The Chopping Block: ColdCard's $100M RNG Hack, AI-Powered Security & Ethereum's Staking Yield Taper artwork

The Chopping Block: ColdCard's $100M RNG Hack, AI-Powered Security & Ethereum's Staking Yield Taper

Unchained

August 6, 2026

This week we dissect ColdCard's ~$100M RNG exploit that Claude Code cracked in 8 minutes, debate whether AI just killed open-source security and Bitcoin maximalism, tear apart Ethereum's EIP-8361 staking-yield taper, and unpack Leopold Aschenbrenner's 67% Situational Awareness blowup and CLARITY...
Speakers: Haseeb Qureshi, Tom Schmidt, Tarun Chitra, Robert Leshner

Topics: Business News, News, Tech News

**Haseeb Qureshi** (0:00)
The reason why volatility is so high in AI is that nobody can predict anything. People keep getting surprised. You see half a trillion dollar deltas in the open and closes on these markets, where Amazon and Apple are getting repriced 15% on a day. These things are trading like shitcoins.
And why is it happening? It's happening because nobody can predict anything.

**Tom Schmidt** (0:19)
Not a dividend.

**Tarun Chitra** (0:20)
It's a tale of two clans.

**Haseeb Qureshi** (0:21)
Now, your losses are on someone else's balance sheet.

**Tom Schmidt** (0:24)
Generally speaking, the airdrops are kind of pointless anyways.

**Haseeb Qureshi** (0:26)
Unnamed trading firms who are very involved.

**Tarun Chitra** (0:29)
I like that eat of the ultimate pun.

**Robert Leshner** (0:31)
DeFi protocols are the antidote to this problem.

**Haseeb Qureshi** (0:35)
Hello, everybody. Welcome to The Chopping Block. Every couple of weeks, four of us get together and give the industry insider's perspective on the crypto topics of the day. Click intro as first you got Tom, the DeFi maven and master of memes.

**Tom Schmidt** (0:45)
Hello, everyone.

**Haseeb Qureshi** (0:47)
Next, you got Tarun, the gigabrain and Grandpuba at Gauntlet.

**Tom Schmidt** (0:50)
Yo.

**Haseeb Qureshi** (0:52)
Next, you got Robert, the Crypto Connoisseur and czar of SuperState.

**Robert Leshner** (0:55)
Good evening.

**Haseeb Qureshi** (0:57)
And I am a Sieve, the head hype man at Dragonfly. We are early stage investors in crypto. I want to caveat that nothing we say here is investment advice, legal advice, or even life advice. Please see ChoppingBlock.xyz for more disclosures.
So boys, it's good to have you all back together. We have an interesting docket this week, starting off with bad news, because that's how we always like to do the show. First bad news, first bad news of the week is an exploit in crypto of a wallet called ColdCard. Now, I have not heard of ColdCard up until this exploit.

**Tarun Chitra** (1:27)
That means you don't follow enough Bitcoin Maxis.

**Tom Schmidt** (1:30)
Yeah, you're not a Bitcoin Maxi.

**Haseeb Qureshi** (1:32)
It's a Bitcoin Maxi wallet. Have you guys heard of it?

**Tom Schmidt** (1:35)
Yeah, I heard of it this week.

**Tarun Chitra** (1:37)
Oh, no, no, I heard of it before.

**Haseeb Qureshi** (1:39)
So Robert and I both first heard of it this week. Tom and Tarun have heard of it before.

**Tarun Chitra** (1:43)
Do you remember this guy NVK, like this Bitcoin Maxi account from like 10 years ago? Very popular, that's the person who made ColdCard.

**Haseeb Qureshi** (1:52)
Okay.

**Tarun Chitra** (1:53)
Started the company.

**Haseeb Qureshi** (1:56)
So ColdCard, very unfortunately, so ColdCard is a very minority vendor in the wallet space. They only do Bitcoin wallets. So most of the, if you think of like Ledger or Trezor, usually these are like multi chain wallets. ColdCard Bitcoin only, so it's really appealing to Bitcoin Maxis. Judging from the numbers that they have published, it's probably something like 1% to 2% market share of the Bitcoin wallet ecosystem. So it's a pretty minority vendor.
They're whole things that they're open source and they're Bitcoin only.
Now, they suffered unfortunately a very massive exploit. It looks like so far there's been almost $100 million in Bitcoin that's been drained from ColdCard wallets. Now, these are hardware wallets. So this means that the key should have been generated on device and only stored in the hardware. Therefore, the only time it should ever have access to the internet is when you plug it into a machine and do a transaction. So how are these machines all getting hacked? Well, it was discovered that there's a vulnerability in the random number generation on these devices. Now, this vulnerability was introduced five years ago in a firmware change that some developer basically just changed some random macros or definitions in some C++ code, seemingly to just get some code to compile, and they didn't really seem to understand what was going on. They wrote a one-word commit on a code change that led to this massive bug, and basically it went from a hardware wallet that's normally using very robust on-device RNG or random number generation, which is the entropy that's used to generate the key, and instead fell back to some very weak software-based random number generation, which is very easy to crack. So these insecure keys were getting generated for the last five years.
Until this weekend, it was discovered that this vulnerability was getting exploited. Presumably, somebody pointed their lasers of their AI agents looking at this code, trying to find out what could have been going wrong that caused all these keys from the same vendor to get hacked. And reportedly, somebody used Claude Code to look at this code and found the vulnerability in eight minutes. Now, this vulnerability that was found through Claude Code, people were saying, oh, this might have been contamination because maybe it was searching the web. And so somebody else took Glm 5.2, an open model, gave it no internet access, and was able to find this bug in 20 minutes.

56 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID