Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money artwork

Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

Unchained

August 7, 2026

A hardware wallet's 5-year-old randomness bug just let hackers drain over $100 million in Bitcoin. How many more waves are coming? Plus, Ethereum's fight over cutting ETH issuance. ======================================================== Thank you to our sponsors!
Speakers: Mike Silagadze, Kain Warwick, Taylor Monahan, Sonya Kim

Topics: Business News, News, Tech News

**Mike Silagadze** (0:00)
Suddenly, your yield goes down to 20 basis points, which is probably where it will end up. Okay, so now you're gonna have tens of billions of dollars of ETH unstaked out there in the market. So clearly, if you're worried by ETH price, which is one of the arguments, that this is gonna be worse, this is actually gonna be much worse.
I think the argument, and again, I would not make the argument to increase issuance, but the argument to increase issuance is in my mind actually stronger than the argument to decrease it. But the strongest thing is just don't f**k with it.

**Kain Warwick** (0:30)
Hey everyone, I'm Kain Warwick and welcome to Uneasy Money because what happens on Chained never stays on Chained. Before we begin, here is a word from the sponsors that make this show possible.

**SPEAKER_3** (0:40)
This episode is brought to you by Cape, America's privacy-first mobile carrier.
Same premium service you'd expect from any other carrier, but designed so your number, your location and your data actually stay yours. Get 33% off six months at cape.co. slash Unchained.

**Kain Warwick** (1:03)
All right. Hey guys, I'm here with my co-host Taylor Monahan, Security Expert and we have a special guest this week, Sonya Kim, co-founder of 3F Labs. Welcome.

**SPEAKER_3** (1:12)
All right.

**Kain Warwick** (1:12)
Our first segment, let's jump straight into it. The Coldcard Teardown. So for those of you who are not aware, I'm going to hand this over to Tay in a second to give us a full debrief here because she's been deep in this. But Coldcard is, was a hardware wallet, one of the minor hardware wallet players out there.
They had a small issue which basically wrecked everyone. So, Tay, why don't you walk us through the details of exactly what's wrong here?

**Taylor Monahan** (1:51)
Yeah. So, the most, I guess basic way I can put this is that one of the critically important jobs of the wallet is to generate a secure private key or seed phrase. The way that you do that is with the thing called entropy, which is just randomness. It's just that it has to be truly random. This is just like a cryptography math thing. It's not super important you understand exactly what it is. It is important to know that you absolutely need it, desperately need it.
For those who have been around for a while, you might have heard of the profanity bug. That was also an entropy issue. Basically, if you don't do the math good enough, then everyone gets wrecked.

**Kain Warwick** (2:40)
Profanity was another one.
There's been a ton of them. There's been a ton of these things.

**Taylor Monahan** (2:48)
It happens quite a bit.

**Kain Warwick** (2:51)
It used to happen more when we were still rolling our own crypto and doing weird stuff. But this thing goes back to 2021

**Taylor Monahan** (3:00)
That's what makes this incident, I think, different and crazier than all the rest. First off, Coldcard is a hardware wallet.
The way that they were getting randomness, they screwed it up in 2021 It got in the code base. It was used for five years before someone discovered it. Once that first attacker discovered it and started to exploit it, it's basically, that was like six days ago, seven days ago now, it's been a free for all since. Because there's basically five years of seeds and private keys that the various attackers are basically mining. I don't know how to explain this.
When you don't have enough randomness, you don't have enough entropy, what happens is they have to mine, they have to literally throw massive amounts of compute out this stuff in order to get it to go. Once they do that, then they take all the funds. But it takes time, it takes energy, it takes compute in order to do this.

**Sonya Kim** (4:10)
So that's why we've seen.

**Kain Warwick** (4:12)
The thing that I think I was like the last time, something big like this happened, and maybe not for vanity, I was trying to explain it to my team at the time.
When you get a vanity address, if you say, I want, and we've talked about the address poisoning attacks, where they make an address that looks like yours or whatever, and the first four, last four might take them 10 seconds to cook. But if they wanted to have the exact same address as yours, with just one digit removed, it would take a trillion years or whatever. And so, if you want 0x, whatever, dead or some address like that, it takes the more you want, the more of the address that you're trying to get, the longer it takes. And you can go to these vanity addresses and be like, hey, I want 0x, Tay is the best. And it'll be like, all right, that'll take a week. Right. Yeah. And then if you're like, Tay is the best and the smartest. It's like now it's going to take like a century. It's like a century. It's like, oh man, I really wanted that, like vanity address. Right. And this is this is kind of the same thing where like the reverse engineering.

49 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID