1
00:00:00,000 --> 00:00:17,420
Welcome in to This Week in Bitcoin, episode 116.

2
00:00:17,740 --> 00:00:22,580
My name is Chris, chrislas.com, jupiterbroadcasting.com.

3
00:00:22,580 --> 00:00:26,980
Well, I'm breaking the release cycle because we have a bit of an urgent issue for cold

4
00:00:26,980 --> 00:00:33,680
card wallet users, particularly Mark 3 cold card users, but it could be affecting 4 and

5
00:00:33,680 --> 00:00:39,080
possibly even the Q. This all started seemingly when a Reddit user reported that a long dormant

6
00:00:39,080 --> 00:00:44,440
wallet was suddenly drained. The seed was reportedly generated using a cold card purchased in 2021.

7
00:00:45,180 --> 00:00:48,860
The user said the seed was written down, never photographed, and never entered into a computer.

8
00:00:49,660 --> 00:00:54,160
In January 2025, they restored that seed onto another cold card to verify the backup and create

9
00:00:54,160 --> 00:01:00,080
a watch-only setup. More Bitcoin was then deposited on April and May of 2026, and then the wallet was

10
00:01:00,080 --> 00:01:07,140
completely drained on July 30th. At first, it just seemed like, well, this is probably no big deal.

11
00:01:07,200 --> 00:01:12,000
This is something specific to this user, their setup, something like that. But then just a couple

12
00:01:12,000 --> 00:01:19,060
of hours ago, CoinKite released a pretty serious security advisory for Mark III wallet users.

13
00:01:19,660 --> 00:01:23,300
And I'll read a little bit of this for you. They say, out of an abundance of caution,

14
00:01:23,300 --> 00:01:28,980
CoinKite is warning all users who generated a seed using the Mark III on version 401 in March

15
00:01:28,980 --> 00:01:36,1000
of 2021, or any subsequent version, their funds may be at a risk. Now, they write here Mark IV,

16
00:01:37,160 --> 00:01:41,880
Q, and Mark V are not affected based on early analysis of the issue. However, that may not be

17
00:01:41,880 --> 00:01:48,060
true, so stay tuned for that. They note that the investigation is ongoing, and it is an early

18
00:01:48,060 --> 00:01:53,900
analysis. They say if the affected at Mark III seed was used in a BIP39 passphrase, our early

19
00:01:53,900 --> 00:01:59,020
analysis indicates that your funds are at a minimal risk from this issue. This means the BIP39

20
00:01:59,020 --> 00:02:06,400
passphrase is not a cold card pin. So to be clear here, what's happened is attackers using AI tools

21
00:02:06,400 --> 00:02:12,180
have begun generating less than random seed phrases that are getting access to people's funds. They

22
00:02:12,180 --> 00:02:17,100
never need to get access to your computer. They never need access to your cold card. If using the

23
00:02:17,100 --> 00:02:23,300
Mark III, you use the random generator built into the Mark III, you are, well, implicitly

24
00:02:23,300 --> 00:02:31,140
vulnerable to this issue. This issue also seems to be, potentially, if you didn't use a passphrase

25
00:02:31,140 --> 00:02:35,140
with that, and if you didn't use proper dice rolling techniques, each one of those increases

26
00:02:35,140 --> 00:02:41,980
your risk to exposure to this issue. So this is where we're at right now. If you have a cold card,

27
00:02:42,080 --> 00:02:45,840
you probably want to consider moving your funds, even if it's a cold card four. I'll tell you more

28
00:02:45,840 --> 00:02:50,780
on that in a moment. It is a developing situation. Don't panic. But you should, out of abundance of

29
00:02:50,780 --> 00:02:55,500
caution as a cold card user, consider moving your funds. Bugs have been found that are being

30
00:02:55,500 --> 00:03:01,700
exploited actively right now in the AI. People are actively losing their funds. At this juncture,

31
00:03:01,700 --> 00:03:09,760
I would migrate funds off any single SIG or a weak multi-SIG if you're using cold card wallets

32
00:03:09,760 --> 00:03:22,448
and you generated on device without dice or a passphrase If that you you are in the risk zone right now The issue appears to remain present through version 5 of the final Mark III version firmware

33
00:03:22,448 --> 00:03:27,128
and something I would consider for the Mark IV as well.

34
00:03:27,228 --> 00:03:28,948
So here's some information we have.

35
00:03:30,728 --> 00:03:33,948
Bitcoinnews.com is covering Instagibs,

36
00:03:34,028 --> 00:03:36,688
a developer who tweeted this.

37
00:03:36,768 --> 00:03:38,428
Sorry, this is the time to panic.

38
00:03:38,428 --> 00:03:43,168
cold card mark 2 and mark 3 vulnerability the bitcoin core developer instagib says that he

39
00:03:43,168 --> 00:03:47,688
successfully reproduced the reported cold card vulnerability on a freshly initialized mark 3

40
00:03:47,688 --> 00:03:52,528
device using only the number of a button presses made during setup adding sorry quote this is the

41
00:03:52,528 --> 00:03:57,188
time to panic he adds he believes this issue affects mark 2 and mark 3 devices but says he

42
00:03:57,188 --> 00:04:06,108
cannot confirm whether mark 4 is vulnerable all right so that's pretty serious again you know

43
00:04:06,108 --> 00:04:10,788
steady is the method here, but I'm out of abundance of caution, even though I don't have

44
00:04:10,788 --> 00:04:18,328
Mark 3s moving my funds. Nick Newman posted on X, it sounds like the Mark 4 Q and Mark 5 are also

45
00:04:18,328 --> 00:04:23,168
vulnerable, but in a different way than the Mark 3. Slightly less problematic than the Mark 3,

46
00:04:23,308 --> 00:04:28,028
but still not great to keep using. If you're using a single SIG cold card at the moment,

47
00:04:28,248 --> 00:04:33,408
you should move assets to a different wallet, multi-SIG, exchange, other hardware to be safe.

48
00:04:33,408 --> 00:04:40,908
And that is how serious this is, is people are even recommending going to an exchange temporarily if you have one of these setups.

49
00:04:42,588 --> 00:04:48,508
Zero Knowledge posted at 5.41 p.m. Pacific time on July 30th.

50
00:04:48,508 --> 00:04:52,388
Mark 4s are vulnerable but millions of times harder to steal from.

51
00:04:52,868 --> 00:04:55,168
Mark 3s can be stolen from a decent laptop.

52
00:04:55,808 --> 00:04:58,308
Mark 4s, 5s, and Qs would need much more compute.

53
00:04:59,008 --> 00:04:59,628
Here's the model.

54
00:05:00,308 --> 00:05:05,308
The attacker has roughly 2 to the 20th UUID range that it knows cold cards fall within.

55
00:05:05,828 --> 00:05:11,788
It checks a 16-button press variancer in user behavior before generating the seed.

56
00:05:12,728 --> 00:05:17,088
He recommends you still promptly remove funds from Mark IV, Mark V, and Q cards.

57
00:05:17,828 --> 00:05:23,828
So in other words, the situation is significantly harder with the Mark IV and the Mark V in the Q.

58
00:05:23,828 --> 00:05:29,468
but with the advances in model technology it probably makes sense to start planning for this

59
00:05:29,468 --> 00:05:38,328
right now not the news i wanted to come back from my break and tell you about so if you generated a

60
00:05:38,328 --> 00:05:45,128
seed a seed phrase and a wallet using a mark 3 you are in the target zone if you're in the mark 4 or

61
00:05:45,128 --> 00:05:51,388
5 or q category you're in the risk zone so i say take it easy slow and steady is the mode don't rush

62
00:05:51,388 --> 00:05:57,328
this and don't dox yourself if you don't need to. And remember the Liquid Network and Blockstream

63
00:05:57,328 --> 00:06:02,528
Block are your friends. So far, there does not appear to be an issue with the Jade or the Bitbox.

64
00:06:02,828 --> 00:06:09,428
Those are also really great hardware wallets. And I think to make it clear to you, this is

65
00:06:09,428 --> 00:06:15,528
independent of if you've used your cold card or used your computer or whatever. This is based on

66
00:06:15,528 --> 00:06:20,808
how the seed phrase was generated, which can be predicted by some of these AI tools. It also

67
00:06:20,808 --> 00:06:21,808
It also reminds us

68
00:06:21,808 --> 00:06:25,728
key generation and key isolation

69
00:06:25,728 --> 00:06:37,396
are two separate things Keeping your private key safe and private is not the same thing as generating it safely It also reminds us that firmware and provenance matters years later

70
00:06:37,876 --> 00:06:38,616
These are wallets.

71
00:06:38,796 --> 00:06:41,016
Some of these that were created in 2021

72
00:06:41,016 --> 00:06:43,176
are now vulnerable in 2026.

73
00:06:43,536 --> 00:06:46,836
And I suspect this is going to be a growing problem.

74
00:06:47,256 --> 00:06:48,096
Here's my thinking.

75
00:06:49,276 --> 00:06:51,736
Multi-vendor, multi-sig is the way

76
00:06:51,736 --> 00:06:53,136
of self-custody for the future.

77
00:06:53,136 --> 00:06:56,056
I think this is going to be just the start.

78
00:06:57,156 --> 00:07:02,556
Cold card is a big target, but there's a lot of incentives to go after Bitcoin wallets in general.

79
00:07:03,336 --> 00:07:11,356
And with AI cybersecurity tooling getting better and better, there's going to be real incentive to focus on Bitcoin because you can get real money.

80
00:07:12,876 --> 00:07:23,116
And I think the plebs that are serious about self-custody, you're going to have to consider multiple hardware vendors, like a Bitbox, like a Jade, and maybe a Q or something like that in a chain like that.

81
00:07:23,136 --> 00:07:29,936
so we have a bit of um picture of the impact so far it's not just theoretical like i mentioned

82
00:07:29,936 --> 00:07:34,216
earlier this is in the wild and people are unfortunately losing a significant amount of

83
00:07:34,216 --> 00:07:40,696
bitcoin due to this and you hate to see it but here's what i know so far rob hamilton posted at

84
00:07:40,696 --> 00:07:48,736
11 30 a.m on july 30th i've oh and i should mention that rob for those that don't know works

85
00:07:48,736 --> 00:07:55,516
at anchor watch uh i have conducted some preliminary analysis of the uh 600 bitcoin

86
00:07:55,516 --> 00:08:04,296
which have moved in a 15 minute period this morning what we know 1 324 utxos were swept

87
00:08:04,296 --> 00:08:12,376
across 500 transactions all within a three block window from these 562 bitcoin was swept again to

88
00:08:12,376 --> 00:08:20,796
a new address which has not moved since. The UTXOs that were swept spanned from 2021 to 2026.

89
00:08:21,696 --> 00:08:28,056
And here's the big one that Rob shares. 100% of the addresses swept were single SIG. None of the

90
00:08:28,056 --> 00:08:33,356
addresses were stolen from Taproot. At a glance, this looks like there was a flaw in an entropy

91
00:08:33,356 --> 00:08:38,936
wallet generation somewhere along the way. Now, Rob posted that before we knew about the CoinKite

92
00:08:38,936 --> 00:08:46,936
situation. It looks like an ocean wallet also may have gotten drained. And then Gary, Gary Garrett,

93
00:08:47,396 --> 00:08:52,596
or I'm sorry, Clay. Sorry, it's live, guys. I'm just doing this live. But he works at Blox as an

94
00:08:52,596 --> 00:08:58,696
engineering lead for BitKey. So Clay Garrett, sorry, Clay. He also added to this, and I think

95
00:08:58,696 --> 00:09:06,236
this is important to note. Blox engineering and security team found another set of transactions

96
00:09:06,236 --> 00:09:08,076
that could be part of the cold card drain.

97
00:09:08,616 --> 00:09:10,276
We're still looking to vet these completely,

98
00:09:10,696 --> 00:09:11,776
but given the situation,

99
00:09:11,856 --> 00:09:13,796
we feel it's important to share early.

100
00:09:14,336 --> 00:09:16,856
There are 695 earlier transactions

101
00:09:16,856 --> 00:09:18,276
with the same full fingerprint

102
00:09:18,276 --> 00:09:19,896
that transactions of the known set had.

103
00:09:20,256 --> 00:09:23,916
These transactions moved another 488.1 Bitcoin.

104
00:09:24,516 --> 00:09:25,536
If this is part of the same attack,

105
00:09:25,536 --> 00:09:30,436
it brings the total to 1,082,500,

106
00:09:30,696 --> 00:09:31,896
and well, it's a lot of Bitcoin.

