Episode notes
“They’re saving all their money in Bitcoin and they’re doing all the right things. They’re self-custodying it. And then overnight, it’s just gone.”
Frostsnap’s Lloyd Fournier and Nick Farrow join me to break down the catastrophic Coldcard vulnerability that made supposedly secure Bitcoin keys guessable and allowed attackers to drain more than 1,700 BTC without ever touching the devices.
We discuss how a five-year failure in Coldcard’s randomness generation went undetected, why every safeguard failed and the role AI played in discovering and exploiting the bug. Nick also explains how he reproduced the attack himself, what the on-chain evidence reveals about the attackers and why this has shaken trust in Bitcoin self-custody.
We also get into whether hardware wallets are really trusted third parties, the limitations of dice rolls and air gaps, how Dark Skippy can leak a seed through a single transaction and why single-signature custody may need to change.
Finally, Lloyd and Nick explain how Frostsnap uses distributed key generation and threshold signatures to remove single points of failure, simplify recovery and secure Bitcoin across multiple locations.
THANKS TO OUR SPONSORS:
FOLLOW:
Danny Knowles: https://x.com/_DannyKnowles
Lloyd Fournier: https://x.com/LLFOURN
Nick Farrow: https://x.com/utxoclub