The Honest Money Show

How did 1,500+ Bitcoin, worth over a hundred million dollars, vanish from hardware wallets, and what does it mean for anyone holding their own coins?

Tim joins Honest Money to break down the Coldcard wallet exploit, the technical flaws behind it, and the hard lessons it holds for Bitcoin self-custody. From weak entropy generation to the growing role of AI in both attacking and defending wallets, Tim explains what went wrong and how to make sure it doesn't happen to you.

This conversation explores how the exploit worked, why open source matters for security, and the best practices that keep your Bitcoin safe in an evolving threat landscape.

🎙️ EPISODE SUMMARY

Tim and Anja discuss the Coldcard hack, hardware wallet security, and how to protect your Bitcoin.

The conversation moves from the details of the exploit and the scale of the losses, through the law enforcement and recovery challenges, to the technical flaws in the firmware and entropy generation that made the breach possible. Tim explains why open source software fosters security through transparency, and what real self-custody discipline looks like.

The episode also examines best practices for creating and protecting your seed, the lessons every Bitcoiner should take from this event, and the future of hardware wallet security as AI reshapes both the threats and the defenses.

🔗 FEATURED LINKS

Galaxy Research: https://www.galaxy.com/insights/research
Galaxy HQ on X: https://x.com/galaxyhq
Alex Thorne on X: https://x.com/intangiblecoins
Red Team First Responders: https://opensats.org/blog/code-red-supporting-first-responders

🔑 KEY TAKEAWAYS

Generate your seed in a trustless environment using dice or a reliable entropy source
Minimise technology in cold storage: simple, offline solutions are safer
Move your coins immediately if you're using a vulnerable hardware wallet
Open source software fosters security through transparency
Weak entropy is a critical and often invisible point of failure
Human beings are extremely poor sources of randomness
AI tools are becoming both a serious threat and a valuable defence
Self-custody demands ongoing personal responsibility and vigilance

⏱️ CHAPTERS

0:00 Introduction to the Coldcard Hack and What Happened
2:19 Can Victims Recover Their Coins?
8:12 The Timeline of Hardware Wallet Development
10:35 The Entropy and Firmware Mistake
14:26 Which Models Are Affected and Urgent Advice
17:06 Temporary Self-Custody Options and Support
19:22 The Three Parts of Bitcoin Custody
23:42 Daily, Operational, and Cold Storage Use Cases
31:53 Does This Mean Self-Custody Is Dead?
33:52 Why Humans Are Bad at Randomness
37:59 What FOSS Means and Why It Matters
46:04 Why AI Is Accelerating Attacks
47:29 Can White Hats Return Stolen Coins?
50:35 Final Thoughts and Resources

🔗 AFFILIATE LINKS

Buy Bitcoin in Australia With a $10 Sign Up Bonus
HARDBLOCK: https://hardblock.com.au/join/honestmoney

Learn to Acquire, Secure, and Manage Your Bitcoin
MINERACKS: https://www.mineracks.com/honestmoney

Shop Signing Devices, Bitaxes, Nodes, Apparel, and More
SHOP BITCOIN AUSTRALIA: https://shopbitcoin.com.au

Collaborative Security, Inheritance Planning, and Retirement Strategies
THE BITCOIN ADVISER: https://thebitcoinadviser.com/honest-money

Reached Terminal Bitcoin? Borrow Against Your Bitcoin Without Selling
LOAN MY COINS: https://www.loanmycoins.com/honest-money

📌 ABOUT THE HONEST MONEY SHOW

The Honest Money Show explores the forces shaping our financial world, from monetary systems and personal finance to Bitcoin. Through in depth conversations with builders, thinkers, and educators, the show challenges mainstream narratives and provides practical insights into financial sovereignty.

🔗 CONNECT WITH US

Subscribe for weekly deep dives into finance, economics, and financial literacy.
Follow us on Instagram, X, TikTok, and LinkedIn at HonestMoneyShow.

⚠️ DISCLAIMER

This podcast is for general information and educational purposes only and is not financial, legal, or tax advice. The views expressed by the host and guest are their own and do not represent any organisation or regulatory body. Financial markets are volatile and speculative. You should seek independent professional advice before making any financial decisions. By listening, you accept that all actions taken are your own responsibility, and neither the host, guest, nor the podcast accept liability for any loss or damage.

#Bitcoin #Coldcard #Coinkite #HardwareWallet #SelfCustody #BitcoinSecurity #ColdStorage #BitcoinAustralia #FinancialSovereignty #OpenSource #Entropy #WalletSecurity #HonestMoneyShow

What is The Honest Money Show?

The Honest Money Show is your guide to understanding what money really is, and where Bitcoin fits in. Hosted by Anja Dragovic, Australia's female-led, Bitcoin-only podcast, it cuts through the noise to explore how money shapes our lives, why the current system leaves so many people behind, and what a clearer, fairer future could look like.

