777: Coldcard Is Compromised with James O'Beirne artwork

777: Coldcard Is Compromised with James O'Beirne

TFTC: A Bitcoin Podcast

July 31, 2026

James O'Beirne joins Marty to break down the critical Coldcard RNG vulnerability affecting devices produced after 2021. They discuss how insufficient entropy generation exposes private keys, why MK2, MK3, MK4, and Q users must migrate funds immediately, and how AI models accelerated the discovery.
Speakers: Marty Bent, James O'Beirne
**Marty Bent** (0:07)
You've had a dynamic where money's become freer than free.
When you talk about a Fed just gone nuts, all the central banks going nuts. So it's all acting like safe haven.

**SPEAKER_2** (0:18)
I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins. In a world of fiat currencies, Bitcoin is the victor.

**Marty Bent** (0:29)
I mean, that's part of the bold case for Bitcoin.

**SPEAKER_3** (0:31)
If you're not paying attention, you probably should be.

**Marty Bent** (0:36)
Yeah, I don't think we can assume everybody's heard. And I know, I think that's a bad assumption just because I've been texting people I know who have coldcards and they're completely oblivious to what was going on last night. So, yeah, sad day.

**James O'Beirne** (0:53)
Yeah, we've talked under better circumstances, for sure.

**Marty Bent** (0:59)
For those who are unaware, there is a massive vulnerability in Coldcards produced after 2021 All models, some worse than others, but essentially the random number generator that creates the entropy for private keys that you produce.
Using the Coldcard is insufficient. Is that the right word?

**James O'Beirne** (1:27)
Yes, you could call it deterministic. So the search space required to get the private key, to guess the private key basically is highly, highly limited relative to what it should be. So basically the funds under the MK2, MK3s with firmware between 2021 and 2023 are just dangling in the wind. So luckily, if you used dice rolls, if you used say over 99 dice rolls to initialize the key, you're safe.
Or if you're using a passphrase, which is basically like the 25th word, you can specify when you're setting up the wallet. If that passphrase is of a sufficient length and complexity, which is longer than most people think, then you may also be safe.
But yeah, those, the MK2, MK3s are affected severely to the point where it's like, you know, you need to drive home from work and migrate your funds.
If you're single SIG under one of those, without a passphrase, without dice, or with a weak passphrase. But we're finding, and it's part of an ongoing investigation as to the current state of the Coldcard Firmware which would affect newer devices like the Q. We're finding that the problem still exists there too, but it's partially mitigated. So estimates right now are that current users of Coldcard devices are getting about 70 bits of security whereas you're supposed to be getting 256 bits during KeyGen. But that 70-bit number is even going down because we're finding that one of the fallback RNGs that is used to paper over the original defect is actually less random than we thought, and is specified by the manufacturer. And they may be doing things like zeroing out certain parts of this ID. And so it might actually be worse than we were thinking last night for current devices. So my headline for everybody at this point is, if you're working off of a Coldcard device, after 2021, you need to migrate your funds pretty expeditiously. If you did all the dice rolls, don't worry, you're probably in good shape. But even so, yeah, I think, unfortunately, people should be making moves to get off of the post-2021 devices.

**Marty Bent** (4:26)
Yeah, I mean, we're trying to find some humor in light of this, but Coldcard, hey, listen, I've been an advocate for Coldcard for many years. If you listen to the show, I recommended it. I have my queue right here. I moved my funds off last night. Obviously, part of managing partner 1031 were invested in CoinKite, which produces the Coldcard. This is very close to home for me personally, to many people I know that have felt very confident recommending this in the past. It seems that the confidence was ill-gotten. We were joking before. It's like the Coldcard souped up to secure enclaves, but you mess up one part of it, the random number generator. It's like you got a Ferrari on top of a lawnmower engine.
Well, pretty devastating.

**James O'Beirne** (5:24)
I'm in the same boat, man. I mean, I'm a single SIG passphrase guy on a Coldcard, I think MK2. My firmware is older and unaffected, but I love CoinKite. They make great products. But the unfortunate nature of security and hardware wallets is that you screw up one thing, you screw up the wrong one thing, and it's toast. So that's the reason why people have been paranoid in this department is because you just simply can't trust one manufacturer or one source for your entropy. When you're doing entropy construction, this is what I do professionally for the last few years, is you have to be utterly paranoid when you're constructing a private key, and you can't just click a button and expect that it will happen.

28 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000779305981