you're an,
you're a target for physical
attacks and torture and stuff.
And this is not like a,
you have to break the bubble of the
iPhone generation sort of thing
in order to get them to,
if you want to adapt and actually hold
onto your own money.
This is not a new problem in history.
I mean, many people tried to start banks,
you know,
in their local town in the United States,
right?
It's just like,
cause banks were just like printing money.
Right.
And they did it.
And then the,
the criminals put Darwinian pressure on
that.
Right.
You can, it's, it's tricky.
You, it's not, so, it's so not impossible,
right?
So you need the right, the right vault,
the right policies around the vault.
Like just be a sensible about it.
And you can self custody, be your own bank.
It doesn't have to know with our system.
You have to know technical things really.
You have to follow technical steps.
Like check this number of matches here.
Okay.
That's not the biggest thing.
That's one check.
Okay.
Should be okay.
And then you put them in different
locations.
Okay.
That, that most people can handle that,
but it is not the kind of normified
experience like,
uh, that,
that appears in some like marketing
advertisements.
Like anyone can do this, whatever.
It's not anyone, it's people who are, uh,
who want sovereignty, true,
real sovereignty and
don't want trusted parties for their base
Bitcoin ownership.
I think that's really important for me.
Like I actually had my Google account
hacked and like thinking about like,
what is the implications
of that?
Like if I had like a smooth thing with
like a Google cloud backup or whatever.
Right.
Um, I think like stuff like bit keys,
they'll back up something to your Google
drive.
Like, what is that thing?
What's the security implications all of a
sudden of me,
my Google account being hacked.
Um, but because my bonnie's in frost nap,
there's just like,
it's not even physically in one
place.
There's no, it's offline,
not physically in one place.
Like what I'm very comfortable in the
situation.
Right.
I've, they, they got my emails and stuff,
whatever.
I don't even read my email.
So it's sort of like, uh, it's,
it was a bit of a scare.
I had to go and make sure that nothing
bad had happened.
Luckily, nothing,
I think they didn't get anything from me.
Uh, but that's still, um, it's,
it's really a good place to be is just
that comfortable.
Everything is offline.
Nothing is in one place.
I'm, uh,
my Bitcoin is so secure that I can't even
conjure it in any place.
Right.
It's almost, it just barely exists,
but it is still easy to recover.
Okay.
So that's, that's the difficulty.
The difficulty is there's attackers.
You got to think about what,
from their perspective, we've got the tools.
That to do that.
So you can get,
you can take these tools and think about
it from this perspective and make
do a really annoying setup for them that
they really hate.
Right.
And then you can also, um, conquer this,
you know, guy called the fuck up fairy.
Right.
So the,
the fuck up fairy is going to make you
lose all your money because you made some
mistake.
Was it something that you didn't
understand and added a passphrase and
forgot it?
Uh, you know, this kind of, this guy,
we don't have that stuff in our system.
We say like, listen,
you've got to put those devices in
different locations.
There's redundancy there.
You've got to tell your loved ones what
to do.
If you pass away or become incapacitated
or whatever, and how to,
what they're meant to
do.
And this is a serious conversation to have.
Like that's one of the interesting things
about it.
And one of the,
actually the best feedback we get from
the product is people who like
finally start talking to their family
about their Bitcoin because of our
product.
Whereas if you to do it properly without
a product, you have multi vendor, multi sig,
and it's
all like, who's going to get the call card?
Who's going to get the, this thing?
Oh, the call card just had a massive thing.
We have to replace that with this one.
You know what?
So we get good feedback that they can
finally talk to their wife or talk to
their children
and say, listen,
this is the thing that you get your money
back.
You go to your sister together.
If I pass away, and this is what you do,
you just plug these into this app and
it's all
back.
There's nothing pins to remember,
passphrase stuff.
We don't do that.
So we do everything is just geographic
distribution, secure locations.
And that's not the iPhone experience, right?
It's not that, that,
that will never be the iPhone experience,
but it's an important experience.
Like it is, it is, um,
it's an intimate experience.
It can be like you,
you have these conversations you would
never otherwise have.
Like,
what do I do if someone's calls and like,
what if, what if I call you up at 2am
and say, I need to get access to my things,
you're not allowed to let me in your house.
You have to have this kind of conversation.
This always is outside the ease of use
that we're used to in our technology.
So you have to sort of just put that to
the side and be a grownup sort of thing.
You have to, you know,
but you grow your inner grownup and say,
I'm going to have serious
conversations.
I am storing my money.
I refuse to leave it all with a trusted
third party.
Uh, I'm,
I need to have this conversation with you.
This is what I, this is what my plan is.
Um, no, it's not for everyone, but we,
Bitcoin will fail if we don't have people
doing this,
right?
That's the thing.
That's the,
why the product exists is sort of Bitcoin
is too important.
We cannot have the holders of Bitcoin be
so vulnerable with,
with having a trusted third
party device in their house.