Expect honest, accessible conversations with some of the most interesting thinkers in the space, the kind that take you from "I don't really get this" to genuinely curious. No hype, no pressure, just money, made clear.

Whether you're brand new to these questions or already deep in them, you're welcome here.

About fifteen hundred Bitcoin lost.

the value in US dollars is over a hundred million dollars.

The exploit was potentially

a generated exploit from an AI.

Bitcoin is the canary.

These same tools are going to be used by nation state hackers

against banks, governments, insurance,

payment processes — every damn thing.

Joining me back on the show today for a

very special and important episode is Tim.

Welcome back to the show, Tim. Hey,

thanks, Anja. It's great to be back. Not

such great circumstances, but yeah, we can

dig into that. Yeah, so let's dive

straight in. Obviously, the Coldcard hack

happened. Specifically, what happened and

what have we learned from that?

Yeah, so broadly, a hack was found for the

Coldcard wallets from CoinKite that they

were able to exploit what is essentially

weak, what's called weak entropy. And that

enabled them to steal and sweep coins that

were stored in Coldcard hardware wallets

and had been for many years. And at this

point today, we're about 1,500 Bitcoin

lost, about 7,500 coins have moved, UTXO,

so some obviously smaller than a Bitcoin

and some multiple Bitcoins. The value in

US dollars is over $100 million. And we've

gone from one attacker exploiting the

vulnerability to, hey, I'll have some of

that as well. And there's around about 15

or 16 groups concurrently attacking the

vulnerability and sweeping people's coins.

So really, really, really tragic for

people who've lost coins. Yeah, so far in

kind of the Australian community, I only

know maybe of one or two people that have

been affected. Is there any chance for

these people to get their coins back?

There is a slim hope. So Australia, along

with Canada and the US, are the top three

affected geographies, at least according

to chain analysis. So not good, not good

in Australia. I'm aware of more people

than that that have lost coins, some

smaller amounts and some much more

significant amounts. Can they get it back?

Is going to depend upon ultimately law

enforcement? At two levels. So the first

will be, can they identify the perpetrator

or perpetrators? And having done so, are

they able to get control of the coins? So

there were a few apparent missteps. So

there is the potential that the original

perpetrator used a blockchain analysis

platform to identify potential candidate

addresses before executing the attack. So

it was a targeted attack. And that was

with a logged on account. So there will be

some credentials associated with that

person, with that account. The second one,

which is, I guess, a bit more of a rookie

error, is having swept about 500

addresses, they then swept them all into a

single consolidated UTXO. So it's very

clear for those first, I think, two

sweeps, which have gone into two

individual addresses, that that was all

executed by the same person. So Alex

Thorne over at Galaxy Research has done an

incredible job keeping on top of this. If

you are in the unfortunate position of

having lost coins, please reach out to

Alex. So he is intangiblecoins on Twitter,

now called X. And he will try and put you

in touch with law enforcement. He will tag

the addresses of the coins that you lost

so that they are included correctly as

being stolen. And that will at least give

a small chance of recovery. So the two

parts of the recovery are, firstly, law

enforcement's got to catch the dude or the

dudette or the people. And then they've

got to get control of the coins. And then

they've got to return the coins. So it's

very difficult to know how likely that is.

The last part of returning the coins,

unfortunately, law enforcement does not

have a good record on that. If we think

about the Bitfinex hack from 2014, 15, the

coins were recovered, some 80,000

bitcoins. They are still in the US

government's control. They have not been

returned to Bitfinex yet. So, and as we

saw with Mt. Gox and the collapse there,

the bankruptcy proceedings and return of

coins to holders, obviously a very

different circumstance. But that took over

a decade. So I would have to say it is a

slim hope.

I'm really, really sorry for everybody

who's lost coins. It has really hit the

community hard because it's not like Sam

Bankman-Fried and friends who were

egregiously fraudulent and literally stole

people's money. This was plebs doing what

they thought was the right thing, probably

air gapping their Coldcard and thought

their coins were as safe as they could be.

That's why it's hit a lot of us pretty

hard. Even if we haven't personally lost

coins, we've been very busy helping people

protect their coins, move their coins into

new wallets, teach them about the entropy

they should have set up and so on. Yeah.

Unfortunately, like Coldcard has very

much been marketed as one of the more

secure wallets to have. And so a lot of

people who were recommending it are now

feeling obviously very guilty about that,

even though, yeah. So let's maybe talk

about the technical detail because from

the research that I've done, it seems like

you could have been something that was

very easily missed in the code. So just

before we dive into that, I just want to

make a comment about the people who have

been recommending Coldcards. Coldcard

was a good recommendation last week, not a

good recommendation this week. The people

I know who have recommended Cold
card,

some of the Australian community, some

international podcasters like Matt O'Dell

and Marty Bent and Stefano Lavera, they

all recommended it because they used it.

