Transcript: ColdCard Hack: What Alex Thorn Found On-Chain
Full speaker-labelled transcript of TFTC episode #780 with Alex Thorn.

Full speaker-labelled transcript of TFTC episode #780 with Alex Thorn. Read the written article: ColdCard Hack: What Alex Thorn Found On-Chain. Click any timestamp to watch that moment on YouTube. Machine transcription, lightly cleaned, may contain errors.
Alex Thorn [0:07] You've had a dynamic where money's become freer than free. Let me talk about a Fed just gone nuts, all, all the central banks going nuts. So it's all acting like safe haven. I believe that in a world where central bankers are tripping over themselves to devalue their currency, Bitcoin wins. In the world of fiat currencies, Bitcoin is the victor. I mean, that's part of the bull case for Bitcoin.
Marty Bent [0:31] If you're not paying attention, you probably should be. Probably should be. Probably should be. Alex, the vibe has shifted from the last time we saw each other, which was a Thursday at the Galaxy event in DC.
Alex Thorn [0:44] Yeah, it was just shifting. I think you came maybe an hour before that PubKey event started and said there Might be some issue with ColdCard. And I, in my head, I was like, you know, oh no, but I was hosting that event. So I got all tied up and I didn't realize that I didn't really see you the rest of the night until, and then the next day I listened to your episode with James O'Bee where you said that you were in a, had to be in a corner on the phone the whole time, which I of course now totally understand.
Marty Bent [1:17] Yeah. Pretty rough. It's been a shitty week, but I wanted to get you on because you and the team at Galaxy have done an incredible job of tracking the attackers. It looks like there's multiple waves of attacks of people brute-forcing private keys of those that were generated on cold card devices and contacting victims. And I think the Knowledge you guys have gathered and the information that you've gathered over the last 5 days is important for people to understand what's going on. And so I have, um, I have the chart here. Maybe we start there. Uh, just what you guys have, have found, um, based off of the information and the outreach they've gotten from victims. And I think you said so far 94 have reached out to you.
Alex Thorn [2:05] Yeah, it's in the mid-90s. I mean, um, it's growing. I mean, all the time. I mean, especially as I do. You know, I did Nick Batia's show yesterday. I did Unchained yesterday, where of course I called for victims to not be ashamed. You did nothing wrong. You did not deserve this. Share. First of all, file police report. Well, first of all, secure. You haven't secured your funds on a potentially vulnerable cold card. Please do that immediately. But also share your drained addresses and the transaction IDs that drain them. I know, you know, it's hard for people to do it, but because I've been saying that, people have been sharing. And it's because of that sharing that we've been able to identify so many of the coins and where they are, what addresses they're sitting in. So, you know, it's also— and sort of in exchange, although I don't think of it— in fact, initially I wasn't even doing it this way, but I can fulsomely trace anything in Bitcoin. I have a very powerful proprietary Bitcoin stack with some clankers sitting on top of it that help me traverse. So I've been providing back like forensic reports to victims that they can then use to report to their local authorities, to the FBI, to— and that we can use as well to report to, you know, crypto exchanges and Chainalysis and all of that so that there's a chance that the funds get frozen. But please do continue to reach out and share those addresses with me so that we can keep building up the picture of the attack as it unfolds.
Marty Bent [3:44] And let's dive into the nature of these attacks. Obviously, it started late Thursday afternoon, early Thursday night, and I think it's become clear that AI was used to identify this vulnerability and then exploit it. You can see that in the patterns of the waves of drainings that we've seen. In the first wave, it seems apparent that the person who started draining the wallets of ColdCard users didn't really understand best practices or how to actually scope through a wallet. it, there was a very specific pattern to this first wave, correct?
Alex Thorn [4:26] Yeah. So this, this pattern, I, I don't— I think they were the first. They're certainly where I learned of the pattern, which was the engineers at Block Inc., obviously the guys behind Cash App, Icky, Spiral, etc., Square. Right. They identified this pattern as a pattern. Right. A key piece of the pattern was a fixed 30 sat per VByte fee on all draining transactions. That was substantially higher than the median fee rate at the time, which being higher than the median is not in itself that surprising, right? Attackers are willing to overspend to make sure they, you know, get the funds. But, um, you know, normal people with urgent transactions don't have many bursts of transactions from previously unknown addresses with a fixed fee rate, right? Like your wallet, your typical wallets will suggest fee rates, you know, if you want it confirmed in this amount of time, right? Fee estimation is actually a big thing Bitcoin Core itself has worked on in Core, let alone all the other wallets, right? So that was a key feature of pattern of Wave 1. This is the only pattern of coins we have very high confidence in our stolen due to this vulnerability that was solely based on a pattern. Right. And so they identified this pattern. It was very mechanical looking. Right. There's a lot about it that looks like it was designed and then executed by automation, I'll say.
Marty Bent [5:58] Right.
Alex Thorn [5:59] And there are others, other patterns that also look like that. Right. These aren't— they don't all look like that, but many of them have features in the topography of the movements and the design of the transactions themselves, the fee rates that look automated.
Marty Bent [6:17] What in terms of where these, these coins are going to? I think the first wave had a lot of address reuse too.
