
Tracking the Coldcard Exploit with Orange Surf
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index, 1% to Boost Bot.
Show Notes
A weekly live show covering all things Freedom Tech with Max, Q and Seth.
Catch up with Orange Surf: https://x.com/OrangeSurfBTC
Check out https://mempool.space
HELP GET SAMOURAI A PARDON
- SIGN THE PETITION ----> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools
- DONATE TO THE FAMILIES w/ USD ----> https://www.givesendgo.com/billandkeonne
- DONATE TO THE FAMILIES w/ BTC ----> https://pay.zaprite.com/pl_JpxtkLv95T
- SUPPORT ON SOCIAL MEDIA ---> https://billandkeonne.org/
TO DONATE TO ROMAN'S DEFENSE FUND: https://freeromanstorm.com/donate
VALUE FOR VALUE
Thanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.
You can support this episode using your time, talent or treasure.
TIME:
- create fountain clips for the show
- create a meetup
- help boost the signal on social media
TALENT:
- create ungovernable misfit inspired art, animation or music
- design or implement some software that can make the podcast better
- use whatever talents you have to make a contribution to the show!
TREASURE:
- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com
- DONATE via Monero @ https://xmrchat.com/ungovernable
- BUY SOME STICKERS @ https://ungovernable.network/shop/
FOUNDATION
https://foundation.xyz/ungovernable
Foundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.
As a sovereign computing company, Foundation is the antithesis of today’s tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can’t be evil”.
Thank you Foundation Devices for sponsoring the show!
Use code: Ungovernable for $10 off of your purchase
CAKE WALLET
https://cakewallet.com
Cake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.
Features:
- Built-in Exchange: Swap easily between Bitcoin and Monero.
- User-Friendly: Simple interface for all users.
Monero Users:
- Batch Transactions: Send multiple payments at once.
- Faster Syncing: Optimized syncing via specified restore heights
- Proxy Support: Enhance privacy with proxy node options.
Bitcoin Users:
- Coin Control: Manage your transactions effectively.
- Silent Payments: Static bitcoin addresses
- Batch Transactions: Streamline your payment process.
Thank you Cake Wallet for sponsoring the show!
MYNYMBOX
https://mynymbox.io
Your go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don't require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.
Explore benefits such as No KYC, complete privacy & security, and human support.
Hello, and Freedom Tech Friday, a live and interactive show taking place every Friday at 9AM eastern and 2PM UK time across the ungovernable feeds. Each week, we dig into the latest Freedom Tech, including free Bitcoin, Monero, encrypted messengers, and privacy tools.
Basically, we wanna talk about anything that helps you take back some control into today's digital panopticon. The show and the topics that we cover are powered by Freedom. Tech, a daily news desk that uses AI to monitor hundreds of sources so that we can continue to bring
I can't even speak. It's been a week, Bear with me. So that we can continue to bring you the signal every single week. My name's q and a. I'm tired, and I'm head of customer experience at Foundation.
Joined as always by Max, head honcho at the Ungovernable Empire, and Seth, who is COO over at Cake Wallet.
Active, so you can help steer the conversation by commenting live, asking questions, boosting the show, or just sharing it with your friends. Top support from the last show with Zach covering the cold card exploit comes from Shadrach, who sent 3,993 sats and said forty hours per week is entropy for your brain. Long live the ungovernables.
Thank you for your support Shadrach, hope you're well. Without further ado, let's dive into the show. Max, Seth, we have an esteemed guest with us as well, who I'm gonna bring on very shortly. But has your week been as busy and ridiculous as mine?
I don't know if I can claim to be quite on the same level since this, like, people freaking out about hardware wallets doesn't impact us as much, but it has been a a very fun and interesting week for many of the same reasons. The AI slop security reports, us continuing to harden our own security policies and practices,
self hosting AI now sitting right next to me, which has been fun. Yeah. I see all that. Going on. That's the new NVIDIA things. Mhmm. Yeah. Mhmm. So they have a show on that soon. We do. For sure. We do. Definitely.
Yeah. Also busy here, mate. Lots of different problems. Very non Bitcoin related problems, but busy. And, yeah, not excited to get into this show because it's just fucking sadness and pain, really, isn't it? But stuff we need to cover, and I am excited to have, as you say, our esteemed guest join us today.
Yeah. I agree. It's a topic that none of us particularly wanna talk about, but, like, it is the news of of of the week of the century in in terms of Bitcoin, I guess. So
if you were, of course, with us last week, you'll know that we spent the whole show with Zach from Foundation talking about the cold card exploit, which at the time was kind of unfolding in front of our eyes, and in in many ways, it still is.
We're still kind of piecing together as best we could back then, and there's a lot more information available now compared to the last show. A week on the picture is a little bit clearer. The the numbers have sadly moved significantly, and the story has only gotten bigger.
So we wanted to come back and cover it properly, what's new, what's developed, and talk to somebody who's been, you know, right in the thick of it, monitoring the mempool and looking at the transactions as he always does from from a data perspective.
Orange surf, friend of the show, has published one of the most thorough reps that I've seen, about the key exposure, and we we can get into that. And he breaks down exactly, how it happened, who's affected, and, oh, I failed failed to mention that he's he's on the team at mempool dot space as where they're kind of lead researcher.
Correct me if I'm wrong there, Orange But yeah. So esteemed guest driven by data, and there's nobody better to to talk about it than than the man himself. So mister Orange Surf, welcome to the show, mate. How are you doing?
Yeah. Pretty good. Thanks. Better than you, it sounds like. Yeah. Appreciate you appreciate you guys. And, yeah, hopefully, I can help dig into a little bit of the details and share some light where, yeah, I think it's all pretty cloudy at the moment.
Yeah. That sounds good. Q, I'll I'll take over here because I know you're a zombie now. Should we go yeah. You're going to bed. Should we recap just for I mean, I think pretty much everyone is up to date, but recap the basics of what happened and and where we're at now.
Maybe, Seth, you can do a rundown on, you know, like, one minute TLDR.
Yeah. I can do that. And then, I'm curious if Orange Sheriff has any any other things to add because I know he's been doing a lot of digging into the the actual exploit and writing about it as well. But, yeah, I mean, the TLDR, if you have been in a coma, for the last week somehow, I think even people in comas were awoken because of this.
But if you've been in a coma, the short answer is that cold card devices, starting with the four .o dot one firmware in 2021 swapped out the way that they did Entropy, the the source that's used to generate secure private keys.
And the way it was swapped out seemed fine, but on accident, they allowed a a fallback to software RNG, skipping the secure element true RNG that was supposed to be how those things were derived.
It's a little bit different on the Mark four, Mark five, and, q models, in my understanding, where they are a little bit more secure, but they also had a similar bug that caused them to be not as secure as they were supposed to be.
Short story is if you had generated a seed phrase with any of those devices, you should assume it it can be compromised and will be at some point, with the only exception of if you were using it in multivendor multisig, or
if you had an extremely secure passphrase. But even if you had an extremely secure passphrase, you should move funds because passphrases usually aren't properly generated, or if they are, they're usually not quite hard enough. So I would I would be extremely cautious and move funds to a newly generated seed
either onto HotWallet to something like Cupcake where you can use an old phone as a an an offline AirGap device or to a a new hardware wallet where you're generating the seed fresh as well.
I think that about covers it. Basically, cold card poned move funds. Mhmm. Yeah. Anything to add to that, Orange Surf?
No. I think that's pretty fair. I'd say in terms of the different devices, there's a bit of confusion, going on between the amount of security that you actually have if you had generated your seed on a compromised mark four five or q.
I saw in the block article, they actually put a lower bound, which was significantly lower than the number of bits of entropy generated using a mark three. So the kind of the the hopeful case for those later devices is that they are slightly more secure,
and and we haven't actually seen many reports or any reports yet of those devices being compromised. It doesn't really change the fact that you should just immediately try and move your funds off of any single signature device that was generated on a cold card
where you're not a 100% sure that it isn't affected. And in the research report that I published, I have listed out the devices that are affected. And, really, if there's any doubt in your mind whether you have a very secure passphrase such as,
you know, 12 randomly selected words, and that's not 12 words that you've just thought of, that's 12 words that you've picked using, you know, dice rolls or something like that or that you have entered a 100 random dice rolls directly
when you were generating that seed. Unless you've done those two things, you should probably just assume that that device is compromised and that you, you should treat it as exposed. And then in terms of, you know, multisig, we can get onto that maybe, in a little bit, and I can share some,
further details on what to be careful of when it comes to multisig because that's the only situation in which you shouldn't just drop everything and and move the funds out in a in a, like, conventional way where you just broadcast publicly in the mempool.
Would it be fair to say if you've generated a seed on cold cards, even if you have used dice rolls, even if you have got a passphrase, that maybe it would be wise to consider moving anyway because you're sort of playing with fire here and with everything going down the way it has and things being missed for five years, etcetera, etcetera.
If it's any significant amount of money, the pain of moving it to something potentially more secure and taking an afternoon to do it is much less than the potential pain of loss. And if that trust is gone in that company, and, I mean, really, should be, would that not be something that should be suggested? Not just like, oh, well,
if it was after March, whatever it was, seventeenth that the software was released in 2021, you know, if it was after that, it's a problem. And if it's not with dice rolls, it's a problem. I would urge anyone if they're my friends and family. It's just if you've used a cold card, move it.
Don't rush things. Don't make mistakes, but don't be, comfortable in the fact that, oh, yeah. I've done some dice rolls. I I would be tempted to agree, except I I do think that if you did dice rolls I mean, I I know people who I'd suggested that they get a cold card, but insisted that they did dice rolls.
They used a second device to verify that those dice rolls were being used to generate the wallet. And Mhmm. Therefore, they they can remember very clearly that I was that paranoid friend recommending that they do this seemingly crazy thing. And so in that case, they know that at the time that they generated that seed,
they were able to verify with a second device with a seed signer that the wallet being derived was deterministic from those dice rolls. Fair enough. In that case, I think I'd still recommend that people, like you say, they move out of an abundance of caution if they can't very
readily remember that that was how they generated it. But in that case, I'd say, actually, you're you're fine provided that you didn't use any of the more advanced features of the cold card. So, for example, if you derived secrets from that seed which you used, then depending on how you generated those secrets,
there could be issues. So, for example, even generating paper wallets, they're not actually generated from the seed. They're generated using the random number generator function. So it's probably easier if you just consider anything that you were doing around the time that you had one of those devices that may be compromised
to be a write off, but there are just probably loads of people out there who have loads of UTXOs. Maybe they've got quite complicated systems.
Maybe there's other negative repercussions that would happen if they just started rapidly moving all those funds around. I mean, maybe they would have to fly to a different country to to get hold of that device. So I think there is a very narrow edge case where they carve out and say, look. It's it's actually okay. You can you can manage
the concerns that you might have by just knowing that if you were doing a 100 dice rolls, it's fine. But, yeah, I think you're right. In ninety nine percent of cases, you could just assume that the device is is compromised.
Okay. So in terms of who's actually exposed to this threat, it's it's basically everyone outside of what you've just mentioned. And when you're talking about negative repercussions in terms of moving UCXOs, I I assume you're talking about privacy reasons and moving things where it's gonna have timing attacks or other ways to monitor,
and sort of unwind people's privacy. Yeah. And also coordination. I mean, you probably have people who have multi multi sig wallets set up between a number of different people. Mhmm. It might not even just be that one individual is in control of the wallet.
And in that case, you know, if you have a, I don't know, a a two of three multisig or a three of five multisig in which one of the devices was a cold card and it's holding, you know, a large amount of funds that have been received for, like, an organization, and
you aren't particularly concerned about those other devices being compromised. It it was more as redundancy that you had the multisig. In that case, again, you might choose to just slowly migrate the funds out as you spend from that wallet with the change going to a new wallet rather than just in one go moving everything.
