The Coldcard Scandal Rocking Self-Custody
What a week in bitcoin!
So one of the most arrogant companies in the self-custody industry recently saw over $100 million in bitcoin from their customers get stolen off their devices. When you setup a cold wallet from an extremely reputable wallet provider, a few things can happen. You can either let the wallet generate your seed for you, which is fine if the wallet uses high entropy to do that, or you can create your own entropy and import that wallet into the device.
I’m not going to get too into the weeds about entropy and the random number generation that runs on firmware chips to create a highly secure wallet for you. I estimate that most of my subscriber base doesn’t care about that and it’s quite technical. The bottom line is that coldcard was creating extremely weak wallets that AI was able to steal from….and it did.
The interesting part here is that coldcard despite how this reads as simple incompetence, may have actually been behind the losses in a more sinister way. And when I say sinister, I mean maybe even directly responsible and may even be stealing the funds themselves.
Let’s look at that for a moment:
Grok was less than impressed at the idea of “odds”
From what I’ve been following since the mayhem began, this just looks truly diabolical. This was a company that was often quoted as saying “Trust, but verify.” After the Ledger debacle a few years back when they launched the backup solution where the device exports your seed words to two other random entities so you can restore it if you lose your seed words (subscription model), many people went to Coldcard, who used that as a massive sales campaign. To be fair though, so did many other wallet providers.
That’s also why I got off Ledger years and years ago as well. In an almost immediately deleted tweet they discuss this in an almost arrogant way. My own funds were off that thing the next day. Since then, they’ve had numerous customer data breaches exposing their customers names and addresses. I’ve read stories of these same customers having their homes broken into and having their crypto assets stolen at gun point. This is why I’ve also discussed the idea of “stealth wealth” in our courses along with more legal infrastructure to protect you.
They of course deleted this
Furthermore the ledger CEO and his wife were recently kidnapped in Paris a little while back along with being tortured. He’s still missing a finger to this day. If you don’t even take your own security seriously, why should people trust you with holding their assets on your device?
But this isn’t about Ledger, it’s about Coldcard.
As of right now, this is the single most significant thing to ever happen to bitcoin self-custody since it’s inception. And when the companies that make these security solutions may end up being the actual criminals, purposely putting malicious code into their devices to steal from you later, we’ve got a serious problem.
And what’s the topping on the cake of this figurative shit sandwich? The emergency hotfix that Coldcard released after this exploit may actually brick user’s devices. I think they’re just trying to give plausible deniability at this point if the time comes they’re ever in a court room and have to testify to a jury.
I think it’s safe to say that company is over and they were never big enough to sue for lost funds. But the customer base should still keep their devices, record their losses, and hold onto them if somehow a class action lawsuit ever emerges from this like in the case of Mt Gox.
So what about Trezor? Every aspect of Trezor’s code, on every single piece of hardware that holds any, is totally open source. It can be audited by anyone at anytime, and it is. Even the firmware, where your RNG seed to secure your wallet is created, is open source and bug bounties for third party developers are always in effect. Furthermore, they’ve created a new standard called SLIP 39 which allows you to create what’s called Shamir Multishares.
I’ll be adding some more content about that in our Self-Custody course sometime soon, but this is where you can create multiple wallets and create a threshold for restoring them. For example, you can create 3 multishare wallets but only need the 20 words for two of them to restore your funds. This is great because you can create these and then spread them out geographically around your city, state, or country. The sky is the literal limit here. For this to be even more secure, the initial seed your trezor generated when you first set it up should be destroyed after verifying the new wallets.
Luckily Trezor is very aware of how important entropy is and they’ve said it online discussions and videos, but this is one of the major threat vectors with AI. It was able to do what it did because the bug was literally making seed words easy to guess. A wallet with high entropy is going to create either 128 or 256bit private addresses. Coldcard was generating 32-40 bit. Just enough that people weren’t generating the same wallets others had, but hardly enough not be able to be brute forced and stolen from.
On the new Trezor safe 7 it pulls entropy from four different sources to make it absolutely as random as possible. Nobody using a trezor is at risk from this Coldcard attack.