1
00:00:00,000 --> 00:00:09,460
rob hamilton damn man crazy crazy 24 hours we have a legitimate emergency in bitcoin um what's

2
00:00:09,460 --> 00:00:14,760
been going on um i in the spirit of emergency i'm just going to start this with if you

3
00:00:14,760 --> 00:00:25,800
or anyone you know has used a cold card mk3 mk4 mk5 q any of those devices with any

4
00:00:25,800 --> 00:00:30,640
wallets that were generated from the device you clicked give me some seed words

5
00:00:30,640 --> 00:00:40,580
um you need to immediately stop what you're doing and contact friends this is a canceling of

6
00:00:40,580 --> 00:00:47,440
weekend plans this is getting on planes for any ability for you to be able to recover your bitcoin

7
00:00:47,440 --> 00:00:54,980
this is uh as about as code red as it can get for bitcoin self-custody as it relates to the

8
00:00:54,980 --> 00:01:01,220
urgency in which you need to act um i will go more into the details with that urgency i want to

9
00:01:01,220 --> 00:01:08,360
caution um slow is smooth and smooth is fast so you need to act very decisively and you need to

10
00:01:08,360 --> 00:01:14,320
be able to act deliberately you should reach out to your friend networks and people that can help

11
00:01:14,320 --> 00:01:21,700
you support um any questions you may have but time is of the essence right now so maybe we should

12
00:01:21,700 --> 00:01:26,600
just start with what happened um because i first stop your podcast if you have to like you need to

13
00:01:26,600 --> 00:01:32,880
stop like you but yeah this is not going now this is not a drill continue um and so i obviously first

14
00:01:32,880 --> 00:01:38,240
saw this pop up on twitter yesterday um i actually had a cold card mark four that was using as almost

15
00:01:38,240 --> 00:01:41,760
like a spending wallet but the amount in there had got to a point where i was like very uncomfortable

16
00:01:41,760 --> 00:01:46,400
as soon as i saw this news i text you being like i've seen this thing with the mark three is overblown

17
00:01:46,400 --> 00:01:50,900
or do i need to do something and again you were like this is not a drill you need to do something

18
00:01:50,900 --> 00:01:55,980
now i wasn't with my wallet managed to managed to sort that out but this is like a serious product

19
00:01:55,980 --> 00:02:00,100
a serious problem that's impacting a ton of people um where did it all start

20
00:02:00,100 --> 00:02:09,640
so uh in early of 2021 there was a change to the cold card firmware as it relates to the

21
00:02:09,640 --> 00:02:18,200
entropy that gets created and that is when a bug was introduced now uh since i will take a moment to

22
00:02:18,200 --> 00:02:26,280
explain the nature of the problem um if you had uh an ear-gapped wallet never talked to the internet

23
00:02:26,280 --> 00:02:35,680
it doesn't matter the things that would save you if you were using a cold card mk3 mk4 mk5 and q

24
00:02:35,680 --> 00:02:47,180
is if you have a sufficiently strong 25th word passphrase if you also rolled dice or provided

25
00:02:47,180 --> 00:02:52,680
your own entropy from outside of the cold card the nature of this bug is that when you turn on

26
00:02:52,680 --> 00:02:57,500
a cold card and you have a clean device and you say this is amazing can you please give me

27
00:02:57,500 --> 00:03:05,240
some seed words those are not secure so i want to be everything else needs to go down yeah

28
00:03:05,240 --> 00:03:09,860
i just want to be really clear so that we don't miss anyone here you obviously said mark three

29
00:03:09,860 --> 00:03:15,340
four or five or q what about the mark one or two if they were on updated firmware and they still

30
00:03:15,340 --> 00:03:20,860
generate those keys after 21 uh to my understanding the mk2 is not supported in any of the impacted

31
00:03:20,860 --> 00:03:25,720
firmware okay i'd have to go double check but the mk if you have an mk1 and mk2 technically

32
00:03:25,720 --> 00:03:32,660
the firmware bug that we're talking about has not been introduced um because that is long end of life

33
00:03:32,660 --> 00:03:39,200
hardware there aren't updates for that really anymore um and so if you have an mk2 or mk1 you

34
00:03:39,200 --> 00:03:43,720
should not be impacted by this okay and then i think we should also be really clear on the pass

35
00:03:43,720 --> 00:03:50,020
phrase because that's essentially a 25th word um at this point that's the only word really keeping

36
00:03:50,020 --> 00:03:56,720
your bitcoin secure is that right if you really only used one word that is right which means you

37
00:03:56,720 --> 00:04:04,100
are not secure you have to assume with what we're discussing right now is that many attackers not

38
00:04:04,100 --> 00:04:10,600
just one person there are many attackers right now who are scanning to get the entire table of all

39
00:04:10,600 --> 00:04:16,060
possible seed phrases a cold card could generate whether it was 12 words or 24 words and they are

40
00:04:16,060 --> 00:04:21,120
sitting on all of those words and they are taking all of the low-hanging fruit of single signature

41
00:04:21,120 --> 00:04:25,700
keys my assumption is they're going to move on to other things but we'll get to that yes

42
00:04:25,700 --> 00:04:31,580
and and so the passphrase is is the only thing keeping it secure if you've done that you should

43
00:04:31,580 --> 00:04:35,620
still probably move funds would you agree absolutely uh especially if it's one word so

44
00:04:35,620 --> 00:04:46,060
like a one word password is not strong um there are different uh perspectives on exactly how to

45
00:04:46,060 --> 00:04:51,680
mitigate this rather than if you're in the zone where you're kind of debating am i safe or not

46
00:04:51,680 --> 00:04:57,500
you just need to stop what you're doing and uh recover your bitcoin before it gets stolen

47
00:04:57,500 --> 00:05:02,460
um in theory if you had 12 like 12 random words that you added on top of that

48
00:05:02,460 --> 00:05:19,696
Okay like you in a better spot but now your entire security model was oh an attacker needs my seed words and my passphrase And the seed phrase is now known by multiple actors at this point or will be imminently over the coming couple of days

49
00:05:19,816 --> 00:05:20,796
if not like maybe a week.