And I think people will have to evaluate that on a case by case basis, but the three or five multisig where one of them is a compromised device, you know, you you do have redundancy there.
Okay. And what are you seeing on chain? Like, what is the story that you're seeing that maybe less technical or people who don't live in the mempool might not be seeing? What is the picture?
Yeah. So, actually, I haven't been doing that much analysis of the actual theft transactions. I've seen lots of brilliant research, in that area by, Alex and Galaxy, amongst other people, and maybe we can link to those in the show notes. But I've mainly been focused on
two things. So the the first being the movement of funds through Slipstream. So transactions being broadcast through a private mempool, and we can get into why that might happen. And also just RBF fee battles, kind of doing some monitoring to see whether or not
people are getting their their spend sniped. And I was expecting to see, you know, lots of people, racing each other to spend these funds and sweep the funds. I think, actually, if that if that has happened, it's it's kind of well, it's probably happened, but it's no longer ongoing
to a significant degree. So I'll be monitoring mainly for the past twenty four hours for multi signature spends that are getting replaced. So this would be for wallets where two of three devices are cold cards, for example.
And in that case, there's a there's an edge case where broadcasting that publicly in the mempool would allow an attacker to RBFU, and I haven't yet seen that happen. I've been monitoring for it. There's a possibility that I've I've missed it or that my node just hasn't seen those transactions.
But so far, we haven't seen that happening, at least not a large scale. So I'm hopeful that a large amount of the funds that are being secured by setups where two of the three, for example, devices where the quorum is being met, the threshold is being met by compromised devices.
I'm hopeful that those people have heard not to just broadcast those things publicly, but it it may just be that we haven't had long enough yet for people to make those mistakes. And, as you mentioned, the man in the coma, maybe
people just are completely unaware of this, and they're gonna go to spend their Bitcoin from a a compromised setup and unbeknownst to them that the act of spending from that multisig wallet is actually putting them at risk.
Do you think that maybe it's not happening as much because the attacker is a little bit naive in in how they're exploiting all of the things that are available to them. I mean, obviously, there are lot of attackers now. So it's it's hard to summarize as, like, the attacker. But it's been interesting to see them
not exploit some things, especially initially, that seemed quite low hanging fruit. And even as we've gone, like, some very low security passphrases have remained safe, that sort of thing.
Yeah. Definitely. And it's one of those things where you don't know how much to say for fear of making it easier. But at this point True. And how capable these, you know, unthrottled models are,
even one ones you can run yourself like yourself, like, it's only a matter of time. So I think, you know, it's it's okay to share most things. There's still one or two things that I'll be careful not to say. But in general, I think the level of sophistication of the attack was quite low.
I think I've seen some speculation of of this being, a long planned attack, and I think there's no there's no possibility that that was the case because it was so amateurish in the way in which it rolled out.
If it had been a long planned attack, I think we would have seen blocks full of these types of theft transactions. They would have come out of nowhere and filled the blocks, and it would basically have just been done in one one hit. And had they suddenly seen Sorry, Orange. I've just I know where you're going with that,
but what if you wanted something to look amateurish so that there was no chance that it was a long planned attack? You know, why would you you were quite yeah. What but why would you want to make something look sophisticated if you were a sophisticated actor
when you can still sweep? I mean, I don't know what the number is now, but you're talking thousands of Bitcoin. I mean, that's a that's a pretty good attack. You you're not gonna be like, fuck. I wish I had more and quicker. Like, that's enough.
And and depending on who the attacker is and what their purpose is, It can be just for, financial gain, or it can be to spread fear. It can be for any type of, reason, and I don't know I don't know if that's true or not. I'm just saying, like, if we open ourselves up to that possibility, you could think that somebody makes themself look
less competent for for reasons. It's possible. I think if it was a sophisticated actor, then rather than being perceived to be incompetent, then they would have just migrated the funds over a long period of time spending each UTXO, sending it to a new output, not reusing addresses,
and we wouldn't necessarily have known what was going on for a while. I think a lot in the first wave, a lot of the sweeps were actually going to the same address. So it was very clear that something was up. And as soon as the report started coming in about thefts, it became quite clear that it that that's what it was.
I mean, if there was an ongoing very slow burn where people were stealing funds, then we may not know about that even now. So it it may be that over time, we discovered that someone had realized that this was happening and that a sophisticated attacker started earlier than the known starting point on, I believe, the July 30.
And then after that, another attacker started and was less competent. And then following that, a more sophisticated attacker started migrating funds in a more sophisticated way, moving UTXOs one by one and to new addresses and and so forth. So I I think probably we've got a bit of everything going on,
but I think that the possibility that this was, you know, orchestrated long in advance and then executed in a really amateurish way doesn't really make sense to me. Fair enough. Fair enough.
Okay. And what else you said there's obviously things that you can't talk about for security reasons.
Is there anything else, like, advice wise that you can give to people who have been caught up in this and either are yet to move funds because of the reasons you'd said or have moved funds and now potentially are at some type of risk with privacy, etcetera? Like, what should be people be thinking about if they
need to move or have already just moved? Yeah. So I think the first thing is just to take your time. At this point, there's less priority on urgency for the sake of an extra hour of really just being careful, making sure that you've got a good setup. I mean, that was different even just a few days ago.
Like, a few days ago, I would have said it's it's probably better to just send funds in a single sig wallet without a passphrase that were generated using the default setup of the device just into a hot wallet. You know? Just better to risk it going into a hot wallet than risk those funds
being stolen. Whereas now the attackers have had long enough that the very low hanging fruit has been swept. If you do have, you know, a passphrase,
then you should still be moving the funds unless it's a very, very secure passphrase with 12 random words. But you have kind of by the nature of the fact that those funds haven't been stolen yet, you've got a a very small amount of time to just make sure you do things correctly.
And I think there's we've already seen reports of people accidentally sending funds to scam wallets and that type of thing. Obviously, that would just be terrible to have have survived this kind of first wave or third or fourth wave or whatever we're on now of attack just to then send your funds to a different scammer.
So I'd say take a breath, make sure that wherever you're sending the funds to is actually secure. Ideally, something that isn't gonna be vulnerable if a single device or provider
has issues. So, you know, a multi vendor multisig would be ideal if you can do that. If you can't do that, then using dice rolls and a very long secure passphrase will give you a good level of robustness provided the device isn't compromised. So, you know, if you didn't have access to another device, then deriving
a new wallet on a previously compromised cold card with lots of dice rolls and a very strong passphrase is gonna be better than just sending it into a a hot wallet, for example.
But you could also have a a multisig wallet like a two of two using Sparrow and that that device if you don't have confidence in that device anymore, which would be reasonable. Mhmm. Then when it comes to actually, you know, what to do with the the transaction, I'm I'm frantically copying and pasting
tables in in it so that I can share share my screen. So maybe in five minutes or so, I can I can share that? But, effectively, there are certain situations in which you shouldn't broadcast your transaction publicly, and that only relates to multi signature wallets.
And, yeah, maybe in in a couple of minutes, I can share my screen and talk through that. Yeah. You tell me when you're ready to share the screen. I've not looked through your reporting yet, but Q assures me it's very good.
So in the meantime, is there anything that you think we haven't covered? I think the most important thing is anyone who's listening who somehow hasn't moved funds knows how to do it and do it correctly. I feel like we've kind of covered that pretty well.
I think we've covered the root cause of how this all kicked off. Is there anything else missing before we go to screen share? Because I don't wanna just keep covering the same ground that people have been talking about for the last week.
I think maybe something I'd like to learn a little bit more about is, like, what what does your setup look like to do all this monitoring? Like, I I know that you've been doing this for a long time at minpool.space and publishing reports and a lot of findings, but
I'd be curious, like, obviously, the the maybe the TLDR about what the setup looks like and what you found useful in your research in building this up alongside all the other work that you've been doing on the the research side.
Yeah. That's really an interesting point. So I I think I've been one of the big biggest beneficiaries of AI out there, really, because my my level of programming was relatively basic. I I was able to do analysis using, you know, simple scripts and stuff.
But then as soon as AI started taking off, I began to explore using it quite a lot. And so, yeah, over time, I've been using AI more and more in order in to actually generate the scripts to do the reporting.
But, obviously, going through very carefully to audit what's happening and really understand how how these things are working, I'd say until very recently, it was almost always the case that there was some significant bug with how
an AI generated analysis script had been written by an AI model, but we're kinda getting to a point now where the first pass is actually normally, it doesn't have a major bug. And there's taste and there's style and there's things you can go in and tweak. And, obviously, if you're able to provide previous examples,
then you can hit the ground running. But I use a permanently online device, which is constantly, you know, dumping data for various different purposes. And then I use that in combination with our mempool
servers to basically pull data from a range of different servers around the world. So we've got, at this point, I think, 60 bare metal servers in seven data centers around the world for Mempool.
And so you you just can't really replicate that level of redundancy and that breadth across the network. So all those servers are running their own Bitcoin node, and those nodes appeared with each other, but they're not, you know, treated in a special way. So they're just then connected out to the broader network.
And that means that we get a very good visibility of of what's happening, and we see transaction replacements. We see things basically as soon as they happen in the network because of that global cross connected network.
And so, yeah, normally, it's a combination of those two things. It's it's doing what I can locally on on devices that I have, you know, physical hands on and then delegating out to the mempool servers using API keys and stuff in order to be able to pull in data where it's not particularly easy for me to collect it myself.
Nice. Yeah. I I hadn't even I I should have connected those dots, but the the access you have at Mempool, obviously, is a is a huge win that you have such a broad infrastructure, so you can see events that maybe were first published in a specific region and get a lot more a lot more access and redundancy throughout,
which I'm sure is a a huge help. Yeah. And something that's quite kind of interesting is often when I do these research reports, I find gaps in
in our APIs or in the kind of features that we offer. So that then leads into kind of a product pipeline of of what should we be building and and how can we add new features to help people doing this type of research. Because if I've needed it for this research, then probably someone else will need it for some other purpose.
So it's often enterprise customers that we have who ask for new features. But increasingly, I think it's things that I'm I'm finding would be quite handy to have.
Very good. How's your copy pasta going? Are you ready to share screen?
Hopefully, it's now coming through.
Is that working on the stream? Yeah. Look at that.
Cool. So I think we've gone through a good amount of this recap, and so I'll skip through a lot of this stuff because it's just very text heavy. If I jump all the way through to this
so this is the main edge case that we mentioned. So this is yeah. If you've got a multi signature device where the quorum is being met, the threshold is being met by compromised devices, cold cards. So two or three with, you know, a cold card queue and a mark four or something like this.
Then at the moment, if you haven't reused addresses, and and that's not just on the receiving side. This is if if you haven't received to an address and spent from that address but still have funds in that address left over, then, actually, the coins in that address are temporarily safe.
But as soon as you broadcast to the public mempool there's two of three, for example, transaction, you reveal the public key of that third unknown, not compromised signed device or specifically the actual the key for that one transaction.
And as soon as you do that, that script has been revealed publicly. And any other UTXOs, the attacker can now basically spend those those same UTXOs because that third key is exposed. And if you do a test send so, for example, you are moving all these funds from this compromised device into a new multi signature wallet,
and you you send some of the funds from one of those UTXOs or all of the funds from one of those UTXOs, there's other UTXOs that are compromised at the same address, then, actually, you're putting yourself at risk. So it's really important that you don't do that
and that you do a test, obviously, using a separate device. If you've got a hot wallet or something on your phone, send into your new multi signature setup, and, obviously, do the normal thing of of deleting everything and recovering everything and checking that the funds are still there. Just don't send into that from
your old setup, especially if there's multiple UTXOs in the same, you know, script, the same address.
