Aug 6, 2026 · 56 min · 13 segments
Bitcoin's most paranoid hardware wallet — air-gapped, 9-volt-powered, "don't trust, verify" — shipped a broken random number generator for five years, and last Thursday somebody's AI finally noticed…
So somebody basically just took a, you know, KimiK3 and said, like, "Go look at a bunch of s- uh, you know, like, open source crypto repos, find me a vulnerability, and make me a millionaire.
Don't make any mistakes."
[laughs]
And they found this vulnerability and did it, and they stole, like, thousands of Bitcoin from people because the model was like, "Holy crap, like, these aren't...
This randomness is broken.
We can basically guess, or we can, like, brute force all of the seed phrases for every single ColdCard user, which means we can have their wallet seed, which means we can load their wallet and spend their funds and take their funds and take them for ourselves." I, I, I can't answer that question.
I haven't looked at it.
I mean, I think Chris is right.
Um, you know, like FTX was, like, bad, but it was like, you know, okay, you play custodial games, then custodial things can happen.
That's kind of like...
It didn't compromise, like, the ethos of Bitcoin and crypto in the way that this is just like a shot across the bow of, like, you can literally do everything right, and it can just go so catastrophically wrong because, you know, uh, there are even extremely technical people that relied on ColdCard because, like, n- people, people looked through the code, and they couldn't catch this.
Nobody could catch it until these amazing models came through.
And yeah, I mean...
Read the full transcript.
Create an account to read the whole episode, search across every transcript, and follow the shows you care about.
So somebody basically just took a, you know, KimiK3 and said, like, "Go look at a bunch of s- uh, you know, like, open source crypto repos, find me a vulnerability, and make me a millionaire.
Don't make any mistakes."
[laughs]
And they found this vulnerability and did it, and they stole, like, thousands of Bitcoin from people because the model was like, "Holy crap, like, these aren't...
This randomness is broken.
We can basically guess, or we can, like, brute force all of the seed phrases for every single ColdCard user, which means we can have their wallet seed, which means we can load their wallet and spend their funds and take their funds and take them for ourselves." I, I, I can't answer that question.
I haven't looked at it.
I mean, I think Chris is right.
Um, you know, like FTX was, like, bad, but it was like, you know, okay, you play custodial games, then custodial things can happen.
That's kind of like...
It didn't compromise, like, the ethos of Bitcoin and crypto in the way that this is just like a shot across the bow of, like, you can literally do everything right, and it can just go so catastrophically wrong because, you know, uh, there are even extremely technical people that relied on ColdCard because, like, n- people, people looked through the code, and they couldn't catch this.
Nobody could catch it until these amazing models came through.
And yeah, I mean...