
Unpacking the Coldcard Exploit
Discussed in this episode
Boost this Episode
Send sats directly to the creators. Value for Value.
Plus 1% to Podcast Index, 1% to Boost Bot.
Show Notes
A weekly live show covering all things Freedom Tech with Max, Q and Seth.
HELP GET SAMOURAI A PARDON
- SIGN THE PETITION ----> https://www.change.org/p/stand-up-for-freedom-pardon-the-innocent-coders-jailed-for-building-privacy-tools
- DONATE TO THE FAMILIES w/ USD ----> https://www.givesendgo.com/billandkeonne
- DONATE TO THE FAMILIES w/ BTC ----> https://pay.zaprite.com/pl_JpxtkLv95T
- SUPPORT ON SOCIAL MEDIA ---> https://billandkeonne.org/
TO DONATE TO ROMAN'S DEFENSE FUND: https://freeromanstorm.com/donate
VALUE FOR VALUE
Thanks for listening you Ungovernable Misfits, we appreciate your continued support and hope you enjoy the shows.
You can support this episode using your time, talent or treasure.
TIME:
- create fountain clips for the show
- create a meetup
- help boost the signal on social media
TALENT:
- create ungovernable misfit inspired art, animation or music
- design or implement some software that can make the podcast better
- use whatever talents you have to make a contribution to the show!
TREASURE:
- BOOST IT OR STREAM SATS on the Podcasting 2.0 apps @ https://podcastapps.com
- DONATE via Monero @ https://xmrchat.com/ungovernable
- BUY SOME STICKERS @ https://ungovernable.network/shop/
FOUNDATION
https://foundation.xyz/ungovernable
Foundation builds Bitcoin-centric tools that empower you to reclaim your digital sovereignty.
As a sovereign computing company, Foundation is the antithesis of today’s tech conglomerates. Returning to cypherpunk principles, they build open source technology that “can’t be evil”.
Thank you Foundation Devices for sponsoring the show!
Use code: Ungovernable for $10 off of your purchase
CAKE WALLET
Cake Wallet is an open-source, non-custodial wallet available on Android, iOS, macOS, and Linux.
Features:
- Built-in Exchange: Swap easily between Bitcoin and Monero.
- User-Friendly: Simple interface for all users.
Monero Users:
- Batch Transactions: Send multiple payments at once.
- Faster Syncing: Optimized syncing via specified restore heights
- Proxy Support: Enhance privacy with proxy node options.
Bitcoin Users:
- Coin Control: Manage your transactions effectively.
- Silent Payments: Static bitcoin addresses
- Batch Transactions: Streamline your payment process.
Thank you Cake Wallet for sponsoring the show!
MYNYMBOX
Your go-to for anonymous server hosting solutions, featuring: virtual private & dedicated servers, domain registration and DNS parking. We don't require any of your personal information, and you can purchase using Bitcoin, Lightning, Monero and many other cryptos.
Explore benefits such as No KYC, complete privacy & security, and human support.
Hello, and welcome back to Freedom Tech Friday, a live and interactive show taking place every Friday at 9AM eastern and 2PM UK time feeds. Each week, we dig into the latest Freedom Tech, including Bitcoin, Monero, encrypted messengers, privacy tools, and anything that can help you take back some control in today's digital Panopticon.
This show and the topics we cover are powered by Freedom. Tech, a daily news desk that uses AI to monitor hundreds of sources so we can continue to bring you the signal every single week.
My name is Q and A, and I'm head of customer experience at Foundation. And I am joined as always by Max, head honcho of the Ungovernable Empire, Seth who is COO, I can't call it, and Zach who is CEO at foundation as well.
Free InTech Friday is a live and interactive show and you can help steer it by commenting live, pre submitting your questions on socials, boosting the show on podcasting two point o apps, and just sharing the show with your friends.
Top support from the last show with John talking about all things mining comes from late stage huddle, who sent 6,006 and said, I really miss the old shows, but I do quite like the new ones. I miss the good old days of when I first found the pleb miner monthly.
I went really far and even tried to get go all in research and if mining using landfill gases was a viable option. But after my DCX immersion rig failed and burned up two s 19 x p's, ouch, then I kinda got a little burned myself, pun intended.
But John's right, we were making money. I probably broke even on the entire operation at my house and ended up making a lot of friends along the way. Cool story and a great show. Go and check that out if you haven't done. John is always a class act as a guest. So thank you for your support, ladies and
Without further ado, Max, Seth, Zach, welcome to the show. It's been busy morning UK time, a late night for for Zach in The US, I know. How are we all doing?
We are doing. It was a a good night for everyone in the space to spend some time auditing their code if they hadn't yet already, or even if they had already, spending a few hours digging deeper. So it was a it was a good late night for, I think, pretty much everybody who touches self custody in this space.
But gonna be a interesting topic to get into. I feel like this might be one of the worst incidents for self custody or at least specifically for Bitcoin self custody I've we've ever seen.
And so I just just the whole thing is just absolutely horrible. Wake up woke up feeling the same I did last night, which is pretty, you know, nauseous and kinda sick to my stomach about everything.
Yeah. Max, how about you? You well? Yeah. Well, yeah, echo the thoughts there, really. It's
it's really just shitty to see. And with all the work that has been done to try and push people to self custody and get coins off exchange and take all the precautions and everything else, a lot of people will be affected by this. And so, yeah, thoughts go out to anyone who is. And
my hope is that today we can try and help anyone who needs the help, give some advice, give a rundown of what's happened. And, also, for anyone who might be affected, just try and stop
them from panicking and making mistakes because they've been forced into this sort of situation. So Yeah. Q, I know that is very much your forte, and you'll you'll be helping people. But I think this is, yeah, an emergency one. We we canceled what we were gonna talk about today, so we pushed that.
But, yeah, it needs to be talked about. So looking forward to getting into it. Yeah. So I guess to set the scene in case anybody's been offline or has opted out of of Twitter and the social sphere.
Before I dive into this, I will caveat that if you're catching up later, this is very much still an involving story. More details are coming out. There's different figures being bounced around everywhere.
