₿ BTC PodsBe a Pod Maxi
← Guests

Guest

Rob Hamilton

THE Bitcoin Podcast

BITCOIN RED TEAM: The AI Arms Race for Open-Source Security | Rob Hamilton

- The Coldcard vulnerability triggered an unprecedented AI-powered security audit of Bitcoin open-source software, uncovering over 10,000 findings across hundreds of repositories. - Rob Hamilton and a team of volunteer developers used Kimi K3 (an open-source Chinese AI model) to identify critical and high-severity vulnerabilities where U.S. frontier models (OpenAI, Anthropic) refused or downgraded security assistance. - Kimi K3's open-weight release in late July enabled rapid, low-cost vulnerability discovery; frontier model companies impose restrictive guardrails that block white-hat security research while claiming to prevent misuse. - The U.S. frontier AI labs are pursuing regulatory capture and attempting to restrict open-source models, creating perverse incentives for institutions to rely on Chinese alternatives for genuine security capability. - Bitcoin's self-custody model remains essential to the project's value proposition; multisignature and collaborative custody solutions mitigate single points of failure exposed by the Coldcard incident. - AI-powered security auditing represents a fundamental shift in how vulnerabilities are discovered; the speed and cost advantages of open-source models over proprietary ones will accelerate adoption regardless of regulatory barriers.

What Bitcoin Did

EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob Hamilton

- Coldcard firmware bug introduced in early 2021 affects MK3, MK4, MK5, and Q models. A one-line code error prevented proper entropy generation during seed phrase creation, reducing randomness from 2^256 to as low as 2^32 bits on MK3 devices. - Immediate threat: Attackers have already begun brute-forcing all possible seed phrase combinations. Single-signature wallets without passphrases or user-generated entropy are being actively drained. Estimated losses already exceed 1,000 BTC and growing. - Multisig exposure: Even multisig wallets are at risk if majority signers use vulnerable Coldcards. Two-of-three and N-of-N configurations using only Coldcards are vulnerable once attackers identify the key combinations on-chain. - Protection methods: Passphrases (25th word), dice-rolled entropy, or user-provided randomness added during setup can mitigate risk. Firmware updates for MK4/MK5/Q add 45–50 bits entropy but remain vulnerable to well-resourced attackers. - Not a broader ecosystem issue: Trezor, Foundation, and other hardware wallets were unaffected. This vulnerability is specific to Coldcard's implementation of the entropy library. - AI's role: Open-source LLM models without safety guardrails (e.g., Kimi K3) made the bug discoverable. The initial attacker was amateur; sophisticated actors are now escalating efforts with GPU farms.

Coin Stories with Natalie Brunell

Urgent Warning for ColdCard Users, with Rob Hamilton

- ColdCard hardware wallet compromise: MK3, MK4, MK5, and ColdCard Q models are affected. MK3 (2021–2023) poses the highest risk; later models have reduced but still significant vulnerability. Attackers can reverse-engineer seed phrases without physical access to the device. - Root cause — insufficient entropy: A single line of code in ColdCard's seed phrase generation reduced the randomness from a full deck of possibilities to only 20 cards' worth. This allows attackers to brute-force guess all combinations in hours rather than the age of the universe. - AI-assisted exploit: An open-weight LLM (KimiK3, released Monday) with fewer safety guardrails than OpenAI or Anthropic models identified and exploited the bug within minutes. Closed-weight models (GPT, Claude) refused similar queries. - Scope of theft: Over 1,000 BTC confirmed stolen across multiple attackers (not a single threat actor). More Bitcoin moving every hour. Additional funds at risk include those migrated to other devices but originally generated on ColdCard, and multi-sig setups using two or more ColdCard signers. - Immediate action required: Move funds urgently to a safe location (exchange, different hardware, or multi-sig with non-ColdCard devices). Run test transactions before moving full amounts. If you added a password or rolled custom dice entropy during setup, your risk is reduced but not eliminated. - Privacy trade-off: ColdCard's no-customer-data policy prevents direct user notification but necessitates public PSA campaigns to reach affected users.

What Bitcoin Did

Should Satoshi’s Coins Be Frozen? | Rob Hamilton

- Bitcoin as a hero's journey narrative — Framing Bitcoin adoption as a literary story arc with call to adventure, mentors, ordeals, and return home, applicable across different user cohorts and motivations. - Quantum computing threat to Bitcoin security — Discussion of how cryptographically relevant quantum computers could expose ~6–7 million Bitcoin with public keys, creating both long-range attacks (on Satoshi's coins) and short-range attacks (on spending transactions). - Proposed responses to quantum vulnerability — Including coin freezing (BIP361), post-quantum signature algorithms, and Robin Linus's BinoHash protocol as alternative approaches. - Institutional vs. cypherpunk values divergence — Tension between newer institutional Bitcoin holders (buying for returns/ETFs) and earlier adopters prioritizing self-sovereignty and property rights. - Property rights as core Bitcoin principle — Argument that freezing vulnerable coins violates property rights, even if intended to prevent theft, and that this sets dangerous precedent for institutional control. - Potential future fork war — Expectation of contentious disagreement over quantum response, possibly pitting property rights advocates against institutional interests.

What Bitcoin Did

Is BIP444 An Attack on Bitcoin? | Rob Hamilton

- BIP-444 (or BIP-405) proposes a soft fork that would restrict transaction data by limiting OP_RETURN to 83 bytes, disabling large data pushes (>256 bytes), invalidating undefined Taproot script versions, and removing OP_IF/OP_NOTIF from Tapscript to stop inscriptions and ordinals. - The proposal would freeze funds for users already employing certain Taproot features (like Liana Wallet's Miniscript implementations) for a minimum of 12 months, marking the first soft fork in Bitcoin history with that consequence. - Activation is proposed for February 1st with a 90-day timeline—much faster than typical UASFs—requiring hash rate support, business economic backing, and futures market signals to succeed. - No mining pools have publicly committed support; only F2Pool has explicitly stated opposition, leaving the effort without the consensus needed for activation. - A successful UASF could trigger chain splits and reorgs lasting hours, but economic actors (exchanges, major custodians, miners) would likely choose the chain with higher market value, signaled through futures markets. - The debate reflects social status games and cargo-culting of 2017 block-size-war tactics rather than genuine consensus support for network rule changes.

What Bitcoin Did

HYPERBITCOINISATION & UPGRADING BITCOIN w/ Rob Hamilton

- Hyper-Bitcoinization and cultural shifts: As Bitcoin reaches $100K and gains nation-state adoption, economic stakeholders are becoming more relevant to protocol discussions, though ideological checks exist from early adopters who hold significant supply. - Bitcoin Script opcodes and the Great Script Restoration: Rusty Russell's proposal aims to restore disabled opcodes by creating a variable operations budget framework, allowing developers more granular tools while maintaining network security and decentralization through rigorous benchmarking. - Covenants as a scaling and security solution: Covenants enable vaults with reactive security (staging addresses with time locks and recovery options), superior to today's proactive-only security model, while facilitating layer-two scaling solutions like Lightning Network improvements. - Competing covenant implementations: The ecosystem includes multiple proposals—CTV (minimal, backwards-compatible), TxHash (more granular), OpCat (concatenation for Merkle proofs), and OpVault—each serving different use cases from vault management to smart contract computation. - E-cash as a cypherpunk scaling layer: Chaumian e-cash enables instant, anonymous transactions within a mint, functioning like free banking with proof-of-reserves, restoring privacy without requiring on-chain footprints for everyday spending. - Layer-two sidechains and inevitability: EVM sidechains (e.g., SpiderChain) and BitVM constructions are inevitable due to Bitcoin's permissionless nature; non-Bitcoin use cases will migrate to Bitcoin for liquidity and permanence, with Anchor Watch now offering A-rated Lloyd's of London insurance for self-custodied Bitcoin.

The Bitcoin Matrix

Rob Hamilton: The Embedded Growth Problem, Institutional Betrayal & The Great Stagnation

- Rob Hamilton's background as a data scientist, coder, and early Bitcoin adopter from 2013 who attended NYC BitDevs meetings and ran his own node. - The concept of **embedded growth obligation**: institutions must maintain growth rates to sustain power; when growth stalls, they abandon honest positions and become parasitic. - Stagnation of physical innovation (atoms) since 1971 versus explosive progress in digital technology (bits); the breakdown of sound money severed economic coordination needed for breakthrough projects. - Stock buybacks at Fortune 500 companies as wealth extraction: IBM spent $220 billion on buybacks (1995–2020) while the company is worth only $120 billion today—capital that could have funded moonshot innovation. - Central Bank Digital Currencies (CBDCs) as a dystopian endgame: total surveillance and programmable money enabling social credit controls and financial oppression. - Bitcoin as a corrective force: sound monetary incentives will restore fair capital allocation, enabling real innovation and rewarding long-term thinking over short-term extraction.