Alex Thorn [6:28] Yeah. So, so waves 1 and 2, and in fact, there's almost a better chart that I tweeted earlier. Well, I have a chart of Wave 1 as a perfect example. Wave 1 alone. These are like called Sankey charts and like they show like fun movements. This is like just the highest level overview chart, right? This shows the various waves. Waves 1, 2, and 3 are high confidence promoted. That's where people are getting this like 13, you know, 56 type number. I've also promoted, like, a lot of what's what we call footprints A through N. These, some of them are pattern matched.
Marty Bent [7:16] All—
Alex Thorn [7:17] but what I should say is that Wave 1 was designed and then later confirmed, but first designed solely by pattern matching from Block. I took the pattern they described they saw. I set off across the entirety of not just confirmed blocks and their transactions, but also the entire UTXO history. So that's not the UTXO set, that's the UTXO set at every single state in Bitcoin ledger ever. Right. It's literally like 3.8 billion rows that I have. Yeah. So if you look at Wave 1 here, this is all Wave 1 now, like each of these 4 funnels, right?
Marty Bent [7:55] Yeah.
Alex Thorn [7:56] These are many addresses in each case being consolidated into 4 independent, what we call collectors, right? They're collectors because they consolidate stolen funds into one step, and then that collector sent to 3 second hop holding addresses. And you can see for some reason there's this little gray band that comes out of the first Funnel here, that's not another second hand. That's actually still sitting in the collector, but I put it on the right side here just to show that like the right side is where the funds sit. So this is actually a pretty typical looking siphoning topology or topography. I'm not sure which. I think what people know what I mean that you see in like other types of crypto hacks, right? It all gets drained immediately into an address the hacker controls, and then often they move it to like the proper setup that they want. Right now, sometimes what you see, especially in a hacker determined to exfiltrate the funds, you know, into the fiat system or into whatever other chosen currency they want, then you start to see radical things like peel chains where they blow up the fund, the, the held coins into like hundreds or thousands of different pieces. And then later they, they, you know, rejigger them into 20 pieces that don't look the same. And they do it again and again, right? Just to make it really difficult to track. Also, often they siphon them into— like if stablecoins are ever stolen, they often immediately transfer them into ETH, right? Because it's more immutable than the stablecoin. Or Bitcoin sometimes immediately gets sent through Thorchain and then sent onto ETH and then sent through another bridge into this thing because bridges are harder to track funds through.
Marty Bent [9:46] Yeah.
Alex Thorn [9:47] Unlike those, all of the coins here in wave 1 are just sitting inert in these 3 addresses on the right. So they have not moved. Right. And this is also true for waves 2 and 3. But one of the other things that's interesting here about wave 1, and I didn't— in the thread where you pulled this, don't have the wave 2. Wave 2 looks quite similar as well. And where it's many victim addresses consolidated into a holding address and then moved to a second address where they currently sit inert. That is a very clear pattern, right? Like Wave 3, which is the other one that's in that thread, just maybe if you pull up as an example, looks totally different. And I will say also, there is no co-spend between Waves 1, 2, or 3 attacker addresses. There were co-spends between those bottom 2 funnels. So this is Wave 3. This is actually much more sophisticated. There is no common collector address. This is 293 chains, and by chains here we mean like you know inputs, like category you know groups of inputs. So three 293 transactions funding 293 staging addresses funding 293 P2SWH vaults, right? So each group of victim addresses was by itself moved into a staging one and then by itself moved into a vault, which, you know, could be a multisig. We wouldn't know until they spend transactions, but none of those have been spent. I think all but 6 of the staging address— of the 293 staging addresses only contained funds from one wallet. And now we can see that because of like co-spends of the wallets. And I also have a lot of victims that I've identified that are in these, right? This is how we— and so the other thing is like Wave 1 was a pattern that was described by Block, which I expanded and later has been confirmed by many victim testimonies, reports. Waves 2 and 3 were identified by Galaxy Research solely by victim reports. Right? Like people started saying my coins were lost, and when I gathered like ten from wave two or like ten from wave three, it started to become apparent. It didn't actually take ten; it takes fewer than you realize because once you get like two or three that look alike, you send the clankers off to look at all the blocks all around that and say, "Does anything else look like a bunch of addresses into a staging address into a you know pay to what script witness script hash script witness whatever into a?" Vault, right? Then you say, oh my gosh, there's an entire burst of transactions that look exactly like that. And that's how, you know, and then of course I start publishing about it. People start saying, I think I might be in wave 3. They send me their stuff. We get further corroboration. It becomes like high confidence. So, you know, one of the— another interesting feature of 1 and 2, I told you they look similar, right? Many victims into very few staging addresses, then into second hops where they're inert. Um, the only 2 of one, like, uh, of really, there's a couple down and talk about footprints, which are these smaller operators that have emerged, but there are a pretty sizable number of people who were drained in wave 1 that were not completely drained, who were later fully drained in wave 2. So there's a number of those that, that gives us some, uh, I would say medium to high confidence that wave 1 and wave 2 are the same attacker.
Marty Bent [13:24] Hmm.
Alex Thorn [13:24] Now, you know, someone could— and by the way, wave 1, to your point, was all just after midnight, July 30th UTC. So some people were like, oh, I was July 29th. And it was like, no, if you look, you were like, you know, West Coast July 29th at night. That was actually early morning UTC July 30th. We use UTC because that's like the default Bitcoin Core and stuff. So it's just like easier to, you know, pick one. Wave 1 happened in 41 minutes. Very identifiable, right? Like you don't usually— because another big identifying feature is that not one of the high confidence, what I call promoted, meaning like we're saying these are drained, like these are no longer a question. Not one of those UTXOs was created before March 17th, 2021, when the, you know, cold card firmware bug was introduced. And I will say, like, there's other patterns, like the, the median dormancy of all these coins is like 4 years. An enormous portion of the coins in waves 1, 2, and 3, which are the majority still of, you know, high-confidence victim addresses, the vast majority had never spent a coin, right? So these are just receiving coins, very indicative of people stacking sats into their cold card and You know, in cold storage. So, you know, I think like there's co-spend which can help identify. But again, everything after wave 1 were patterned to the extent we found patterns. There are some where I'm not seeing a pattern, but I have a victim report. The one that I see, it looks credible and drained. And so we've incrementally added those too. But also we found something like we're up to in the graphic, uh, the first graphic you showed, we were up to footprint N. That means we have multiple— the footprints are we have multiple victims where the topography looks similar. They don't necessarily co-spend. A few of these co-spend, and so we're very confident and have promoted. Um, but as you can see, this graphic is everything that we haven't yet confirmed. This goes up well over 2,000 Bitcoin. The shaded ones are I think not confirmed, right, by any owner. Right. These are patterns that we found but haven't yet gotten a confirmation at all. Some of those footprints are— they're identified by the fact that victims showed us. And we've, you know, said, is there anything else that looks like this? But we don't quite have enough confirmation that we should extrapolate it out to transactions that we don't actually have confirmed by a victim. Right. Right? Because there are plenty of transactions in waves 1 and 2 and 3 that we haven't actually gotten a victim report about, but we're very confident are part of the wave. So that's just some background on the methodology that we've been doing. And just as background, like, I have direct victim confirmation for about 400 Bitcoin of the 1,500 or so that we currently call high-value promotes. So A sizable amount have I've talked to.
Marty Bent [16:35] Yeah. It's so heart-wrenching.
Alex Thorn [16:41] Yeah.
Marty Bent [16:42] But I think explaining if you haven't, if you have a cold card, I don't care what your setup is. I mean, if you roll dice, you should be fine. But if you don't have confidence that you did it correctly, just get it off.
Alex Thorn [16:53] I agree. Yeah. And another important thing to say, but again, And I have a ColdCard MK3, I believe, with no password and no dice in a multisig quorum that cannot reach signing threshold. So it, it really can't be affected at the moment. And in that quorum, I've never spent. So there, the address isn't known to hold coins on-chain, for example, um, because it's, you know, like a— it's a script hash address that has never revealed its script, right? So But I, and I haven't, because I know that that isn't vulnerable at the moment, I haven't actually rotated the cold card out yet, but I absolutely will. So, and I will say I haven't updated this analysis since like midday yesterday, but I can say in waves 1, 2, and 3 for sure, there are zero multisigs identifiable. So as far as I'm concerned, there's no evidence that any multisig setup has been breached here. Now, of course, if you had like, say, a 2-of-3 multisig quorum where 2 of 3 are cold card MK3s like mine with no passphrase and no dice roll, that is vulnerable. I haven't seen one instance yet of it being attacked. It's probably, you know, Rob Hamilton and the red team working on this is probably more— and James O.B. are probably more apt to actually talk about that. But I, I understand that's probably lower on the tier of priorities that the black hats are looking at to search namespace for. It's more complicated. But all that being said, like, I am of the view that like anything on a cold card at all, including my subthreshold quorum key, should be rotated. I mean, it's— there's just no reason to, to stick around if you have any doubt whatsoever, in my opinion.
