PodBrowser
Unchained

Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

Friday, 7 August 2026 · 4 min read · Listen to the episode ↗

Taylor Monaghan broke down how a flawed entropy generation method introduced into ColdCard's codebase in 2021 silently fell back to a weaker library without detection, leaving five years of private keys vulnerable to attackers once the bug was found. Losses now exceed 100 million dollars across roughly 1,600 to 1,800 Bitcoin stolen from thousands of victims, with on-chain analysis identifying at least four distinct attacker waves.

Taylor Monaghan explained that ColdCard's hardware wallet contained a flawed entropy generation method introduced in 2021 that went undetected for five years. Entropy, the randomness required to generate secure private keys and seed phrases, was being sourced from one location and silently falling back to a different library without detection, leaving five years of weak seeds available to attackers once the vulnerability was discovered. The codebase had received no security audits at any point, and well-known Bitcoin developers who attempted to engage with the ColdCard team were treated poorly and stopped investigating. The vulnerable code hops between repositories and programming languages including Python and at least one other language such as C or Go, making the chain of failure difficult to follow.

Total losses exceed 100 million dollars, representing approximately 1,600 to 1,800 Bitcoin stolen from thousands of addresses and thousands of victims, with losses expected to continue growing for weeks and months as attackers continue mining weak keys from wallets still in use. Galaxy Research analyst Alex Thorne has conducted on-chain analysis identifying at least four distinct waves of attacker activity, with uncertainty about whether the first two waves share the same threat actor. Later waves are considered more likely to involve professional cryptographic crackers who optimize scripts and deploy compute at scale rather than a lone actor who discovered the bug with AI assistance. Monaghan assessed that North Korea is not the likely attacker because North Korea primarily uses social engineering and does not typically conduct compute-intensive entropy cracking attacks of this kind.

ColdCard deleted all user data as a marketing differentiator from Ledger, leaving the company with no mechanism to warn affected users to move their funds. Monaghan described entropy vulnerabilities as the worst class of wallet vulnerability because attacks unfold over weeks and months and victims cannot be proactively notified at scale. Almost all early victims who came forward were users who had rolled dice to contribute entropy but had not rolled enough times, leaving their entropy trivially crackable. Rolling 50 or more times is considered probably safe, and the Korean Bitcoin community reportedly rolled 500 times rather than the recommended 50.

Matthew Green wrote after the 2015 TrueCrypt audit that if code cannot initialize randomness with confidence it should fail loudly rather than fall back silently, a principle the ColdCard codebase violated. In cryptography, silent fallbacks are dangerous because failures must be explicit, unlike general software where graceful fallbacks improve user experience. Trezor and Ledger, by contrast, operate with large organized teams, peer review processes, code commenting standards, and structured build systems. The speakers argued the broader community failed by trusting the ColdCard team based on their reputation as committed Bitcoiners rather than verifying their actual security practices. For non-technical users, the recommended protective step is to ask wallet teams directly about their security audits and review those audits. A visible sign of poor security hygiene accessible to non-technical observers is a single committer pushing directly to main without peer review.

EIP A361 proposes reducing ETH issuance and was given only a 48-hour community comment window before consideration for inclusion in the next Ethereum hard fork, a timeline described as offensive and immature for a network securing roughly 500 billion dollars in assets. No major DeFi protocols or builders were consulted before the proposal was put forward. The current blended ETH staking reward rate is approximately two and a half percent combining MEV and base staking rewards. If issuance is cut, staking yield could fall to around 20 basis points, potentially causing tens of billions of ETH to be unstaked and sold, which one speaker argued would be counterproductive to ETH price since stakers generally do not sell their holdings. Lido, EtherFi, and lending protocols relying on ETH looping would all be materially harmed by an issuance reduction.

Fees burned via EIP-1559 can achieve the same deflationary effect as reducing issuance without reducing staking rewards, and one speaker argued this makes issuance reduction redundant. One speaker argued the strongest position is simply not to change issuance at all, and that virtually no economists would support targeting a zero percent annual increase in money supply. The push to minimize staked ETH was characterized as philosophically driven by an efficiency argument originating from Ethereum Foundation insiders including Justin Drake rather than from empirical modeling of holder or marginal buyer behavior. The decentralization of Ethereum governance away from the Ethereum Foundation has enabled more opinionated organizations to push narrow proposals without a broader mandate, and fragmenting the previously unified Foundation voice has produced more public chaos over protocol direction. The issuance change proposal was described as unlikely to be jammed through given the current process, though advocates were expected to keep pushing it.

This summary was generated from the episode transcript and can contain mistakes.