AI Just Cracked Coldcard's Security
Brian walks the timeline: roughly 600 bitcoin (about $38M) swept from 500 wallets almost instantly, a figure Block's security team says has since grown past 1,000 BTC, all traced to a flaw that let Coldcard's on-device seed generation default to far too little entropy, live since 2021 and unnoticed for five years. Coinkite first said only the MK3 was affected, then aligned with Block's finding that the MK4, MK5, and Q are exposed too, deprecating the MK3 and pushing firmware updates. Michael lays out the math: a real key is 256 bits and effectively uncrackable, while this exploit collapsed entropy into the 30-to-40-bit range, and the hosts warn single-vendor multisig can be reconstituted from the wallet's own configuration, echoing Wizardsardine's call for affected users to move to new devices quickly. The hosts argue the deeper shift is AI: cheaper compute has lowered the barrier for digital, social, and physical attacks, so an old setup no longer holds up at today's prices. They close by contrasting it with Onramp's Multi-Institution Custody: bitcoin secured across three independent institutions in a 2-of-3 design, with custody insurance through Lloyd's of London covering Onramp's operations against private-key compromise (not client assets), and the client retaining title throughout.
Chapters
00:00 - Introduction to the Cold Card Exploit and Its Impact 02:18 - Technical Breakdown of the Firmware Vulnerability 05:11 - Implications for Hardware Wallet Security and Industry Risks 08:45 - What the Exploit Means for Cold Card Users and the Industry 11:01 - The Changing Landscape of Bitcoin Custody and Security Strategies 20:18 - Potential Impact on Other Hardware Wallets and Industry-Wide Risks 22:39 - Adapting Custody Strategies: Multi-Sig and Distributed Security 33:22 - The Future of Bitcoin Security and Industry Evolution


