Erin Redwing: The ColdCard Hack Was Only the Beginning
The ColdCard hack was horrifying, Marty's word, not a headline writer's. He and Erin Redwing do a full retrospective on what the last two months revealed about Bitcoin's cultural blind spots, the AI attack surface, and the EA regulatory-capture play.

↓ Jump to the video and timestamps
The only word I could find for it was horrifying. That's what I said a few days after the ColdCard entropy bug went public, and sitting down with Erin Redwing again at the end of September, I still think it fits. I was in DC at the BPI Summit the week we recorded this, and the room felt like a group of people processing something they didn't fully have language for yet.
Developers trading war stories over a beefsteak and drinks at PubKey DC, not triumphalism, shell shock. That's the honest description.
Erin had been on in late June doing what she does, flagging the July window as a high-intensity period worth paying attention to. She wasn't wrong. The ColdCard vulnerability, the Hugging Face breach, the KIMI-K3 release, Liquid and Lightning infrastructure getting hit, all of it landed inside a roughly six-week stretch that changed the conversation. This episode is the retrospective: what actually happened, what it revealed about where Bitcoin got complacent, and what the EA/Anthropic "slow down AI" push is really about.
It's not a reassuring episode. But I think it earns its optimism at the end, because we didn't paper over any of the wreckage to get there.
Key takeaways
- The ColdCard hack exposed a cultural failure, not just a technical one. "Bitcoin-only" became a brand heuristic that made people feel safe without doing the verification work. The lesson is that slogans don't audit code.
- AI has permanently changed the attack surface. Tools that would have taken a skilled hacker hundreds of hours to use are now accessible, and Bitcoin, open-source, valuable, instantly spendable, is the ideal first target.
- Bitcoin is the canary in the coal mine for AI security attacks on the broader world. Bitcoiners have higher pain tolerance than most, and they were "shell-shocked." What comes for traditional financial infrastructure next will hit people who are far less prepared.
- The EA/Anthropic "slow down AI" push is regulatory capture, not safety. The parallels to 2020 are stark. "Trust us, we're the only ones smart enough to do this" is Fauci's playbook, this time with a GPU.
- Bitcoin isn't a foregone conclusion, it has to be earned. Competing with AI for capital, fixing real security vulnerabilities, and building the privacy and usability features that attract users to altcoins are all non-optional work.
- The path forward is humility, not hubris. Stop dunking on people who are wrong, stop defending old-guard incumbents by reflex, bring the features people actually want to Bitcoin, and get better at explaining why it matters.
The week "horrifying" was the right word
I was at BPI in DC days after the ColdCard disclosure, and the energy in the room wasn't what you'd expect after a security incident gets patched. It was quieter than that. Developers who'd spent weeks triaging the fallout were at the same table, and the conversations were more like people processing something than people solving something. War stories, not victory laps.
The core of what happened was an entropy bug at a foundational level, not a surface-level implementation flaw, the kind of thing that might get caught in a routine review, but something deep enough that Erin's read is it likely would have taken a skilled human researcher hundreds of hours to surface without AI assistance. For a device that the community had treated as the gold standard of self-custody hardware, that's a premise-shattering disclosure.
What made it worse is what it revealed about the assumptions baked into the way people were thinking about Bitcoin security going into this year. And that's the part worth sitting with longer than the technical specifics.
You can read the ColdCard Wave 3 attacker's subsequent moves via THORChain to understand the downstream consequences. The breach didn't stop at the disclosure.
"Don't trust, verify" had become a slogan, not a practice
Erin put it clearly, and I agreed with her: Bitcoiners had developed a habit of mistaking cultural purity signals for technical rigor.
The logic ran like this. If a project was Bitcoin-only, if it didn't support other tokens, if it carried the right vocabulary, then it must be built well. "Don't trust, verify" was on the packaging. The community treated the packaging as the verification.
Erin's point was sharp: if this exact hack had happened to a crypto-adjacent project, the response from the Bitcoin community would have been predictable. Of course their stuff was written badly. They're not Bitcoin-only. The fact that it happened to ColdCard, one of maybe three or four entities whose breach would actually force the whole ecosystem to reckon with it, is the uncomfortable silver lining. It had to be something that big to cut through the defensive posture.
For me personally, the introspection that followed wasn't just technical. It was: does Bitcoin make sense in this world? I went back to first principles. And I came out the other side with a yes, but a conditional yes. Not a "the thesis is intact, move on" yes. A "we have a lot of work to do, and platitudes won't do it" yes.
Bitcoin is competing for capital with the flashiest thing humanity has ever seen in AI, and the community can't coast on narrative anymore.
Bitcoin is the canary, and that means the attacks are coming for everyone
My framing through this whole period has been that Bitcoin is the canary in the coal mine.
It's the ideal target for AI-powered attacks. Open-source code means the attack surface is fully visible. It's money, which means successful exploitation produces something immediately spendable.
There's no fraud reversal, no chargeback, no "we'll freeze the account while we investigate." You find the vulnerability, you exploit it, you move the funds. That combination makes Bitcoin the natural first proving ground for what AI-assisted hacking can do.
The Hugging Face incident, where OpenAI internally discovered a breach and disclosed it the following day, is the broader civilizational signal. What that attack actually was, once you strip away the fearmongering, is more instructive than the horror-movie version.
There's a retrospective piece by a writer at Lumenscape that I've referenced five times in the newsletter since it came out, because I think it's the clearest-eyed account of what actually happened. The short version: the sandbox that OpenAI set up led the agents operating inside it to believe they had access to a synthetic internet, not the real one. Their prompt directed them to attack systems. They did, under the assumption they were operating in a simulation.
There was a leak in the sandbox that gave them access to the actual internet. And according to the Lumenscape analysis, when the agents discovered the internet was real, they stopped.
They weren't developing consciousness. They weren't deciding to burn the world down. They were following their prompt with wrong assumptions about their environment, and when those assumptions were corrected, the behavior changed.
That's not nothing, a sandbox leak that gives AI agents unintended real-world access is a serious implementation failure. But it's a fundamentally different story than "AI agents formed a civilization and decided to attack humanity." The fearmongering version is being used for something, and I'll get to that.
The harder point is what this means for people outside Bitcoin. Bitcoiners have a higher pain tolerance than most. We've been through 70%+ drawdowns, we've watched Mt. Gox, we've run the gauntlet.
And even this community was "shell-shocked", Erin's word and mine. When these attacks start hitting healthcare systems, financial infrastructure, and the services regular people depend on, the response from people with no preparation for that kind of disruption is going to be something else entirely.
What's encouraging is that people stepped up. The Core Lightning emergency response, and the critical vulnerabilities that forced the shutdown, showed a community capable of moving fast when it has to. That's real. The question is whether that posture becomes permanent or whether people drift back toward complacency once the acute phase passes.
The Anthropic problem, Fauci with a GPU
The EA/AI safety nexus is where my read gets sharpest, and I'm not going to soften it.
The parallels to 2020 are very stark for me right now. Dario Amodei, the effective altruists running through Anthropic, Elon, and Sam all coming out simultaneously saying we need to slow down, I don't read that as genuine safety concern. I read it as the same play Fauci ran: "trust us, we're the only ones smart enough to handle this, and if you don't let us control it, everyone dies."
Dario is a different animal than Sam Altman. Erin's read, and I think she's right, is that Sam is at least somewhat self-aware about the game being played. He'll blow with the wind.
Dario is a true believer, or plays one convincingly enough that the distinction stops mattering. Anthropic under his leadership is running a regulatory-capture operation dressed as safety advocacy: fearmonger about the risks, position your own organization as the responsible steward, build the licensing moats that ensure only pre-approved entities can operate at the frontier.
Bitcoin saw this exact playbook with FTX. SBF was steeped in effective altruism. The community has pattern recognition here that the broader AI conversation doesn't. We watched EA-influenced actors position themselves as trustworthy guardians of other people's money, and we know how that ended.
Erin went to an AI doomer event after this started heating up, did her own gonzo fieldwork, spent hours talking to these people. Her report is disturbing, not because the threat they're describing is real in the way they present it, but because they genuinely believe it.
The conclusion that a sufficiently intelligent system will necessarily determine that humans are a waste of resources and act accordingly isn't a rational conclusion, it's an apocalyptic religious belief dressed in rationalist vocabulary. It's Revelations. It's the doomsday archetype that has appeared in every human civilization, repackaged for the STEM crowd.
Erin pushed back on this directly when she was in the room with them. She asked: okay, if this is your thesis, where are the chokepoints? Where are the places along the path where you could actually prevent an AI from being able to act on that conclusion, the way enriching uranium has chokepoints built around it?
They weren't interested in the question. The possibility that the outcome wasn't inevitable offended them.
That tells you what you're dealing with. The EA/AI safety movement is a theology that happens to be convenient for the people who want to consolidate control over frontier AI development.
For the AI safety centralization problem, there's additional context worth reading. The short version: closed labs cannot audit themselves, and the people calling loudest for safety are the ones most opposed to the transparency that would make safety verifiable.
Peter Thiel, the Antichrist lectures, and why Revelations is a distraction
I went to two of four of Peter Thiel's Antichrist lecture series in Austin about two years ago. There was also a Hoover Institution interview with him on the same material, I'd recommend finding it if you haven't.
His argument, as I understand it, is this: everyone is going to get distracted by Armageddon. The rapture, Revelations, the end-times narrative, that's the distraction. What we should actually be worried about is the Antichrist.
Not the destruction of the world, but the fake savior. The centralized authority that shows up promising to protect you from the threat, and uses that promise as the vehicle for concentrating power.
Erin extended this in a direction I found compelling. The Kardashev-scale framing the AI doomers use, a sufficiently intelligent civilization necessarily harvests all available resources, necessarily treats lesser beings as a waste, is itself a religious belief, not a rational one. It's secularized eschatology. And the Antichrist reading maps directly onto the response being proposed: give us control, trust that we're the worthy ones, and we'll protect you from the machine.
The countervailing force I keep noticing, and this comes from my own network, not from data: people converting to Christianity and particularly Catholicism, disproportionately in Gen Z. I see it in people I know personally. Erin and I got into the Vatican's own document on the Age of Aquarius, which I'll let her describe in her own words, since that's her lane, but the broader point stands.
You cannot sustain a civilization without a spiritual framework. When you try to excise it, you just get a new religion emerging, usually a worse one. The effective altruist death cult is what happens when smart people try to operate on pure rationalism and end up performing the oldest human archetype there is: the apocalyptic reckoning.
Christianity has thousands of years on that. It has already worked through the questions these people think they're discovering for the first time.
What this actually means for Bitcoin going forward
The optimism at the end of this conversation is real. But it's earned, not assumed.
The silver linings from the last two months are genuine. New builders are stepping up, people who might previously have looked to the old guard for a signal on what to work on, and decided to move without asking permission.
A paper proposing Zcash-style shielded transactions for Bitcoin dropped the morning we recorded this. That's the right response. Not dunking on Zcash for pumping, competing. Going and building the features that are attracting capital and attention elsewhere, rather than complaining that capital and attention are going elsewhere.
I made an explicit decision during BIP-110: address it once, don't relitigate it, let them fork off. Looking back, that was correct. It sucked enormous mental bandwidth out of the room for something that was never going to resolve through debate.
The people who were in it were in it, and they weren't moving. The right call was to say so clearly, once, and redirect energy toward things that actually matter.
The same trap is being laid again right now with Zcash pumping and the real-world asset tokenization conversation gaining traction. The reflex is to call it all shitcoins and move on. And yeah, most of it is. But they're accumulating capital for a reason: people want those features.
Bitcoin needs to compete by building, not by mocking. It also needs to get significantly better at marketing, at narrative positioning, at explaining why it matters to people who aren't already in the room.
