Buying Bitcoin IS political activism - activism that works.

Bitcoin

AI assisted bitcoin hack: on Coldcard wallet

3 Mins read

Last weekend, many “bitcoiners” started posting about losing bitcoin, secured in their cold storage. Not just any cold storage, But in ColdCard, which is like a gold standard of hardware wallets. Based on user reports, this site tracks the lost bitcoins in Coldcard hack: https://coldcard.rip. This is just an estimate.

Bitcoiners (me included) always talk about exchange hacks, from Mt. Gox to Wazirx in India, how 1000s of users lost their bitcoin in a single exchange hack and the need for self-custody. Even the first video on our “Bitcoin in Tamil” youtube channel is about self-custody:

But now even self-custody is not safe? Hardware wallet / cold storage is pointless?

What really happened?

Trezor helped establish many foundations of the hardware-wallet industry. The founders of Trezor literally co-authored BIP-39 seedphrase. Most other hardware wallet either fork or use Trezor libraries in a way, including Coldcard. But few years back when Coldcard changed their code, they broke the entropy logic. They introduced a bug:

Rather than generating a random number out of 2^256 possibilities, the bug reduced the space to a small set ~2 ^ 40 possibilities. This allows people with huge brute force capabilities and AI assistance to brute force into those small set.

This beautiful video explain the bug in detail:

For those who are too busy to watch above video:

Is the end of self custody?

Let’s dig into it a little. The point of Self custody is to avoid “Single point of failure / SPoF”.

With exchanges, it’s a huge SPoF honeypot. An exchange (with all it’s security hardened infrastructure) holding 1000s of lakhs of customer’s bitcoin is a big invite for hackers to break their systems and steal the bitcoin, which we see happening all over the world.

But are we doing self-custody in a way that avoid this SPoF? Especially since, I am advising many of my friends on self-custody. For them, I am the “Bitcoin expert”

Me and my friend, Saravanan mani (the bitcoin maxi and best adversarial thinker i know in real life), sat together on this years back. Thanks to his adversarial thinking mind, he asked all edge cases like what if the Hardware wallet got broken, what if someone stole your wallet and those kind of Questions and came up with a elaborate setup:

Damn. Coldcard was in our list, back then. But thanks to their premium price, we didn’t go for it 🙂

After doing this, we divided the self-custody into 3 phases:

  • Starters
    • Those who are starting out small. Phoenix wallet
  • Decent accumulation
    • Trezor wallet + Passphrase
  • Generational wealth
    • Multi vendor, Multi sig -> Yet to explore into this. None in my circle (Indian middle class), reached this stage.

Having said that, If anyone in my circle used Coldcard, they would still be safe, because of the long passphrase in our setup. We advice 40 character, strong, unique passphrase. Too bad, that many bitcoiners missed this step and lost the funds!

Anyways, we are following the AI assisted attacks space closely, to see if the current practices that we follow needs to be re-visited.

Typical bitcoiner’s journey. Please follow the best practices to avoid the traps.

AI hardening of bitcoin stack

Following Mythos / Fable launch, every software stuff is under AI scrutiny / hack. Here are few initiatives to harden the bitcoin stack:

  1. Project Loupe: https://www.projectloupe.org/p/loupe-project-update-1
    • Launched by Block / Jack dorsey. The bitcoin core, ldk, bdk and many core projects are being scanned and hardened
  2. The Red team: https://x.com/Rob1Ham/status/2084523368783438198
    • Dynamically created in last 4 days, following Cold card bug.

Trezor and Blockstream are not affected by this specific bug.

This incident does not prove that self-custody has failed. It proves that self-custody must be layered, reviewed and never based on blind trust in one device or company. This incident will force better testing, stronger standards and more scrutiny across the ecosystem. A year from now, Bitcoin self-custody will likely be safer than it is today.

Until then, I will continue monitoring these risks and will contact everyone who followed my advice if our setup ever needs to change.

Thanks. Stay humble, Stack sats!



Leave a Reply

Your email address will not be published. Required fields are marked *