What Bitcoin Did
What Bitcoin Did

The Coldcard Disaster: Everything You Need to Know | Lloyd Fournier & Nick Farrow

August 21, 2026

AI Summary

5 min read

In October 2023, roughly 1,200 Bitcoin wallets containing nearly 2,000 Bitcoin were silently compromised. The victims were not careless. They were doing everything right—self-custodying, stacking sats, using what was widely considered the gold standard of hardware wallets: the Coldcard. Then, overnight, their funds were gone. The attacker didn't need physical access, a phishing link, or a supply chain intercept. They just ran an AI model against publicly viewable firmware code and found that the "most secure" hardware wallet on the market had been generating predictable private keys for years.

The Entropy Failure: A Needle in a Very Small Haystack

The root cause was not a sophisticated cryptographic backdoor but a catastrophic failure in how the Coldcard Mark III generated randomness. A hardware wallet's most fundamental job is to produce truly random seed words. Properly done, this means 256 bits of entropy—a search space so vast it's often compared to a needle in a galaxy of haystacks. The Coldcard Mark III, however, was producing seeds with roughly 20 to 40 bits of entropy. As Lloyd Fournier explains, "It's like a needle in a very, very, very large haystack. But if it's the proper 256 bits, it's like a needle in a galaxy." With only 20 bits, the search space is millions of possibilities, not billions of trillions. An attacker could brute-force every possible seed phras

Continue reading the full summary in the app — free to try.

Read Full Summary →

Free • No credit card required

What you'll learn

  • 1 (00:02) **The Human Cost of the Coldcard Disaster** - Lloyd Fournier and Nick Farrow describe the emotional toll on Bitcoiners who did everything right and lost their savings overnight.
  • 2 (01:30) **Initial Discovery and Panic** - Lloyd and Nick recount how they first heard about the vulnerability and their immediate reactions.
  • 3 (03:13) **Why Was This Overlooked for Years?** - The guests analyze how the vulnerability, found by an AI model, escaped human and automated review for so long.
  • 4 (08:05) **The Technical Failure: How Randomness Broke** - The fundamental cryptographic error is explained: a tiny state space for the RNG made the "random" seeds predictable.
  • 5 (11:34) **The Unimaginable: Collisions and Lost Funds** - The discussion turns to real-world cases of seed collisions and the scale of the theft.
  • 6 (19:19) **How Easy Was the Attack to Run?** - The guests explain that the attack was trivial to execute, even for non-experts, likely using an AI model.
  • 7 (22:50) **CoinKite's Arrogance and Missed Warnings** - The hosts criticize CoinKite for ignoring clear warning signs and for focusing on fancy features over fundamental security.

+ Full timestamped outline available in the app

Show Notes

“They’re saving all their money in Bitcoin and they’re doing all the right things. They’re self-custodying it. And then overnight, it’s just gone.”

Frostsnap’s Lloyd Fournier and Nick Farrow join me to break down the catastrophic Coldcard vulnerability that made supposedly secure Bitcoin keys guessable and allowed attackers to drain more than 1,700 BTC without ever touching the devices.

We discuss how a five-year failure in Coldcard’s randomness generation went undetected, why every safeguard failed and the role AI played in discovering and exploiting the bug. Nick also explains how he reproduced the attack himself, what the on-chain evidence reveals about the attackers and why this has shaken trust in Bitcoin self-custody.

We also get into whether hardware wallets are really trusted third parties, the limitations of dice rolls and air gaps, how Dark Skippy can leak a seed through a single transaction and why single-signature custody may need to change.

Finally, Lloyd and Nick explain how Frostsnap uses distributed key generation and threshold signatures to remove single points of failure, simplify recovery and secure Bitcoin across multiple locations.

THANKS TO OUR SPONSORS:

LEDN

SWAN

ANCHORWATCH

BLOCKWARE

BITKEY

CAPE

FOLLOW:

Danny Knowles: https://x.com/_DannyKnowles

Lloyd Fournier: https://x.com/LLFOURN

Nick Farrow: https://x.com/utxoclub

What Bitcoin Did

More from this podcast

What Bitcoin Did →