₿ BTC PodsBe a Pod Maxi
The Bitcoin Layer

Tracing the Stolen Coldcard Bitcoin w/ Galaxy's Alex Thorn

8/3/2026 · 44 min · transcript via whisper

Tags

Key topics

Coldcard firmware vulnerability: A March 17, 2021 firmware update introduced a silent failure in the random number generator, causing devices to default to weak entropy for key generation. The bug went undetected for five years.

Three confirmed attack waves totaling ~1,350 Bitcoin (~$88 million): Wave one (1,082 BTC across ~1,195 addresses in 41 minutes), wave two (76 BTC, ~1,400 addresses over 3.5 hours), and wave three (208 BTC spread across 293 individual script hash vaults). All funds remain inert in attacker-controlled addresses.

Attack mechanics and AI enablement: Attackers scanned the blockchain for vulnerable addresses both by generating seeds with the faulty RNG and deriving addresses ("bottoms up"), and by scanning known addresses for weak keys ("top down"). Open-source LLMs like Llama/Kimmy lack safeguards that frontier models enforce, making vulnerability detection and transaction construction trivial with modest compute.

Victim profile and recovery prospects: Victims are largely self-custody Bitcoin holders who followed best practices—they neither leaked keys nor made mistakes. Recovery depends on attacker identification (one paid API account used in wave one shows promise) and law enforcement action. Coin tracing is visible on-chain; if attackers are caught, full restitution may be possible since funds haven't moved.

Broader security lessons: No weakness in Bitcoin's cryptography itself; this is a hardware wallet manufacturer bug. Other major hardware wallets have been confirmed free of this vulnerability by red teams. The incident highlights the need for stronger software verification practices in the Bitcoin security industry.

Recommended actions: Users with doubt about their Coldcard security should migrate off immediately. Multi-sig setups (even with a compromised Coldcard) remain safe if the device cannot reach signing threshold. Victims should file reports with authorities, preserve their hardware as evidence, and contact Alex Thorn on X for analysis support.

Market & price signals

Galaxy Research cited $88 million in confirmed stolen Bitcoin across three waves (~1,350 BTC), with a potential fourth wave bringing the total to ~$115 million if confirmed. No market price discussion or macro context provided. Funds remain inert; no evidence of sale or exfiltration to exchanges, DeFi, or centralized intermediaries.

Actionable insights

If you own a Coldcard, assess your entropy practices. If you did not roll dice to add entropy or have any doubt about your key generation method, migrate your funds off Coldcard immediately—either to a trusted custodian (River, Coinbase) or to a multi-sig setup where your Coldcard cannot reach signing threshold alone.

File a report with authorities (FBI IC3, local police, Canadian Anti-Fraud Center) if drained; contact Alex Thorn (@IntangibleCoins) on X with transaction IDs and drained addresses to receive free analysis. Preserve your Coldcard hardware as ownership evidence for potential recovery proceedings.

Consider multi-sig collaborative custody providers (Casa, Unchained, Nunchuk) as a hedge against single-device firmware bugs. Even if one key is compromised and publicly known, a properly structured multi-sig remains secure and eliminates the risk of total loss from a single hardware wallet vulnerability.

Episode sponsorships

Paid placements mentioned in this episode. BTC Pods is not sponsored by or affiliated with these advertisers. Links are included so you can find offers mentioned on the show.

No sponsorships in this episode.