₿ BTC PodsBe a Pod Maxi
← Guests

Guest

Alex Thorn

THE Bitcoin Podcast

Bitcoin Will Never Be the Same Again | Alex Thorn

- Bitcoin likely bottomed near $58K in July/August 2025 based on historical cycle patterns, despite compressed volatility and reduced amplitude compared to prior cycles. - The Coldcard hardware wallet exploit resulted in approximately 1,800 BTC ($116M–$130M) stolen from long-term self-custody holders, with 90% still held by attackers in initial collector addresses. - Victims of the Coldcard exploit did everything correctly—used cypherpunk hardware, self-custody, no exchange exposure—yet were compromised by a five-year-old entropy generation vulnerability in the device firmware. - The exploit displays multiple distinct attacker waves and "footprints" with different operational security patterns, suggesting both amateur and sophisticated actors; wave one likely leaked identity to a paid RPC data service. - AI-enabled vulnerability discovery is dramatically altering the threat surface for all software; the Bitcoin community's red-team audit effort led by Rob from Anchor Watch is a necessary response to the "Clanker Wars." - Reduced Bitcoin volatility reflects market maturation and growing institutional adoption rather than a ceiling on long-term upside; cycle bottoms remain a stronger indicator than cycle tops.

Coin Stories with Natalie Brunell

Alex Thorn: Tracking the Stolen Bitcoin and the "Red Team" Racing to Find More Bug

- Over 1,700 Bitcoin worth approximately $112 million has been stolen from approximately 8,300 Coldcard wallet addresses through a five-year-old seed generation vulnerability. - The attacks have occurred in multiple waves, with Waves 1 and 2 containing the largest amounts (over 1,000 and 1,200 Bitcoin respectively) and remaining largely unmoved since exploitation. - A volunteer "Red Team" of Bitcoin developers is comprehensively auditing open-source Bitcoin software repositories using AI to identify similar vulnerabilities; they've scanned over 500 repositories and found no issues in LibSecP256K1 (Bitcoin's core signature math). - The Coldcard vulnerability went undetected for five years partly because Coinkite became hostile toward the open-source community, discouraging code audits and vulnerability submissions. - Alex Thorn has identified diverse threat actors—from organized early attackers to opportunistic copycats—and is working directly with victims to provide forensic reports and help them file claims with law enforcement. - The exploit was likely operationalized using AI, and the Wave 1 attacker appears to have queried victim addresses through a blockchain data provider with a paid account, leaving traceable footprints.

Bitcoin Magazine Podcast

Tracking the Coldcard Hackers: Inside the $120M Bitcoin Theft with Alex Thorn

- Over $120 million in Bitcoin drained from Coldcard hardware wallets via a critical entropy bug in firmware released March 17, 2021. The attack is ongoing across multiple waves and footprints, with at least 1,600 BTC confirmed stolen from ~7,500 addresses. - Alex Thorn (Galaxy Research) identified Wave One (1,082.65 BTC), Wave Two (76 BTC), Wave Three (293 separate attacker addresses), and multiple smaller "footprint" patterns. Wave One attacker likely identifiable via centralized RPC provider logs, per Block Inc. engineers. - Vulnerable devices: Coldcard MK3, MK4, MK5, Q, and upgraded MK2 models. Users who generated keys on these devices after March 21, 2021 should assume compromise and migrate funds immediately—even to centralized exchanges if necessary. - Attackers likely using AI assistance to exploit the vulnerability; multiple independent threat actors now copying the attack. Vulnerability permits seed phrase and private key derivation without access to stored keys. - The bug stems from weak on-device entropy generation; Coldcard switched from a vetted open-source RNG to a faulty proprietary one that fell back to no entropy. Thorn characterizes this as **negligence, not malice**. - Multisig and collaborative custody (Casa, Unchained, Nunchuk) emerge as the only responsible path forward for self-custody. Single-signature hardware wallet custody model is now considered too risky.

