PodBrowser
Unchained

The Chopping Block: ColdCard's $100M RNG Hack, AI-Powered Security & Ethereum's Staking Yield Taper

Thursday, 6 August 2026 · 4 min read · Listen to the episode ↗

A developer's one-word commit message five years ago left ColdCard wallets generating cryptographically weak private keys, and nearly $100 million in Bitcoin has since been drained across at least three confirmed attack waves, with a firmware patch arriving too late for affected users. The hosts argue the incident exposes a structural collapse in open-source security logic, because AI tools let attackers spend thousands of dollars finding vulnerabilities that defenders, spending only a few dollars on identical models, will miss entirely.

Nearly $100 million in Bitcoin has been drained from ColdCard wallets because a developer changed random macros in C++ code five years ago, apparently just to get the code to compile, and documented the change with a one-word commit message. The bug caused devices to fall back from hardware random number generation to weak software-based RNG, leaving private keys generated during the vulnerable period cryptographically recoverable. ColdCard shipped a firmware patch over the weekend, but any wallet whose keys were generated during the vulnerable window has very likely already been swept, making the patch irrelevant for affected users. At least three confirmed waves of attacks occurred, with a possible fourth wave collecting dust amounts from remaining balances.

The speed of AI-assisted discovery alarmed the hosts. One researcher found the bug using Quad code in eight minutes; another found it using GLM 5.2 with no internet access in roughly twenty minutes at a cost of about two dollars. The hosts argued this breaks the traditional security logic of open source software. Defenders spending a few dollars of compute on code reviews will miss vulnerabilities that require fifty to one hundred dollars of compute to find, while attackers motivated by a hundred million dollar prize will spend one thousand to tens of thousands of dollars. Because AI models used by defenders are largely identical across users, multiple reviewers duplicate the same investigative work and add no marginal security benefit. AI can also effectively decompile closed-source binaries, making the open versus closed source distinction largely irrelevant. The only meaningful defense identified is the software company itself spending one thousand to fifty thousand dollars of AI-powered hardening on its own code before attackers do.

This pattern is showing up not in large protocols but in smaller ones. Total dollars hacked in DeFi hit recent lows over the two months since April, but the number of individual incidents reached all-time highs both months, reflecting a wave of small protocols with around five million in TVL being systematically raided. The hosts predicted the industry will not adapt its security norms until several more major hacks occur, after which consolidation among wallet and crypto projects will follow.

A proposed Ethereum EIP authored by Pintail, Justin Drake, and others would taper ETH staking yield toward zero if more than fifty percent of ETH supply becomes staked, suppressing excess staking demand by reducing the reward rate as participation rises. The proposal has generated widespread negative reaction. Tom noted that EIP 1559 and the shift to proof of stake already represented major monetary policy changes, and further adjustments erode credibility, though he considered the proposed reduction of roughly one percent per year in inflation marginal and unlikely to move markets on its own. Tarun argued that constantly changing monetary policy undermines hard money credibility regardless of the directional outcome, and noted that Solana's inflation proposals involved significantly more research. He also observed that nominal staking yield has largely collapsed, leveraged staking is no longer popular following hacks, and stablecoin yield now exceeds staking yield partly due to real-world asset demand. Tom warned that abruptly cutting staking yield to near zero would trigger massive unstaking queues and collapse many DeFi protocols that depend on staking yield for their business models. Tarun characterized the EIP as a bear market phenomenon and said a more gradual tapering approach is more probable than the aggressive version currently proposed.

Leopold Aschenbrenner's Situational Awareness fund raised capital estimated at several billion dollars, reached peak AUM of 45 billion dollars, gained over 400 percent in June, and was up over 1500 percent since inception before collapsing approximately 67 percent in July. During the fire sale Aschenbrenner was forced to sell his entire liquid book to Citadel at a significant discount, leaving roughly 10 billion in AUM, much of it illiquid private Anthropic exposure. The collapse was attributed to excessive leverage on AI and semiconductor names combined with a wipeout in the Korean stock market. The core structural problem identified was that leverage makes returns path dependent, meaning an investor can be correct about endpoints and still be wiped out by the path taken to get there.

The Clarity Act faces a deadline around August 7th before congressional recess, after which passage becomes very unlikely. Polymarket prices a 25 percent chance of passage, while a separate market shows approximately 42 percent odds of a floor vote, with speakers noting that if a floor vote occurs the bill is more likely than not to pass. The primary obstacle is ethics provisions tied to Trump's visible crypto profits, and a bipartisan Tilis-Gallego ethics amendment sent to the White House had received no response as of recording. Robert predicted that if Senate Republicans and Democrats agree on ethics language Trump will not veto, Clarity has a strong chance of passing, and that without such agreement it will not pass before recess. If the August deadline is missed, Kalshi puts odds of passage in 2027 at 30 percent, and speakers said the bill will not survive in its current form but that clarity as a concept is not dead, with renegotiation likely under a different compromise.

This summary was generated from the episode transcript and can contain mistakes.