So this is this the the what we're gonna talk about is like a snapshot in time
and to the best of our knowledge based on the the information that we can gather up. So please ensure that you do your own research as well. But, yeah, if you have been offline for the past twenty four, forty eight hours, a quick sit rep as to where where we are and why we're all sounded so dejected.
In the early hours of yesterday morning, somebody emptied around about 600 bitcoin out of roughly 500 separate wallets, which is somewhere near the tune of like $38,000,000. And it all happened within the span of like half an hour.
I believe every one of those was a single signature wallet and as far as anybody can tell, the people who lost the money, the the rightful owners of those wallets did absolutely nothing wrong.
They bought what is, you know, an industry regarded hardware wallet, a cold card. They would have wrote down their seed words, kept them offline and did, you know, they dotted all the i's across all the t's and they did what people told them to do as a best practice.
The devices involved are cold cards. And according to the CoinKites advisory, this covers mark three devices on firmware version four point o one and later, as well as Mark four and Mark five devices, are the later devices on anything before version 5.6.
And also their QR code based device, the Q, for firmware versions 1.5 or earlier. But there is also separate reports from the team over at Block who've got a great post on this one, which I'll I'll bring up shortly when I'm stopped talking and the guys take over.
They also reckon that the Mark two, which is older again, obviously, is also in scope as well. The alternative products that they offer, TapSigner, OpenDime, SatsCard, all that sort of stuff are at the current state believed to not be affected.
So a quick TLDR before we dive into the technicals. Underneath it, all what happened basically was a random number generator problem. In a rewrite, a significant rewrite of the core card code back in March 2021, the c generation code quietly stopped using the device's hardware randomness and started using
an ordinary software randomness instead, which is I believe calculated from things that are kind of entirely predictable if you know what you're looking for. The hardware itself was fine that that hasn't been exploited.
It was the way that the the software was changed.
The code simply stopped asking for anything from the hardware, I believe. And we're gonna get into the technical detail. That's why it's actually awesome of this sort of stuff. But yeah. So so basically, the the TLDR is that if you are a cold card user of any of those devices on firmware versions
that I mentioned, and crucially, firmware versions when you generated the seed, not now, That's the crucial point. Then you need to take some action, and I will be posting links in the chat if Seth or Max haven't done so already as the links to the the technical deep dive, the the post by block as to, you know,
what action you should be taking and so that you can confirm whether or not you are affected.
Guys, was that a fair summary before we get into the technical details? Did I miss out anything blazingly obvious? The the one thing I did actually before I hand it over is that I believe that the communicated number is now significantly more than 600 Bitcoin. As I said, this is still evolving, but I believe there's been posts estimating
upwards of a thousand as well. So like I say, this is still ongoing. And the the the the kind of case of urgency if you are in the affected group is is great.
Yeah. I think the only thing to touch on forgive me if I forgot it. Was trying to or if I missed it, I was trying to dig up other links. But the two main callouts are if you did generate your seed using your own Entropy properly,
you're safe. So if you did dice rolls but did them properly, which is the huge caveat because lots of people have lost money by doing seed rolls improperly and just creating their own bad entropy.
Or if you used a very secure passphrase, you're safe for a while at least. But the I think the most critical takeaway is no matter what model you had, essentially, you should move funds. Because even the later models that are vulnerable, yes, they're more secure, but they're more secured to the tune of
sometimes hours depending on situations to sometimes likely unbreakable. But it depends on so many factors that you definitely should not keep funds on a seed generated on a cold card in general, and it would be would it be safest to move over? And then like you mentioned, the amounts, like,
the last we've heard, and it's hard to know for sure all of the the funds that are stolen without users reporting. The last we've heard from our chain analysis was over 1,000 Bitcoin, but that will increase. It was very clear from the initial attack
that the user doesn't really know how Bitcoin works or was just testing it first because he only did SegWit addresses, and he did not do them to a very deep
deep look ahead for addresses. So he was very likely missing a lot of funds in the initial breach. And that doesn't even include things like BIP 85 child seeds, which would affect which would be affected, other script types. There's definitely a lot more funds at risk than have been stolen so far.
Yeah. I I think it's worth kind of zooming in a bit to to mention that bit 85 because that's not not the only kind of subsequent thing that's downstream of the the randomness. Right? Because there's other things like they have they have other features such as like
passwords and all that sort of stuff, which presumably if they're being deterministically derived from some really poor entropy, they're also gonna be at risk. Right?
As far as I understand it, yeah. And the the BitPay five one is really important because that's become more and more of a standard for people to use for their hot wallets.
So you may think, okay. Well, I moved all my funds off my cold card, but any attacker with private keys can easily derive all of the child seeds that you've ever created from it too. So any hot wallet or if you've used that to load into another hardware wallet or whatever,
you should consider those compromised at the same time and move any funds off of those. And folks are asking, of course, like, is my mark four affected? Is my queue affected? And
the one question that I've found difficult to answer is asking is when they ask, like, how how long do I have? Right? Like, hours, days, weeks. And this is where you you, like, have to transition from a technical vulnerability where you're talking about, like, bits of entropy, as in, like, how long would it take to crack the seed
to, like, the game theory of who's the attacker, how many attackers are there, and are they gonna like, if if you just woke up and you're like, oh, good. I'm gonna join in on this hack. There's probably gonna be, like, hundreds of copycat, you know, hackers and folks that are gonna be trying to crack these seeds for probably years now.
You know, you you have to consider like, if someone wakes up and says, I'm gonna try to do this. Maybe they don't start with the, you know, the the lowest entropy, which is basically no entropy on the mark three for scenes generated after early twenty twenty one. Maybe they,
actually wanna spend a little bit of money on it. And, you think, you know, that, oh, you saw 30 something like 32 bits of entropy. Someone posted that. And, oh, I have, like, the queue, and I just jitter in my seed, like, six months ago. I mean, I I would just move everything, you know, as as, urgently as possible.
And I'm I'm glad we're able to talk about it today so that, you know, queue and Seth can help advise folks on, you know, the best way to do that in a safe, secure way. Because as Max said at the opening, like, you know, we don't wanna or as we all we we don't wanna mess anything don't wanna mess anything up by moving too quickly.
