**SPEAKER_1** (0:00)
Welcome back to the Daily Crypto Roundup. Bitcoin has suffered one of the most disturbing security failures in its history, and this time, the victims were not people leaving their coins on a reckless offshore exchange. They were experienced holders using one of the industry's most respected hardware wallets. Nearly 600 Bitcoin, worth roughly $38 million, has reportedly been stolen after a flaw in Coldcard firmware allowed attackers to recreate wallet recovery phrases.
At the same time, Bitcoin has fallen back towards $63,000.
Coinbase shares have plunged after disappointing earnings. Strategy has reported an $8.33 billion operating loss, and Shiba Inu's explosive rally is already beginning to fade. And before today's main stories, a quick word from Kraken. Kraken is one of the longest-running and best-known cryptocurrency exchanges in the market. New users who sign up through our link can qualify for the current 20 XRP offer, subject to the terms shown on the Kraken page. The link is in the description. This is not financial advice, and cryptocurrency trading involves a risk of loss. If you value daily crypto coverage without the hype, follow the podcast, leave a rating, and share this episode with one person who needs to understand what is happening.
Today's biggest story is not simply about $38 million being stolen. It cuts directly into one of Bitcoin's oldest arguments. That holding your own private keys is always safer than trusting somebody else. Coldcard is produced by CoinKite and has built a strong reputation among serious Bitcoin users. But researchers reportedly discovered that certain firmware versions generated wallet seeds with far less randomness than users believed. In simple terms, the recovery phrases were not random enough. Once an attacker understood the weakness, they could work backwards, reproduce private keys and drain wallets without physically stealing the device. The flaw has now been patched for newly generated seeds. But that does not automatically protect seeds created using vulnerable firmware. CoinKite's chief executive told affected users to create entirely new wallets under the updated guidance and move their funds.
That distinction is critical. Updating the device does not magically make an old compromised recovery phrase secure. A recovery phrase is effectively the master key to the wallet.
Once there is a realistic possibility that somebody else can reconstruct it, the wallet must be treated as exposed. The controversy has become so severe because many of the victims appear to have followed the standard Bitcoin advice. Buy a reputable hardware wallet, generate the keys offline, protect the seed phrase and avoid centralized exchanges. This does not prove that self-custody is dead, but it does expose the uncomfortable truth that self-custody replaces counterparty risk with several different forms of technical and operational risk. You no longer need to trust an exchange, but you must trust the device architecture, the firmware, the seed generation process, the supply chain, your backups, and your own ability to avoid mistakes. For technically capable users, that trade-off may still be worth making. For ordinary investors, however, an insured custodian or a spot Bitcoin exchange-traded fund may suddenly look much simpler.
Several industry observers believe the Coldcard incident could accelerate demand for regulated custody and Bitcoin ETFs. There is also an artificial intelligence angle. CoinKite's leadership and other security specialists have warned that AI-assisted code analysis can find old vulnerabilities far faster than human researchers could in the past. That means open-source code can be reviewed more rapidly by defenders, but also by attackers. The old idea that Bitcoin can be placed on a device, locked away for 10 years and forgotten, may become increasingly unrealistic. Security is becoming an active process rather than a one-time setup. The Coldcard fallout arrived as Bitcoin was already weakening. The Bank of Japan kept its benchmark policy rate at around 1%, with the decision passing by 8 votes to 1
One board member argued for a rise to 1.25%, while the bank indicated that further rate increases remain possible if inflation and economic conditions develop as expected.
Why does Japan matter to Bitcoin? Because Japan has historically been a major source of cheap money. In a yen carry trade, investors borrow yen at relatively low interest rates, convert that money into another currency, and buy assets offering higher returns. Some of that liquidity can eventually reach equities, technology stocks and crypto. When Japanese rates stay relatively low and the yen remains weak, the trade can continue. When the Bank of Japan raises rates sharply, or the yen strengthens quickly, traders may be forced to unwind those positions, sell risk assets, and repay their yen loans. Holding at 1% therefore avoided an immediate shock, but the wider backdrop is still difficult. Bitcoin slipped below $63,000 during United States trading as equities weakened and treasury yields rose. The 30-year United States treasury yield moved towards levels not seen for almost two decades, while the Federal Reserve's preferred core inflation measure remained at 3.3% year-on-year in June. Higher bond yields make safer assets more attractive and increase the opportunity cost of holding speculative assets that produce no guaranteed cash flow.
4 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000779316436