Marty Bent [18:46] So, freaks, This was brought to you by our good friends at Square. If you run a business, you need payments, you need hardware, you need software, invoices, point-of-sale tools, and a system that does not turn every basic operational task into a headache. Square spent years making it easier for small businesses to get paid and keep moving. And now with Block leaning deeper into Bitcoin, Square sits at an important intersection. Real-world merchants, payment infrastructure, and the future of Bitcoin commerce. We're making Bitcoin everyday money freaks. If you are starting or upgrading your business setup, You can get up to $200 off Square hardware at square.com/go/tftc. All right, freaks, you know I don't take sponsor money from products I wouldn't use myself, so listen up. The Aven Bitcoin Visa card is one of the most interesting things I've seen in the Bitcoin lending space in a long time. Here's the deal. You can get a line of credit up to $1 million backed by your Bitcoin without selling a single sat. No games, no annual fees, no minimum draws, and your Bitcoin is custodied by BitGo, one of the most trusted names in digital asset security. Aven never lends it out. There's no rehypothecation. You stay in control. You can lock in a fixed rate for up to 10 years. 10 years. That's 10 times longer than most lenders out there, or go interest only for up to 5 years. Rates start at 8.99% APR. For a product that lets you keep your stack and still access liquidity, it's hard to beat. On top of this, guess what? You also get 2% unlimited cash back every time you use the card. Spend fiat, keep your Bitcoin. That's the whole game. If you've been stacking for years and you need liquidity without triggering a taxable event, This is worth a serious look. Go to aven.com/bitcoin. That's aven.com/bitcoin. Check it out. Yeah, and it's a timing thing that— I mean, bringing this back to the waves, obviously waves 1 and 2 had a very specific pattern, but that is the game theory at play right now. It's just a ticking time bomb if you have private keys generated with the affected versions of the firmware, which started being released in March of '21. So I think version 4.0.0 and beyond are affected. Different models have different levels of entropy. Older models, I think, have more— I'm pretty confident— have more entropy, but still not a sufficient amount of entropy to protect you from a brute force attack. So move your coins if you haven't already. And the game theory is such that once The alarm bell was sounded last Thursday and it became obvious that this was exploitable. You just have to assume that other actors are going to enter the fray to try to exploit this too. So the time bomb could be accelerating. The pace of the clicking, ticking of the clock can be accelerating. So move with haste. And I think that's another weird factor that's entered The conversation too is there's, I mean, I've been listening to Spaces and following this discussion since Thursday night on the train ride back. People were already talking about this because you had people like Wicked Bitcoin, Portland HODL, Rob Hamilton, Praveen, basically downloading the scripts to brute force private keys or seed phrases on their computers, and they were able to identify wallets and the ethical conundrum of do we sweep this as white hat hackers into addresses that we control in the hope that we can get this back to the original owner. That conversation started pretty early Thursday night. I think there has been confirmation that some people have engaged in white hat sweeping of these coins, but it gets into the, again, the ethical dilemma, but then just the logistics of even if you do that, how do you get the coins back? And I think that's another important detail. And if there is a scenario in which we identify the attacker or white hats have swept funds and they want to return them, I think the ability to prove that you were the individual that actually created the private key initially depends on you actually having your physical device.
Alex Thorn [22:46] Yeah. And You mentioned a couple people there too. You got to shout out to Wicked— Wicked's— I think— what is he, Wicked Smart Bitcoin? Is that— and he doesn't even say that anymore. But that guy's been doing like Spaces, just helping people to, you know, answering Q&A on self-custody at the most granular level. I have literally listened to him help dozens of people like move coins off their cold cards live. Reminds me of the old Clubhouse days a bit.
Marty Bent [23:16] Yeah. What— because I know you identified somebody, I forget from which wave, that sent it to a casino.
Alex Thorn [23:24] Yeah, this one was pretty ugly. Like, not from waves 1, 2, or 3. Those coins are inert. They're not— they haven't moved. Right. And those are the key ones that we were watching because they comprise the largest share of the known stolen coins, 1, 2, and 3. Yeah, there was a victim that we traced and that I think 7 or 10 of their 17 Bitcoin was instantly moved to Thorchain, which is a cross-chain DEX that lets you effectively send Bitcoin into a multisig controlled by their validators. And you can put an Ethereum address, for example, and a trade order in an OP_RETURN. And then they spit out the equivalent ETH on the other side in Ethereum. And so you enter your Ethereum address in the hop return, plus some other instructions about the trade that you want done.
Marty Bent [24:20] Mm-hmm.
Alex Thorn [24:22] Luckily, the way it works is it's pretty easy to trace through there, at least in my limited experience tracing. And then, then it's a matter of using the Etherscan API to follow where it goes. And Etherscan has a lot of deposit addresses for exchanges and services labeled. These were something like, I don't know, $450,000 worth of the Bitcoin. Now, ETH was deposited at an offshore casino that I'd never heard of called Dual.com. And so I told the victim this and gave instructions on how to send a preservation request and a freeze request to the Casino, um, and they— this was like at 1 AM on Sunday morning, so like late Saturday night Eastern time. And they did get a response, and it was like, we're not going to freeze until we get a police report demanding the freeze. And I found that to be offensive because it was midnight on a weekend. There was literally zero chance that, um, a police report was going to be sent anytime soon. And I, I thought the prudent measure for any sort of financial institution when receiving a credible cryptographic forensic report effectively proving that the funds emanated from a stolen address, um, would be sufficient to just— I'm not saying take the coins from the casino