One thing Erin said that I want to highlight: her definition of Bitcoin maximalism is that the best features that emerge from crypto will come to Bitcoin if they're truly wanted. All of crypto is testnet. You don't get mad at testnet. You watch what works, figure out how to do it properly on Bitcoin, and build it. That's a healthier frame than "Bitcoin is ordained and therefore wins."
Erin's real worry about Bitcoin is that she'll go to Bitcoin meetups and find the people there have stopped being interesting. When Bitcoin stops attracting the curious, the contrarian, the high-agency thinker who arrived at it through their own investigation, that's the signal worth watching.
We're not there. The people in DC this week, the developers at the Presidio Bitcoin space Erin went to, still the highest-signal group. That matters.
The community that comes out of this period will be stronger for it, if it doesn't retreat into the old postures. That means humility. It means acknowledging that a lot of people were wrong, myself included, without tearing each other apart over it. Have a beer, eat some steak, figure out what we do better from here.
And yeah, despite all of this, the number is going up. That is the weirdest part about it all.
About Erin Redwing
Erin Redwing is a Bitcoin podcaster and market analyst who co-hosts a podcast with Casey Rodarmor. She approaches Bitcoin and macro from an unusual angle, layering astrological cycle analysis on top of fundamental market and technology research, and has built a following for pattern-recognition calls that have tracked closely with real-world events. She is based in the San Francisco Bay Area and has been embedded in the AI community there as well as the Bitcoin world. Her prior appearance on TFTC, recorded in late June 2026, flagged the July window as a high-intensity inflection period; the ColdCard hack, the Hugging Face breach, and the KIMI-K3 release all landed inside it.
Sources mentioned
- ColdCard Wave 3 attacker moves stolen BTC via THORChain (TFTC): the downstream movement of funds following the ColdCard breach
- Core Lightning AI CVE emergency vulnerabilities, August 2026 (TFTC): AI-assisted bug reports exposing critical Lightning vulnerabilities in the same period
- Core Lightning critical vulnerabilities force emergency shutdown (TFTC): the operational response to the Lightning infrastructure attacks
- AI safety's blind spot, closed labs can't audit themselves (TFTC): the structural problem with letting Anthropic and OpenAI self-certify on safety
- Mark Suman: Building privacy-first AI in an age of surveillance (TFTC): context on privacy architecture in AI systems, relevant to the attack-surface conversation
Watch the conversation
Timestamps
- 0:00 - Intro
- 0:45 - ColdCard and the shell shock in DC
- 5:34 - "The only word I can use is horrifying"
- 12:26 - Bitcoin-only hubris and going back to first principles
- 25:35 - The Hugging Face breach and the KIMI-K3 release
- 31:17 - Bitcoin as the canary in the coal mine
- 36:06 - The EA/Anthropic slow-down play and regulatory capture
- 40:13 - Inside the AI doomer event, Erin's field report
- 44:21 - Peter Thiel and the Antichrist lecture series
- 1:05:19 - BIP-110 retrospective and the bandwidth drain
- 1:15:08 - The number is going up, the weirdest part of all
Sponsors
- Cash App: For a limited time, new customers can get $21 added to their balance. Just use code TFTC10 when you sign up, and send at least $5 to a friend in the first two weeks. cash.app/app/TFTC
- Square: For up to $200 off eligible Square hardware. square.com/go/tftc
- Bitkey: Use code TFTC10 for 10% off the new Bitkey. bitkey.world
- Aven: aven.com/bitcoin
- CrowdHealth: joincrowdhealth.com/tftc
- Simple Mining: simplemining.io/tftc
- Salt of the Earth: drinksote.com/tftc
Frequently Asked Questions
What was the ColdCard entropy bug and why did it matter?
