PodBrowser
On The Brink

Weekly Roundup 08/07/26 (Coldcard hack continues, Ethereum mulls an issuance tweak, ai16z winds down, Clarity deadline looms) (EP.733)

Friday, 7 August 2026 · 4 min read · Listen to the episode ↗

This week's episode centers on the Coldcard hardware wallet hack, which Nick Carter argues is worse than FTX in human terms because victims were ordinary people storing retirement savings, with over 100 million dollars lost traced to a flawed entropy source from a sparsely maintained GitHub repository. The hosts also discuss Ethereum researchers proposing EIP 8361, which would taper staking yield to zero once half the supply is staked, drawing sharp criticism from Aave and Lido.

The Coldcard hardware wallet hack dominated the episode, with Nick Carter arguing the losses are worse in many ways than FTX because victims were ordinary people storing retirement savings rather than traders holding paper gains in altcoins, with FTX losses estimated at roughly 10 to 11 billion dollars compared to over 100 million dollars lost in the Coldcard incident. The root cause was identified as bad entropy generation, described as the most basic responsibility of a hardware wallet manufacturer, with the entropy source appearing to trace to a GitHub repository with only one or two contributors. Carter contrasted this with Trezor, which uses multiple redundant entropy sources, and noted that entropy flaws are nearly impossible to detect because there is no way to visually inspect a public key and identify low entropy.

Matt Walsh argued Coldcard gained outsized market share by positioning itself as Bitcoin-only, a reputation amplified by the Bitcoin podcast ecosystem including through promotional giveaways. Once the weakness became known, additional attackers began targeting wallets protected by a 25th word passphrase, with base-level wallet difficulty around 40 bits and passphrase-protected wallets around 50 bits, both still crackable. Victims were advised not to discard affected devices because they may be needed to prove chain of custody, and filing a police report was recommended. Multi-device multi-signature setups using multiple vendors such as Casa or Unchained were described as remaining safe, and a two-of-three multisig arrangement using two Coldcards was said to still not be at risk from the reported vulnerability.

Walsh raised the point that mainstream media has not covered the AI angle of the hack, suggesting the vulnerability may have been discovered using a model such as Claude. Carter noted that frontier AI models refuse to assist with cybersecurity-related queries for safety reasons, meaning defenders like Rob Hamilton at Anchor Watch cannot use the best available tools while bad actors use open-source models with no such restrictions. Carter predicted whether frontier AI models can be used for defensive cybersecurity will become a major policy question for the AI industry over the next five years. The hack was floated as potentially marking the end of self-custody as the default correct approach for average Bitcoin holders, with ETFs cited as a likely alternative.

Six Ethereum researchers proposed EIP 8361, called the tapered issuance burn, which would cut staking yield to zero once half of the Ethereum supply is staked, phased in over 18 months. The proposal drew significant backlash, with the Aave CEO saying it makes ETH less viable as an asset and the head of Lido staking calling it a death knell for network security. The underlying tension was described as token holders wanting less inflation and higher fees versus users wanting lower fees and more issuance, with Bitcoin's fixed issuance cited as a superior approach.

Eliza Labs and the ai16z token reached a peak market cap of 2.5 billion dollars before a class action suit alleged the project falsely marketed itself as a decentralized venture fund governed by an autonomous agent while actually being controlled by founder Shaw Walters and insiders, allegations the founders disputed. The project was described as having wound down, with the lawsuit cited as a contributing factor. The speakers argued early-stage venture investment is one area AI agents are unlikely to disintermediate because of the human underwriting element involved.

A former FBI counterintelligence agent was charged with stealing approximately 1 million dollars in crypto from wallets tied to an adversarial nation he was investigating, having accessed seed phrases during his investigation. Charging documents revealed he had used ChatGPT to research vacation destinations triangulated to Portugal and had asked the model how to invest 1 million dollars with a goal of retiring around age 40 with a vineyard lifestyle in southern Europe.

The market structure bill faced ongoing back and forth over an ethics provision as of Thursday, with the Senate scheduled to go on recess August 8th and a cloture vote unlikely before Saturday at the earliest. A Wall Street Journal article about the stablecoin bill was widely criticized for containing factual inaccuracies, yet a senator cited it on the Senate floor as a reason to oppose the bill, illustrating how Journal coverage tends to be treated as authoritative regardless of accuracy. If cloture passes before recess, a full floor vote would be set up for September; if no cloture vote happens, the question becomes whether the bill can advance at all after the midterms.

This summary was generated from the episode transcript and can contain mistakes.