They leave all their money on it and it
can be robbed from them.
Entropy, whatever can just disappear them.
That's not a, like,
that's not a revolutionary force that can
actually bring about good stuff
in this world.
If we have those people so vulnerable.
So, yeah.
So with the device, um, is it,
how many of those little components do
you need to join
to make one multi-sig wallet?
You should at least have three.
I, if I, when you, when I start,
whenever I start talking to someone,
I start getting the
information on their, you know,
their family setup.
I often find that four is the best number.
Um, more redundancy.
Like I said,
the fuck up fairy with two out of three,
the fuck up fairy has to hit you
once and then you're in trouble, right?
Uh, once or they have to hit you twice,
but once and you're,
you're at risk of being hit
another time and it's over.
So I like the two out of four.
Um, you know, having,
you have like one in your house,
you have one like totally separate.
You don't know about with your spouse, uh,
in their family home or some other place
that
you don't, you don't even know about.
You have one that you can access maybe
with a lawyer or accountant,
some professional or
like a sensible friend, you know, uh,
with good security in their, in their house.
And you like leave one with them.
Yeah.
Yeah.
So, so don't, and someone who like will not,
will be able to handle the situation when
you're
like knocking at their door at 2 AMs with
a guy with a knife at you, right?
If that, that happens to be the case.
Right.
And then you have one like far, far away.
Right.
And then your spouse knows about the one
far away and she knows about her one.
And then you know about your two with
your buddy and your buddy knows that you,
you know,
you tell your, you,
you sort of tell them how they're meant to,
what they're meant to
do.
If you are not no longer there and the
recovery then is,
is there's nothing impeding the
recovery other than those two,
those people meeting and figuring out
what you want.
Right.
And if one of them has got, you know,
if you've got leave a will and you give
them specific
instructions, which I recommend you do.
It's a,
it's a weird thing to go to a friend and
give them specific instructions about
this
device and what you are meant to do and
what you're not meant to do.
But it's a good conversation to have.
I thought I have always,
I always found it rewarding this
conversation, actually.
It's kind of interesting.
It's outside the,
it's outside the normal slop conversations.
Right.
Yeah.
So, but like in that case, in that case,
let's just kind of go through an example
with four
devices that are geographically
distributed.
In case there is an attack and the
attacker wants you to go to a secondary
location, is
there a way to still protect yourself?
So you're not giving away everything at
once?
Like you kind of incrementally making it
harder and harder for them to get to,
you know, the
full stack.
Yeah.
So whenever you start to try and limit
things,
you usually have to involve some kind of
service
that will like pro like implement this
program.
There are people who want to do this kind
of stuff, like with the Bitcoin rules.
So like in the Bitcoin script or, uh, yeah,
to, to put these kinds of limits and things
in, um,
we don't have that kind of feature yet.
And so we don't, we're not against it.
We're, and we,
and there are obviously one of the things
you can do is put the limits on
the device as well.
Device can say, no, you've already spent,
you know, this much.
Yeah.
Like spending limits.
But the problem is, is that there's backups,
right?
And we don't,
we believe that backups are important.
You must have, you,
you need to have like some exit that is
not depending on the device.
And so these backups always allow you to
circumvent the policies.
And so when you have this kind of home
invasion, like where you scenario,
don't know, like the,
the question maybe you should ask is like,
okay, they,
what you might tell them is like,
this is my buddy, Steve, or my,
my accountant is Larry and he's at this
address and he's open
nine to five and my thing is there.
Um, they might, I mean, there's two,
there's two things they can do.
They can call up Larry right there and
there and say, just read me the seed words,
right?
They don't have to go physically go to
the other location.
Just read me the seed words.
In that case,
what you want to have informed Larry is
to not, do not receive, read the seed words,
no matter what they say.
And just call the police and tell them
your address immediately.
Right.
Uh, you can, you can make, you can make a,
you can make a gay, I mean, if you're,
if you're, if he's, Larry's up to it,
you could make some deception where
you're like,
I'm just looking for the seed words.
Right.
And you've already called the police, uh,
sort of thing.
But I don't even think you need deception
all the time.
It's, it's, it's, you cannot,
Larry can just say, listen,
I've just called the police, uh,
and put down the phone.
Uh, the, the, the, yes, it's possible.
Some, it leads to some retribution or anger,
but the thing, um, the,
the thing is that that is what they don't
want you to do.
Right.
So you should usually be doing what they
don't want you to do.
Um,
especially if they're not in the situation,
but if you're in the situation,
you should be cooperative.
But if the other people outside the
situation, uh,
they have to call the police because that
is,
puts the attackers in such a difficult
position because they are in your house.
They do not want to be there.
If there are police coming,
they are going to go.
Um,
they are probably not going to leave a
trail of bloodshed along the way because
they may get picked up on the way and
they don't, they do not want to go to jail.
They don't want to turn this one night
into jail forever.
Uh, so criminals are emotional.