Okay. Makes sense. What you should do obviously, that's what you shouldn't do. What you should do is you should broadcast it using a private relay service. So at the moment, slipstreams slipstream by Marathon is the the best option available.
So you can effectively send them your signed transaction, and they won't publish it. They will just put it, you know, out there in their NoseMempool. It won't be broadcast out to the rest of the network. And then when they find a block,
that transaction will get mined. And so the attacker will see that transaction for the first time when it's actually confirmed or at least has one confirmation. There's Is that why you is that why you were saying that I think you said the attacker or attackers were using slipstream
for sending out from people's wallets as well. Is is that the reason so that no one can, like, RBF or whatever? Well, I don't actually know if anyone's, spotted any theft transactions that were using Slipstream.
It's Oh, I might have misheard that then. Sorry. I mean, there hasn't been too much sleep anywhere around here, so I I could have been on my end as well. But I think, yeah, the the most of the use of SIP stream that I've seen has been migrating funds actually from Unchained
where I think a lot of people were using two or three sets of that involve two devices that were cold card devices. And so a bit further down here, I've got some graphs showing the the data, basically. So this is looking at all the transactions that have been mined by Mara since this attack began,
and it's just focusing on the multisignature spends, the unknown. So, obviously, there's there's ways you can have multisignature using Taproot where you don't reveal, you know, that it's a multisignature address.
But but in some cases, can see for the more kind of legacy traditional ways of doing multisig, you can see that it's multisig. And so in those cases, I've looked at all the transactions that were mined by Mara that weren't seen by the MEMPL space
nodes prior to confirmation. And so these are effectively all the multisig spends that were broadcast using Slipstream. You can see now kind of we're we're getting up past 5,600 Bitcoin that has gone through this kind of side channel and has avoided being at at risk,
which is significantly more than the amount of Bitcoin that that is known to have been stolen. So I think this is really interesting to see because these kind of dark mempools or private mempools are something that there there are trade offs with having these.
But in this case, it was clearly a a net positive for the whole, you know, community and the network that we're we're able to have people sweep these funds in a secure way.
Yeah. It's really fascinating because I I think a lot of times the dialogue around private win pools is only negative. And, yes, there are absolutely downsides to having a a part of the network that is not transparent to the rest of the nodes on that network.
It can can cause some bad things, but especially in Bitcoin because we don't have MEV and other issues like that, They're often kind of just viewed as a negative. So it's it's fascinating to see, at least what I from what I can remember, the first, like, known good only positive use case
for something like this for for a private mempool. Was cool to see that that this actually had an impact and protected a massive amount of of funds in the process. It is. I mean, I was I was definitely in the camp of private mempools being just strictly bad.
The only edge case that I'd identified, which I think other people have talked about, is in in the event of some kind of quantum attack, you have exactly the same kind of system where an attacker might be able to steal funds that are
exposed for a short period of time whilst they're in the mempool. And if you could just immediately broadcast those to a a miner who isn't going to relay them, then as soon as you mine them in a block, they're they're safe.
But that was obviously very speculative, and I don't think many of us are too concerned about a quantum attack immediately. So it wasn't something that was really on my radar as a useful feature.
Whereas, you know, as soon as this started happening, people with these compromised two of three multisigs realized that, actually, this could be utilized for that purpose. And we've seen a number of different wallet providers and, you know, service providers like Unchained and Nunchuck have integrated this API.
So instead of broadcasting directly to the mempool, there's an option now to broadcast into these private channels specifically for this type of transaction where it's exposed. In in any other case where you have funds that are, for example, in a single sig with a passphrase
or single sig with dice, it's better that you just broadcast that publicly and get it confirmed as soon as possible because the trade off of using this type of thing is, for example, Mara only has four to 5% of the network hash rate. So you're gonna expect to wait quite a long time before these confirm.
And, obviously, it's gonna be a pretty sensitive time while you're waiting. You're gonna be worrying for a while. So if if it's all possible, you wanna be broadcasting publicly except for if you've got the threshold of your multisig where the devices are compromised.
Yeah. A quick question for you on that, actually. Like, do you think this is something that mempool dot space would add in the future? Like, obviously, y'all don't mind, so you wouldn't be the ones actually providing the private mempool.
But it seems like something, like, with your accelerator and the other things that y'all have done, that it would be in a good fit seemingly alongside the things that you do? It's an interesting idea. I'll take it back to the team.
Yeah.
I think, ultimately, where there's a a clear net benefit of this type of service, I think it's it's compelling. Obviously, there's there's trade offs like you mentioned before. And so how widely available that type of service would be, I think, is
is is the kind of the dial that you could tweak there. Like, maybe maybe this type of service is is available for a period of time for this sweeping of exposed funds, but not in the future.
Maybe it's only for certain types of transactions, but I think it's definitely at least opened my eyes to the possibility that this type of feature could be of use to the Bitcoin community rather than just being a bit of a hindrance.
Are there any other things like this that do, like, throughout your research and watching what's been happening with the Gold Card case that surprised you as, like, a useful tool or something that needs to be more broadly adopted or even just, like, something about the attacker patterns that keyed you into, like,
I guess, ways that we can improve the broader tooling around this. Obviously, not the entropy issue. Like, that that's that's something that should be sorted all the time. But outside of that, other things like like Slipstream that proved themselves as a useful tool that kinda popped out at you as you're as you've been digging into this.
I think generally monitoring, you know, I've been spinning lots of things up to do monitoring and to track addresses and whatnot. And we've had lots of plans to to help improve the the monitoring side of things for a while. So I think going forward, people are gonna want to have more live visibility of what's going on with their wallet.
For example, I think, actually, I can scroll down somewhere else here. I built this monitoring tool that's basically constantly looking for replace by fee transactions in the mempool, and then it's it's particularly flagging any that have a changed output address that are multisignature spends.