But, yeah, this is this is like a game theory situation now. And with with AI, I think there's probably gonna be thousands of people worldwide, maybe more trying to, you know, crack these cold card seeds now, and I think it's just gonna continue for years.
Yeah. I think that's a really quick call out before we move on too is because this vulnerability is known, and it's not like a,
oh, just update your app and you're secure or even update your firmware and you're secure. Like, you they are releasing new firmware, but if you install that, you still have to generate a new seed and move funds. So that means that, like you said, people and and only increasing number of people are gonna be trying to breach this.
And most of the estimates on what the actual valid entropy are, if we're talking a thousand people with GPUs, we're talking a day and a half to breach the the higher theoretical entropy levels of what was available on m k four and q.
Just just to be clear, Seth, on that point, where you're talking, like, a a day, day and a half, that is presumably seeds that are generated just off the device without any added entropy and without passphrases.
So there's sort of there's sort of three layers to this, which would be generated just without any any extra bits, which is then extremely low and either already swept or, like, moments away probably.
Then you've got dice rolls, and that depends how you've done it. Because I remember me and Q covering this a long time ago, which was like, if you've rolled dice in a certain way, you're actually lowering the entropy, and it's even worse than what we originally thought the random generated was.
But if you've done it correctly in a 100 plus, then maybe you're in a better situation and then passphrase on top, but it depends how strong the passphrase is. So could you sort of run through those three layers a little bit? And, before I finish on that, it's like, I think regardless of all of that, I agree with what's been said is move
move as fast as is safe regardless, but just to to give a sort of rough estimate for people. Yeah. I I can take this one. Going off of the the Coincare blog, which Seth has posted earlier, talking about dice rolls.
To clarify your point earlier on, like, dice roll potentially weakening, that was a separate bug that they had where they weren't enforcing a minimum to see like rice Yeah. And use that terrible entropy for a c. They they did fix that.
That was quite some time ago. The way that they're communicating this now is that if you did 50 to 98 independent roles, that's that's kind of contributed to a 128 bits of entropy and completely sidesteps the the vulnerability that we're talking about.
And if you did 99 or more, then it's the same thing, but you've got you've now got 256 bits of entropy. So if you're confident that you did that, then you have less reason to to panic. The only other one is if you have an extremely secure passphrase. And by that, I'm probably talking five minimum words or something to the, you know, equal
entropy if you kind of use random strings. If you kind of let the device generate the seed with the bug that we're talking about, but then added a very secure passphrase on top, you are adding a significant layer on top. But again, like Zach's been alluding to, with AI and stuff, like if you've got half of the secret,
then it's only a matter of time before somebody was with enough kind of compute power is able to kind of have a good crack at that. So I wouldn't count yourself as kind of completely safe if you find yourself in that position. I would still be looking to move funds. You'll probably just classify it as not hanging fruit hours.
The only other criteria of user would be multi vendor, multi sig customers where cold card forms only one of your presumably a two of three minimum, which is the the common one.
Then obviously, even if that device is completely compromised, it's not enough to to compromise or move funds out of there. Would I still be looking to rotate that key out? Absolutely.
But, yeah, know, that's the beauty of multisig, especially if you have a a minimum threshold, something like a two or three, and call card is only one of those keys, crucially, then you can count yourself as as safe from this, but, you know, you still need to take some action and rotate that key out as well.
And one thing I wanted to add is, like, when when you're seeing, like, how many bits of entropy exist for the seed generation, that 32 bits, if you go ask your AI, you know, how long would it take to crack 32 bits, it'll say something like I think it's, like, seconds. Right? Seth and Q, it's like
It depends on the amount of hardware, but, yeah, it's, like, thirty minutes for a regular, like, desktop computer seconds if you have any sort of real compute. Yep. Right. So that's actually much more nuanced than that because an attacker that that's just step one. So an attacker needs to do that.
And then for each exit for each possible seed, the attacker needs to, you know, follow the derivation path. So if you're if you're segwit, there's a specific derivation path. Right? If you're there's there's all these, there's probably, you
know, maybe four standard derivation paths that an attacker might check, then they have to check, you know, the index. Then they have to and then even if they find, you know, coins at that specific, you know, index with the specific address,
you you might have multiple accounts, which which is, like, kind of the account index, like account zero, account one. And then they start looking at the actual addresses
and what seems like may have happened at least last night or yesterday as the attack was ongoing is that then there's a a gap limit with addresses. And so, sometimes you have a gap of 10 addresses, 20 addresses, 30 addresses before you find coins at the next address.
And I don't think that that that the attacker properly, you know, looked at that from a gap limit perspective. So people were reporting that they had some coins stolen, but not all. So all I'm trying to say is that it's it's not exactly a function of, like, the entropy purely. It's up to, like, creative attackers now to figure
out, you know, how how far ahead are you looking in the gap limit,
you know, what accounts are you looking at, what derivation paths are you looking at. Maybe someone clever realizes that there's some wallet that uses, a nonstandard derivation path, and no other attacker has looked at, you know, that software wallet yet that might be connected to cold card.
And then, you know, Seth and Q were saying, right, passphrases and, you know, what if you have a one word passphrase? What about low entropy dice rolls? You know, someone rolled five dice rolls. I just saw someone posting on x that there's some reports from user right now
that they have a a weak passphrase, but it it they're they're safe right now, and so they're able to move their funds. So this is this is, like, a very, very complicated,
I think, sequence of of attacks right now. And and the good thing for cold card users is that if you have anything right now except, like, the mark three with no passphrase or or no dice rolls, like, if have anything else, I think it looks like right now, like, you're okay, and there's time, you know, to react to this.
Yeah. We've we've got some great questions coming in. I know there'd be a lot of interaction on this one. Which one shall I do first? Quick question from Bon on Twitter. He's saying, what about the option some people did where you allow the device to to generate the what we now know is is a weak seed.
At night in dash rolls on top of that, did the firmware even add the dash rolls properly? My understanding is yes, it did. So even though you've kind of given it little to no entry from the device itself, the dice rolls, as long as they're they're a sufficient amount, which 99 would be, then you still have
a sufficient amount of total entropy to generate a secure seed. I haven't validated that. That's just my understanding of what the stuff I've read this morning. If there's any pushback to that in the between the guys, please let me know, but I'm pretty sure you should be safe in that specific scenario.
Yeah. That matches everything I've seen. It's just, yeah, just the important 99 plus dice rolls part because, obviously, that not only have people screwed that up in the past, not done enough, but there was that cold card bug that I posted a YouTube video about that would allow you to do way too little
dice rolls and proceed or reuse the same number, all of those sorts of things. So that's the very important piece is dice rolls, quote unquote, on its own is not enough. Doing them correctly is enough to protect you against this attack.
Yeah. And I think, ultimately, if you're not sure because it might have been a few years ago, then you just need to on the side of caution and and start to look at moving funds out out of that just just to be on the safe side.
Another question, Zach, I'll I'll level this one at you for obvious reasons. Jim on Nosdas saying, how does Foundation's product compare in terms of security? I know you will be well versed in this in the past twelve hours.
Yeah. Well, the the first thing is one of the questions a lot of people had as well was isn't foundation affected because didn't you guys just clone ColdGuard? And people are starting to are very surprised to hear that no.
So that's the first thing I would say. It's it's it's it's we did it in a in a different way with the, entropy generation. So there's a couple things. One is that, of course, all Passport models, implement and combine multiple sources of entropy.
So depending on the model, right, it might include the secure element, the processor. But what all our models have, which is really cool, is something called an avalanche noise source, which is an open source circuit, schematic that we, adapted from this hardware hacker named Bunny who did a really cool,
crowdfunded project called b trusted or precursor, and it allows us to have a really great source of randomness, source of entropy on the circuit board itself without relying on black box silicon. It just uses standard, components like resistors and capacitors and some other stuff.
And, we integrate that into all of the entropy generation as well because we didn't want to only rely on black box, you know, silicon because who knows if that stuff is backdoored. So we've confirmed, of course, with, both with humans and with the help of the latest, AI
models. And, of course, you know, we as a company have have cyber access as well to, the latest GPT cyber, model. You know, we've confirmed that none of our entropy generation is affected
by this and nor has it ever. You know, one of the great things about AI is we're able to look back through every commit, right, every change to the code base, which prior to AI would be very difficult to do and would be very time consuming.
And now it can be done in in minutes or tens of minutes, and so it's very helpful. So on on passport devices, you know, the the entropy generation works as expected. What I do wanna point out, though, is that, you know, the the intent the cold card team did intend to combine multiple sources of entropy.
It just was not wired up correctly in the software. So, like, the intent was to combine, sources of entropy from the, you know, the, the secure element and the MCU. There may have been other sources. I don't remember.
And it just unfortunately was was not wired up correctly in software. I don't know if that helps answer the question. Yeah. So, I mean, that seems to to somebody less technical, like, you know, a a a pretty big fuck up. Like, how how aware can we can you go in a little bit deeper as to how something like that kind of happens?
And I know you can't obviously speak for the for the Coincare team, but, like, how does something like that happen, and how does it go unnoticed in a in a source view for viewable project for what we now, like, five years?
Yeah. Yeah. It's tough. I mean, firstly, I would say that, like, it is scary right now in in the AI world. I don't wanna you know, what what's the term? You don't wanna throw stones in a glass house. I don't think hardware wallet companies should be jumping on the train piling up on this because every time a new,
model comes out, right, a a new step in step up in intelligence with AI models, it's going to be easier to find potential, exploits or vulnerabilities. And all code bases likely have vulnerabilities, or or most certainly have.
The question is, is it a vulnerability that's like a showstopper, right, or is it something that can be fixed or patched or maybe just has open edge cases or or so on? The the code to generate, entropy, right, or randomness is probably the most important code for a hardware wallet
outside of maybe, like, like, the code to deal with entering PINs, right, like PIN or password attempts and rate limiting that code. And so, like, one thing is most hardware wallets engage security auditors and or are very friendly with, like, the security community and take security reports seriously.
And so when we did Passport, Founders Edition, we engaged security audit team, the same guys from who did the wallet.fail presentation many, many years ago. They're called Key Labs, and then we engage them again for, when we were building KeyOS before we started shipping Passport Prime.
So there's an aspect here of of one, like, having free and open source software, where, and and a good bug bounty program or fair bug bounty program and being respectful and engaging with security researchers because they will want to come look at the code, find issues, and be rewarded. Not really monetarily,
I think, is what drives most of them, but also, like, the recognition. Like, if you're to to post, like, a put up a a security, know, a blog post and and thank the security researcher and let them publish, you know, the fact that they found an explant. It's it's all called responsible disclosure.
And so that's really important. But it's also really important to not be so you know, to to to realize that that no one is perfect and to engage outside security auditors, which is very commonly done. And outside security auditors aren't perfect either, but you know that one of the first things they look at is, like, the entropy
generation, right, the seed generation because of how important that code is. I don't know, Q, if you're trying to lead me to talk about my my post on x from last night too. You know me too well.
But in this specific situation, you know, cold card did have correct entropy and c generation prior to that early twenty twenty one period where they made a major change, to the code base.
And, so if for any Coldcard user from before early twenty twenty one, should be unaffected by this. And back then, Coldcard used a lot of GPL code, which is like a copy left software licensing that requires that Coldcard, therefore, fully open sources their code in return
under the GPL license. It's a very cool license that we use at Foundation as well. And they had treasure code in the code base. And, of course, when Foundation announced in mid twenty twenty that we were building passport and that we were using some cold card code as a base to help get started.
Everyone knows, you know, the story of maybe not, but everyone back then knows the story of how NVK got really upset and said he regretted GPL and free and open source software, and they set out on a major effort to rip out all GPL code from the code base, including the Trezor crypto libraries and and other stuff.
Now that wasn't the only stated purpose. They were also adding in, like, the the new libsec stuff, and and they were working on that for a long time and and so on. But they ended up changing the code the the license of the code to what's called source available instead of open source,
and they ended up using a new library. I don't know if it was written by Coldcard or if it was someone else because I don't think the guy who wrote it is is affiliated with the company, but it's called LibNGU.
And they released like, the this code change that caused the, you know, the Entropy bug in early twenty twenty one was a direct result of doing this major change to the code base. And it even said in the release notes, like, something along the lines of, like, the last GPL code was removed.
And so they were able to fully and and officially swap the licenses. And this LibNGU
library where it could have been, like, a great library that the whole space wanted to build on, but they made up a a a software license, something like the something Bitcoin license. Like, it was just a made up software license. It's not it wasn't an open source license.
And so it was it's that library has only ever been used by Coldcard, as my understanding. And I don't think it had many eyes on it. And, that's that's where this bug was introduced, where it went from from calling the old the old source of entropy to calling something, within this library, within the LibNGU library.
And, and whatever however it was wired up behind the scenes there, it did not correctly, incorporate the entropy. So I feel like there's I don't wanna say that like, decisively say that the decision to abandon, you know, free and open source software caused this. I don't think that's, like, a fair characterization.
I think that's probably a little too it's it's it's I you you can't say that it caused it, but you could definitely say that it was causal. It was part of the impetus to do this major, rewrite of a huge chunk of the cold card code.
And it seemed to be, to me at least at the time and and with foundation and, you know, Q obviously lived this with me. I think you did, or maybe you joined after Q. But it it seemed at the time to be. Yep. Yeah. It seemed to be very reactionary and and and kind of driven by, like, rage and, like, vindictiveness.
And I don't think there was any reason to to rip out a lot of that code, like the Trezor crypto library. And we still use that Trezor code, in parts of the old Passport, firmware for for Passport Founders Edition and and Passport,
and Passport Core or or the second generation. It's yeah. I mean, I could probably talk for hours about this, but it's it's my my takeaway is that free and open source is is the way to go because and and engaging with security researchers and engaging security audits and being very
humble, right, that no one's perfect and that we need to, you know, bring in as much of the community as possible to to get eyes on on the code and make sure that there there these types of horrible, you know, vulnerabilities do not exist.
Yeah. That's a good recap and a good roundup. There is a question from BTC Wrestle on on Nosto, which is very timely. Obviously, this is what we're talking about only affecting cold card users, but there's bound to be thousands of other people out there that have got other hardware wallets
that are gonna be asking themselves this same question because they're gonna be feeling uneasy, is completely understandable. And his question is, how can you verify that your the seed generation on another hardware or software while it had sufficient entropy?
Well, my my read of it basically is you can't look at a seed and tell whether it has bad entropy or not just by kind of looking or interpreting from the words. It doesn't work that way unfortunately.
The only thing you can do, and Zach kind of already covered this, is I guess work out the the firmware version that you had on the device when you did the c generation and then unleash, you know, the the the latest models on that if you're not a technical one user
to to, you know, look for, you know, how the entropy was derived, which is exactly what we've done internally through, like Zach said, through all of the previous commits to see if we, number one, currently have any vulnerabilities, which we don't. And number two, have ever had any vulnerabilities in the past, which also we don't.
That would be the only kind of way in which you could give yourself some comfort if you were using something that's not a cold card because you can't just look at 12 or 24 words and be like, yep. That's a good seed or that's a bad seed, unfortunately.
Any push back to that or am I did I did I hit the mark? No. I I think with AI, like and that's also why I I I think the AI companies really need to enable normal people to to check these code bases and not flag it for, like, cyber abuse because we live in an era now where if you're interested in buying,
you know, a a hardware wallet or something like that and the code is open source, which I think is an absolute requirement, you could point it to to the you you don't have to point it to the GitHub, or you can just ask your agent to go try to figure out and check everything. And it might not always give perfect results, but
it's it's gonna give pretty good results. And, many people are saying, and and we've experienced this yesterday, that all you had to do yesterday was ask your AI. At least how I asked was I asked it to go look around 2021 if there were any changes to the cold card code for seed generation.
Now that's maybe more of a pointed question, but you could also just ask it to look at a specific company or project, and it'll dig up everything. It'll go on Reddit. It'll go on GitHub. It'll look in the issues. It'll look at the previous commits. It'll look on x if you have it set up that way.
And, you know, you you could this is, I think, an area where we see that open source and and transparency and approach all that kind of stuff is is is very helpful, because it creates this, like, environment where now the AI can help
find issues or validate that. Like, no. It looks like it's okay. It looks like there aren't any, you know, catastrophic bugs that would affect seed generation.
Yeah. Yeah. Good point. Seth, I'll level this one at you. I've I've it comes from Drinkor on x. It's just a a screenshot of what I believe is to be Lloyd's thread where he's talking about you know, he's given a great breakdown of what's gone on here.
And the the quote in the picture says, for even non cold card users could feel some ripple effects from this. To be clear, not from a security perspective, but more so from a privacy perspective.
The quote says, if you participated in was Wasabi coin joins or pay joins with people who use vulnerable cold cards, your privacy is damaged because those users full transaction histories are now easily traceable, shrinking anonymity sets for everybody involved.
Seth, do you wanna unpack that one for first and foremost, do you agree? Yeah. Yeah. Definitely agree, unfortunately. If you were, like, if you were mixing to a cold card or had sent in funds from a cold card to Sparrow to Mix and HotWallet, like, whatever that path was. If it included cold card, it could it could damage the anonymity
set of not only you, obviously, your entire transaction history is revealed. So if your private keys get pwned, the attacker knows exactly where they came from and exactly where they went through the mixes.
But also with those anonymity sets, as these continue to get unwound over time, like, these the transactions exist forever. So, yes, quote, unquote, only a thousand Bitcoin have been stolen so far, but that number will drastically increase and just the number of wallets pwned will drastically increase.
And that will mean that if those users are participating in any of this privacy tooling, you should expect that your anonymity set is reduced. Now that's not to say, like, necessarily that, like, you need to do anything
if you weren't one of these cold card users, but it's just something you kinda need to be aware of and keep in the back of your mind if if you have a very advanced threat model specifically.
But I think the maybe broader implication of touch on too, and maybe we can kinda want them talking about what a migration path could look like for people, is that you do need to worry about security, obviously, when migrating funds off of your cold card. And so getting into something that's secure is obviously vital.
But you also do need to consider privacy. That's one of the the downsides of Bitcoin's blatant transparency is that when you move funds, it becomes very clear. And if you move funds together, common ownership input heuristic means that Chainalysis,
etcetera, will be able to to guess that those inputs are owned by the same person. So the common approach to just sweep your wallet all to a new a new address is simple and, I guess, good for security reasons because you can do it more easily,
but you need to understand that you're then linking all of those inputs back together. So, like, if you if you mixed via Whirlpool into a cold card for post mix and then you now migrate all funds by just sending all of your funds altogether at the same time, you undo everything you've ever
gained through using Whirlpool because you link all of those outputs back together at the end, and it's as if you never did Whirlpool. So maybe we can touch a little bit on, like, kind of the strategies for migration, but just quick tips would be, obviously, move to a good secure place. If you have another good hardware wallet,
you can use that. Make sure you don't reuse your cold card seed.
If you don't have a hardware wallet, you can use something like cupcake, which lets you turn an old phone into a an air gap signing device, which is an especially good interim. You don't necessarily have to keep with cupcake forever, but it's a good stop gap until you get another hardware wallet if you do prefer hardware wallets.
Or even just moving to a known good hardware wallet, something like Spero wallet, something like Envoy, something like Cake Wallet is better than having your funds vulnerable to this specific breach. But then when migrating, a really key thing to keep in mind is if at all possible, try to move individual UTXOs
one at a time to unique addresses. It's still gonna leave some footprint because if you do them all at the same time, it's gonna be possible for someone to guess that those are linked together, but it's still much better than you sweeping your entire wallet in one transaction and revealing that to the world.
So in an ideal world, you move individual UTXOs to new addresses every time on the new new wallet with new seed. And, theoretically, if you can, you try to randomize the timing of those transactions. But we're we're humans. We're not gonna be able to do that perfectly randomly.
Yeah. Just on that point about moving individually UTXOs rather than sweeping, I think it's worth people considering how at risk they are. Like, if you're someone who doesn't have a pass raise, doesn't have dice rolls, and you're, like, seriously at risk, but just weighing up how much you worry about timing analysis and,
you know, moving individual UTXOs rather than the sweep and whether it's worth the risk depending on how much you have, etcetera. And then maybe also thinking about what you can do in the future to help with whatever privacy you've undone might be a good thing. But I I think
the most important thing is just getting them safe. Get your get your savings safe, and maybe wouldn't normally be the advice that I would give, but that matters more than the privacy for most people unless you have a serious threat model.
Yeah. Completely agree. Like, it's no good having perfect privacy if you've got no coins left. Yeah. Security first, privacy second. A couple of things I would add to this, and I have a a an opt sweet out about this this morning just to convey the the urgency.
It's times like these where scammers and impersonators, although they are prolific day in day out in the Bitcoin space, they're they're gonna be firing on all cylinders right now because they know that there's gonna be thousands and thousands of people in a panic state.
So it's worthwhile recapping some of the absolute basics. There you should never under any circumstances give your seed words to somebody else. Irrespective of whether they look like me or Zach or somebody official from CoinKai or any other hardware wallet manufacturer, we are too busy to be reaching out to you directly to offer you to
make your funds safe. If you find yourself in that position, it is almost certainly not legitimate and you should cut communication immediately.
There is never a reason that you ever need to enter your seed words or hand them over to somebody else even if they are promising to do good things and help you get out of that panicked state. That just doesn't life just doesn't work that way. So remain vigilant.
And what was the other one I was gonna say?
It was oh, the upgrade I've I've had a couple of questions around is upgrading the firmware enough? Hopefully, by now, you've been on for the whole call, you should know that that is not the case. No is the answer. Updating your firmware is not enough. This whole scenario
is stemmed from how and when the seed was generated on the call card device. Irrespective of what you're running now and irrespective of what you're running tomorrow if you update the firmware.
So you need to kind of take a step back, look at your your stack, figure out if you're one of the the affected users. And if you're not sure, I would suggest reaching out directly to them, although they are quite clear on the blog post
as to which firmware and which devices are currently known to be affected. As I said at the top of the call, it's not to say that that isn't gonna change. This is rapidly evolving, but that's accurate as of right now. Go on, Max. So did you say it was anything before 2021?
When when was it this change went in? So, like, anything before a certain time was, like, presumably okay, and then anything after is, like, definitely not. What was that? What was that? I believe the the big change that caused this went went on in 2021, which is firmware version four.
In theory, if you did it before then, I think you're safe. Although do not take that for granted. You need to do your own research and confirm that because as I've said multiple times, this is rapidly evolving and there has been reports, I believe, from the block guys that said that the mark two is also vulnerable.
Now I don't know whether it's the mark two running a specific firmware from 2021 onwards. I presume that's it. But, yeah, don't use the date as the hard timeline as to whether or not you're safe here. Like, there's multiple factors.
How you generated the seed, what firmware you were on, what device you were on when you generated it. That one leans more into how how at risk. The later devices are slightly less at risk, but that absolutely doesn't mean that you don't need to take any action here.
Like, is if you are a cold card user, you need to be taking action even if that action is to just take a step back and think about when you generate the seed, what firmware, etcetera. That's the minimum you should be doing today without fail. Yeah. Yeah.
I've got a question on on Twitter from Johnny Iverson. I think I might have touched on this briefly, but keen to know if anybody's got any further comments. He said, if you have a cold card as of one of three sorry, as one third of a multi vendor multi sig, do you recommend moving funds?
Although likely safe, it seems it may be smart from a privacy standpoint. Yeah. Good summary. Are your funds at risk? No. Even if that one seed is compromised, obviously, if it's a two or three, which I assume is what you mean here, where you need two keys to sign off to move any funds, then no, your funds are not a risk.
Would I recommend you take action? Absolutely. You just have more time to to do this in a in a more calm and collected way. Because like you say, one key is not enough to move any funds. But would I migrate that key out of your quorum? Yes. 100% and and do it sooner rather than later with an alternative device.
And yes, if if you are if you do find yourself in that position, that does mean that you're gonna have to move all of your funds because of the way that, you know, traditional Bitcoin multisig works. As soon as you do a key rotation,
you get a new list of addresses that are controlled by the new quorum of keys, and you're gonna have to migrate all those funds. So also bear in mind what Seth was talking about earlier in terms of like consolidating your funds or moving UTXO by UTXO.
That's a decision that you need to weigh up based on your your privacy needs, I guess. Like, if you've got a 100 GTXOs and they're all mixed outputs and you absolutely wanna keep them safe as keep them separated, then you're you're gonna need to take your time and move those those UTXOs one by one.
I guess for most people, it's gonna be an in between stage where they kind of just consolidate some just to minimize the the kind of running around that they've got to do in terms of number of transactions, I guess.
Guys, have you seen any more any more questions pop up? No. I just I was just seeing on one of the groups, someone else has just been drained with that they had a passphrase. I don't know what obviously, like, how strong the passphrase was, but I didn't know if that had already started, but presumably it has.
Yeah. Bonnie's sorry, Seth. Bonnie's asking, has anybody heard of anybody losing funds on a mark three with firmware prior to the version four where we know that the or we're quietly confident that the the bug was introduced?
I haven't heard of any specifics with that, like, kind of scenario,
But that's not to say that they're not out there. Not everybody is on older firmware, but from what I've seen and from what, you know, speaking to team members and stuff, it sounds as though that that firmware, if it was live on your device when you generated the seed is has been pretty well vetted in the last eight hours or so,
and you're probably gonna be safe. But again, I sound like a broken record. You need to do your own due diligence as well.
Seth?
Yeah. No. I was I was just gonna say that, like we talked about before, just because the attacker wasn't attacking specific aspects of this doesn't mean that that won't happen. The bug the bug is out. So if you are affected by this, don't think just because, oh, I have an okay passphrase or I only used BIP 85
seeds out of this or something more complex that that you're safe from this in general.
Yeah. I I think maybe the only other thing I'll add, and I'm I'm sure that there's more we can get into, is just also don't let it shake your belief in self custody. Like, unfortunately, seeing a lot of takes that are basically send your coins to an exchange. You should have been using them anyways. Or
trust River or trust a custodian. Like, the that's the, like, that's the solution to this when they've lost far more Bitcoin than this in the long run. And this isn't this should not be the moment where you say, like, I'm not gonna worry about self custody at all.
But it should remind you that not only do you have to take personal responsibility for self custody, but that there is still trust involved. I think a lot of people, whenever they approach things like this, they just think, oh, I'm doing self custody, so I'm now trustlessly using Bitcoin.
But you're always relying on something unless you're brilliant enough to understand and audit the code of all the devices that you're using of the signer of the the software wallet, all of these things.
Like, there is trust involved. So it is important who you choose to trust, but also just understanding that you you do have to have defense in-depth if you're talking about, like, your your family's future wealth. You need to make sure that there are other protections in place.
So it's it's definitely sad, but should not scare people away from self custody. Just make you think a little bit deeper when you're talking generational wealth for sure. Yeah. Absolutely.
There's a question on x from BTC stoic. I I don't know whether the questions got chopped or whether they pressed enter too soon, but they said I've seen posts from more technical people saying this is fine.
I'm not sure what you mean by this, but if you're just talking about the the situation, then I, you know, hard disagree that it's there is
not fine. But it would be helpful to know if there's some way to check if anybody here knows. So BC stoic, like if you are talking about the situation, I've already answered that. If there's some context missing from your question, please drop it in the chat again.
There's a question on Noster from Umni. What are the odds of exchanges being affected? And then they followed up with pretty sure MVK on a podcast recently said that they audited all their software using the latest anthropic models.
Yeah. I also saw that. I I guess the model missed it. It would well, yeah, clearly, either either that or it was missed and and ignored, which I find very, very difficult to believe. What are the odds of exchanges being affected?
Well, they're only gonna be affected for the criteria that we've already talked about, I guess. And that is if they were using any of the affected firmware and they have a single signature wallet, which I find very difficult that any good exchange will be doing. So most of them are probably gonna be fine even if
well, no. They're not gonna be using their sole call card as an exchange operation. Like they don't work like that unfortunate well, thankfully, should I say. So I'd imagine most of them are fine and they've probably got far more sophisticated things at bay, which most of them don't talk about for obvious reasons.
Oh, BTC stoic is followed up. Sorry. I meant a 100 dice rolls plus large passphrase. Yeah. We've covered that. That as long as the the dice rolls were were done, I guess,
you know, as you would expect with, you know, it's it's not like a bias dice or anything silly like that. Then that on its own, I believe is gonna be enough because you you know, there's enough entropy there that you, you know, outdo all of the the lack of entropy from the the buggy software.
And if you're using a large passphrase on top of that as well, then you can you can consider yourself pretty well covered, especially compared to everybody else out there who's unfortunately fallen prey to, you know, just allowing the device to derive the seed and not using a passphrase or using a very weak passphrase.
Alright. We are coming up to time and I'm not seeing any more questions roll through. Guys, is is there anything we haven't covered off in terms of like practical steps for people, you know, stuff that they should go and read to, you know, a lady who might have about specific devices, be it call card or anything else?
I think so. Go on. Yeah. I I think maybe I've missed it, but we could touch a little bit on multisig. I think, Minh, you maybe pretty heavily have said, for most people, multisig is maybe overly complicated.
At least we have historically said that and said, like, keep it simple.
You know, with this unfolding, and as Zach rightly said, like, it's not a time to just dunk on people. It's it's a time to reflect. And I think maybe multisig as it's more accessible now, especially multivendor multisig starts to look much more appealing and and hopefully not necessary, but maybe lets you sleep easier at night
no matter how good a company is.
Things can happen. AI is moving fast. I just I wonder if it's worth us rethinking our statements. Yeah. Yeah. Can I Go on, Seth? Go ahead. Yeah. I just wanna touch on that there is an interim solution. It reminded me not an interim, but an in between solution is a better word, where,
like, I have been very vocally against pass phrases for a long time simply because a lot of people lose money by not understanding what a passphrase is, not saving it securely, and losing everything. Like, we we've seen this at cake a lot where users just see a passphrase option,
ignore all of the copy that warns them about what it is and how it works, create it, not save it, and then complain because they they can't restore and get their funds back later. But that being said, I think there is a place for us to rethink improving how we offer passphrases as an option for users,
especially because we can make it so stupid simple to save into their password manager, especially on mobile devices to to pair with it where when you're using a
yeah. I'm blanking on the term. But when you're using something like Envoy on mobile or Cake on mobile with a hardware wallet, we should make it trivial and clear what a passphrase is, why you might want to use it, how to generate it securely, and even prompt to to generate securely using your password manager,
and make sure that it's backed up properly. Because there there are ways to make that onboarding much simpler, and passphrases do help to protect against this. But, obviously, they do bring that major downside of if you lose your passphrase, you lose all your money.
So I think they are maybe a solution we need to think more about from a UX perspective of how do we solve the main hurdle of passphrases more for our users as an in between. Because I just like, multisig in general, I still just think it's it's way too onerous for the average person.
Multivendor even more so, plus then you're having to give a give up your information to multiple vendors about where you live, and
it just it it compounds a lot of problems. But I do think that maybe past phrases or something we need to think more deeply about and not just dismiss as a, just keep your safe phrase safe. You'll be okay, which, honestly, I've kind of leaned more towards just for the simplicity.
But maybe rethinking more of the UX around it to figure out ways that we can make it as seamless as possible for users who do want that out of layer security to be able to do it in a way that doesn't require them to fully even understand how fast phrases work, but to to, yeah, abstract some of that away.
Yeah. Absolutely. Zach, any any sign off from you before I close this out? I mean, I don't wanna push us over time necessarily, but I feel like there's there's a component of this, which I I I'm still kind of upset about, which is that I I do feel like
I I feel like the entire Bitcoin community and Bitcoin podcasters and educators who which is where all new Bitcoiners get their information from. And I feel like there there needs to be some serious reflection after the incidents of the last twenty four hours
because
free, like, free and open source software is a really important principle, and it's one of the reasons that got me well, I think I got into Bitcoin first, and then I got into open source. Right? I became an open source advocate because of Bitcoin, because I, for years, listened to podcasts like TFTC,
you know, with Marty Bent and Matt O'Dell, Stefan Lovera. Like, that was very formative for me between 2017, 2016, and then ongoing when we started foundation in 2020. And when NVK decided to migrate the code base away from open source, there was an opportunity
for someone to say, hey, man. Are you sure that's the best idea? Are you sure like, why are you attacking open source? You know, why are you taking this action to rip out all of this Trezor GPL code from your code base?
Maybe take a step back and realize that how important it is. And so many folks who advocated for years on every podcast that I listened to that had such an impression on me and so many others,
they just turned, like, a blind eye to it. And I don't wanna say everyone because not everyone did, but, like, largely turned a blind eye to it and let this happen. And I'm not saying that that's fully responsible for what happened yesterday, but there is definitely, like, a responsibility from the Bitcoin podcaster and educator community
that to to to call out bad behavior when you're defaming other companies or projects like Foundation or Seed Signer, you know, Seed Signer is a fantastic open source project, there's a obligation to call out bad behavior and to also defend free and open source principles for both hardware and software.
And in this specific incident with this specific individual and company, almost everyone in the in the Bitcoin community turned a blind eye to it because they were his friend or they were sponsored.
And I just it just eats me up the entire situation. I'm not saying it would would have been preventable. It's totally possible that this bug would have still been introduced. But, like, what's the point of having these principles if if you selectively decide to just ignore them when it's for a friend?
And so that's kind of how I feel about the whole thing right now. You can probably hear my voice. It's just like it's it's it's just it I'm really fucking upset about it because this there's no reason it should have gone to this point.
And I'm a huge advocate of open source and supporting other open source companies. And and we've been saying for years, Q, Seth, myself, like Max, you, that open source is a core part of Bitcoin and a core principle.
And it was and and it just so happened that this individual, right, NBK and I'm I'm not saying it was obviously, it was an accident. It was not intentional. But this should have been this was an open source project, and it should have been an open source project, and this should not have happened.
And all Bitcoiners and educators that advocate for free and open source should not have turned a blind eye to this six years ago. So that that's that's all I'll say right now.
Yeah. I hate to kind of close this out on this. Thanks for that, Zach, by the way. But it I've just seen a tweet from Kevin from Wizard Sardine. It looks like there's a a fresh wave of drains going on literally as we speak. So I guess just if you're a cold card user, please please please take action.
Please stay vigilant. Be careful of, you know, who's DM ing you. Stay extremely vigilant. People will not reach out directly to you. If you need support, then you should use the official channels, but you need to take action soon.
Even if that's just checking whether or not you're in the affected parties, but please, for your own sats, you need to take action immediately like this is not a drill. If you do need support, go through the official channels only and ignore all DMs.
Alright. We are overtime. I'm gonna close out of that and there's inevitably gonna be more details revealed over the course of the next days. This is literally unfolding right in front of our eyes as we're recording this live.
So my heart goes out to everybody that's affected. This is, you know, a very, very sad day for Bitcoin. And the the saddest thing of all is that the users that are affected did all the right things. Like, they they followed all the advice and they they were not at fault.
The the the device or the way that the device the software on the device handled the the the entropy was, which is, you know, truly sad. So my heart goes out to everybody. And, yeah, I will close out of that. But please, if you're a Call Card user, take some action. And if you're not, you know, go and enjoy your weekend. Thanks, everyone.
Thank you for listening to Freedom Tech Friday. To everyone who boosted, asked questions, and participated in the show, we appreciate you all. Make sure to join us next week on Friday at 9AM EST and 2PM London.
Thanks to Seth, Max, and q for keeping it ungovernable. And thank you to Cake Wallet Foundation and my Nim Box for keeping the ungovernable misfits going. Make sure to check out ungovernablemisfits.com to see mister Crown's incredible skills and artwork.
Listen to the other shows in the feed to hear Kareem's world class editing skills. Thanks to expatriotic for keeping us up to date with Boost's XMR chats and sending in topics. John, great name and great guy, never change and never stop keeping us up to date with mining news or
continuing to grow the mesh to Dell. Finally, a big thanks to the unsung hero, our Canadian overlord Jordan, for trying to keep the ungovernable in check and for the endless work he puts in behind the scenes.
We love you all. Stay ungovernable.
Machine transcript; expect the odd mishearing. Click a passage to play from there.




