**SPEAKER_1** (0:00)
Thursday night, I sat at my desk with my heart pounding in my throat, refreshing my wallet balance, waiting to find out if my family savings were still there. Over 1,300 Bitcoin was drained straight out of cold storage over the weekend. Not off an exchange, not out of some hot wallet on a phone, out of hardware wallets sitting in people's safes belonging to long-term holders who did every single thing they were told to do. So, does this mark the beginning of the end of Bitcoin self-custody? Are we better off handing our Bitcoin to BlackRock? Was not your keys, not your coins, just a massive larp? Today, I want to carefully walk you through what actually broke, what it's going to take for self-custody to survive this, and why the whole tragic event has made me ponder the way I think about trust, faith, hope, and what we're all actually doing here.
I'm not going to cover this ColdCard tragedy from the outside. Thursday evening, I saw a post on X about a vulnerability specific to ColdCard Mark 3 devices. I've used a Mark 3 for my stack for years. Then I read that if you rolled your own dice for entropy and used a passphrase, you were probably fine. I did both. So I felt this wave of relief and told myself I'd probably move the funds in the morning for extra caution. Then I went back on Twitter a couple hours later, and it was the stories. People's entire life savings gone. The scope kept expanding by the hour. More models, more firmware versions. The ground just kept moving. Fear started to rise. So I opened my Sparrow wallet to check my balance. My heart was pounding at this point. Panic coming up into my throat. Just waiting for it to refresh. My funds appeared. And right there, I decided I wasn't waiting until morning. I stayed up late moving all of my funds to a new wallet that night. The only reason I still have my Bitcoin is that a few years ago, I decided to nerd out and roll dice for my entropy with my new ColdCard. I did it mostly for fun and the novelty of it. At the time, I honestly thought it was completely unnecessary. That's the margin. That's it.
Before anything else, because this is still happening as I record, if you generated your seed on any ColdCard, any model, move your funds today. Not this week, today. If you move that seed onto a different brand of wallet, you're still exposed because the weakness is in the seed itself. If you're not technical, you could send it to whatever exchange you bought it from temporarily, or a reputable phone wallet while you sort out a proper setup. The most important thing is to try not to panic. Just move calmly and deliberately. Galaxy Research has counted 1,367 bitcoins swept out of 4,585 addresses across three waves, and the fourth one looks like it's running today.
Galaxy's read of the data tells you what this really is. Smaller addresses dominate by count, larger ones by value. That's the shape of individual self-custody, not institutional holdings. The average coin taken had been sitting untouched for over three years.
These were the patient hodlers of Bitcoin. How could something like this happen?
If the most respected, air-gapped, open-source, Bitcoin-only hardware wallet on the market quietly produced guessable keys for five and a half years and the whole industry missed it, what is a normal person supposed to verify? Answering that question starts with what a private key actually is. Rob Hamilton runs Anchor Watch, and he's been one of the many heroes working around the clock helping people personally move their funds all weekend. He was on Coin Stories with Natalie Brunel for an emergency update on the situation. Maybe the best way to start is let's talk about a deck of cards. A card deck is a really great way to play games, because if you have 52 cards in a deck, every time you shuffle them, there are more possible ways you can arrange the cards in the deck of cards than there are atoms in the observable universe, right? There is just so many cards.
Yeah, so this is really kind of the beautiful part of cryptography when it works correctly is that you can take very simple things and make abundantly complicated things. The way Bitcoin works ultimately is I have a very large number that you will never be able to guess.
That is the simplest way to break down how Bitcoin security works.
The issue what we have here is that instead of dealing with, say, a full deck of cards, we are only dealing with 20 cards in the deck. And the thing is 52, 20 still sounds like a large number, but it greatly reduces the possible number of ways you can arrange that deck of cards. And that allows you to basically, without ever talking to the hardware wallet, know that instead of looking at the universe of the full deck of cards, you're looking at a subset and it allows you to aggressively, very quickly, guess all of the random combinations. If your Bitcoin is basically a needle in a cosmic-level haystack, what's happening here is someone found the exact area of the pile of hay and is just rapidly combing through every single strand to try and find where the Bitcoin sits. So let's put real numbers on that deck of cards analogy. A 24-word seed carries 256 bits of randomness. The number of possible wallets has 78 digits in it. And plenty of you use 12 words, so let me be clear, because I've watched people panic about this over the weekend.
13 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/YOUR_EPISODE_ID