depositor. I'm saying don't allow them to be withdrawn, right, until an investigation is complete. I guess they declined to do that, though they did promise me via DM that they would preserve the information about it, which, you know, and I don't know what jurisdiction this dual.com is actually registered in or if they are, but that may be all that's required. And, you know, they wrote back on X that there— it was unreasonable to demand solely based on a report that their customers could not withdraw. It is an interesting thing about— it raises a lot of interesting ideas. One is that, you know, I have the victim report. The victim can prove they do possess the keys, but the nature of this exploit is that they are not the only one who now possesses the keys. And eventually everyone might possess the keys to all of these coins, right? Um, and that's, that's tricky. That's one reason why we really encourage people to formally file like victim reports with the local police, um, the FBI's IC3, um, Canada's Anti-Fraud Center, the, um, you know, Royal Canadian Mounted Police. I've got a whole list, by the way, if people need to know who to contact in their jurisdiction. these exist all over the world, right? There's— some of them share information with each other and all that is to establish victimhood early because there could be a time if funds are recovered where many people use keys to claim that they're theirs, right? And it becomes a whole cluster. That's why I also tell people not to destroy their cold cards even after they've moved funds off of them or had their funds drained, because there might be forensic evidence on the cold card that can be used to establish their you know, you know, that they're the primary owner in the chain. And another thing that it raises is the question of hold authority. This came up once recently with a hack and a DeFi hack, and it's— forgetting which one it is. There's been many where ZackXBT and others notified very early to Circle that Funds were being exfiltrated and bridged— sorry, bridged over Circle's sort of— I think it's called CCTP, cross-chain stablecoin bridge, which is an interesting version of a bridge, by the way, that's more secure than some of the like lock up funds on one side, reissue them on the other because it goes through Circle, but it goes through Circle. So Circle is the issuer of USDC, just cancels them on one chain and reissues them to you on the other. which is actually safer in a lot of ways because, um, it, it's not like locking them up to create a honeypot on one side of the chain, which is how so many DeFi bridges are, um, exploited. Anyway, they didn't— they— Circle declined to stop this even though they'd been warned for like 6 hours loudly on Twitter that this was happening. And they said that they needed what was called hold authority. Um, this is now in clarity, this idea of hold authority. It says that you know, if you credibly know that or have reports that there's, you know, this type of fraud or whatever going through your centralized platform, you, you can hold it, freeze it on your platform for some amount of time. I think in Clarity it's 48 hours while you investigate and you are totally immune from civil liability. So I understand, you know, I think there's an argument to be made in the case of the Dual.com with this One that I talked about, like, you know, are they worried about being sued by their client who they promised, you know, their user, you know, instant withdrawals? Like, I, you know, I get that it's a little tricky, but I'm becoming a little bit like, you know, Tayvano, if people follow her, who used to was like head of security at MetaMask and had MyEtherWallet, big, big, I think, participant in the SEAL, you know, rapid response crypto hacks team. She has just zero patience for this type of behavior. And just the more people I've talked to from the ColdCard hack and seeing this type of thing and just like knowing the funds are there and not being able to get them to act is incredibly frustrating. So yeah, we haven't— I got to say, the vast majority of coins we have not seen that type of exfiltration behavior from. Maybe there's luck. Maybe they do have KYC at dual.com, and, you know, with the police report, maybe they'll be able to identify that hacker. But that's the other part of the story, Marty. That is definitive— well, it could also be, but very doubtful. I would say definitively not the same hacker from waves 1, 2, and 3.
Marty Bent [30:35] Well, didn't Block report that waves 1, 2, and 3, the hacker was obviously using some chain analysis tool that was a paid service.
Alex Thorn [30:45] So yeah, I think this is Wave 1 in particular, which is the, the one that they really blogged about where I got that first pattern to work with. They said that, and I don't know how they figure this out, but I think Clay from Block said that they, from, from BitKey, I believe, right, said that they confirmed this, uh, with the blockchain infrastructure provider I don't want to— I don't know the details, but what I do know and what they said was, and what I assume is, a blockchain infrastructure provider is like a, in this case, a party that you can connect to their RPC, right, and pull blockchain data from potentially from many chains, right? They have APIs or RPC providers. There are many of these, to be clear. It's a great service. Especially for, you know, blockchains like Ethereum and Solana, which are even more cumbersome to run than Bitcoin. Right. Many people use these for many— obviously, to be clear, obviously totally legitimate reasons. But somehow Block said that they had identified that the same entity they believe to— this pattern they observed that what I now call Wave 1 had queried, like, I guess a lot of the addresses that they ultimately attacked. Through this blockchain provider, and that in talking with the blockchain provider, they learned that this entity had used a paid account at the blockchain provider. So I think this is very promising as potentially the ability— and that authorities have been notified. So potentially the Wave 1 attacker could be identified and that, that could be very, very promising. You know, knock on wood. I don't want to, you know, get ahead of ourselves here, but, um, yeah, you know, you say run your own node, verify your own transactions in the blockchain. Apparently Wave 1 hacker did not do that. So even though it would have been pretty trivial to do so.
Marty Bent [32:43] Yeah, he didn't spin up his own node. And that, I mean, that begs the question too, like, what, what can these attackers do now that they have the coins? Obviously you mentioned like Thorchain and splitting.
Alex Thorn [32:53] There are things I think, yeah, I've seen some Bitcoiners who aren't as haven't, you know, followed or been as close to like most of these hacks are like centralized exchanges or like smart contracts and DeFi, right? Historically, bridges, DEXs, obviously centralized exchanges, you know, many such instances. It doesn't happen very often in the Bitcoin ecosystem directly outside of centralized exchanges because there is no DeFi on Bitcoin. Right. It's pretty simple protocol, which makes it a lot more secure in my view at the protocol level than many of these others, which are much more complicated. And, and it doesn't have the generalized scripting that others do. So like, you know, you don't have people creating novel new programs and stuff like that. Multisig is native on Bitcoin, whereas it's not on Ethereum, etc., etc. So people have been saying like, well, what, what can they do? We can track it everywhere. They can be just— the hackers can themselves be expert money launderers. They can pay money launderers. These people exist. They have methods. Like, it is possible for them to exfiltrate these coins. It is hard. It's definitely hard. Right. There are mixers and tumblers, you know, in the Bitcoin world that they could use. But those are like very watched targets by law enforcement. Right. So you can bridge to another network that has privacy protocols, right? The fact that the one we talked about that went to dual.com didn't go through like Tornado Cash first on ETH before going to dual.com is surprising. Suggests they really were not very sophisticated, even, even though this attack seems so sophisticated and it is pretty sophisticated. That shows you like how it's degrading, like waves 1 and 2 and 3 are more sophisticated and Who knows why they're sitting inert on Bitcoin? I can tell you it's, it's not because it's impossible for them to exfiltrate the funds, but it is difficult to do so without getting caught. Right. And that, that is a silver, uh, um, or, uh, potential positive that it isn't easy, but it, but I, I would caution, don't hang your hat on that. It is possible to launder money out of Bitcoin.
Marty Bent [35:08] Freaks, look at me. I'm glowing. I've got like an angel's halo. going around me. You know why that is? Is I feel good. I feel taken care of. I feel blessed, healthy, happy. And that is because I'm a CrowdHealth member. My family and I have been CrowdHealth members for 5 years now. Literally this month, 5 years ago, we joined CrowdHealth. We've had 2 babies, we've had multiple health events, and we're never going back to health insurance. CrowdHealth is crowdfunded healthcare. So you, you sign up for CrowdHealth, you pay a monthly fee, you help out with other people's bills, uh, and it's significantly cheaper then health insurance. We were on COBRA as a family of 3 when I left my last job before I went full-time to TFTC. Went on The Crowd Health. Now as a family of 5, we pay, I believe, $700 a month. It's significantly cheaper. They're going to negotiate prices lower for you. They've consistently negotiated healthcare prices as much as 50%, 60%, 80% in many cases. They help out with babies. If you have a pregnancy, you pay the first $3,000 and The Crowd covers the rest. If you have A regular health event, you pay $500 and the crowd pays the rest. Go to joincrowdhealth.com, sign up today, use the code TFTC, opt out of health insurance. I'm uninsured, baby, and I love it. Use the code TFTC at joincrowdhealth.com and you'll get $99 a month for the first 3 months that you're on the CrowdHealth platform in the community. Bitcoiners, you found sovereign money. Now find sovereign health and sovereign healthcare. Sup freaks? When you take Bitcoin seriously, you start with custody. You want to control your keys, avoid single points of failure, and make sure your savings cannot disappear because you or someone else screwed up. This is what Unchained has been focused on since 2016. Unchained is the leader in collaborative multisig custody and Bitcoin financial services that keep you in control. They secure over $12 billion in Bitcoin for more than 12,000 clients. That means about 1 out of every 200 Bitcoin sits inside an Unchained vault. Their model is simple. You hold 2 keys, they hold 1 key. It always takes 2 keys to move Bitcoin, meaning their single key can't access your Bitcoin on its own. Just resilient shared custody that gives you institutional-grade security while keeping you sovereign. Unchained also lets you trade straight from your vault, access Bitcoin-backed commercial loans, open a Bitcoin IRA where you hold your own keys, and set up personal, business, trust, or retirement vaults. They even offer inheritance solutions built for long-term hodlers. Or opt for the highest level private client service with Unchained Signature and get a dedicated account manager, discounted trading fees, exclusive access to events and features, and much, much more. If you want a partner that helps you secure and grow your Bitcoin without giving up control, go to unchained.com and use the code TFTC10 at checkout to get 10% off your new Bitcoin multisig vault. That's TFTC10 at unchained.com. I mean, there's been a massive reaction. Obviously, you and your team are tracking this, but it seems like there has been somewhat of an immune response to not only obviously for ColdCard victims, but it has incited this urgency across the industry to begin auditing every system.
Alex Thorn [37:59] Yeah.
Marty Bent [37:59] And that's something that's been fascinating to watch unfold over the last 5 days is the speed with which Rob Hamilton, the new CEO of Bitcoin, and the red team that are working on basically auditing as many projects as possible are uncovering. I mean, they haven't disclosed any, but Rob did come out and confirm that all the vulnerabilities that they have found so far do not put funds at risk immediately. or funds at risk at all, I believe he said. Don't quote me on that. Could double-check that. But I think it's— I said this yesterday on RHR, like, by no means is this something that this ColdCard hack, this ColdCard vulnerability was human error. It seems like AI was used to discover from these attackers and they've exploited it. But there have been reports of others in the past that we've all been made aware of now that were reporting that they had collisions and their coins were getting out there. So this has objectively been possible for 5 years. It seems like there were some users reporting that they went to their wallet and funds were swept. And I think maybe that wasn't an attacker, it was just a coincidence of somebody creating a private-public key pair using a cold card and sweeping the funds once they noticed there was some there already. But AI is a very, very big and is becoming a larger sub-theme to all of this, both the exploit side and the reaction to it as well.
