Topics: Business News, News, Education
**Natalie Brunell** (0:00)
So many people had done everything right and lost their life savings.
**Clay Garrett** (0:03)
If you knew the seed, you could basically predict every random number that it would spit out. It was a tough day, but we designed Bitkey to be resilient against things like this. People do find seed phrase management difficult. Some of the people who are willing to say that privately do not really feel comfortable going and saying that publicly, because there is the sentiment that, well, if you don't have a seed phrase and keep it yourself, you're not a real Bitcoiner. There was a post on X recently that likened seed phrases to if for your entire life, you had to make sure you didn't lose your birth certificate or you died.
**Natalie Brunell** (0:33)
And you don't need a seed phrase with it. Wait a second, if I don't have a seed phrase, then somehow my Bitcoin is vulnerable. And how do you answer that?
Hey, everyone. Welcome back to the show. Joining me this week is Clay Garrett. He is the head of Bitkey at Block. Thanks so much for joining me, Clay.
**Clay Garrett** (0:54)
Absolutely. It's great to be here, Natalie.
**Natalie Brunell** (0:56)
Where I want to start is your team just jumped in when the Coldcard hack happened, and you were investigating it really from when it first broke that people had lost their coins. Can you talk to me a little bit about that? Like, what did your team see?
And I can't even imagine those early days for you because it was so sad to find out that so many people had done everything right and lost their life savings.
**Clay Garrett** (1:18)
It was a tough day. And we saw the activity on X pretty soon after it. It surfaced. And the first thing that was important for us at Bitkey was let's dig in and try to understand the root cause of this so that if there's anything that affects our code or our customers, we need to be on top of that. We need to understand. We need to respond. For example, if there was something like among some large shared dependency that many wallet providers use, we would want to know that. In the end, there was nothing that affected Bitkey. This is completely isolated to coldcards. But we didn't know that right away. There were three discoveries that we made in the early hours of the investigation after we started. The first one was really centered on what was the root cause of the hack.
A lot of people at the time when it first started assumed that there was something wrong with the random number generator, seemed like an interview problem. That turned out to be true, but it was not clear right away what was the source of that. The good news is that Coldcard's source was public. It was not open sourced in terms of being able to be free to be used, but it did give us a view on the code and allow us to dig deep and analyze it. The Bitcoin security team started digging in immediately into the code base for Coldcard. What they found is that the code had a misconfiguration where it intended to route the entropy through the hardware random number generator. But because of the misconfiguration, it actually routed it through the software one. It was even a deterministic one where it's basically, if you knew the seed, you could basically predict every random number that it would spit out.
That was enough to make it quite easy for an attacker to iterate through all the possibilities, check the blockchain and see if they found any addresses that had funds on them as a result.
Initially, it looked like only the older models of Coldcard were affected after a certain firmware version. I think even that was announced in the Coldcard announcement. But we identified that there were additional issues that caused even later models to be affected as well. We published what we found as soon as we could because we wanted to give visibility to those who were wondering, am I affected? What do I do if so? In the moment, it's tough because you always want to make sure that your information is completely accurate and right, but you're also up against time and people's funds. So we just made a call to put it out there and try to help however we could.
The second and third discoveries were more about the analysis of the on-chain activity. So we were trying to understand anything we could about the attackers' activity, movement to try to understand what was happening.
We wanted to discover a pattern in the first batch that was widely known. It was about, if I remember correctly, about $40 million worth of Bitcoin. That pattern was that all of them used a very specific fee rate. So it was, I think, exactly 30 Sats per Vbyte, which was quite high and unnecessary. So you think if someone is genuinely spending, why pay all the extra fees when the fee rate is not that high? So we started looking previously into the blocks that had come before the one that was known about, and found multiple transactions that had that same pattern. I think in the end, it was another close to another $40 million found that really almost doubled the amount that was known at the time. That amount has increased since then, but this was just in the early hours. So we also published that, again, to just give as much information as we had to the community. We wanted to be transparent, and this is a community investigation. It was a community event. Everyone was jumping in and trying to help, so we wanted to just share what we could as we went.
39 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID