π’ LIVE : Did Bitcoin Maximalism Cause the Coldcard Hack? | Zach Herbert & Nick Neuman
Description
π’ LIVE Thursday, Aug. 6, 12 PM ET A firmware bug that shipped in March 2021 routed Coldcard seed generation to MicroPython's Yasmarang software randomizer instead of the device's hardware random number generator. Because both functions carried the same name, the code compiled without error. Seeds generated on affected firmware carried roughly 72 bits of entropy instead of 128 β enough for an attacker to reproduce them offline. Coinkite disclosed the flaw on July 30, 2026. Attackers have since drained more than $130 million in bitcoin across multiple waves and thousands of addresses. The mechanics are now well documented. The question we're asking is why nobody found it for five years β and whether bitcoin's self-custody culture, with its trust in a small set of vendors and its hostility to outside scrutiny, made that possible. Camila Russo is joined by Zach Herbert, co-founder and CEO of Foundation, maker of the Passport hardware wallet, whose early firmware was built on Coldcard's codebase before Coinkite changed its license; and Nick Neuman, co-founder and CEO of Casa, which builds multisig self-custody for bitcoin.
Tags
Related Videos

Why Anthropic's Escaped AI Agents Still Think They're in a Simulation: DEX in the City
Unchained
17 views

Why Abu Dhabiβs Sovereign Wealth Fund Is on Public Blockchains #podcast #web3
Unchained
22 views

Giannis Antetokounmpo Reportedly Spreads His Cash Across 50 Banks
Unchained

Does Wave Three Prove the Coldcard Attacker Changed Tactics?
Unchained
16 views

SpaceX Shares Tumble Despite Earnings Beat
CoinDesk
41 views

Crypto's Bear Market Is a Trap Before the Real Inflection Point
Bankless
148 views