Alex Thorn [39:47] Yeah, absolutely. And You know, it's worth noting, I think, and I'm not going to cite any of the names because I forget them, but bugs in the entropy random number generators in crypto wallets have existed before and have been found without AI. So it's not that AI was needed to find this bug in the implementation of Coldcard's random number generator, but it is pretty likely that it was used and it's definitely being used by attackers to operationalize the vulnerability. Rob and the red team, there's a bunch of efforts going on, right? I'm focused on on-chain tracing of funds because that's what I'm good at. Rob and many others are just burning tokens, like evaluating, doing code review with Frontier Cyber-enabled models, but also like Kimi and GLM, the open-source models, on like basically any thing they can get their hands on in the Bitcoin community. So other hardware wallet codebases, like libraries that underlie important Bitcoin infrastructure, like everything you can think of, which is a huge effort. There's also, like we said, people like Wicked literally helping individuals migrate coins. There's people that are trying to replicate the attack in order to like determine how many addresses are still at risk.
Marty Bent [41:11] Right.
Alex Thorn [41:13] And you need substantial compute for that. People are chipping that in. There is a huge immune response from the Bitcoin community in reaction to this exploit. But to your broader point, Marty, about attacking and defending with AI, that's been a, you know, a huge problem, right? Like, you know, you remember there's the OpenAI— I know you guys covered this— the OpenAI lab leak that hacked into Hugging Face, which itself is an AI model repository. Hugging Face said they couldn't use Frontier models to defend themselves. They kept hitting all the cyber safeguards, and so they had to fall back on Chinese open-source models. And to me, the idea that American companies have to rely on Chinese AI models to defend themselves is absurd, and something needs to give here. I don't know if it's just the sort of safetyism emanating from the Frontier Labs. Or if it's in reaction to the US government's midnight phone call to Anthropic that halted the release of Mythos. But something needs to change. And I wrote this on X, you know, to the extent that I have any reach, I'm escalating that to the highest levels I have access to because it's absolutely insane. Even myself, I primarily am using Claude Code. and Codex and even asking again on a database that's local of Bitcoin data, which is public, right? Even saying, hey, I have a report from a victim that they were drained, you know, in this transaction ID. Can you like pull the transaction information out of my own computer? And I'm hitting Fable 5 Safeguard and getting downgraded to Opus, right? Like, it's insane. It's just insane. something's got to give here.
Marty Bent [43:04] No, it does. To think that— I mean, it's something that we've been saying in Bitcoin, just in the concept of trying to throw KYC/AML restrictions on Bitcoin, bring it to the chain level, or prevent people from accessing privacy-preserving tools. It's like, well, yeah, you can try to prevent people from using Bitcoin in a peer-to-peer fashion or using it in a private way, but criminals don't care. They're going to use it that way no matter what. They're criminals because they do not have a high regard for the law in the first place.
Alex Thorn [43:40] That's right.
Marty Bent [43:40] And so when it comes to this discussion around AI and defending against attacks and being proactive to secure your systems and make them more robust from a security posture, it's insane that we have to fight this battle, particularly in the US right now. Everybody's using Kimmy, I believe Gwen came out with a new model just yesterday that's in the mix. And I think the red team, I saw Rob or Callie say that they did get access to OpenAI's Edge Enterprise Frontier model. Yeah.
Alex Thorn [44:17] And I can just say, I know of some crypto, big crypto companies that have access to either Glasswing or OpenAI Frontier cyber models and have been doing work on, you know, codebase review and vulnerability reporting, responsible disclosure, stuff like that, and stuff that also helps Bitcoin. And also, I think there's— I don't know if it's pronounced like this, you know, when you've only read something, you never heard it said out loud. Project Lupe is an open source, like, LLM security vulnerability project. I don't know who runs it, but I know Steve Lee is involved. And they're also working on this. So there are a lot of efforts. It's not just Bitcoin or even blockchains. Like, this is a global question. Like, every company needs to upgrade. We're in an arms race right now. I do think like it's like going to be episodic and we'll get to a, you know, it'll plateau where the defenders have caught up to the attackers. And so there's a little bit of a détente. I think governments will impose some actual, like, pausing and safeguarding as these things get better and better. For better or worse, I think they will. Even I think the Chinese government will eventually not allow, like, the most dangerous because, you know, the open source models can be used by their people as well. And so, like, I think you'll see, but we are definitely still in early innings where it is like attackers are outpacing defenders. And so defenders. And by the way, that's like true for like every weapon on earth, you know, like the Mongols like defeated the whomevers because they had horses. They were shooting arrows from horses and that had never been seen before. Right. Like we're kind of in that era, right? Like, you know, the American Revolution, they kind of invented guerrilla warfare and that was overwhelming to the British's column warfare. So like, we're still in that stage, but I think it'll be episodic where, um, you know, you reach plateaus and then who knows, maybe step function increases cause another. episodic arms race and blah, blah, blah. But we're definitely still in a period where the defenders don't have access to good enough defensive tools, I don't think.