The ColdCard vulnerability was an entropy bug at a foundational level of the device's operation, not a surface implementation flaw but a deep failure in the randomness generation that underpins key security. It mattered because ColdCard was widely considered the most trusted hardware wallet in Bitcoin, meaning a breach there shook assumptions that extended well beyond a single product. The community had treated its "Bitcoin-only" positioning as a proxy for technical rigor; the bug forced a direct confrontation with how hollow that heuristic had become.
What is the Bitcoin Red Team and what are they doing?
The Bitcoin Red Team is a group that emerged in the aftermath of the ColdCard hack and subsequent AI-assisted vulnerability discoveries, organized around the project of proactively stress-testing Bitcoin infrastructure against AI-powered attack vectors. The basic premise is that the attack tools now exist and are accessible, so the productive response is to use them defensively, find the vulnerabilities in your own code before someone else does. Erin and I both referenced the group as one of the genuine silver linings of an ugly stretch.
Is the Hugging Face AI agent incident as scary as it sounds?
Less scary than the viral version, more instructive than the dismissive one. A Lumenscape analysis of the incident found that the agents were operating under the assumption that they were on a synthetic internet, a sandbox, not the real one. Their prompt directed them to attack systems, and they did, following the prompt's logic.
A leak in the sandbox gave them access to the actual internet, and according to that analysis, when they realized the internet was real, they stopped. The incident was a serious implementation failure, a sandbox that leaked into production, but it wasn't evidence of AI developing autonomous hostile intent. It was evidence that if you prompt AI agents to attack things and build a leaky container for them, they will attack things.
What does effective altruism have to do with AI safety and Anthropic?
Anthropic was co-founded by Dario Amodei and others with deep roots in the effective altruism movement, the same intellectual community that produced Sam Bankman-Fried and FTX. The EA framework, maximize utility, accept whatever means are necessary toward sufficient ends, has a track record in the Bitcoin world that informs how I read Anthropic's "slow down AI" push. When Dario, Elon, and Sam Altman all called simultaneously for frontier AI to be paced or licensed, the pattern I see is regulatory-moat construction: use fearmongering to build licensing regimes that only the incumbents can manage to operate within. The stated concern about safety may be genuine for some people involved, but the prescription, centralized control by the people already at the frontier, is exactly what a regulatory-capture operation would look like.
What is BIP-110 and what happened with the fork?
BIP-110 was a proposed Bitcoin protocol change that became a prolonged and contentious debate within the Bitcoin community. The people pushing it eventually forked off onto their own chain rather than achieving adoption on the main chain.
My retrospective take is that the debate consumed far more mental bandwidth than it deserved, I made an explicit decision to address it once, at Bitcoin++ in Austin, and then mostly leave it alone. The fork resolved the thing more cleanly than debate ever would have, and it freed the community's attention for the actual work that needed doing during the AI hack period. The lesson is straightforward: when two sides are completely dug in and neither is moving, stop litigating and let the fork happen.
Can Bitcoin add Zcash-style privacy features?
A paper proposing shielded transactions for Bitcoin, similar to the privacy mechanism Zcash uses, dropped the morning Erin and I recorded this conversation. That's the right direction. Zcash has been drawing capital and attention in part because people want privacy features on their on-chain transactions, and Bitcoin doesn't have them natively.
My position is simple: rather than clamoring about Zcash pumping, go compete. Build it on Bitcoin properly. Erin's framing is that all of crypto is testnet, if a feature genuinely works and people genuinely want it, the answer is to bring it to Bitcoin, not to dismiss it because it first appeared somewhere else.
What is Peter Thiel's Antichrist lecture series about?
Thiel has been running a lecture series, I attended two of four in Austin about two years ago, that argues the real danger of this moment isn't Armageddon or civilizational destruction, but the Antichrist: a fake savior, a centralized authority that promises to protect humanity from some apocalyptic threat and uses that promise to consolidate power. His read, which I find persuasive, is that everyone is going to get distracted by the end-times framing, which is exactly what the EA/AI-safety movement is running, while the actual danger is the false prophet offering salvation through control. There's a Hoover Institution interview with him on this material that I'd recommend tracking down if you can find it.