They may get angry and this kind of thing.
It is a, it is a risk,
but all things added up,
you should tell them not to read the seed
words out.
And call, call the police or some,
someone who can come to the door.
Right.
Uh, and knock on it.
And so this is, uh,
this is probably what will happen.
Now they may, you may,
they may decide to keep you there and
they'll send one guy over to Larry or
whatever.
To do the tack on him.
That's also a risk, right?
So Larry's address,
they've managed to social engineer them
themselves.
Like being an Uber driver or Uber
delivery or something into the,
into the Larry's place.
If they hadn't counted on doing this,
it's going to be very tricky for them to
pull them off.
Like the probability of any kind of
success in any of these situations is
unfathomably low.
And that's why if they know that you're
doing this system in the first place,
they're not going to target you.
Um, but yeah, that the,
the instructions you should give those
other people is just do not read anything
over the phone.
Be sensible with people calling you,
you know, uh, you know,
if they're saying they're my buddy or
saying something,
then they need to come up to your
apartment.
You know,
they've trusted they could handle the
situation.
Uh, but it's not, it's not like two,
attacking two houses at one night is like
way harder.
Right.
And if she's not a house,
it's like an office building or something
like it's not even open.
It's just like,
it's the criminals just don't want to be
there.
They're going to exit the situation.
Um, so that's how the system will work.
Right.
So you, you, people get concerned like, oh,
if I leave with my mom,
they just call up my mom and, you know,
threaten my mom and my mom will just do
what they say.
It's like, well, it depends who your mom is.
Right.
So you need to be talking to people, uh,
who will follow the instructions.
Right.
Will not just panic and read over the
seed words,
no matter what they get sent in pictures
or whatever.
Uh, yeah.
So that's the, that's the basic,
the way the system works.
Now there are getting out of such a
situation, still just a skill, um,
that no one should ever have to exercise.
Right.
One thing I think does help is to be able
to give them some money.
So if you have a lightning wallet or
something that you can give them probably
does help.
Uh, this attacks are new.
And I don't want to say that we have like
strong conclusions on any of these things,
but the key thing is don't have all your
money in your house and you won't be as
much of a target.
Uh,
calling people out from that house or
visiting other houses is such a huge risk
for them because they're in your house
already.
They're not in a kidnapping,
like that's basically a kidnapping in
someone else's place.
Right.
When you might as well just do a
kidnapping then.
Right.
So you do a kidnapping and you put them
somewhere else and then you're,
you're safe while you're doing the
kidnapping.
If you're doing a kidnapping in someone
else's house, it's just, it's, um, it's,
it's a no go.
It's a non-start.
It does happen.
It has happened like a couple of times.
Like a home invasion has turned into a
kidnapping.
It doesn't end well, well for the criminals,
but it's not a great experience,
but it's still, uh,
it's still better than giving them all
your money.
Um, yeah, that's what I would say.
It's,
it's never great to have a bunch of
violent people in your house and nothing,
nothing will ever change that.
But having your entire savings in there
with them is not improving the situation
at all.
Like in case you thought it was like,
not the criminal psychology is that
that's going to, you know,
having an outside is going to,
is actually an improvement to the
situation.
They want to leave that.
They are nervous.
They want to leave that situation as fast
as they can.
Man, Lloyd, this is just,
this conversation is so insightful and
I'm glad we had it, but it's like,
it's heavy.
And to think about these things,
like it's so important to do so and to be
prepared before you ever need it.
But it is, it's hard.
It's a hard conversation to have.
Yeah, I, I, I agree.
Uh, it's, it's, it's hard,
but once you like,
once you start looking at it, it just, um,
it is, it relaxes you.
Like it's better to answer the question.
Right.
I mean, it's not like, it's not,
it's better not to just hope that doesn't
happen to you.
It's like,
I know exactly what I'm going to do.
Okay.
Yeah.
Like anyone for any reason could come
into my house and kill me at any time.
Right.
To me, there's no,
there's no physical force field that will
prevent this kind of thing other than my
door or whatever.
But if they're really intent on it,
they will get me.
Um, but the probabilities are low.
Okay.
So that's,
and you're just managing a low
probabilities in the end.
Right.
So that's, uh, that's, uh, that's,
you should, you should explore that,
you know, demystify the situation, um,
about what you want to come out of that
situation.
Uh, don't,
there's no need to throw your hands up in
the air.
Things are not so predictable that you
can control all the situation, but it's, uh,
you can set it up.
So the outcomes are not catastrophic.
Right.
Yeah.
That's the main thing.
Um, well,
thank you so much for your time today.
Um,
I'll obviously add all your details in
the show notes.
So people know how to find Frostnap and
can find you on Twitter as well.
Um, do you have any other things you'd like
to share with my audience?
Uh, no, thanks.
Uh, thanks for listening.
Thanks for the interview me Anja and, uh,
stay frosty out there.
Stay frosty.
All right.
Thanks.