This wasn't something that they were paid

to do and they did it because they were

paid. I know each of them secured their

own coins and their family's wealth using

Cold
card. They walked their talk and they

are absolutely gutted to find out they

have been, they feel misled, deceived and

hoodwinked. And I feel, yeah, I feel for

those guys. It is a very difficult thing

to make specific recommendations for

Bitcoin security. And when you do, you

kind of, yeah, you take a little bit of

responsibility for those coins that you

help secure. Yeah, very tough. So what

happened? So the timeline looks something

like this. So stepping back a little bit

further, I've got some notes on this.

2014. So in 2014, Slush and Stick in

Trezor created the first hardware wallet.

Before 2014, there were no hardware

wallets. And they created the very first

one. In 2017, CoinKite forked the open

source software, the FOSS software that

Trezor had built for their firmware. And

they started building a new hardware

wallet. And in 2018, they launched

ColdCard Mark I and followed that on with

iterations Mark II, Mark III, Mark IV,

Mark V, and most recently the ColdCard Q.

In 2020, a new company called Foundation

Devices started up and they did exactly

what CoinKite did. They forked the

CoinKite firmware and started building on

that. And that is the beauty of FOSS, is

you get to stand on the shoulders of the

giants who've come before you. So the

founder of CoinKite was very upset about

that, which quite frankly was pretty

hypocritical, given that he had started

his own company the same way or started

building the product the same way. So

irrespective, he made the decision to

remove the GPL license, which is one of

the major FOSS licenses, free and open

source software, and downscale it to a, I

think, Creative Commons license. So it was

source viewable. Everybody could look at

the source. One of the implications of

that, though, is by removing his firmware

as GPL, he could no longer use anything

below that was GPL, because you inherit

the license that keeps things open. So he

had to remove GPL components and replace

them with new components. Some of those

components were written in-house, and that

is where the core coding error to do with

the entropy came in.

So there

were two parts to that, two significant

failings. So the first was that if the

random number generator couldn't be

invoked, then it would fall back to a

software random number generator. So

random number generators are the mechanism

by which a hardware wallet or a software

wallet comes up with a random number. And

so we want that to be very, very random, a

very, what's called, technically, that's

called a high amount of entropy. And as it

turns out, the fallback mechanism did not

have a high amount of entropy. It had 40

bits or less, I think. That meant that the

range of possible keys, instead of being

billions, you know, atoms in billions of

galaxies across the universe, came down to

a much smaller amount. Well, that was the

first error. That was an implementation

error. Probably, in my view, the more

egregious and unforgivable error is that

there was a fallback there in the first

place. So from a security perspective, you

want to stop. You always want to err on

the side of caution. It's not, hey, excuse

me, can we get through that special door?

Oh, you don't have the code. Oh, that's

all right. We'll just go around the side

door. It's like, no. If you can't use the

hardware that you're supposed to be using,

that is to do with the creation of the

secret, then you stop. And maybe that

means the device has failed. So the reason

for those design decisions are only going

to be known internally at CoinKite. Same

with the code change. But CoinKite is

accountable for all of those. And I'm sure

there's, well, I've seen some of the

conjecture about whose fault it is,

theories about it. There will be an

unlimited amount of time that law

enforcement and forensic investigators and

lawyers will dig into that in detail, I'm

sure. So in a nutshell, the secret

creation component of the wallet was not

fit for purpose. The secrets that were

created, the C words, were not

sufficiently random. Someone discovered

that vulnerability, built an exploit and

ran the exploit and is thousands of

Bitcoin richer. And plebs are thousands of

Bitcoins poorer. And it's devastating. It

really is devastating. So when the news

first came out, I believe they only

mentioned that MK3 was the hardware or the

model that was compromised. All the others

were still deemed safe. But now it seems

like that it's MK4, MK5 and the Cures. Is

that correct? That's correct. That's

correct. So MK3, the Mark3 with the

compromised firmware is the most

vulnerable. If you are listening to this

and you have coins on a CoinKite Mark3,

you need to go and read their security

advisory. If the wallet was created with

the compromised firmware, I really hope

that you added the dice roll entropy and

or created a strong passphrase. If you are

listening to this, irrespective, get it

out, create a new secure wallet and move

your coins ASAP. Yeah. And on that note,

if someone is feeling very spooked or not

confident following these events, should

they be rushing this process? If they're

on a Mark3, getting your coins out of the

Mark3 ASAP, they really need to hustle.

