Was the $116M Coldcard Hack an Inside Job? | Meet the CTO Who Wrote the Backdoor! | Simply Originals artwork

Was the $116M Coldcard Hack an Inside Job? | Meet the CTO Who Wrote the Backdoor! | Simply Originals

Simply Bitcoin

August 6, 2026

The Coldcard wallet exploit is raising difficult questions far beyond a software vulnerability.

Topics: News Commentary, News

**SPEAKER_1** (0:00)
So, there's this moment in March of 2021, where a co-founder of a Bitcoin hardware wallet company logs into a secret GitHub account. Six stars, one maintainer, nobody's heard of it, and signs a single commit that changes how every wallet the company ever ships is going to create its random numbers. He doesn't tell anyone it's him. The account is a pseudonym. It looks external. It looks like some random open source stranger. So nobody audits it. Because why would you audit a stranger who turns out to be the CTO, the insider? Five years later, that single commit turns into the largest hardware wallet theft in Bitcoin's history. One thousand eight hundred sixteen BTC.
So far, it's growing worth approximately one hundred sixteen million. Fifty two hundred wallets drained. Oh, and here's the part that should make your blood run cold. The company told you it was coming.
Yeah, in twenty twenty one, in their own words in a tweet, Coldcard makes retirement hacks impossible. And when somebody asked what a retirement attack was, they defined it perfectly, accurately, in their own words, scare quotes and all. But nobody connected the strings until tonight, because tonight we're going to answer the question nobody wants to ask out loud.
Was 730 an inside job? We're not accusing anyone of crime, that's for the courts. I'm going to hand you the receipts and let you decide. And by the time we're done, you're going to understand why the man at the center of this story has been sitting at the table the whole time, eating steak. By the end of this video, you're going to understand one, how one line of code in March of 2021 turned impossible to guess into guessable by a bored computer in a weekend. Two, the pseudonym hiding in plain sight, the Switch account, the Doc Hex handle, and why the man who named his secret account after a Matrix character was playing a very different Matrix character the whole time. And three, why the media's reaction to this could be a bigger story than the hack itself, because the headlines are doing exactly what they were designed to do, make you hand your keys back to the simulation. We got a big one today. Let's get to it. Send it.

**SPEAKER_2** (2:24)
Someone breaking your house is definitely a concern, but what I worry more about is, let's say I set up a hardware wallet and I set it up using a private key that wasn't generated with sufficient entropy that was somehow guessable or predictable by someone else. And you think you've got X number of chats in your wallet and then one day you wake up and go to check your balance. And because someone else owned your key before you did, or was able to guess it somehow, your Bitcoin is gone.
That is a nightmare scenario and something that some people have experienced.

**SPEAKER_1** (3:00)
People knew for years. They were just silenced and smeared by those who lost people's life savings. Now let's talk about how the world found out, because the coverage tells you everything about who's running the narrative. July 30th, Galaxy Research maps a single sweep, 1196 addresses drained in 41 minutes, not days, 41 minutes, a thousand eighty-three Bitcoin, gone, roughly 70 million dollars in the blink of an eye. Then it keeps coming, wave after wave, four sweeps, over five days, until we're past 5200 addresses, past 1800 Bitcoin, north of 116 million dollars, every single one of them, a Coldcard, the wallet that marketed itself as the Paranoid Option, the gold standard, the thing you buy when you don't trust anyone. And what does the mainstream call it?
A randomness bug. I'm quoting, Fortune says a randomness bug. The Hacker News says seeds turned from impossible to guess into guessable ones. Just by happenstance, a randomness bug, like the wind blew and a few seeds fell all over. Like your lottery numbers just happened to match the guy in front of you at the gas station. Here's what actually happened without the corporate anesthesia. A device that exists for one purpose, generate randomness nobody on earth can predict, got its randomness downgraded to roughly 40 bits on the MK3, 72 on the MK4, MK5, and Q. Against 128 bits, a 12-word seed is supposed to give you 40 bits. That's 2 to the 40th possible seeds. A consumer graphics card could chew through that in a weekend, maybe faster. So when a news outlet tells you a randomness bug, what they're really saying is the lock was a postcard for five years. And the word bug is doing a lot of heavy lifting. Okay, time to pivot. This should make you furious. Watch the language. The Coldcard exploit reignites the Bitcoin self-custody debate, as if the lesson is, maybe don't self-custody, as if the conclusion from a wallet lied to you for five years is give your coins to the exchange, actually. Fox Business runs the number, the street tells you to call your friends, and the consensus forming underneath it all. You can't protect yourself, so let the professionals hold it. Let the ETFs hold it. Let Larry Fink and BlackRock hold it. And the man at the center of it, the one whose code did the change, whose company was told four years before the money moved that the randomness was suspect, that man has a handle on X, and it's the same handle the community's been reading for years. Let's meet him, allegedly. Okay, now here is where the evidence board gets, gets a little interesting. Hold on to your tin foil, because this one is cryptographically proven, not inferred. And it starts with a Bitcoin developer who decided to actually look. Coldcard's crypto runs through a library called LibNGU. And when you actually read the firmware, what do you find? A random number generator, for a device holding billions in Bitcoin, backed by a repository with six stars, maintained by a single person using a pseudonym. The account is called Switch, but S-W-I-T-C-K.

12 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID