**Natalie Brunell** (0:00)
Welcome to the Coin Stories News Block, powered exclusively by Ledn. I'm Natalie Brunell, and in about 10 minutes or less, I'll provide you with insightful updates on Bitcoin, financial markets, and the global economy. Everything you need to know in one block. Let's go.
Let's start with the story the entire Bitcoin community is talking about right now, because it affects anyone who has ever used a coldcard hardware wallet. This past week, attackers drained more than 1300 Bitcoins worth tens of millions of dollars from thousands of wallets that all had one thing in common. Their recovery phrases were originally generated on coldcard devices. The number is still growing as Galaxy Research continues tracking additional waves of the attack.
Now, to be clear for some context, in dollar terms, this is not the largest theft in Bitcoin's history. Mt. Gox, Bitfinex, and FTX were all bigger, but those were exchanges, centralized platforms where someone else holds your keys. This is the first time a major self-custody device has been compromised at such a scale, and that's what makes it so alarming. And this is also important. It doesn't matter if someone later moved their Bitcoin to a different wallet or even a multi-sig setup. If the seed phrase was originally created on an affected coldcard, you're at risk. So here's what happened. When you set up a coldcard, you either let the device generate your seed phrase for you or you create your own using physical dice rolls. Now, most people, of course, take the simpler route and let the device handle it. That seed phrase is supposed to come from a dedicated hardware random number generator, RNG, which produces what's called entropy. It's essentially randomness that's so complex that guessing the seed phrase is mathematically impossible. But in March, 2021, a code change in a Coldcard firmware update switched that process. Instead of using the device's dedicated hardware to generate your recovery phrase, affected Coldcard started using a much weaker method, one that produced seed phrases that were far, far easier to guess. Think of it like the difference between a combination lock with a trillion possible combinations versus one with a few thousand. And nobody noticed this. Not Coinkite, not users, not reviewers for more than five years. Well, this week, someone figured it out. The attacker reconstructed private keys remotely, never touching a single physical device, and they swept wallets clean across thousands of users. Galaxy Research reported the initial wave drained over a thousand addresses in just about 40 minutes. Coinkite has confirmed the flaw and published an advisory and believes the attacker may have used AI to find the flaw in the code. They acknowledge that their own AI review of the same code missed it entirely.
Now I want to say something personal about this. Coldcard used to be a sponsor of Coin Stories. I have used the product myself. I want to be transparent about that and I also had to move funds last week. I feel terrible for promoting a product that failed the people who trusted it. When you produce free content, sponsorships are part of how the work gets funded. I do the best I can to partner with companies I believe in and products that I actually use and trust. But as I've learned, no product is infallible and this situation is a painful reminder of that. So my heart goes out to everyone who is affected. Losing Bitcoin, especially from a device you trusted to keep it safe is devastating.
As soon as the story broke, I recorded an emergency episode with Rob Hamilton from Anchor Watch to walk through exactly what happened, what it means for self-custody and what steps you need to take right now. The episode has no sponsor and no ads. It is just information, so please go listen to it. If you own a Coldcard, check the advisory and take the steps that are recommended to move your Bitcoin if you haven't already. Self-custody remains one of the most important principles in Bitcoin. But this is a reminder to stay vigilant, to diversify your security practices and never assume any single device is beyond failure.
Ledn has a perfect track record of protecting client assets during every market cycle, backed by proof of reserves. Ledn is the home of Bitcoin-backed loans for the serious holders. The larger the loan, the lower the rate. Your Bitcoin stays custody and is never lent out for interest. Get a quarter percentage point off your first loan at ledn.io/natalie.
Let's turn now to strategy because a significant shift happened last week. During its Q2 earnings call, strategy confirmed that it will no longer allocate 100% of future capital raises to Bitcoin purchases. Instead, proceeds will be split between buying Bitcoin and strengthening the company's cash reserve with the ratio depending on market conditions. Saylor explained it this way. If we sell $1 billion of credit, I don't think you'll see 100% Bitcoin and zero US dollars is the norm. I think it'll be a ratio.
3 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID