Chat_177 - Security Is Just a Hard Problem with Lloyd Fournier
8/25/2026 · 123 min · transcript via whisper
Tags
Key topics
— Frostsnap rethinks multisig using Shamir secret sharing, keeping key shares separate on devices that never reconstruct the private key in a single location; instead, devices produce signature shares that combine on-chain into a single signature.
— The Coldcard entropy vulnerability exposed fundamental weaknesses in RNG implementation: weak fallback randomness (Yasmurang), compiler flags that disabled the hardware TRNG, and layers of obfuscation that made the bug extremely difficult to detect even with AI code analysis.
— BLS signatures eliminate the need for randomness during signing by using pairing operations and group elements instead of field scalars, making them deterministic yet cryptographically secure—a major advantage over current ECDSA for hardware wallet security.
— Dark Skippy attack demonstrates that even air-gapped hardware wallets with user-chosen seeds are vulnerable at signing time: a malicious device can leak seed words by embedding them in transaction signatures.
— Hardware wallet manufacturers are inherently trusted third parties for entropy generation and signing; true security requires either offline randomness contribution (like a phone or laptop) or alternative cryptography that eliminates signing randomness entirely.
— Quantum computing risk remains speculative and early-stage; proposed safeguards include taproot quantum-leaf backups triggered by a "quantum canary" challenge (breaking a smaller elliptic curve) rather than preemptive migration to quantum-resistant addresses.
Market & price signals
— None discussed.
Actionable insights
— Recognize that self-custody is not solved by hardware alone; multisig security depends on verifying consistency across devices (via short confirmation codes) and understanding that software wallets can trick individual devices with fake addresses if they cannot verify other devices' public keys.
— Evaluate custody tools not by smooth UX alone but by whether they reduce your trust in manufacturers: Frostsnap includes your phone or laptop in key generation so that even malicious devices cannot steal funds without also compromising your personal device with known-good entropy.
— Until quantum computers materially exist, advocate for zero-cost protective measures (taproot quantum-leaf backups) rather than forcing all users to migrate addresses; use an objective trigger (breaking a 160-bit elliptic curve bounty) to activate migration, not subjective claims about Q-day timelines.
Episode sponsorships
Paid placements mentioned in this episode. BTC Pods is not sponsored by or affiliated with these advertisers. Links are included so you can find offers mentioned on the show.
— Bitbox hardware wallet: use code GUY for 5% off at https://bitbox.swiss/
— HODLUP board game and other games from The Free Market Kids: use code GUY10 for 10% off at https://www.freemarketkids.com/collections/games-1