Episode Details
Back to Episodes
What Went Wrong with Coldcard: A Deep Dive into the Hack
Description
How did 1,500+ Bitcoin, worth over a hundred million dollars, vanish from hardware wallets, and what does it mean for anyone holding their own coins?
Tim joins Honest Money to break down the Coldcard wallet exploit, the technical flaws behind it, and the hard lessons it holds for Bitcoin self-custody. From weak entropy generation to the growing role of AI in both attacking and defending wallets, Tim explains what went wrong and how to make sure it doesn't happen to you.
This conversation explores how the exploit worked, why open source matters for security, and the best practices that keep your Bitcoin safe in an evolving threat landscape.
🎙️ EPISODE SUMMARY
Tim and Anja discuss the Coldcard hack, hardware wallet security, and how to protect your Bitcoin.
The conversation moves from the details of the exploit and the scale of the losses, through the law enforcement and recovery challenges, to the technical flaws in the firmware and entropy generation that made the breach possible. Tim explains why open source software fosters security through transparency, and what real self-custody discipline looks like.
The episode also examines best practices for creating and protecting your seed, the lessons every Bitcoiner should take from this event, and the future of hardware wallet security as AI reshapes both the threats and the defenses.
🔗 FEATURED LINKS
Galaxy Research: https://www.galaxy.com/insights/research
Galaxy HQ on X: https://x.com/galaxyhq
Alex Thorne on X: https://x.com/intangiblecoins
Red Team First Responders: https://opensats.org/blog/code-red-supporting-first-responders
🔑 KEY TAKEAWAYS
Generate your seed in a trustless environment using dice or a reliable entropy source
Minimise technology in cold storage: simple, offline solutions are safer
Move your coins immediately if you're using a vulnerable hardware wallet
Open source software fosters security through transparency
Weak entropy is a critical and often invisible point of failure
Human beings are extremely poor sources of randomness
AI tools are becoming both a serious threat and a valuable defence
Self-custody demands ongoing personal responsibility and vigilance
⏱️ CHAPTERS
0:00 Introduction to the Coldcard Hack and What Happened
2:19 Can Victims Recover Their Coins?
8:12 The Timeline of Hardware Wallet Development
10:35 The Entropy and Firmware Mistake
14:26 Which Models Are Affected and Urgent Advice
17:06 Temporary Self-Custody Options and Support
19:22 The Three Parts of Bitcoin Custody
23:42 Daily, Operational, and Cold Storage Use Cases
31:53 Does This Mean Self-Custody Is Dead?
33:52 Why Humans Are Bad at Randomness
37:59 What FOSS Means and Why It Matters
46:04 Why AI Is Accelerating Attacks
47:29 Can White Hats Return Stolen Coins?
50:35 Final Thoughts and Resources
🔗 AFFILIATE LINKS
Buy Bitcoin in Australia With a $10 Sign Up Bonus
HARDBLOCK: https://hardblock.com.au/join/honestmoney
Learn to Acquire, Secure, and Manage Your Bitcoin
MINERACKS: https://www.mineracks.com/honestmoney
Shop Signing Devices, Bitaxes, Nodes, Apparel, and More
SHOP BITCOIN AUSTRALIA: https://shopbitcoin.com.au
Collaborative Security, Inheritance Planning, and Retirement Strategies
THE BITCOIN ADVISER: https://thebitcoinadviser.com/honest-money
Reached Terminal Bitcoin? Borrow Against Your Bitcoin Without Selling
LOAN MY COINS: https://www.loanmycoins.com/honest-money
📌 ABOUT THE HONEST MONEY SHOW
The Honest Money Show explores the forces shaping our financial world, from monetary systems and personal finance to Bitcoin. Through in depth conversations with builders, thinkers, and educators, the show challenges mainstream narratives and provides practical insights into financial sovereignty.
🔗 CONNECT WITH US
Subscribe for weekly deep dives into finance, econ