They really need to hustle. Unfortunately,

there was a story from someone in

Australia who was warned about this, I

think, on the Friday or the Saturday. And

they said, oh, I'm busy. I'll do it on

Sunday. When they came to look at it

Sunday, coins were gone and they were

swept on, I think, Sunday morning. So

those sorts of things are really

heartbreaking. So, yeah, move them. I've

got friends that have moved fairly

significant amounts of funds onto phone

wallets. They've downloaded a wallet, set

the wallet up. You're just using the

phone, create me a seed, write the seed

down, back up and move the whole whack

onto the wallet. And just gone, OK, it's

not going to get swept. Now I've got a

little bit of breathing space for

everybody else who's on Mark4, 5 or Q, or

in fact, any of the coin, any of the coin

kite wallets, the coin alt card wallets.

At this point, my perspective is the

design flaw with allowing a fallback on

the random number generator is so

egregiously bad that what other design

decisions for which I do not have the

competence to go and look at hardware,

firmware code and evaluate, but others may

and probably will. What other poor

decisions have been made? In my view, if

it's a cold card, you need to move your

coins off. Period. Yeah. We've heard from

a few exchanges in Australia that some

people have been moving their coins to an

exchange as like a temporary interim

measure. Is that reasonable advice for

like a quick fix if you don't have the

means to acquire another wallet or I don't

know? Yeah, it is. The first thing is not

to lose the coins. And if you have an

exchange with this, you've got an existing

account on, then moving those coins onto

the exchange to give you the breathing

space of a few days or a week whilst you

dodged a bullet there. Okay, I'm going to

have a calm, quiet space. I'm going to set

up a new wallet. I'm going to test the

wallet with a small amount. I'm going to

make sure I've got the seed phrase backed

up. And now I'll transfer. So that is a

possibility. Several other groups have

come out offering assistance and help.

GuardBlock at HardBlock have done so. If

you need to move your coins in there

quickly. Peter and Andy's group, the

Bitcoin Advisor, have also offered that.

No charge. No obligation. Just get your

coins in safe custody first. Have some

breathing space and then step back and set

up your new wallets and take the coins

back. As has Rob Hamilton's Anchor Watch

in the US. Anchor Watch is insured by

Lords of London, but not available to

Australians, unfortunately. So US only. So

yes, number one thing, save your coins.

Number two, get yourself some breathing

space. Figure out what you didn't do on

the Coldcard. And then select the new

method and move your coins back into self

-custody. Yeah. So let's go back to the

basics of self-custody. Obviously,

everyone has different advice. What the

different ways to self-custody your coins.

So what have we learned from this

particular scenario that we can do better

moving forward? Yes. I think that's a

really good point to start on you. Is

there are three things that are important

with Bitcoin. So I don't want to get stuck

into the details of are you using seed

phrase or Shamir secret sharing? Are you

using a passphrase? Are you using

multisig? Are you using collaborative

multisig? Are you using three or five? Are

you using frost? Are you using legacy

multisig? None of those things. They all

come back to this basic idea of a secret.

So the secret could be single seed, could

be multisig. You can have passphrases on

it. You could have all sorts of all sorts

of mechanisms. But in the end of the at

the end of the day, it's a secret. The

secret is your Bitcoin. If you control the

secret, you control your Bitcoin. So.

Three, three things that are important.

The first thing is creating the secret.

That was the thing that the Coldcard,

especially the Mark 3, was not fit for

purpose. So if you used the Coldcard to

create the secret, you outsource that. You

introduce trust that did not need to be

introduced. Instead of taking the time to

use entropia, which is my personal

favorite, or dice or cards, and there's

various mechanisms and approaches for

doing that. Instead of building the

entropy in a trustless way in the real

world, you said, ah, I'm too busy for

that. Trust me, bro. I'm going to take the

trust me, bro option. Coldcard. You just

create. You create the randomness. You

create the seed words for me. And I'll

just take them. It'll be good, right?

Yeah. So the first thing that essentially

all wallets or all Bitcoin needs is the

creation of the secret. The second thing

is you need to protect the secret. So on a

hardware device, that will be keeping the

private key in a secure enclave, making

sure that there's no way into the secure

enclave. And we can look back in history

and we can see, well, the very first

Treasors, if you've got physical access to

that Treasor and about 100 bucks worth of

electronics, you can extract the private

key from the secure element. Ledger showed

that. Ledger showed that's possible with

some of their ledgers. Ledger have a

security, a black hat team or white hat

team internally. So they try and crack

their own devices. And they showed that

was possible. They needed a quarter of a

million dollars worth of machinery and

special lithography and x-ray from memory.

But the general takeaway there is hardware

devices need to be physically secured. If

you have control over a hardware device,

you can potentially compromise it.

Obviously, the hardware device

manufacturers work very hard to make that

exceptionally difficult. And they always

strive to make it impossible. So that's

the second thing, protecting the secret.