And so in this case, I'm actually also saying it has to have one output in the transaction. So previously, it may have had multiple outputs. Like, all of these top four had two outputs of in this one, four outputs in the original transaction that got replaced by a new transaction that had a single output,
which is you know, that's what you would expect if someone was sweeping using RBF and stealing the funds. They just send all those funds to one address. And then if that address changes, so the address isn't common from the original transaction, then, again,
that's a bit of an indicator that it could be a theft is what you'd expect a theft to look like. And, obviously, we're we're concerned with, like, two of three, type multisigs, so that's what I've, I've kind of called out here. So,
like, this type of tool, is something that I have had in the back of my mind to to build out for a while. Obviously, we have a a page for replaced by fee transactions on MemplSpace, but we don't have anything that allows you to to do this kind of filtering and more detailed analysis.
So I think probably coming out of this, there's gonna be lots of people that want that type of of tool, whether that's to monitor their own transactions or to monitor what's happening more broadly on the network.
And we obviously have all that data to hand. We just haven't yet made an interface that people can use to to access that and to explore it. So I think that's definitely something that we're looking at.
And and then, you know, how that relates to your personal wallet, I think, is also of interest. Like, a lot of people probably want to have a unified place that they can come to with multiple different wallets
that they're tracking. And some of those might be their own. Some of those might be they they want to attract to track the spending of certain types of UTXOs. And, again, that type of tooling is something that's been, you know, discussed, and it's kind of vaguely on the radar,
but it hasn't had the the real use case. And I think now now we've seen everybody's, like, springing up these dashboards to try to track what's going on. I think the use case is is becoming reasonably clear.
Yeah. Definitely. I wondered with with what you've been looking into, have you got any insight into what's being hacked, if anything, with pass phrases? For example, if someone's not rolled dice and then they've got, like, you know, one word versus two versus three versus four, five, six, seven, all the way up to 12,
can you see or have any insight into how secure that's making people if they're being swept at this point? So there is a I I can't remember off the top of my head the site, but there is a a website, I think James had burned made, which is, he's created a bunch of decoy or, like, tripwire wallets.
And I saw that. So he he's tracking he's tracking that so that that you know, his own wallets or wallets that people that he he knows that have submitted those to him to track. He he's doing that. I've I've looked publicly and and kind of scraped, x to try and find people reporting the different types of theft.
So in the MEMPL research report, which is research.memple.space, there's some kind of some listed out there. I can share this tab, which shows different phases of attack that I kind of expected as soon as I started looking into this. And so far, it's reasonably
it's holding up reasonably well. So the first phase would be basically purely offline. You just derive these low entropy wallets and then scan for UTXOs. So you'd expect that, first, you'd get the the single sig mark two and three with no passphrase, no dice throws.
Then you'd have the ones that have a weak passphrase or a very small number of dice rolls that were mixed in on top. Then you'd expect the mark fours, five, and queues with no passphrase and then four, five, and queues with, again, a weak passphrase or a small number of dice rolls.
And and so far, I've seen mark threes with no passphrase, single sig mark three with a two word passphrase, and then a mark four with no passphrase in that order. So I'd expect probably the next one would be well, that that single signature mark four is
you know, it would be very surprising if that's real because it is supposed to be 72 bits of entropy, involved with that. But the the report from Block that I mentioned before puts the lower bound on, the security of those at down at 32 bits, which is even lower than the known level of Mach three. So,
obviously, we're still kind of operating under uncertainty, but I think it's likely that these these four would all happen first. And then the next step would be the multisig with address reuse. So if if you've reused the address for spending and you still got coins there and you've got a quorum that's being met
by by two compromised out of three devices, you kind of expect those to be stolen next, which is what I'm monitoring for live. And then on top of that, you could obviously add, some some extra passphrase to one of those devices.
At that point, you start getting to a really, sophisticated attack. And and I guess it's just gonna be a question of how many funds do the attackers find as they're going. Because kind of like mining, you know, they're burning
real cost as while they're trying to to grind out these addresses and and try to to steal. And if if they're able to you know, say they've got a million dollars to perform the attack,
If they if they're unlucky for enough time, then they'll burn through that million dollars before finding enough funds to keep it going. If they get lucky and they find loads of funds early on, then their their war chest will grow, and they'll be able to continue scanning for a lot longer. So I I guess it just depends
how many funds are there in these different setups.
And as they kind of progress forwards and their costs keep going up, so at some point, it won't be economical anymore at that time. But in in a way, I kind of think of it like, you know, mining for gold or something like that. Like, at at a certain time when you were just using hand tools,
the amount of labor that it would cost and the amount of time to actually exchange that gold would be, you know, it wouldn't be economical anymore. But if you had a time machine, you could jump, you know, fast forward to the technology we have today. All of those old mines would basically be the the best mines in the world.
Yeah. And so I think the the risk here is that people kind of just get complacent and think, well, I haven't had my funds stolen. It's been a week, so it's probably fine. You know, the attackers are probably still out there. They're probably continuing.
And if they get lucky and they find a bunch of funds, then they could actually ramp up the the amount of money they're spending on the attack. And also in the future, when their ability to to scan for these, addresses goes down, we'll probably see further further thefts.
Yeah. I agree. You know, the amount of attackers is likely to multiply and the cost of the attacks is likely to go down over time. So that was kind of back to my original point on, like, don't be complacent. Just just move. Just just try and do what you can rather than sort of guesswork.
And given all of what's going on, do you have any recommendation for self custody for people? I'm not saying, like, specific hardware necessarily or anything like that. But, you know, for years, there were sort of two crowds around pass phrases, and a lot of people strongly recommended against them.
You had other people who strongly recommended. You don't think about anything without them. People who recommended dice rolls, people who said it was too complicated, like multisig and, again, that has its own complications.
