HomeVideos

The safest way to store Bitcoin was just hacked...

Now Playing

The safest way to store Bitcoin was just hacked...

Transcript

162 segments

0:00

As if last year hasn't been hard enough

0:01

on the hodlers, last week what used to

0:03

be the safest way to store Bitcoin

0:05

turned out to be the fastest way to lose

0:07

it when Coldcard, a security-obsessed

0:09

air-gapped Bitcoin hardware wallet, was

0:11

hacked. The bad news is that a lot of

0:13

people lost a lot of money, but the good

0:15

news is that it's only about half as

0:17

much as they would have lost if the same

0:18

thing happened a year ago. Since July

0:20

30th, attackers have drained over 1,600

0:22

Bitcoin, worth about $100 million,

0:25

from over 7,000 wallets. And the

0:27

craziest part is that they pulled it off

0:28

without any malware, phishing, or lead

0:30

pipes. The victims weren't your typical

0:32

degenerates clicking random Discord

0:34

links, either. They were the responsible

0:36

ones with the not your keys, not your

0:38

crypto tattoos lecturing you about how

0:40

you don't actually deserve freedom if

0:42

your coins were on an exchange. In

0:44

today's video, we'll dive into how the

0:45

hack works and learn why victims are now

0:47

bidding against the hackers in real time

0:49

to try to buy back their own money. It

0:51

is August 5th, 2026, and you're watching

0:54

The Code Report. If you've never seen

0:55

your net worth drop 60% in a day, you

0:57

may not know that the way Bitcoin works

0:59

is that your coins are controlled by a

1:01

private key, which comes from a 12-word

1:03

seed phrase. If you have those words,

1:05

you have the Bitcoin. And since the

1:06

entire security model depends on those

1:08

words being unguessable, they're chosen

1:10

by your wallet using a random number

1:12

generator. A properly generated seed

1:14

phrase has 128 bits of entropy, which

1:17

means if you try a billion guesses per

1:18

second, the universe would end before

1:20

you got close. And this principle is

1:22

exactly why hardware wallets exist in

1:24

the first place, to generate keys on a

1:26

dedicated offline device with a special

1:28

chip whose entire job is to harvest

1:30

genuine randomness from the physical

1:32

universe. And no device took this more

1:34

seriously than Coldcard, made by

1:36

Canadian company Coinkite. It's

1:38

air-gapped, open source, and marketed to

1:40

people who are worried the government is

1:42

going to make you get a license to make

1:44

toast in your own damn toaster. But it

1:46

doesn't matter how sophisticated your

1:47

random number generator is if you never

1:49

actually use it. And for the last 5

1:51

years, without them knowing, the

1:52

Coldcard never did. Here's how it

1:54

happened. The Coldcard's firmware runs

1:56

on MicroPython, which ships its own

1:58

basic random number generator, which was

2:00

built for simple jobs, but it's nowhere

2:02

strong enough for generating keys. The

2:04

Coinkite knew this, so they wrote their

2:06

own generator, and by setting a specific

2:08

flag to zero, they disabled

2:10

MicroPython's generator, or at least

2:12

that's what they thought. But here's

2:13

where things went wrong. Both number

2:15

generators exposed a function with the

2:17

exact same name, and the crypto library

2:19

would decide which one to use based on

2:21

an if not defined check. And because the

2:23

flag was technically defined just as a

2:25

zero, the check passed, and every seed

2:27

phrase was generated by the basic

2:29

MicroPython number generator, not

2:31

Coldcard's sophisticated generator. But

2:33

it turns out, because a bare metal chip

2:35

has no operating system, there's nowhere

2:37

for MicroPython's number generator to

2:39

get real randomness from. And so

2:41

instead, it fakes it using the chip's

2:43

serial number and a timer, both of which

2:45

are deterministic. So instead of

2:47

guessing a seed phrase out of every atom

2:48

in the universe, you could just loop

2:50

through all possible combinations of

2:52

serial numbers and timer values, and

2:54

come away with everyone's keys. And on

2:56

July 30th, that's exactly what the

2:58

attacker did. In under an hour, the

3:00

first attacker drained over 1,000

3:01

Bitcoin from nearly 1,200 addresses,

3:04

hitting the biggest wallets first. Then

3:06

two more attacks happened over the

3:07

weekend, which pushed the total to

3:09

nearly 1,800 Bitcoin from over 7,000

3:11

addresses. The Coinkite CEO apologized

3:14

and took full accountability, but by the

3:16

nature of the attack, they couldn't just

3:18

issue a firmware update to solve the

3:19

problem. Because Bitcoin has no way to

3:21

rotate a key, the only way out is for

3:23

victims to generate a brand new seed and

3:25

move their coins with an actual on-chain

3:27

transaction. But of course, because this

3:29

is Bitcoin, every transaction waits in

3:32

the public mempool until a miner

3:33

includes it in a block, which means the

3:35

attacker can just watch the mempool for

3:37

anything coming from a compromised

3:39

address. They can then sign their own

3:40

competing transaction with the same keys

3:43

and a higher fee, and miners will

3:44

confirm the highest bidder first. So

3:46

when a fourth attack went live on Monday

3:48

morning, the only way to win was to skip

3:50

the public mempool entirely and send

3:52

your rescue transaction directly to a

3:54

mining pool since the bot can't outbid a

3:56

transaction it never sees. So, yeah, the

3:59

official rescue plan for your trustless

4:01

decentralized money was to put all your

4:03

trust in one centralized miner and hope

4:05

for the best. As for Coldcard, every

4:07

unsold device in their warehouse carried

4:09

the same broken firmware and so they had

4:11

to hold shipments and take the remaining

4:12

inventory out to the pasture. But, all

4:14

of this could have been avoided had they

4:16

just built their product with Lovable,

4:18

the sponsor of today's video. Lately,

4:20

I've been wanting to make the world a

4:21

better place, so I use Lovable's AI

4:23

development platform to build my own

4:25

predictions market, which lets you

4:26

gamble away your life savings on things

4:28

like future video topics or how many

4:30

scam Altman jokes I'll make this month.

4:32

I started with plan mode where Lovable

4:34

mapped out the flow and let me edit the

4:36

plan before writing any code. Then, it

4:38

built the whole thing including auth,

4:40

payments, and a managed Postgres

4:42

database on Lovable Cloud. It did get

4:44

stuck in a loop on a database policy

4:46

bug, but then I moved back into plan

4:47

mode and Lovable was able to fix it on

4:49

its own. Then, I gave the app its own

4:51

MCP server so that right here in Cload

4:53

Code, I can pull live odds or hold

4:56

trading whenever I'm losing a bet to

4:57

make sure the house always wins. Over 50

4:59

million projects have already been built

5:01

with Lovable and you can try it out for

5:03

free today with the link below. This has

5:04

been The Code Report. Thanks for

5:06

watching and I will see you in the next

5:07

one.

Interactive Summary

Loading summary...