Roundtable_023 - Staying Humble
8/4/2026 · 116 min · transcript via whisper
Tags
Key topics
— Coldcard firmware entropy failure generated weak keys (equivalent to 8-character passwords) on Mark 3+ devices, enabling mass GPU brute-forcing of wallets in minutes instead of requiring computational energy exceeding the sun's output.
— Transition from open-source (GPL) to source-available firmware in 2019–2021 reduced scrutiny and may have introduced the bug; the fallback pseudo-random number generator should never have existed as a design choice.
— AI and LLMs have fundamentally changed vulnerability discovery: attackers now require only hours with language models to find and exploit weaknesses that previously required deep expertise.
— Hardware manufacturers must adopt continuous entropy validation testing (running devices 24/7 generating seeds) and include physical dice with every device to give users agency over randomness.
— Multi-signature setups with at least one compromised key remain vulnerable; users must spend all funds at once via high-fee transactions or out-of-band mining to avoid revealing script hashes that expose remaining keys.
— Open-source code is non-negotiable for security-critical software; source-available licenses enable regulatory capture and reduce community auditing that would catch such failures.
Market & price signals
— Bitcoin price remained flat (~1% movement) despite the hack disclosure, suggesting limited mainstream awareness or confidence in self-custody resilience among broader market participants.
Actionable insights
— If you hold a Coldcard Mark 3, 4, 5, or Q generated without dice rolls: immediately move funds off the device using any software wallet (Sparrow, Green, Aqua, Nunchuk). New firmware fixes the entropy issue only for future key generation; previous seeds remain compromised.
— For multi-signature setups using any Coldcard: spend all funds in a single high-fee transaction or coordinate an out-of-band transaction to avoid exposing the script hash on-chain, which would allow attackers to brute-force your remaining keys.
— Add physical dice rolls to your key generation workflow going forward, regardless of hardware manufacturer claims about entropy; this removes trust in any single device and aligns your practice with proven cryptographic principles.
Episode sponsorships
Paid placements mentioned in this episode. BTC Pods is not sponsored by or affiliated with these advertisers. Links are included so you can find offers mentioned on the show.
— Bitbox hardware wallet: use code GUY for 5% off at https://bitbox.swiss/
— HODLUP board game and other games from The Free Market Kids: use code GUY10 for 10% off at https://www.freemarketkids.com/collections/games-1