Marty Bent [46:24] No. I mean, obviously Bitcoin's being affected right now, but there was a report out of Minneapolis, I believe, or Minnesota a couple weeks ago about a water treatment plant being affected by some virus and shutting down. If you think of how antiquated the software around grid system— grid systems are today, energy systems. Like, this is— I mean, when it comes to the broader discussion about getting access to frontier models to people that need to defend these systems, I think it's, it's an imperative. It is a national security issue at this point.
Alex Thorn [47:02] Yeah, it, it is. And I have to say, like, I don't have the answer on what the policy should be exactly. I just know that current status quo isn't good enough.
Marty Bent [47:16] No, I know you got to jump here. Thank you for taking some time to hop on. Um, I really wanted to get you on so that anybody who may be a victim out there and isn't aware of the research that your team is doing and the, the data gathering—
Alex Thorn [47:31] Yeah, follow— you can see we publish a fair amount on GLXY research on X, but So you can get all the info on how to contact me and us through that. But that account's DMs are not open, so you can DM me on X @IntangibleCoins. I would love to help. And Marty, I just wanted to say like, thank you for, you know, being in this community. I know it's been a really tough time for, you know, you guys as longtime users of ColdCard as well. I've used ColdCard. I think the first rap I ever did on Galaxy Brains had a line about using ColdCard keys because we hold hard cheese. So, and also I've been explaining this attack to journalists, to institutional investors who are interested but not affected because, you know, they use custodians and stuff like that. And one of the things I've been saying about why this is so demoralizing and such a tragedy, though I believe anyone having their money stolen for basically any purpose is terrible, is that, um, these victims didn't do anything wrong, and they didn't even do anything risky. In fact, if, like I said, the vast majority of the coins being stolen, their addresses, addresses had never spent their coins, and they'd only received And the average, the median dormancy of the coins being stolen is like 3.8 years. These are long-term DCA Bitcoin believers, the cultural demographic of people that use Coin Kai. I mean, I've got a block clock over my shoulder, the last 250 episodes of Galaxy Brains. The people that use these are largely most philosophical believers in Bitcoin. And this sort of strikes at the core of the self-custody, you know, work hard and save in Bitcoin. You know, again, nobody deserves to have their money stolen, but these people didn't put their coins on a shady crypto exchange to speculate. They didn't accidentally, which, uh, you know, leak their coins, didn't, you know, drop their hardware wallet unlocked on the ground. They didn't accidentally upload their seed phrase. Not that those, you know, those are mistakes, but these people didn't make any mistakes. And that's what makes it so upsetting and why people are worried about sort of the future of the self-custody movement. And I would just say self-custody is not dead. This was a poorly implemented thing. Random number generators do work. They are proven to work. This one was not proven to work. And That's why Rob and the red team and many others, Portland and Calais and others who are helping, are so essential. I think the wake-up call for us in the Bitcoin world is that, you know, verifying and auditing code is not like a checkbox, like it's something we've got to be doing, you know, 24/7, 365. But I personally do believe this will damage the, you know, single-sig you know, keep your hardware wallet under the bed and put your seed in a seed plate. I think the future of self-custody is multisig collaborative custody. I do believe that firms like Casa and Unchained and Nunchuck and the Miniscript-based ones like Liana Wallet and AnchorWatch and others— I'm sorry if I'm forgetting others— there are ways to provably and to really diversify the exposure to hardware wallets or specific key generation mechanisms. That might sound difficult when I say multisig collaborative custody, but actually there are many strong companies that provide this as a relatively cheap service. So, you know, if you are hellbent like I am in doing self-custody, look into those. I think we need to be a lot more deliberate about the risks that people take. I do think telling people to roll 100 dice, just not going to work for the majority of people. But there are easier ways. You don't have to be permanently demoralized about self-custody.
Marty Bent [51:43] I agree there. I'm not going to give any advice at the moment, but I think the only advice I will give is if you have a cold card, if you're for some reason just becoming aware of this, just move your funds ASAP. Alex, thank you, brother. If you aren't following Alex and the team at Galaxy Research, If you're a victim, um, make sure you're following them, make sure you're reaching out. Again, I think police reports, if there is a chance of recovery of funds, like having that police report and holding onto your device will be, will be critical. So make sure you follow that, that advice. And, um, this is obviously a developing situation, so make sure you follow the teams that are on top of this, which Alex and the team at Galaxy is, is very much on top of this right now.
Alex Thorn [52:29] Thanks a lot, Marty. Good to be here. Yeah, please reach out if you're affected.
Marty Bent [52:33] Peace and love, freaks. Okay, thank you for listening to this episode of TFTC. If you've made it this far, I imagine you got some value out of the episode. If so, please share it far and wide with your friends and family. We're looking to get the word out there. Also, wherever you're listening, whether that's YouTube, Apple, Spotify, make sure you like and subscribe to the show. And if you can leave a rating, on the podcasting platforms. That goes a long way. Last but not least, if you want to get these episodes a day early and ad-free, make sure you download the Fountain podcasting app. You can go to fountain.fm to find that. $5 a month gets you every episode a day early, ad-free. Helps the show, gives you incredible value. So please consider subscribing via Fountain as well. Thank you for your time, and until next time.
Alex Thorn [53:26] Okay.