And if you're not using a hardware wallet,

then you're protecting the secret in

another way. Perhaps you're encrypting it

on a USB. Perhaps you're encrypting it

with very strong encryption and you're

creating multiple copies. And maybe you're

keeping them in digital places. Maybe

you're keeping them on devices. And then

the third thing, so we can we need to

create the secret. We need to protect the

secret. And the last thing is we need to

use the secret. because although we love

to save Bitcoin and protect our savings

from overreach and inflation and all of

that, there comes a point where we want to

spend Bitcoin. And that, I think, is where

there's a little bit more subtlety. So

this is the way I think about it. So the

segregation of the different types of

custody that you want or the different

types of control and protection that you

want is different depending on how often

you use the stack. So for example, if I've

got the self-custody version of Wallet or

Satoshi, I'm fine with that on my phone. I

might have a couple of hundred bucks in

it. When I go to a bush bash or a meetup

and someone's selling soap or beer or

coffee or lunch, I can easily just spend

that. So that's something that I would use

on a daily or weekly basis. Easy. So would

I prefer to be able to create the secret?

Yes. Can I? Lightning kind of depends. If

you're going to run your own Lightning

node, yes, you can. But yes, that's out of

the reach of most people. So you're going

to use a wallet where that's going to be

created for you. And that's probably, it's

not ideal, but it's okay for small

amounts. And it's about balancing the

risk. And we're going to use that

frequently. The other end of the scale is

your cold storage. So I've started buying

Bitcoin. I have no plans to spend it. I

know it's part of a long-term plan. I'm

not going to touch it for five to 10

years. Okay. One hundred percent. I am

going to create those seeds offline. I am

not going to introduce any trust me bro

component into that. And maybe I'll use, I

might start off with just a single

signature because I don't have very much

Bitcoin. And then as I accumulate more and

more Bitcoin and as the price of Bitcoin

goes up, then maybe I'll start thinking,

hey, single SIG is a bit of a point of

failure. And you move to multiple

signatures. So in that case, you

absolutely categorically want offline seed

creation. No ifs, no buts, no wiggle room.

The second part of that, the protection of

the key, you want minimum tech, i.e. no

tech. So how are we going to record those

words? Maybe you put them on steel plates.

Maybe you write them on multiple pieces of

paper that are kept in very secure places,

possibly bank vaults. Everyone has

different thoughts on this. It's not my

role to make decisions for anybody except

me. So that's the securing part. And the

little story, I think you've probably

heard me tell this at a bush bash, is when

I first started in IT, the really cool

personal storage was eight inch floppy

disks. And then I think when I got to uni,

it was five and a quarter disks. And then

it was three and a half inch disks. And

then it was CD drives. And then it was DVD

drives.

And now we've got USB Cs. And if you go

and buy a new laptop, some of them don't

even have the original USB A ports on them

anymore. They certainly do not have CD

drives. And they most definitely don't

have floppy drives. So the key point I'm

making there is, if your storage is for

the long term, you want the absolute

minimum of tech. Tech is not your friend

for long term storage. In my view,

hardware has no place in cold storage.

Super simple. But that's just my

perspective. But as a general rule, you

want the minimum of tech in your cold

storage. So creating the key, protecting

the key. The last part, of course, is

using the key. So again, cold storage,

it's the most important part of your

Bitcoin. That's where you want to keep

that air gap between the key and the

signing. So you'll often hear people talk

about signing devices as opposed to

wallets. So not all signing devices can

hold a key. The Seedsigner is a good

example of that. So that's what's called

ephemeral keys. You've got to physically

load the key into the seed signer in order

to sign a transaction. There's a trade-off

to that. The trade-off is if you're using

a Seedsigner, that means your seed has to

be physically available to you somewhere.

And so if you talk a lot about using a

Seedsigner on a daily basis, that means

your seed is available somewhere. So those

are the two opposite ends of the spectrum.

And then there's one in the middle. And in

a Bitcoin business or for people who are

using a lot of Bitcoin or using Bitcoin on

a daily, weekly, monthly basis, that's

what I think of as an operational wallet.

So you might be spending hundreds or

thousands of dollars a month, for example.

And so you don't want the complexity of

maybe getting multiple keys that are kept

in different places altogether on a weekly

basis or a monthly basis. Way too much

friction. So that's where I think a

hardware signing device can be really

good. I've used a number of them. My

favorite at the moment is one they don't

make anymore, which is the Foundation

Passport. Very simple. Looks like a Nokia

3310. It's kind of a flashback for the old

dude, right? And it has the basics of I

can read the partially signed Bitcoin

transaction from Sparrow. I can sign it on

the device. The key is on the device. And

that makes life easy. It's a nice balance

in between. So I think those two things

together are a good framework for thinking

about how you set your keys up. So if

you're early in your Bitcoin journey,

you're still learning, you've figured out

that it's an important part of your

financial future, probably your cold stack

is, or most certainly your cold stack is

the most important thing. So you

definitely want analog key creation,

secret creation.