What Bitcoin Did

The Most Bullish Thing About Bitcoin | Alex Thorn

- On-chain metrics suggest Bitcoin bottom approaching: Thorn analyzed topping and bottoming indicators across prior cycles and found that while 2024's top was dampened (many topping indicators peaked well before the all-time high), bottoming signals are now activating. The 58K level has held multiple times and represents a materially higher floor than the 15.7K start of 2023. - Seller exhaustion as a key bottom signal: Dormant coin movements in 2024–25 were among the largest on record, but this supply awakening is now abating. Large holders who bought at 40–60K during consolidation have faced multiple chances to exit (including 82.5K in April), leaving minimal remaining seller pressure. - AI debt and debasement narrative could reignite Bitcoin demand: Enormous capital spending on data centers worldwide is creating substantial fiscal impulse and debt issuance. As the debasement story resurfaces, Bitcoin could move from bear market chop to sustained rallies, particularly if institutional and retail demand reawakens. - Noah Doe abandoned property case poses legal risk: An anonymous plaintiff has filed suit in New York to claim legal title over ~39,000 dormant Bitcoin addresses, including Satoshi's coins, under state abandoned property law. If granted, this could enable lawfare against anyone moving dormant coins to exchanges, even though it cannot directly seize private keys. - CLARITY Act deadline is September; passage odds declining: The regulatory bill provides broad protections for non-custodial developers, self-custody, and institutional clarity. However, the House and Senate recess next week, leaving only days for compromise on ethics provisions. Post-midterm passage is unlikely; odds are roughly 50–50 as of mid-July. - Treasury companies and Saylor's macro impact questioned: While Michael Saylor has been a large buyer, a counterfactual question emerges: would Bitcoin price be higher without treasury company demand? The structures are mathematically price-followers, buying tops when leverage exists. ETF and Saylor demand may be replacement rather than additive.

TFTC: A Bitcoin Podcast

#780: Dissecting The Coldcard Hack with Alex Thorn

- Coldcard vulnerability exploited across three distinct attack waves; Galaxy Research has tracked over 1,500 BTC stolen, with ~400 BTC directly confirmed by victims. - Wave One (41 minutes, July 30 UTC) used a fixed 30 sat/vB fee pattern and consolidated victim funds through four collectors into three final addresses, all currently inert. Waves Two and Three identified via victim reports and pattern matching; Wave Three shows significantly more sophisticated topology with 293 independent transaction chains. - AI-driven exploitation observed operationalizing the vulnerability; attackers queried addresses via paid blockchain infrastructure provider accounts, potentially enabling law enforcement identification. - White-hat sweeping efforts underway by security researchers (Wicked Bitcoin, Rob Hamilton, others) to secure vulnerable funds; ethical and logistical challenges arise around proof of original ownership and fund recovery. - Multi-sig adoption now positioned as essential infrastructure; single-signature cold storage model viewed as increasingly untenable; collaborative custody platforms (Casa, Unchained, Nunchuck, Anchor Watch) and open-source solutions recommended. - Broader AI arms race between attackers and defenders; frontier model access restrictions limiting security researchers' ability to audit Bitcoin and critical infrastructure code; national security implications flagged.

The Bitcoin Layer

Tracing the Stolen Coldcard Bitcoin w/ Galaxy's Alex Thorn

- Coldcard firmware vulnerability: A March 17, 2021 firmware update introduced a silent failure in the random number generator, causing devices to default to weak entropy for key generation. The bug went undetected for five years. - Three confirmed attack waves totaling ~1,350 Bitcoin (~$88 million): Wave one (1,082 BTC across ~1,195 addresses in 41 minutes), wave two (76 BTC, ~1,400 addresses over 3.5 hours), and wave three (208 BTC spread across 293 individual script hash vaults). All funds remain inert in attacker-controlled addresses. - Attack mechanics and AI enablement: Attackers scanned the blockchain for vulnerable addresses both by generating seeds with the faulty RNG and deriving addresses ("bottoms up"), and by scanning known addresses for weak keys ("top down"). Open-source LLMs like Llama/Kimmy lack safeguards that frontier models enforce, making vulnerability detection and transaction construction trivial with modest compute. - Victim profile and recovery prospects: Victims are largely self-custody Bitcoin holders who followed best practices—they neither leaked keys nor made mistakes. Recovery depends on attacker identification (one paid API account used in wave one shows promise) and law enforcement action. Coin tracing is visible on-chain; if attackers are caught, full restitution may be possible since funds haven't moved. - Broader security lessons: No weakness in Bitcoin's cryptography itself; this is a hardware wallet manufacturer bug. Other major hardware wallets have been confirmed free of this vulnerability by red teams. The incident highlights the need for stronger software verification practices in the Bitcoin security industry. - Recommended actions: Users with doubt about their Coldcard security should migrate off immediately. Multi-sig setups (even with a compromised Coldcard) remain safe if the device cannot reach signing threshold. Victims should file reports with authorities, preserve their hardware as evidence, and contact Alex Thorn on X for analysis support.

Hell Money

BITCOIN CORE HAS A SERIOUS PROBLEM

- Vegas trip recap: Hosts discussed their Bitcoin conference attendance, Vegas meetup with fans, and conversations with influential figures in the Bitcoin community. They noted unexpectedly high recognition and influence despite self-described "random" podcast content. - Bitcoin Astrology panel: First-ever Bitcoin Astrology panel at the conference, featuring high female attendance and discussion of 2026 as a significant year astrologically. Hosts plan to release the recording. - Quantum computing debate: Main stage quantum panel featured Alex Thorn, Root & Code, James O'Byrne, Hunter Beast, and Alex Pruden. Discussed grifters in quantum space (Project 11 example), the importance of engaging respectfully with technical critics, and the hypothetical doomsday scenario of quantum breaking elliptic curve cryptography while providing no other useful applications. - Hodlinaut's Bitcoin Core article: Second piece in a series examining informal governance and "soft power" within Bitcoin Core. Claims promotion and sidelining decisions are based on personality and likability rather than strict meritocracy (examples: Luke Jr. disfavor, Gloria Zhao rapid rise). Hosts discuss whether this is problematic or simply normal organizational behavior. - AI adoption among developers: Smart developers extensively using AI in their workflows. Hosts noted that AI pivot is becoming common at Bitcoin conferences, with projects rebranding around AI and sovereignty themes. - Paul Sztorc's e-cash fork: Discussion of Paul's potential drivechain fork and risk of mission creep as supporters push additional features. Urged focus on core drivechain testing rather than feature snowballing.

What Bitcoin Did

Was Bitcoin’s Price Suppressed? | Alex Thorn

- Bitcoin has declined nearly 50% from its all-time high of ~$126K due to decay in buying demand, whale selling, other asset outperformance, and tax loss harvesting at year-end. - The Jane Street market manipulation narrative is likely "cope" from frustrated investors; the firm's trading activities do not necessarily indicate intentional price suppression of a multi-trillion dollar asset. - Sentiment is among the worst ever, but this reflects narrative damage from Bitcoin's failure to trade like gold last year, not fundamental deterioration in Bitcoin's use case or technology. - AI disruption to labor is emerging rapidly; individuals should begin using AI tools now to avoid a future gap where early adopters can "acquire robots" (productivity tools) while others cannot earn capital to do so. - The four-year cycle did largely repeat despite many believing "this time was different"—a 52% drawdown would be the mildest in Bitcoin's history, though a 70%+ correction is unlikely. - Regulation, government pivot, and narrative-driven catalysts (ETFs, presidential support) have already been unlocked; Bitcoin now must gain adoption through education about its **fundamental value as savings technology**, not macro tailwinds.

What Bitcoin Did

TRUMP, INSTITUTIONS & BITCOIN DOMINANCE w/ Alex Thorn

- Trump administration's executive order on crypto establishes a working group to evaluate a potential national digital asset stockpile; David Sachs cautiously distinguished between a "Bitcoin reserve" and a broader "digital asset stockpile," signaling Bitcoin will likely dominate any holdings. - Operation Choke Point 2.0 appears to be ending: banking regulators have admitted to coordinated efforts to deny services to crypto and Bitcoin businesses, with the Fed, FDIC, and new SEC leadership now signaling policy reversal. - Paul Atkins confirmed as incoming SEC chair; both Republican commissioners worked for him and are already acting on crypto reforms, suggesting alignment on regulatory relief. - Bitcoin's dominance within the current cycle is historically high and strengthening; the Ethereum-to-Bitcoin ratio has collapsed 50% since Ethereum ETF approval, reflecting market preference for Bitcoin over other cryptos. - Meme coin frenzy stems partly from unit bias (Bitcoin seeming "too expensive") but more deeply from generational economic anxiety; younger cohorts choose gambling over savings because they fear the future won't improve. - Institutional adoption via ETFs differs materially from 2017 retail mania; ETF holders are predominantly hodling with few outflow days, providing market resilience but potentially limiting explosive retail-driven rallies.