For people who might be listening and wanting to update things, do you have any thoughts or, like, best practices now? Yeah. So I I guess my first thought is the idea that we're gonna have one setup, one recommendation that we can give people, you know, as a blanket recommendation,
and that that's gonna be safe and easy to use and appropriate almost regardless of the amount that you're custodying is obviously Yeah. Incredibly wrong. Yeah. I think and and this is just kind of anecdotal, but it seems like North America was particularly badly affected by this. And I imagine that that's because,
typically, within the Bitcoin space, North America is, like, at least a few years, maybe five years ahead of the rest of the world in terms of the the kind of adoption cycle. And as a result, I think you had far more people with a relatively low technical competency who were
getting into Bitcoin in, you know, North America in comparison to lots of the rest of the world, which is actually still quite techy. And I think a lot of those people were, you know, buying the recommended device and using it in the default way, and they didn't necessarily have particularly good understanding of what they were doing.
And and we felt good about that in a way because they were able to get onboarded in a way that a lot of people felt was was secure. And, obviously, the the typical recommendation was that, you know, even a bad personal
setup using an off the shelf device from a list of, you know, say, or six of these kind of approved devices by the community, if you like, was better than leaving them on exchange. And that was kind of the main priority was to get people off the exchange,
not at any cost, but with a certain degree of prac like, pragmatism. Like, if we can get someone off an exchange, then, okay, it might not be perfect that they're using this thing without knowing all the intricacies, but it's better than leaving all these funds on Coinbase.
And I think we're just gonna see more experimentation now with different types of setups. Obviously, what BitKey has been doing is is very targeted at getting people off of an exchange without them having to learn too much about the the risks associated with seeds.
Obviously, they had an enormous amount of pushback when they began doing that, and and they've kind of taken on some of the recommendations in terms of adding a screen to the new device. But I think things like that, where they're they're trying to meet people where they are without requiring them to basically just have blind faith are
are very valuable. I think the same kind of thing applies to people making it easier to use multivendor multisig. I think, again, if if you're able to provide people with a user experience, which is is good without completely obscuring from them the importance of backing up seeds and, you know, having good sources of entropy, then I think
it should be possible to continue, like, really ramping up self custody. The the the risk I think that we've got is that a lot of people now say, well, that to me because I I'm no longer interested in Bitcoin because the of this disaster where all these people did everything right, quote, unquote, and then still lost funds.
And and also just people saying, well, I'm interested in Bitcoin, but I don't feel confident to hold it myself. But I think there's a lot of people working very hard at the moment to make self custody easier
and to make the devices user friendly and make sure that those devices are robust. And, obviously, there's a huge amount of work going on at the moment to improve the robustness of the software that people are using. And I think we're probably in the, yeah, the real,
is it the pit of desperation on the on the adoption curve? Like, this is you know, I think people are are feeling pretty rough right now. But, hopefully, we're gonna come through this with much more robust recommendations.
And, I mean, for one for example, when it comes to rolling dice to generate seed, it's great that people are talking about that more. It's something that I've been recommending for people for a long time.
I've made various little projects making weighted dice and showing people how even a a really heavily weighted three d printed dice, which has got a steel bolt head in one side of it, is
is actually gonna generate you enough entropy if you just keep doing enough dice rolls. But where we've got wrong in the past is we've had these advanced features, but we haven't had much kind of hand holding. So we haven't had a really tight guardrail on, for example, you must roll a 100 dice or more
and do lots of sanity checking on the entropy that's generated to check the well,
we can't be sure that the the the person's used the dice. But if they enter a 100 number ones, then we can just reject that outright. We can do some relatively straightforward checks there. So Mhmm. I was just talking to Q before this call. Like, I've got an idea that I'm
gonna put out there probably later today of of how we might be able to standardize upon a method of generating seeds from dice, which is just basically a protocol that builds in all these best practices when it comes to using dice rolls, you know, not entering it in an online device, using a
a setup with at least a 100 dice rolls, etcetera, And and, basically, just make it so that people aren't having to just discover this for themselves because I've seen in the last twenty four hours people recommending doing dice seed generation,
but they're using a calculator on a mobile phone to compute the the values. And, obviously, that's just undoing all of the hard work that they've done. Yeah. Yeah. And like you said, there's there's a lot of people working very hard to make this easier and
more possible for people to self custody. One of them is asleep on its desk at the moment, the robot in the top right corner. But, yeah, I feel confident that some good can come out of this. It's obviously been a terrible situation, but it it is, in a lot of ways, a big wake up call where
a lot of people felt that sending sending funds into their cold storage that they've been told is safe was the best feeling because it's like no one can ever touch this. This is absolutely off the map and and and not up for grabs. And a lot of people were wrong, and we were overconfident.
And, you know, the don't trust verify thing was not followed. And so I think now companies making it more possible for less tech literate people to to not have to jump through hoops that they're gonna fuck themselves on. But, yeah, sort of, like you say, meet people where they're at. I I do feel that things are
way more simple than they were before, and it just seems that actually the the crew that were trying to do things in what felt like the most technical way are the ones that have have been fucked here, which is very sad.
Yeah. I think, ultimately, the the question is if someone's buying a device and and then it's generating a seed for them, if if that device does what it's advertised to do and and it has the, you know, the the actual as described security model of the cold card was very good.
It it wasn't that they were they were, you know, trying to use a random a single chip that generated the randomness, and it just didn't work. You know, they they had multiple things that had to go wrong in order for this to happen. It's just that they that they did go wrong. So for example, the foundation
devices use multiple different sources of entropy. The the reason for doing that is if any given source of entropy is poor, then it's effectively, like, you get the the
amount of entropy is as much as the best source. So you can't, like, lower the amount of entropy by combining lots of different types, so you might as well just have lots of different sources and mix them all together. And as a result, you'll have
it's like a the high waterline. You'll have the best source of entropy from any of those combined. And that implementation is what's important. And, you know, the way that the foundation devices works is it does have multiple sources of entropy.
