**Dante Coco** (0:00)
Massive news today. If you're a Bitcoiner and you've gone down the rabbit hole of self-custodying your Bitcoin, then you need to listen up. You may be one of the thousands of people out there whose Bitcoin is at risk of being stolen, not due to any fault of your own, but a bug found in the code of wallet manufacturer Coldcard. This isn't clickbait, this is not a drill, this is real. And there's some people out there that believe that this bug find isn't random, like Dr. Jeff Ross. Is this actually just a coincidence? I get why people are asking that question. The timing is genuinely weird. You've got Scott Besson, the Treasury Secretary, publicly pressuring the Senate to pass the Clarity Act. And in his announcement, he quotes Satoshi Nakamoto directly, which is strange, but especially for a government official. And at the same exact time, hundreds of Bitcoin are being drained out of these wallets who were affected by this bug. This is sending people scrambling towards exchanges, where with the passing of the Clarity Act, those assets can be seized, controlled, frozen, and regulated with the new laws that are coming out. So here's the question on the table. Is the Coal Card exploit being utilized, intentionally or not, to scare Bitcoiners into giving up self custody, while Washington finalizes the rules for custodial crypto? And regardless of whether you're interested in that or not, you need to tune in, because we have some steps to help you protect your Bitcoin, if you're one of those that could be affected. We've got a lot to cover.
This is Dante Coco, Bitcoin Simple. Let's go.
I've personally been in Bitcoin for 10 years, and I've never seen a story as concerning as the one that we're about to break down today. Let me get my personal thoughts on the table right away. I don't think that this is a coordinated attack. If you haven't heard, there was a bug found in cold cards code by Block, the creators of Square and Bitkey. What they found was their random seed generator wasn't in fact as random as it should be. Nerds would call this term entropy, and the seed generation from cold card wallets, specifically MK3, didn't have enough entropy, which can lead to the discovery of the private key, which will allow your Bitcoin to be spent, sent and used. This is a wallet generation problem that started in 2021 and is coming to roots in 2026 after some deep dive discovery and people finding out that single SIG wallets, not using Tapper were being drained. I don't believe that this was a live back door where a switch was flipped so that Senate members can vote to add more provisions and more security and surveillance into a bill that's about to be passed with the Clarity Act. But that still doesn't negate the fact that if you have purchased cold card products in the last several years, my advice would be to you to generate a new wallet and to send your Bitcoin to a new address. If you're not sure what to do or how to do it, this is exactly why we partnered with the team at The Bitcoin Way. Members of their team will teach you exactly how to do this step by step and how to help you mitigate the process of you losing hard earned Bitcoin that you've stacked and saved over the years. Schedule a meeting with the team using the QR in the description. This isn't affecting everyone in Bitcoin or all Bitcoin wallets. This is affecting a subset of old single SIG wallets that were randomly generated by cold card products, mainly the MK3. MK4 and MK5 may also be affected. So while Jeff's instincts are correct in that you need to pay attention to who benefits from this sort of crisis, I don't think it was a coordinated attack.
I'm glad to see Dr. Jeff Ross is back, but I don't see any connection here. The point that we need to get to right now, how do you mitigate from your Bitcoin being stolen right now? Here's a great explainer from Stefan Lavera on how to do this exactly.
**Stefan Lavera** (3:25)
Everyone, a quick important security warning for people, especially for listeners and followers out there. If you are using a cold card, a big serious security vulnerability has been found relating to low entropy. The main vulnerability is on the cold card, Mark 3 version firmware 4.0.1 from a few years ago, but it is still also impacting newer versions, whether that's the cold card Mark 4, the Mark 5, or the cold card Q.
There are some mitigating factors where if you used dice rolls, so let's say 50 rolls for a 12-word seed or 99 rolls for a 24-word seed, or you had a strong passphrase, or you are using multi-seed with multiple devices, then you are mitigated from this vulnerability. But otherwise, you should strongly consider checking your setup, checking your coins, and migrating to a safer setup. Now, if you only have a cold card and you don't have anything else, don't worry, don't panic. There is a thing called the BIP39 word list. So this is a practical mitigation step for you. That BIP39 word list, which I'll link in the description, there are 2048 words there. You go through and find seven randomly, write down in order those seven words, create a new wallet on your call card, use those seven words as your passphrase. So you have the new seed words and the seven word passphrase, and then migrate the coins out of your old insecure setup into the new passphrase protected one. So this will give you some breathing space while you think about your next steps, and longer term, think about things like multi-seed using multiple device types, and maybe using dice rolls for adding entropy to that setup also. So that's the situation as it currently is. It is now 10 a.m. in Dubai on Friday the 31st of July. I'll try to keep updates going as this situation will evolve further. But that's the main step. So don't panic. Think about your setup and migrate into a passphrase protected setup if you don't have another device to move to.
11 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID