**Optimist Fields** (0:02)
After 87 million dollars has been drained from Bitcoin wallets, everyone is now rightfully scared and wondering, am I safe? Am I next? Should I send all my Bitcoin to BlackRock or Coinbase? So today, we're going to be showing you all the new developments, all the information we have so far on what happened with this hack. And of course, as we saw, more wallets were drained over the weekend. We saw about four different attacks that happened. And of course, we're also going to be discussing what this means for Bitcoin. If everyone is too scared to hold their own private keys. So, you know, this week is going to be a little different. We're going to try to do our best to do a normal show for you guys. But obviously, I think we're going to try to get a lot of security experts on the show, give you guys the tools so you guys are fully protected. But before all that, of course, that's going to be this week. Hopefully by the end of the week, we can kind of get back to normal. But without a doubt, one of the biggest days, one of the worst days in Bitcoin history, bar none for all of us Bitcoiners. Yes, there's been other very bad days, but this one, it might be one of the worst. But anyways, let me get into this, guys. So as of now, wow, before the show, it was 1,300. It is now 1,660.6296 Bitcoin that have been bought. It's been drained, literally before I started the show, it was like 1,390. So there was a couple really big ones that just happened. So obviously guys, if you, you know, we're touching grass this weekend, there is a huge vulnerability in cold card. I would, and we were kind of recommending this, just get off cold card right now.
If you haven't done it, like it's only a matter of time until your coin is most likely going to get sweet from cold card. Now, there is a bit of caveats here, and I'll get into that in a little bit. But as of now, 1,660 Bitcoin have been swiped from cold card because there was a vulnerability in the seed generation.
And I am going to break all this down. Actually, where do I start? I think maybe here, I'll start here.
This is a good write up here guys to really explain what happened. So if you are interested in the more technical breakdown of this, I'm just going to kind of paraphrase here. Go to btcinsider underscore, and there is when random bytes run but doesn't work. This is an article. It's going to tell you the technicals as much as we know. But just to break it down, essentially what happened, and this is in layman terms guys, I am paraphrasing, but all weekend, all I basically did was just follow along on Twitter, try to understand exactly where the vulnerability was, what actually happened. And the best way that I can put it is essentially the cold card software from 2020 to, I guess, yesterday pretty much, or sorry, Thursday and Friday.
The random number generator, the true randomness, I'm sure you guys all heard of the entropy, just getting real randomness, pure randomness to create your seed phrase. Apparently when they switched their code from C to Python, it was basically triggered off.
It wasn't hitting the random number generator on the cold card, and so it was making a predictable seed. So it's basically extremely easy to brute force and guess the seed phrase. Now, if you want to get a little more technical on it, essentially most 12-word seed phrase have about 128 bits of entropy. Most 24 words have 256 bits of entropy, which is basically like uncrackable by the computation and the computers that we have right now. What happened was essentially if you are using an MK3 from the 2020-2021 era, when you were creating a seed phrase, it had about 30 bits of entropy, which is not...
It's almost at zero. It's just like... It's very hackable, very predictable. And then further, if you were using the MK4 up to the Q model, I think it had higher entropy around like 70 bits, which is obviously lower than 128 So still predictable, but it essentially means you just have more time to get access to your Bitcoin. So now I'll break down exactly here. And also huge shout out to Rob Hamilton. Actually huge shout out to a lot of Bitcoiners on Twitter. This might be... And I know it's a horrific incident, a horrific hack, but there was a silver lining here that I saw over Twitter. And again, I'm going to show you what happened, but we are going to be, I think, talking about the broader implications. I don't want to make it all doom and gloom. Again, for clarity, this, as far as we know so far, and from all of the information that we have as of now, this is just a cold card specific issue. This is just one manufacturer. So everyone else, yes, we are all now kind of re-evaluating how we custody our Bitcoin. And there's a broader conversation of like, self custody is dead, which we talked about on Friday, but we'll probably get into that a little more today. Again, a cold card specific problem here, but I am going to cover, again, one of Rob Hamilton's really good threads, kind of explaining who's protected, who is still liable to lose their funds. And he did a really good thread.
75 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID