777: Coldcard Is Compromised with James O'Beirne
7/31/2026 · 46 min · transcript via whisper
Tags
Key topics
— Coldcard RNG vulnerability: Devices produced after 2021 (MK2, MK3, MK4, Q models) contain an insufficient random number generator that limits entropy to ~70 bits instead of the required 256 bits, making private keys vulnerable to brute-force attacks.
— Migration urgency by device and setup: Single-signature users without dice rolls or strong passphrases on post-2021 devices must move funds immediately; multisig scenarios are more complex and depend on whether public keys have been revealed on-chain.
— Safe mitigations: Users who performed 99+ dice rolls during key generation or use a sufficiently complex passphrase (substantially longer than six BIP39 words) are protected and do not need to migrate.
— AI acceleration of vulnerability discovery: Language models like Claude 3 independently reproduced and identified the vulnerability within hours, demonstrating how advanced AI tools lower the barrier to finding security flaws in open-source projects.
— Multisig complexity: In multisig setups, vulnerability depends on whether all signing keys are from Coinkey products and whether their public keys have been exposed on-chain; if any non-Coinkey device is required to spend, the setup remains secure.
— Broader hardware wallet trust collapse: This event underscores systemic risks in single-vendor solutions and reinforces the need for multi-manufacturer, multi-signature custody with user-supplied entropy sources.
Market & price signals
— None discussed.
Actionable insights
— Immediate action for affected users: If you own a Coldcard MK2, MK3, MK4, or Q produced after 2021 and did not use 99+ dice rolls or a cryptographically strong passphrase, migrate your funds to a trusted exchange or new secure setup within days. Perform test transactions with small amounts first to avoid panic-driven errors.
— Evaluate your current hardware setup: Multi-vendor multisig is now the practical standard for self-custody. Audit whether any single hardware manufacturer can move your coins unilaterally; if so, restructure. Bitcoin's bearer-asset nature and honeypot effect will continue surfacing vulnerabilities—assume security is an ongoing process, not a solved problem.
— Use external entropy: Going forward, incorporate physically verifiable entropy (dice rolls, hardware RNG you can audit) into key generation rather than trusting device-generated entropy alone. Plan for covenants and vault mechanisms to provide recovery windows if future hardware exploits occur.
Episode sponsorships
Paid placements mentioned in this episode. BTC Pods is not sponsored by or affiliated with these advertisers. Links are included so you can find offers mentioned on the show.
— For a limited time, new Cash App customers can get $21 added to their balance by using code TFTC10 when you sign up and sending at least $5 to a friend in the first two weeks; terms apply. Bitcoin services by Block, Inc. See Bitcoin disclosures at https://cash.app/legal/podcast.
— Square offers up to $200 off eligible Square hardware; visit https://square.com/go/tftc.
— BitKey allows you to secure Bitcoin in collaborative multi-sig with no seed phrases and a built-in screen for transaction verification; use code TFTC at https://bitkey.world/ for 10% off the new BitKey.