But you could imagine there's a different device out there that has you know, it it says it's gonna combine 10 different sources of entropy, and everyone might think, well, that's even better. But if in the implementation step that's not achieved,
it's irrelevant. And I think maybe where we went a bit wrong or where I went wrong was evaluating a lot of these things based on the as described architecture. And I think with the cold card specifically, the reason it wasn't picked up earlier is because of the way in which the
the code was structured combined with the submodule dependency. It meant that it was quite a lot of work to kind of dig through. And so presumably, that's why people didn't an early scans using different AI models supposedly I've not verified myself, but supposedly didn't pick it up.
And then we get Sorry. Sorry. Cutting you off. Go ahead. I was just gonna say, do you think that a lot of the reason that people weren't scanning this code was because the incentive was lower because it wasn't, fast, and therefore people, couldn't use it anyway, and therefore, they're not gonna scan. And this is just another reminder
that, it's an important thing when we're dealing with security and securing our Bitcoin, and the whole ethos around everything should be free and open source.
I mean, my good reaction is to say yes, but I just I don't know. I mean, I don't know if you've seen it. There's this kind of famous video of, you know, I've got to count how many times the basketball gets passed around,
and and the basketball gets passed around. And then at the end, says, did you notice the gorilla? And there's, like, a guy in a gorilla suit jumping around, and you just don't see him. And it's because you're focused on the wrong thing. I think maybe each time people have have taken a look at these things, they've they've assumed certain
fundamental things. And one of those is that the call to the, you know, get random to the true random number generator actually hits the true random number generator. And then when you've done the testing,
the testing has been on the randomness coming out of the true random number generator, which was working correctly. It was just that the actual function call wasn't executing. And so, I mean, you know, there's it's always clear in retrospect, but I think the the big mistake was in, yeah, in treating the the fundamentals as as a given.
And and it it's a very small mistake. Like, basically, there's a I think in there's, like, an if if if one if the function calling had been, like, if rather than if defined, if it'd been an if, then everything would have been fine.
And I'm sure somebody who knows, you know, their way around hardware, when they're now looking at that software, would would say, well, this is just obviously wrong. But the point was that, like, at the time when people were looking at it, they weren't spotting things.
And I'm I'm sure there must have been people out there who who did take a look at this code in a superficial way, and and it just kind of passed the smell test and that things seemed reasonable.
You know, they were they were making calls out to a true random number generator. I think where AI is incredibly useful is it doesn't necessarily have the fatigue that a human reviewer has. So you can just tell it, you know, no. Go back again and Yeah. Review it, you know, a thousand times in different ways,
and and a person would basically give up after having scanned it a few times and not found any issues. Whereas I think by prompting these models in different ways, you know, you can basically just hammer through and eventually find the weakness. And I think the reason these
like, the k three model is able to do this aside from the guardrails is just because of, like, how long it will work for and how deeply it will recursively pull the the submodules. And it was only because it had, like, all those submodules that it could see this kind of combination of of errors.
Obviously, on top of that, if you have a business that's building on top of your software, then at some point, they're gonna review that code. But I think what we're seeing it now across the whole ecosystem with people, you know, deploying updates, and a lot of those projects
are very widely used. You know, they're pure play fast projects with no economic model at all, and yet they're still all issuing kind of emergency updates. So I I don't think the the fact that something's open source inherently adds a layer of security because people are going to use it.
But I think there's obviously other benefits that you get from that model. And I would hope that going forward, any any project that's, you know, involved in signing is going to undertake an audit of of this very specific aspect of their code, which is the
in practice, the generation of the entropy, not is their their architecture appropriate, but but is it implemented correctly? Mhmm. Yeah. Very good. We're coming up to time now or or just slightly over.
So I just wanted to say a big thank you, Orange Surf and Q and Seth and everyone who's joined us, everyone in the live chat. We didn't get to any questions. Was there anything just before we jump off queue question wise that I've missed that I really should have done, or is it about time to close the show out?
No. I I think we're good. There's been a couple of bits of back and forth, but nothing that's crucial has gone unanswered. So thank you both for for driving today while I try and relax for an hour. And, yeah, thanks to to Orange here for imparting us with
his wealth of knowledge as well. It's very interesting to to listen to. So hopefully, we're we're kind of on the downslope of of, like, the new kind of,
you know, facets to this vulnerability, I guess. And that things are slowly starting to calm down and we find ourselves in the the new paradigm that is, you know, everybody looking at everybody else's code, which, you know, I guess we could look at as a as a silver lining.
And people are act actually, you know, verifying rather than just trusting, which is good to see. So hopefully, we're all gonna come out stronger on the outside of this. And, yeah, we're overtime. Gonna wrap us up. Alright, sir. Thanks very much for joining us. Really appreciate it, mate. My pleasure, as always.
One last thing I'd love to just throw out there, which is if if you know anybody who's been affected by this or who has been recommending these devices and maybe is feeling absolutely terrible for having done so, just reach out to them, you know,
just be there for them because I think there's probably a lot of people out there who are really in a in a bad way at the moment. Yeah. Absolutely. And if anyone is in a bad way and wants someone to talk to, you can always reach out to them. Uncoverned Walls will happily have a chat through with you. Absolutely.
Alright. Thanks, everybody. Hope you all have a good weekend. And as always, stay ungovernable.
Thank you for listening to Freedom Tech Friday. To everyone who boosted, asked questions, and participated in the show, we appreciate you all. Make sure to join us next week on Friday at 9AM EST and 2PM London.
Thanks to Seth, Max, and Q for keeping it ungovernable. And thank you to Cake Wallet, Foundation, and my Nim Box for keeping the ungovernable misfits going. Make sure to check out ungovernablemisfits.com to see mister Crown's incredible skills and artwork.
Listen to the other shows in the feed to hear Kareem's world class editing skills. Thanks to expatriotic for keeping us up to date with Boost's XMR chats and sending in topics. John, great name and great guy, never change and never stop keeping us up to date with mining news or
continuing to grow the mesh to Dell. Finally, a big thanks to the unsung hero, our Canadian overlord Jordan, for trying to keep the ungovernable in check and for the endless work he puts in behind the scenes.
We love you all. Stay ungovernable.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