You probably want the minimum of tech in

the protection.

And the signing device, you can kind of

figure that out later. Because if you're

not expecting to touch it for 10 years,

it's all good. The middle one, that's

where you've got, that's where you're

potentially going to bring a hardware

signing device into it. And then usually

the daily spending, you're probably on

your mobile phone. So three things,

creation of the key, creation of the

secret, protection of the secret, use of

the secret, daily use, spending, weekly,

monthly use, operational. Maybe there's a

hardware wallet in there. And third, the

cold storage. Yeah, you want the minimum

of tech and you want, you absolutely

categorically want offline key, offline

secret creation. Yeah. For people who are

listening into this and thinking, gosh,

this all sounds so complicated. And

obviously there's some people as well that

have been saying that this event makes

self-custody dead. Is that true? Most of

us, most of us can read and write and we

can write down 12 words. And if you can

write down 12 words, you can do self

-custody. Now, where Bitcoin is

unforgiving is that there is no CEO to

call up. I mean, I've tried calling him a

few times, he never answers. But you do

need to know what you're doing. So the,

and that comes back to the issue of

entropy, which is why I'm such a big

proponent of doing creation of the secret

should be done in the real world. So you

use dice, you use cards, or you use

something like the seed pills in tropia,

where you're pouring 1,024 little, little,

little pills into, into the, you know, the

kitchen mixing bowl. And you pull 11 of

them out and you write those down on a

piece of card. And then you use a

mechanism. I use a Seedsigner. I think

you can use passport, foundation's

passport. You can use Ian Coleman's. He

has a webpage that you can download and

use offline. I put your 11 seed words in

and it tells you the 12th. So the 12th

word or the 24th word is a checksum. So

it's calculated from the other 11 or the

other 23. So you do need some tech to do

that. But you want that tech to be

offline, not connected to the internet,

because you've got to put in those 11

words or those 23 words. So you don't, you

don't want to do all of the careful,

thoughtful, considered work on the kitchen

bench, dishing out the, fishing out those

11 little tiles, only to then type it into

an online device where someone's logging

it or watching it or so on and end up

compromising. And if someone wants to

randomly select their own 24 or 12 words.

I'm not here to tell you what to do, but I

can, I can share what I've learned. And

one thing I know is that human evolution

is really good at recognising patterns. We

can pick the cheetah and the lion out of

the foliage. And those of us who can get

away and run up the tree before we get

caught, maybe not a great example with

leopards because we can find fruits, but

we're really good at recognising patterns.

And it's something we do at a very basic

level. Humans are really bad at random.

And I think in the, it might've been in

the Bushbash chat that someone was posting

about, if you ask a human, if you ask

someone to give, give you a random number

between one and a hundred, there are, I

think three numbers that are presented

more than 50% of the time. Everyone

thinks, oh, that's an unusual number. I'll

go with that one. They tend to be primes.

So 57, 17, 43, that kind of thing. So

we're really bad at being random. We're

really good, really good at recognising

patterns. And we do that pattern

recognition at a really subconscious

level. So we're blessed to have Piers,

Piers Cockrum in our broader Australian

Bitcoin community. He has built a site

called Wallet Playground. I think I'm just

going to just double. Walletplayground

.com. Walletplayground.com. On

Walletplayground.com, there are entropy

tools. And you can, you can see how

different things work. You can see, there

was a guy in the US called Jimbo. He

invented a very secure and random

mechanism for using a deck of cards to

create seed braces. And it's not just, oh,

I'll pick them out randomly. There is a,

there is a quite a defined process. Same

with using dice. There is a defined

process. Those are all available on, on

Piers site. And then there's my personal

favorite, which is the Entropia. I bought

that locally, hands up on the Sunshine

Coast, printed, printed them all out on

his 3D printer. I think it was $150. So in

some ways, quite expensive. I really only

used it a couple of times up until about a

week ago. And it's had a hammering over

the last, it's been borrowed by lots of

friends and it's had lots of use. And I've

been very, very glad. The key thing I like

about it is you don't have to explain

entropy. You don't have to explain

randomness. You can just pour all the

pills in the, in the jar as I did in a

kitchen bowl, as I did with my brother.