107
00:09:32,776 --> 00:09:33,896
Let me see if I can find, oh, I'm sorry.

108
00:09:33,956 --> 00:09:34,696
Nope, not that much.

109
00:09:35,156 --> 00:09:36,116
The decimal point's right here.

110
00:09:36,256 --> 00:09:37,456
1,082 Bitcoin.

111
00:09:37,556 --> 00:09:38,836
That's a lot of Bitcoin, actually.

112
00:09:39,716 --> 00:09:54,404
Wow that a treasury company right there They moved a treasury company There were 500 sweeps into this collector across blocks 960188 and 960191 And he has a mempool space link for this I put a link to this in the

113
00:09:54,404 --> 00:09:58,625
show notes too if you want to go through this on your own. He continues through multiple posts

114
00:09:58,625 --> 00:10:07,044
detailing the multiple sweeps. He says, we scanned all 888,661 transactions in block 96050

115
00:10:07,044 --> 00:10:09,125
through block 960, 230.

116
00:10:09,644 --> 00:10:11,044
Each match in the original wave

117
00:10:11,044 --> 00:10:12,125
had these shared properties.

118
00:10:12,304 --> 00:10:13,865
Version 2, lock time 0,

119
00:10:14,345 --> 00:10:15,804
final sequence on every input,

120
00:10:15,924 --> 00:10:17,024
one output and inputs

121
00:10:17,024 --> 00:10:18,865
from one source address,

122
00:10:19,944 --> 00:10:22,064
a PTW PKH hash destination,

123
00:10:22,345 --> 00:10:24,264
one homogenous supported input type,

124
00:10:24,365 --> 00:10:25,544
and a 30SAT, whoa,

125
00:10:26,564 --> 00:10:28,004
V-byte pre-signing fee estimate.

126
00:10:29,524 --> 00:10:31,404
Hmm, they overspent on that.

127
00:10:32,044 --> 00:10:33,424
Again, these patterns here are strong,

128
00:10:33,485 --> 00:10:34,324
but we have not confirmed

129
00:10:34,324 --> 00:10:35,764
that they are related to the drain.

130
00:10:35,764 --> 00:10:40,965
please reach out if you spot anything and he posted that as of an hour ago as i go live

131
00:10:40,965 --> 00:10:47,064
so um over a thousand bitcoin so far

132
00:10:47,064 --> 00:10:57,904
and essentially a treasury worth a dat worth of bitcoin uh it's serious and so i i i guess i have

133
00:10:57,904 --> 00:11:00,985
to recommend that you move your coins even though i don't want you to do it in a panic and i don't

134
00:11:00,985 --> 00:11:05,664
want you to have to dox yourself if you've been able to avoid that so far. So be considerate.

135
00:11:06,105 --> 00:11:09,564
If you have a Mark IV, you probably have a little bit of time, but probably don't want to wait too

136
00:11:09,564 --> 00:11:14,304
long because now that this is known, this is only going to accelerate. So that's why I wanted to get

137
00:11:14,304 --> 00:11:19,365
on here early and let you know. Just a short show, no boosts, no updates, nothing like that. I just

138
00:11:19,365 --> 00:11:23,444
wanted to get this message out there so you guys know what's going on. I should get out of here,

139
00:11:23,644 --> 00:11:27,504
but that's the update for me. If I have anything else significant, I'll try to break in. Otherwise,

140
00:11:27,504 --> 00:11:31,304
I'll give you a complete update with everything I do know and anything else that's developed

141
00:11:31,304 --> 00:11:36,004
on Wednesday's regular episode. But I do appreciate the support. If you would like to

142
00:11:36,004 --> 00:11:41,444
support this here emergency pod, as they say, or keep the show going, boost.jupiterbroadcasting.com.

143
00:11:41,544 --> 00:11:47,164
I think we're kind of in a summer lull looking back over the summer episodes. So this could be

144
00:11:47,164 --> 00:11:51,625
a good chance to step up and make episode 117 a banger. Thanks for joining me and I'll see you then.

145
00:11:57,505 --> 00:12:27,485
Thank you.

146
00:12:27,505 --> 00:12:57,485
Thank you.

147
00:12:57,504 --> 00:12:58,004
you