And he's like, oh my God, how many of

these are there? 1,024. And he's like, oh,

they're different on each side. And I

said, yeah, 2,048 sead worth. And he goes,

oh, wow. So he pulls one out. We write

that down. I said, now chuck it back in,

give it a swirl. He goes, oh, okay. I get

how it's random. I said, yes, you and I

could sit here until the end of the

universe. And we'd never pull out the same

12 in a row. Same, same 12 twice. So you

do need, you do need, you need a defined

process to achieve the required level of

entropy that guarantees the security of

your secret. And that's what Coldcard did

not have. It was not fit for purpose. Let

worries. So you mentioned FOSS before,

which stands for free and open software.

Is that it? Free and open source software.

Source software. That's it. What's the

significance of that? So FOSS, the free is

free as in freedom, not free as in beer.

Now they, it is a very important part of

Bitcoin because FOSS software is software

that everyone can see, anyone can

contribute to, if they're smart enough and

their ideas are good enough and their

skills are good enough. And you can build

on top of it. So everyone who's built a

product on or around or on top of Bitcoin

has been able to leverage that. And that's

why the importance of FOSS in the Bitcoin

community is really, really, it is really,

really significant. You cannot step away

from that. And I think the CoinKite

decision to revoke the GPL license was,

will be used as a case study of why that

reversing that decision led to, ultimately

led to their downfall and the loss of so

many customers, life savings and funds. So

the, so free and open source software,

it's, it's just so important. FOSS or

free, free open source software networks.

So there's quite a few of them and they

all lead to total domination. So I'll give

you a few examples. When you send an

email, you send an email to me, I have no

idea what type of computer you use when

you wrote it on your phone, what software

you use to write it. And you have, you

have no idea what I read it on, what type

of computer I use, what software, and you

don't need to know because the underlying

connection between those two things is the

protocol SMTP, Simple Mail Transport

Protocol. Beautiful. Same with HTML. HTML

is an open protocol that anyone can use to

render information, create websites. Tor

is another example where it's a, it's a

protocol that can be used for the secure

transport. PGP for the security of signing

and messages and Bitcoin. Bitcoin is open

source software for the transmission of

value. So. Yeah, it's come up for me as

Yeah. So everybody, everybody likes to

use, uh, open protocols, but nobody wants

to pay for them. So that's where the,

that's where the rub can be. However, open

source software means we get to stand upon

the shoulders of the giants who've come

before us. Ideally we contribute into

those and other people come along and

build on top of our stuff or reuse things

that, that we've built. And in that way,

more and more people get access to more

and more functionality and software.

So I, in the corporate world, I use windows for

30 years, I guess. Um, and now I'm very

strongly an open source, uh, proponent. I

use Linux. Um, it's a far superior product.

It doesn't scan my, my data. It

doesn't charge me annual licensing fees.

Um, so you mentioned

before that there are

multiple hackers. Now there was one to

begin with, and now we've got more than

one. How do we know? And what exactly does

that mean? So I think it was Rob Hamilton

at Anchor Watch that might've initially

identified the possibility that the

exploit had been built by one of the

recently released open weight models. So

most of the U S models, uh, you cannot use

for cyber defense or cyber security or

cyber offense. And so as a consequence,

um, um, the open weight models, um, uh,

predominantly coming out of China are the

frontier, uh, the frontier models as far

as cyber security goes. So on that

conjecture, uh, a small number of

Bitcoiners, uh, have banded together as

what's called the red team. And they are

using those, those open weight models to

verify and validate that the vulnerability

existed and could be exploited. Rob did

that within, within moments, um, and then

didn't stop. So he did the broader thing,

which was to step back from helping people

directly. Uh, he has a whole company to do

that. And he started then saying, well, if

there's a vulnerability of that severity

in the coin kite, uh, ecosystem, let's,

and, and this new open weight model, uh,

two and a half trillion parameter model,

uh, uh, has the capability to identify the

vulnerability and build the exploit. Let's

point it at some of the other things in

the Bitcoin ecosystem. And so he started

doing that. Um, I think by Saturday, he'd

spent $3,000 worth of tokens. It was 5,000

by Sunday, but by Monday it was 10,000.

Um, and now they're spending 10,000 a day.

And there's a group of them working around

the clock, uh, generally referred to as

the red team, uh, the red team in a

cybersecurity context, uh, the guys who

have no holds barred in trying to hack

something. So you might engage a

cybersecurity company to, uh, to do a

penetration test and they'll have, you

know, they have a black hat team. They'll

have a white hat team. And they'll have a

red team. and the red team, uh, doesn't

have any of the constraints that the other

two teams have. And they can try every

dirty trick they can to, to attack your

particular, um, to attack your particular

service platform or software or hardware.

So whilst the, the phrasing red team for

the Bitcoin red team, uh, that's where it

comes from. They're committed to

responsible disclosure and they have been

working literally around the clock for,

for the five or six days since this

vulnerability came to, came to light. Um,

there have been hundreds of projects

affected and I think over 4,000, uh,

disclosures have been made. So it's quite

literally an avalanche of disclosures. The

wonderful thing is because we've got

access to open weight models, we can use

that for defense. So there's no question

that it's going to be used for offense.

And that's, that's clearly where in my

view, that's clearly where the other

attackers have come from. They've seen the

noise about this on Twitter. They've gone,

Oh, new open weight model. Let's point

Kimmy at the coin kite code base. Can we

discover the vulnerability? Oh yeah. Can

you build me an exploit? Oh yeah, no

problem. Here you go. And then

unscrupulous people will then try and

attack, uh, uh, potentially vulnerable

wallets sweeping coins where they, where

they were successful. So, Alex Thorne over

at galaxy, uh, research has been keeping a

note of these. And if you, as I mentioned

before, if you've been affected, please

reach out to intangible coins on Twitter.

Let him know that you have lost coins.

He'll be interested in the details. Um,

that is, that is a small thing you can do

that might increase your odds of assisting

law enforcement to get your coins back. It

is a slim chance, but, uh, that's, that's

the starting point. So ultimately, it's

the rise of AI tooling that has

accelerated the attacks. The beauty is

those same, that same tooling can be used

on the defense as well. So this is going

to be a cat and mouse for quite a while.

And Bitcoin is the canary. So these same

tools are going to be used by nation state

hackers, but they won't be used against

Bitcoin. They'll be used against banks,

government, insurance, payment processes,

every damn thing. It'll, it'll be a, it'll

be a, it'll be a rough old ride. It'll be

a bit heavy. I think was the phrase I

used, uh, last week. Yeah. Is there anyone

who is, that we know of at least, um,

who's actually trying to hack those coins,

get there before the criminals do with the

intent to return it? Well, um, possibly,

Anya, I honestly don't know the difficulty

in doing that as a white hat hacker is how

do you validate the owner of the coins? So

you find it, you find a vulnerable

address, you calculate the seed, you look

at the wallet, you see there are 28 UTXOs

in that wallet, you sweep the whole

wallet. Okay. Now you've got someone's

life savings. How do you identify who to

return those coins to? It's a, it's a

very, it's not a, it's not a trivial

issue. And you are in a very, uh, tricky

legal position, irrespective of the moral

position. So, yeah, I've heard, I've heard

the argument that coin kite could have

known of this, but, but couldn't tell

customers because it would be exploited.

Now that's possibly a defensible argument

in 2025, maybe even the tail end of 24

when, you know, when, when good AI tooling

was starting to arrive, but not in 2021

when this arrived or 2022 or 2023 or even

2024. But at this point, uh, you just need

to move your coins. Yep. And final

question. So anyone who is using a

different, um, hardware device that

hasn't, you know, completely different

manufacturer and brand who may have also

used the device, uh, to generate the, the,

the seed, then they're not generating it

themselves. Has this kind of taught us

that we really should be upgrading our

self custody setup so that we're not

waiting for this kind of thing to happen

to another? A hundred percent. Yeah. A

hundred percent. So, yeah, if you're

feeling, uh, if you're out there feeling

comfortable because you don't own a cold

card, you need to step back and go, did I

generate my secret? Did I do, did I use

the trust me bro approach and generate it

using the device? Or did I go through a

little bit more effort and be completely

sure that there is no possible compromise

to the entropy, to the randomness of the

secret? If you can't remember, assume the

worst and assume you took the easy route.

Um, and that's okay. Now you've got time

to step back, learn a little bit more, do

it correctly, and then you will sleep

better. Absolutely. Well, thank you very

much for your time. Obviously this is one

of the more important episodes I've done

on the show. Do you have any final things

you'd like to share with the audience? Um,

yeah, thanks for having me on, Anya. It's

a, it's a really, it's been a really

challenging period for a lot of people,

obviously, um, people who've lost coins,

you know, my heart goes out to you. It's

just, it's just absolutely tragic. Um, for

the many, many people that's joined in the

decentralized global support desk, uh, for

supporting Bitcoiners and receiving panic

phone calls and messages from friends and

family and others we've helped along the

way. Thank you for stepping up and helping

them secure their coins. And if you need

help, there are plenty of resources, uh,

uh, the resource I mentioned earlier, uh,

on, uh, peers, resource, wallet,

playground, wallet, playground.com has

lots of, lots of good advisory articles

there. Um, peers himself is also, uh, in

the industry. That's what he does. He

helps people set up wallets. So if you

have, uh, if you have, um, if you want to

learn more about self custody, great place

to start equally, um, explore guard block

from hard block or reach out to the

Bitcoin advisor. So the critical thing is

make sure your coins are safe. And then

you've got the, the, the clear thinking

space to make a calm, considered, rational

decision without. Great. Thank you. You're

very welcome. Thanks, Anja. Okay. Now I