50
00:05:20,996 --> 00:05:23,636
But honestly, this is something that you need to move as fast as possible.

51
00:05:24,496 --> 00:05:27,196
So the only way you're secure is if you create your own entropy

52
00:05:27,196 --> 00:05:29,856
and doing that obviously comes with its own risk

53
00:05:29,856 --> 00:05:31,636
that you have to do that very carefully, very consciously.

54
00:05:32,776 --> 00:05:36,116
Is it kind of to the point where if you're using a cold card device,

55
00:05:36,216 --> 00:05:37,316
just move off it for now?

56
00:05:37,496 --> 00:05:44,416
wait and let the dust settle then see what happens um yeah like there there are a couple things so if

57
00:05:44,416 --> 00:05:51,736
you have a cold card and you generated your own entropy there is no identified bug in any of the

58
00:05:51,736 --> 00:05:57,056
firmware from the operations of anything else besides the generation of the seed now to be very

59
00:05:57,056 --> 00:06:02,856
clear the most important thing a hardware wallet can do is give you a secure seat phrase yeah power

60
00:06:02,856 --> 00:06:04,876
users will roll dice and do

61
00:06:04,876 --> 00:06:06,816
other things to bring their own entropy

62
00:06:06,816 --> 00:06:08,836
into it so it exists outside of the

63
00:06:08,836 --> 00:06:11,096
cold card. Tragically,

64
00:06:11,656 --> 00:06:13,016
exactly for reasons like this

65
00:06:13,016 --> 00:06:14,836
of not trusting the cold card

66
00:06:14,836 --> 00:06:17,016
and that you're not going to trust it to provide

67
00:06:17,016 --> 00:06:18,156
that information reliably.

68
00:06:19,496 --> 00:06:20,356
If you

69
00:06:20,356 --> 00:06:22,916
have a very strong passphrase or you

70
00:06:22,916 --> 00:06:24,956
roll dice, for the time being, there's no

71
00:06:24,956 --> 00:06:26,896
urgent need to move as long as you're

72
00:06:26,896 --> 00:06:28,776
very sure that you

73
00:06:28,776 --> 00:06:29,636
rolled those dice.

74
00:06:31,676 --> 00:06:32,816
To add to that,

75
00:06:32,856 --> 00:06:34,776
for migrations and things to do.

76
00:06:34,976 --> 00:06:37,196
That is, there's a longer conversation

77
00:06:37,196 --> 00:06:37,916
we need to have there.

78
00:06:38,276 --> 00:06:39,336
If it's a single signature,

79
00:06:39,556 --> 00:06:41,116
specifically with the MK3,

80
00:06:41,516 --> 00:06:42,776
you need to do that right now.

81
00:06:43,676 --> 00:06:47,036
The MK3 is identified to have

82
00:06:47,036 --> 00:06:49,636
two to the 32 bits of entropy.

83
00:06:50,216 --> 00:06:54,596
Now, if you're familiar with seed phrases,

84
00:06:55,076 --> 00:06:56,376
right, like these words,

85
00:06:56,696 --> 00:06:59,276
is that there's a list of 2,048 of them.

86
00:07:00,256 --> 00:07:01,696
And each time you can pick one,

87
00:07:01,776 --> 00:07:02,476
you can even have them

88
00:07:02,476 --> 00:07:07,736
sometimes be the same word each time you're basically picking 2048 multiplied by 2048 multiplied

89
00:07:07,736 --> 00:07:13,536
by 2048 so if you take 2048 times 12 you're close to 128 bits of entropy which is really good and if

90
00:07:13,536 --> 00:07:19,596
you do the 24 um you're at 202 to the 256 both of the like we're talking numbers that are in the

91
00:07:19,596 --> 00:07:25,116
scope and size of there are more possible seed word combinations than there are atoms in the

92
00:07:25,116 --> 00:07:30,776
observable universe and to explain why this is a problem the nature of cryptography and bitcoin

93
00:07:30,776 --> 00:07:38,736
security ultimately is that everyone your bitcoin address ultimately in one way or another results

94
00:07:38,736 --> 00:07:46,276
back to a large number some number between zero and two to the 256 that is the universe that is the

95
00:07:46,276 --> 00:07:55,456
the universal proverbial needle in a haystack and the idea is not that someone can't know my number

96
00:07:55,456 --> 00:08:00,596
it is for someone who doesn't know the number to be able to guess it they have to basically guess

97
00:08:00,596 --> 00:08:05,236
all of the numbers in the universe and the universe will go through a heat death before

98
00:08:05,236 --> 00:08:10,096
someone's able to get there with all of our modern computing right the problem with the cold card

99
00:08:10,096 --> 00:08:16,396
firmware with this firmware change was with some of the changes i saw it succinctly summarized as

100
00:08:16,396 --> 00:08:26,096
there was code that said hey use extra secure entropy um and then continue there was basically

101
00:08:26,096 --> 00:08:32,996
a one-line error that just said oh does this function exist somewhere if so you can skip

102
00:08:32,996 --> 00:08:39,896
the entropy and rather than is this function true right it was like a true false statement

103
00:08:39,896 --> 00:08:45,756
and rather than it being is this true we should invoke that uh you can skip the entropy it was

104
00:08:45,756 --> 00:08:51,276
like oh this exists so we can skip the entropy that's the best highest level it is one line of

105
00:08:51,276 --> 00:08:59,016
code um of how i can describe this issue but the thing is with the mk3 since you have two to the

106
00:08:59,016 --> 00:09:04,496
32 bits that is trivial for consumer hardware to be able to brute force all of the c phrases

107
00:09:04,496 --> 00:09:12,016
the mk4 the mk5 and the q have updates to the firmware the those updates to the firmware

108
00:09:12,016 --> 00:09:20,236
are not better in the sense of you don't have to worry about this they are extra entropy what

109
00:09:20,236 --> 00:09:24,196
people in the industry are estimating right now somewhere between 45 and 50 bits of entropy

110
00:09:24,196 --> 00:09:30,576
which is more that is a significant amount more extra protection but with someone with a data

111
00:09:30,576 --> 00:09:35,116
farm of gpus they will get this information and now the people that know that money's being stored

112
00:09:35,116 --> 00:09:40,676
on it it will be consumed rapidly and quickly so uh if you did not use a passphrase if you did not

113
00:09:40,676 --> 00:09:47,576
use um a seed phrase like uh if you did not roll dice you need to right now stop what you're doing

114
00:09:47,576 --> 00:09:49,356
and you have to treat those funds

115
00:09:49,356 --> 00:09:50,736
as you're in a race against the clock

116
00:09:50,736 --> 00:09:52,336
across many teams of hackers

117
00:09:52,336 --> 00:09:53,916
who are going to get your Bitcoin.

118
00:09:55,376 --> 00:09:57,276
So the obvious question is like,

119
00:09:57,356 --> 00:09:59,056
how is this bug not spotted?

120
00:09:59,836 --> 00:10:02,136
Like for me, like this is obviously

121
00:10:02,136 --> 00:10:03,616
source viewable software,

122
00:10:03,856 --> 00:10:05,036
but I can't read that code.

123
00:10:05,336 --> 00:10:06,996
You can like, did you ever go through

124
00:10:06,996 --> 00:10:08,336
and read the cold card code?

125
00:10:08,416 --> 00:10:10,016
Like how was that not spotted early?

126
00:10:10,016 --> 00:10:12,996
Yeah, I had gone through it previously.

127
00:10:13,636 --> 00:10:15,956
I had gone through it with my own eyes

128
00:10:15,956 --> 00:10:19,476
And I'd also had gone it through earlier versions of large language models.

129
00:10:20,316 --> 00:10:33,053
And what I have observed and I think this is an important part of the story is the latest open source bleeding edge model Kimi K3 which is from China

130
00:10:33,193 --> 00:10:38,453
It's an open source model, does not have the safety guardrails that OpenAI and Anthropic have.

131
00:10:38,553 --> 00:10:45,973
And so when this incident started happening, myself and many people in the industry started looking exactly at where this would go wrong in the code.

132
00:10:46,473 --> 00:10:48,273
And Fable would downgrade me.

133
00:10:48,333 --> 00:10:49,513
So you can't use the leading model.

134
00:10:49,513 --> 00:11:04,113
This is a cybersecurity thing. And then using OpenAI, it would kind of like be coy and generally nudge that something may be going on, but not tell me details. I put it into Kimi K3 and it instantly just read out the entire incident and exactly what went wrong.

135
00:11:04,113 --> 00:11:13,473
and so uh there is something to be said that for a long time uh security through obscurity was used

136
00:11:13,473 --> 00:11:17,273
in places and that is no longer possible if the code exists and people are able to walk through

137
00:11:17,273 --> 00:11:24,953
and see it it will be exploited it's um so when i first saw this i assumed that it was a

138
00:11:24,953 --> 00:11:29,513
lazarus north korea type hack very sophisticated but i've read some stuff online that says it's

139
00:11:29,513 --> 00:11:33,013
maybe a bit of an amateur doing this doesn't really know exactly what he's doing but still

140
00:11:33,013 --> 00:11:38,993
managed to exploit this bug the first the first attacker was i would say an amateur um there's a

141
00:11:38,993 --> 00:11:45,313
lot of on-chain heuristics of what you could tell in the movement patterns they only moved bitcoin

142
00:11:45,313 --> 00:11:51,153
addresses that were more than 0.15 bitcoin why someone wouldn't run a little extra logic and just

143
00:11:51,153 --> 00:11:59,973
get 0.1 bitcoin at six thousand dollars for no extra cost really that's weird they did not properly

144
00:11:59,973 --> 00:12:06,073
scan full addresses so people were getting hacked and they still had funds that were sitting in the

145
00:12:06,073 --> 00:12:09,973
addresses was that i did see something about that was it because it was only looking at like the

146
00:12:09,973 --> 00:12:15,993
first 200 utxos or something like that it was looking uh what it was doing is looking for the

147
00:12:15,993 --> 00:12:23,713
first gap so if you create an address and you didn't use it and then you made another address

148
00:12:23,713 --> 00:12:27,493
and you use that second address the moment the bot saw that there was no more addresses it stopped

149
00:12:27,493 --> 00:12:34,373
looking uh and this is initially would have kept you safe but this is going back to the point now

150
00:12:34,373 --> 00:12:40,073
there are multiple attackers now executing this and i'm assuming they're getting more and more

151
00:12:40,073 --> 00:12:46,653
sophisticated so like that's it and that's why you can see different on-chain movements and seeing

152
00:12:46,653 --> 00:12:51,013
different wallets being used um different transaction behaviors you can just tell by

153
00:12:51,013 --> 00:12:56,593
some basic fingerprinting that different actors are going about this that makes sense so but this

154
00:12:56,593 --> 00:13:00,893
is something you can do trivially like i could do it on my laptop if i had like the skills yeah

155
00:13:00,893 --> 00:13:05,793
uh there are reports of white hat hackers which is people who are trying to do it for the good

156
00:13:05,793 --> 00:13:11,853
who started seeing this exploit started running code and came into dozens of bitcoin and they

157
00:13:11,853 --> 00:13:15,873
swept them because they were trying to do they'd rather at least try to find a way to give it back

158
00:13:15,873 --> 00:13:22,393
to the right owner and then try to uh let an attacker take it so people will be in a panic

159
00:13:22,393 --> 00:13:24,393
hearing this if they're using a cold card.

160
00:13:25,113 --> 00:13:27,113
I want to talk about some of the other devices

161
00:13:27,113 --> 00:13:29,793
because cold card was initially like a fork of Trezor.

162
00:13:30,253 --> 00:13:34,093
And since then, Foundation has forked cold card.

163
00:13:34,093 --> 00:13:37,153
Are those other forks from the same thing safe

164
00:13:37,153 --> 00:13:38,653
from the same original source code?

165
00:13:38,833 --> 00:13:41,013
Yeah, neither Trezor nor Foundation

166
00:13:41,013 --> 00:13:43,373
use the library that was compromised with the cold card.

167
00:13:44,193 --> 00:13:46,773
Okay, so basically anywhere is safe

168
00:13:46,773 --> 00:13:47,793
apart from cold card right now.

169
00:13:47,833 --> 00:13:49,473
This isn't like a broader self-custody attack.

170
00:13:49,573 --> 00:13:50,493
This is a specific cold card.

171
00:13:50,493 --> 00:13:54,693
The use of this library was specific to cold card or realistically mainly cold card.

172
00:13:55,173 --> 00:13:57,713
So what should people do if they're panicking right now?

173
00:13:57,993 --> 00:13:59,113
Where should they be moving funds?

174
00:14:02,253 --> 00:14:08,153
This is something that is for each individual person to kind of make that judgment call.

175
00:14:09,453 --> 00:14:14,253
I am, while I am the co-founder and CEO of AnchorWatch, I want to be fair to everyone

176
00:14:14,253 --> 00:14:18,793
and talk about how I would console someone if I did not run this company.

177
00:14:18,793 --> 00:14:21,233
and I was trying to help a loved one through this.

178
00:14:21,433 --> 00:14:23,073
If you had used a Bitcoin exchange

179
00:14:23,073 --> 00:14:26,073
and your Bitcoin is, you know, in the system,

180
00:14:26,193 --> 00:14:29,153
you give an exchange dollars, you get Bitcoin,

181
00:14:29,253 --> 00:14:30,253
you withdraw it to self-custody.

182
00:14:31,353 --> 00:14:32,613
Immediately short-term,

183
00:14:33,193 --> 00:14:35,613
sending it back to that exchange is not a bad idea

184
00:14:35,613 --> 00:14:37,233
if you have no better place to do this.

185
00:14:38,713 --> 00:14:40,393
I'm a big fan of River, personally.

186
00:14:40,533 --> 00:14:42,953
I have high confidence in the infrastructure over at River

187
00:14:42,953 --> 00:14:45,093
if you're looking for a good Bitcoin exchange.

188
00:14:46,193 --> 00:14:47,773
I'm talking to other people in industry.

189
00:14:47,773 --> 00:14:50,753
I just know that River runs their own custody.

190
00:14:51,033 --> 00:14:52,213
They're not outsourcing it to someone else.

191
00:14:52,253 --> 00:14:55,773
And I think that's an important thing to be aware of, and they do proof of reserves.

192
00:14:58,213 --> 00:15:02,913
I think really genuinely proof of reserves is kind of table stakes if you're going to leave your funds out in exchange.

193
00:15:03,033 --> 00:15:04,853
And River is the main place that does that.

194
00:15:06,753 --> 00:15:16,973
As it relates to other options, now, you could, in theory, go to a Best Buy and pick up a ledger in the States today.

195
00:15:17,773 --> 00:15:18,873
You can get bit keys there as well.

196
00:15:19,233 --> 00:15:20,353
You can get bit keys as well.

197
00:15:21,513 --> 00:15:26,773
Those are good immediate emergency options to get things set up properly.

198
00:15:28,373 --> 00:15:42,949
And to be clear the whole context of this advice is your funds are imminently going to be hacked if you on a cold card without the entropy and without the dice and without passphrases So my advice is not set this up and hang out for the rest of your life This is

199
00:15:42,949 --> 00:15:50,289
you need to do something in the next 24 hours. Now there are other services like there are

200
00:15:50,289 --> 00:15:55,769
Unchained, there's Casa, there's us at Anchor Watch, there's a Swan Vault as well. There are

201
00:15:55,769 --> 00:16:01,129
many products across the industry that offer these things in collaborative custody. I think those are

202
00:16:01,129 --> 00:16:08,409
all great measures to be able to provide extra support to people um if you have a friend um we

203
00:16:08,409 --> 00:16:13,189
won't say who but as we were starting this podcast you and i got a call from a mutual friend who was

204
00:16:13,189 --> 00:16:20,769
basically breaking into a friend's house who was on vacation and getting this pin over the phone to

205
00:16:20,769 --> 00:16:29,009
then move the funds before they got hacked uh they had a reliable self-custody wallet to be able to do

206
00:16:29,009 --> 00:16:36,889
that right um the universe and space of this has to be very carefully thought out and this goes back

207
00:16:36,889 --> 00:16:43,789
to um something i believe i said before is that um slow is smooth and smooth is fast so you need

208
00:16:43,789 --> 00:16:48,749
to have a decisive plan that is good enough for the trade-offs right now and decisively execute

209
00:16:48,749 --> 00:16:55,129
you do not have days to really war game out your optimal option here it's just most important that

210
00:16:55,129 --> 00:17:01,069
you take action now there's so many things that are very unfortunate about this um from a user

211
00:17:01,069 --> 00:17:05,669
perspective like one of them especially comes down to sort of privacy um because if you're in a panic

212
00:17:05,669 --> 00:17:10,729
now you might have a ton of utxos on a cold card some of which may be like non-kyc bitcoin stuff

213
00:17:10,729 --> 00:17:13,909
that you don't really want to mix but at this point you kind of just have to move everything

214
00:17:13,909 --> 00:17:22,809
together like that's one of the really unfortunate outcomes indeed yeah uh while you could if you

215
00:17:22,809 --> 00:17:28,629
are technical enough spend the time building a careful transaction graph i'm going to assume most

216
00:17:28,629 --> 00:17:35,269
people aren't and so you have to make a cost benefit analysis for your own position to understand

217
00:17:35,269 --> 00:17:40,429
is that with any of these movement options and how you're going to execute about them you are the

218
00:17:40,429 --> 00:17:44,649
best person to be able to understand your circumstance and that's why i try to keep the

219
00:17:44,649 --> 00:17:50,949
advice very open-ended in general to meet different people depending on where they could be in their

220
00:17:50,949 --> 00:17:54,649
self-custody journey and their Bitcoin journey and their technical competency.

221
00:17:55,769 --> 00:18:00,929
And then the other side of that is the thing that is very harsh about this situation that's

222
00:18:00,929 --> 00:18:05,629
completely unlike a Mt. Gox or an FTX is that the people that have been affected by this have done

223
00:18:05,629 --> 00:18:10,169
everything so right. Like they've taken the time to learn self-custody. They've bought what was

224
00:18:10,169 --> 00:18:14,569
sort of perceived as the most secure Bitcoin hardware wallet. They've done everything correct

225
00:18:14,569 --> 00:18:17,969
and they've still been fucked in this situation.

226
00:18:19,109 --> 00:18:21,989
Do you think this sets back Bitcoin self-custody

227
00:18:21,989 --> 00:18:23,009
in a significant way?

228
00:18:30,009 --> 00:18:35,389
I think it would be naive to say

229
00:18:35,389 --> 00:18:36,889
that in the short term

230
00:18:36,889 --> 00:18:40,189
that there's going to be a massive re-evaluation of this.

231
00:18:40,189 --> 00:18:49,929
many people lost their life savings because of this um i think it's important for bitcoin

232
00:18:49,929 --> 00:18:58,729
as a technology as people who send and receive bitcoin regularly to be thinking about

233
00:18:58,729 --> 00:19:04,989
where to go from here uh the capturing of bitcoin as a decentralized network

234
00:19:04,989 --> 00:19:12,209
is accelerated if the only place you can hold it is at a quality like a specific exchange that is

235
00:19:12,209 --> 00:19:18,449
inevitably bitcoin is freedom money cannot work if you're not able to freely be able to

236
00:19:18,449 --> 00:19:23,149
call your money and own it and touch it yourself now

237
00:19:23,149 --> 00:19:30,929
i think there's a this is so pressing and breaking it is difficult for me to come out

238
00:19:30,929 --> 00:19:34,169
with my prescriptive list of these are the things we should be thinking about and doing

239
00:19:34,169 --> 00:19:43,229
I think most important right now, what we should be doing is informing people, letting them know that this is happening, giving them ideas for contingencies.

240
00:19:43,569 --> 00:19:53,869
There's a couple of more threat models I do want to go over for maybe more advanced users as it relates to ways that your funds could additionally be put at risk.

241
00:19:53,869 --> 00:19:59,229
and i'm going to start there because i think that's actually more important than like the

242
00:19:59,229 --> 00:20:06,329
bigger question is if you have a multi-signature wallet and they are only using cold cards and

243
00:20:06,329 --> 00:20:11,129
those cold cards are only generated using this entropy your funds are at risk and you need to

244
00:20:11,129 --> 00:20:20,229
immediately make whatever moves you need to do to get that fixed if you have let's say a two of three

245
00:20:20,229 --> 00:20:22,309
and you have two cold cards in a ledger

246
00:20:22,309 --> 00:20:24,649
and you did not do the passphrase

247
00:20:24,649 --> 00:20:25,889
and you did not do the dice rolling,

248
00:20:26,349 --> 00:20:27,449
your funds are at risk

249
00:20:27,449 --> 00:20:30,309
and you need to make moves immediately to rectify that.

250
00:20:30,829 --> 00:20:32,169
Now, to explain,

251
00:20:32,769 --> 00:20:35,829
I feel fairly confident this is what's going to happen.

252
00:20:36,689 --> 00:20:39,389
Can I ask you a question on that part first?

253
00:20:39,429 --> 00:20:41,049
So you said if you have a two of three

254
00:20:41,049 --> 00:20:43,029
and say one device is a ledger,

255
00:20:43,089 --> 00:20:43,729
one device is a Trezor,

256
00:20:43,789 --> 00:20:45,669
one device is a cold card Mark III,

257
00:20:46,209 --> 00:20:47,989
even in that situation, your funds are at risk?

258
00:20:48,329 --> 00:20:48,629
No.

259
00:20:48,629 --> 00:20:49,909
So if you have...

260
00:20:49,985 --> 00:20:51,565
a treasure, a ledger, a cult card,

261
00:20:51,685 --> 00:20:52,685
your funds are not at risk.

262
00:20:52,965 --> 00:20:55,365
If you have two cult cards and a ledger,

263
00:20:55,785 --> 00:20:57,265
your funds are at risk.

264
00:20:57,545 --> 00:20:59,525
Yeah, because those two can...

265
00:20:59,525 --> 00:21:02,025
Yes, and this is to get a little bit

266
00:21:02,025 --> 00:21:03,545
for those that need to know,

267
00:21:03,645 --> 00:21:06,025
because I have talked to...

268
00:21:06,025 --> 00:21:07,925
I've probably talked to at least

269
00:21:07,925 --> 00:21:09,105
a half dozen people specifically

270
00:21:09,105 --> 00:21:10,345
in this situation, if not more,

271
00:21:10,685 --> 00:21:12,505
where they have two cult cards and a ledger

272
00:21:12,505 --> 00:21:13,805
or two cult cards and a treasure

273
00:21:13,805 --> 00:21:15,385
or two cult cards and a jade

274
00:21:15,385 --> 00:21:17,365
or two cult cards and a foundation device,

275
00:21:17,445 --> 00:21:19,705
whatever, two cult cards and a seed signer,

276
00:21:19,705 --> 00:21:30,345
right the necessary thing to understand is that when you go to spend bitcoin in the bitcoin network

277
00:21:30,345 --> 00:21:35,105
let me actually just take a half step back here what is going to very likely happen across multiple

278
00:21:35,105 --> 00:21:40,965
uh hackers is they are going to build an entire list of every single seed phrase combination that

279
00:21:40,965 --> 00:21:46,765
the cold card would do without entropy what they are going to do from there is they are going to

280
00:21:46,765 --> 00:21:51,525
start realizing, wait, if I have all these seed phrases, I can actually see if my wallet's being

281
00:21:51,525 --> 00:21:57,065
used on chain. And they're going to say, okay, out of this, you know, billions, we're going to say

282
00:21:57,065 --> 00:22:03,065
that we have this many that could be in use at the moment. They're going to look at those and

283
00:22:03,065 --> 00:22:08,125
they're going to see what are they doing with it. And to be clear, if you use your cold card

284
00:22:08,125 --> 00:22:14,605
in a multi-seg, they can see, wait a second, that person spent from this address and that public key

285
00:22:14,605 --> 00:22:16,765
is tied to my list of seed phrases here.

286
00:22:17,045 --> 00:22:18,185
They're going to be able

287
00:22:18,185 --> 00:22:20,885
to basically monitor your wallets.

288
00:22:21,405 --> 00:22:22,225
Here's what happens.

289
00:22:22,445 --> 00:22:23,805
If you have reused addresses,

290
00:22:24,385 --> 00:22:27,485
those reused addresses have the raw public keys

291
00:22:27,485 --> 00:22:29,385
of how you spend that Bitcoin sitting on chain.

292
00:22:30,005 --> 00:22:32,105
And if it's a two of three and the attacker says,

293
00:22:32,185 --> 00:22:33,845
oh, I have key A and key B,

294
00:22:34,465 --> 00:22:35,465
they'll just take the funds.

295
00:22:35,865 --> 00:22:38,405
They don't need to wait for you to do anything.

296
00:22:38,605 --> 00:22:40,385
If you have not reused addresses,

297
00:22:41,025 --> 00:22:44,065
you are in a very delicate position

298
00:22:44,065 --> 00:22:49,425
and this is a little bit advanced and i want to be clear this is a very specific circumstance

299
00:22:49,425 --> 00:22:55,865
if you have a multi-signature wallet and that multi-signature wallet is a majority for the

300
00:22:55,865 --> 00:23:02,825
threshold uh cold card signers that are impacted by this issue you should look into using something

301
00:23:02,825 --> 00:23:08,065
like mara slipstream and the reason why is when i go and broadcast a transaction to the bitcoin

302
00:23:08,065 --> 00:23:13,785
network anyone on the network can see the transaction data before it gets confirmed but

303
00:23:13,785 --> 00:23:18,745
it's not in a block yet which means an attack by flea exactly so an attacker will be able to

304
00:23:18,745 --> 00:23:22,865
replace by fee and change the address from your address to an attacker's address if you use

305
00:23:22,865 --> 00:23:28,225
something like mara slipstream you will be able to have it broadcasted to a mining pool that has

306
00:23:28,225 --> 00:23:33,225
over five percent network cash rate they find multiple blocks a day and it will just appear

307
00:23:33,225 --> 00:23:39,125
confirmed on chain which will mean the attackers will not be able to do anything and so i know it's

308
00:23:39,125 --> 00:23:43,325
a very specific circumstance but i've talked to easily a half dozen people who are in this exact

309
00:23:43,325 --> 00:23:48,765
position and you can reach out to mark like there are ways for you to be able to do that um

310
00:23:48,765 --> 00:23:54,225
if you only have cold cards if you have a three of three if you have three cold cards and it's a

311
00:23:54,225 --> 00:23:58,305
two of three they will find your funds they will look at all the seed phrases and once they have

312
00:23:58,305 --> 00:24:02,545
all the possible seed phrases they're going to run through all of the common metrics of different

313
00:24:02,545 --> 00:24:06,525
multi-sig thresholds among those keys if they haven't already been spent on chain if you've

314
00:24:06,525 --> 00:24:11,145
spent from your multi-sig address once on chain they will be able to trivially scan and see that

315
00:24:11,145 --> 00:24:18,305
it's there and be able to attack you um and know that yeah so in that situation slipstream doesn't

316
00:24:18,305 --> 00:24:21,765
help you so what do you do you just have to set an incredibly high fee rate and hope you just have

317
00:24:21,765 --> 00:24:27,265
to go you just have to rip it you you don't have a yeah so if you've and to explain this let's say

318
00:24:27,265 --> 00:24:33,965
you have a two of three multi-sig and they're all cold cards you and you've spent from it before

319
00:24:33,965 --> 00:24:41,065
attackers will be able to see oh key a key b key c that matches seed one two and three boom boom

320
00:24:41,065 --> 00:24:48,325
connected i'll be able to move my funds so if you have a an n of n two of two three of three whatever

321
00:24:48,325 --> 00:24:53,265
multi-sig wallet that is only cold cards that are impacted by this issue you need to move funds

322
00:24:53,265 --> 00:25:00,265
right now like you you are marginally safer than a single sig and the reason why is because you need

323
00:25:00,265 --> 00:25:05,745
to have an attacker know all of the seeds in the universe to be able to attack it but that is a

324
00:25:05,745 --> 00:25:10,845
ticking time that you're racing against the clock you need to immediately make moves if that is the

325
00:25:10,845 --> 00:25:17,205
position you're in oh it's such a terrible situation to be in um do we know how much bitcoin's been

326
00:25:17,205 --> 00:25:21,205
stolen from this attack so far i saw yesterday it was like 600 but i'm sure it's increasing it's

327
00:25:21,205 --> 00:25:26,005
over 1100 at this point and there's probably more clusters going on all the time um i occasionally

328
00:25:26,005 --> 00:25:28,925
was poking around the men pool to see if i can find more things it's going to be thousands of

329
00:25:28,925 --> 00:25:32,085
bitcoin before this is done and it's going to happen in waves what i'm describing right now

330
00:25:32,085 --> 00:25:36,965
this race against the clock the lowest hanging fruit were hit and that was probably one attacker

331
00:25:36,965 --> 00:25:45,105
the starting gun has been fired off the everyone has declared the emergency every black cat hacker

332
00:25:45,105 --> 00:25:49,405
on the internet with an llm is going to be able to start poking around seeing what they can find

333
00:25:49,405 --> 00:25:56,965
they and because there are multiple attackers now there's a an inevitable outcome where well

334
00:25:56,965 --> 00:26:08,382
capitalized ones are going to come in spend millions and millions of dollars on graphics GPU computing because they know that they can pop one vault what you be able to have an attacker do is

335
00:26:08,382 --> 00:26:12,782
they're going to be able to look through the full list and just pop it right out and you are just

336
00:26:12,782 --> 00:26:17,402
marginally safer because it's not the lowest hanging fruit but you are not safe period

337
00:26:17,402 --> 00:26:22,402
so this started as obviously like an amateur attack as we spoke about a little earlier

338
00:26:22,402 --> 00:26:26,322
but this is now you have to assume the best attacks in the world are now having a go at this

339
00:26:26,322 --> 00:26:29,222
yeah this is everyone

340
00:26:29,222 --> 00:26:33,302
it's a it is a real mess

341
00:26:33,302 --> 00:26:42,022
so when you compare this to like a Mt. Gox or a FTA

342
00:26:42,022 --> 00:26:44,562
the number of coins is going to be far lower

343
00:26:44,562 --> 00:26:47,222
but is the damage going to be greater

344
00:26:47,222 --> 00:26:50,022
because it kind of arose people's trust in self-custody essentially

345
00:26:50,022 --> 00:26:53,682
like cold card was the golden child of Bitcoin self-custody essentially

346
00:26:53,682 --> 00:27:01,842
i like i said earlier it would be naive to say that in the short term that this is not going to be

347
00:27:02,582 --> 00:27:09,782
a uh a very negative downward pressure on self-custody and for i know multiple people

348
00:27:09,782 --> 00:27:17,902
who've lost either some money or their life savings uh i have spent the past 24 hours i have

349
00:27:17,902 --> 00:27:25,742
talked to directly on a one-on-one context dozens of people um in a larger platform i've talked to

350
00:27:25,742 --> 00:27:33,242
now thousands of people trying to raise the alarm bell about this and the stories keep on coming in

351
00:27:33,242 --> 00:27:42,822
this this will have a downward trend on self-custody i think that doesn't have to be the

352
00:27:42,822 --> 00:27:47,862
end of the story but i think there needs to be as the post-mortems wrap up and we do a full

353
00:27:47,862 --> 00:27:56,382
debrief of this the entire ecosystem has an opportunity to build from here and find improvements

354
00:27:56,382 --> 00:28:06,102
um we are now almost 30 minutes into the podcast so um in some conversations people are talking

355
00:28:06,102 --> 00:28:12,042
about we need covenants and vault-like structures yeah things that can improve self-custody my

356
00:28:12,042 --> 00:28:16,942
biggest concern for the health of Bitcoin as a network is that the default option being holding

357
00:28:16,942 --> 00:28:21,402
it at a custodian or an ETF wrapper. I am not opposed to those instruments existing. I think

358
00:28:21,402 --> 00:28:26,522
those are inevitable structures that happen with hyper Bitcoinization. But the value proposition

359
00:28:26,522 --> 00:28:33,722
of Bitcoin itself will be diminished greatly if those are the only real options. And being able to

360
00:28:33,722 --> 00:28:40,422
to explain this, the way Bitcoin works today, if you have the requisite amount of signatures,

361
00:28:40,422 --> 00:28:44,362
you can send any amount of Bitcoin anywhere within reason.

362
00:28:44,462 --> 00:28:46,362
There's weird corner cases,

363
00:28:46,482 --> 00:28:48,462
but let's just say for the sake of conversation, that's true.

364
00:28:49,822 --> 00:28:52,122
Things like covenants would allow you

365
00:28:52,122 --> 00:28:53,842
to be able to have things like,

366
00:28:54,482 --> 00:28:56,782
I only want to be able to send to these addresses.

367
00:28:57,522 --> 00:28:59,022
I only want to send this much Bitcoin.

368
00:28:59,382 --> 00:29:01,122
This is something at AnchorWatch

369
00:29:01,122 --> 00:29:04,382
we are able to offer as a product level service, right?

370
00:29:04,542 --> 00:29:06,922
It is an application that sits on top of Bitcoin

371
00:29:06,922 --> 00:29:09,662
where we say AnchorWatch is a required co-signer

372
00:29:09,662 --> 00:29:18,242
to move funds but we will in exchange for like us being able to help you out we'll say okay well

373
00:29:18,242 --> 00:29:22,502
you only can send to the addresses you give us so addresses a b and c otherwise we at anchor watch

374
00:29:22,502 --> 00:29:29,702
won't sign it's effectively a covenant as us acting as a cosigner gives that feature or i only

375
00:29:29,702 --> 00:29:34,122
want to send one bitcoin a month that's something we can do at anchor watch it's something you can't

376
00:29:34,122 --> 00:29:39,082
do on the bitcoin blockchain level if it were to be democratized to the bitcoin blockchain level

377
00:29:39,082 --> 00:29:46,682
anyone in their basement would be able to have orders of magnitude better security

378
00:29:46,682 --> 00:29:52,482
than any of the enterprise leading custodians today and that's an important point because

379
00:29:52,482 --> 00:29:59,682
when bitcoin is in flight once it gets confirmed in a block it's over whereas with covenants and

380
00:29:59,682 --> 00:30:03,502
in general vaulting you would be able to send to like a staging address so you'd be like wait a

381
00:30:03,502 --> 00:30:07,402
second why did my funds move it's sitting in my staging address and then you can pull the emergency

382
00:30:07,402 --> 00:30:13,282
ripcord to like pull the funds out now it doesn't solve the key management problem

383
00:30:13,282 --> 00:30:20,762
right i think it's an important thing to call out that it is a mitigation it is necessary but not

384
00:30:20,762 --> 00:30:26,422
sufficient to be able to improve these things but the ultimately you need to send bitcoin to an

385
00:30:26,422 --> 00:30:32,742
address somewhere and those addresses have to ultimately be tied to keys so there is a lot of

386
00:30:32,742 --> 00:30:41,242
learning, I think, within the ecosystem about where do we go from here. And I think there'll

387
00:30:41,242 --> 00:30:46,262
be plenty of time to discuss that in the coming weeks after the initial incident response and

388
00:30:46,262 --> 00:30:51,682
everything can be done as much as possible to keep people safe. Right now, I think the main focus is

389
00:30:51,682 --> 00:30:56,962
just letting everyone know this is happening and they need to immediately remedy this if they're

390
00:30:56,962 --> 00:31:04,462
impacted how do these um there's a thing like an unchained or a cassette let's say you have a two

391
00:31:04,462 --> 00:31:20,958
of three with one of those um if i have so one key will be on your phone generally one key will be held by the company one key is held by you If I holding my key let say on a cold card how do I know that the counterparty

392
00:31:20,998 --> 00:31:22,278
the unchained or the CASA is not?

393
00:31:23,938 --> 00:31:27,958
The unchained or the CASA counterparty is not what?

394
00:31:28,478 --> 00:31:30,718
Like holding one of their key on a cold card

395
00:31:30,718 --> 00:31:32,278
because that would then put the multi-sigual risk.

396
00:31:32,278 --> 00:31:34,458
You can't prove that.

397
00:31:34,458 --> 00:31:40,898
You can't with any wallet wealth in a very tragic sense of irony.

398
00:31:42,398 --> 00:31:47,918
Very soon people will be able to prove if they were using the cold card keys because attackers will have them.

399
00:31:48,058 --> 00:31:48,178
Right.

400
00:31:50,458 --> 00:31:55,098
The ideal structure, though, is that it's not something that can be an issue.

401
00:31:55,098 --> 00:32:01,858
because if you have sufficient randomness there's no you should not be able to fingerprint and say

402
00:32:01,858 --> 00:32:06,938
oh that that x pub came from a ledger and that one came from a jade that would be a breaking in

403
00:32:06,938 --> 00:32:12,218
the underlying cryptography assumptions that is a truly random number that is seeding all of your

404
00:32:12,218 --> 00:32:17,298
secrets so i guess the point i'm trying to make i'm trying to make people feel comfortable here

405
00:32:17,298 --> 00:32:21,698
if they are using a castron unchained like have either of those made a statement about how they're

406
00:32:21,698 --> 00:32:22,498
generating their keys?

407
00:32:22,658 --> 00:32:24,218
Because I'm convinced

408
00:32:24,218 --> 00:32:25,418
that neither of those companies

409
00:32:25,418 --> 00:32:27,138
are using the on-device

410
00:32:27,138 --> 00:32:28,678
random number generator.

411
00:32:29,598 --> 00:32:30,118
But have they made

412
00:32:30,118 --> 00:32:30,918
any statements about that?

413
00:32:31,878 --> 00:32:32,738
To my understanding,

414
00:32:33,238 --> 00:32:34,878
Unchained has made a statement.

415
00:32:35,558 --> 00:32:36,678
I believe Casa has made

416
00:32:36,678 --> 00:32:37,558
a statement as well.

417
00:32:37,998 --> 00:32:38,798
And we at AnchorWatch

418
00:32:38,798 --> 00:32:39,618
have also made a statement

419
00:32:39,618 --> 00:32:41,038
that this does not impact us.

420
00:32:41,958 --> 00:32:45,618
And so I think it's an important thing

421
00:32:45,618 --> 00:32:46,978
to look in your vendors

422
00:32:46,978 --> 00:32:48,078
to see if this is an issue.

423
00:32:48,178 --> 00:32:50,018
I think that's a very reasonable concern.

424
00:32:51,698 --> 00:32:56,178
but i think everyone at this point has made some public statement to the effect of that

425
00:32:56,178 --> 00:33:00,178
i'm not aware of any i'm not aware of any bitcoin business even through like

426
00:33:00,178 --> 00:33:05,578
hushed private circles who are impacted by this i haven't heard anything yet they may exist but i

427
00:33:05,578 --> 00:33:09,478
have not heard anything i i definitely don't want my words to be twisted there like i think a cast

428
00:33:09,478 --> 00:33:13,418
for an unchained like anchor watch i'm sure all those companies are set up brilliantly um i just

429
00:33:13,418 --> 00:33:16,738
i just want to try and make people comfortable with moving funds to those places if they need

430
00:33:16,738 --> 00:33:25,678
understood um anchor watch how do you set up your multi-sig uh yeah so the nature of what we do it's

431
00:33:25,678 --> 00:33:31,038
somewhat different is we use what's called mini script and that allows us to do more advanced

432
00:33:31,038 --> 00:33:36,398
scripting functionality uh rather than just a two of three we are able to say we have a two of three

433
00:33:36,398 --> 00:33:41,138
you have a two of three we all have to get together and sign and move things we could do is we have a

434
00:33:41,138 --> 00:33:43,598
Two of three and you have a single key, right?

435
00:33:43,638 --> 00:33:45,438
And we act as that cosigner still, right?

436
00:33:46,598 --> 00:33:58,878
The nature of how anyone generates keys is an extremely sensitive thing because you just need to keep that on a need to know the exact mechanics.

437
00:33:58,998 --> 00:34:00,678
But our process has been peer reviewed.

438
00:34:02,118 --> 00:34:09,438
There are many, I think most actors in the industry have their own very rigorous key generation ceremonies of what they go about for being able to.

439
00:34:11,138 --> 00:34:19,038
evaluate that so when like i really like single sig self-custody like i think i think you should

440
00:34:19,038 --> 00:34:22,858
have different trade-offs for different amounts of bitcoin that you're holding like if maybe you

441
00:34:22,858 --> 00:34:26,718
have one sort of deep cold storage which is geographically dispersed multi-sig and that's

442
00:34:26,718 --> 00:34:32,098
great but the simplicity of single sig is really important too i think i i would definitely still

443
00:34:32,098 --> 00:34:38,038
use that occasionally um how do people think about that going forward because i've always i've

444
00:34:38,038 --> 00:34:42,138
always said that like the most likely you are to lose bitcoin is through your own complexity in

445
00:34:42,138 --> 00:34:46,038
your own setup like complexity being the enemy of security and do you think people are going to make

446
00:34:46,038 --> 00:34:50,438
the mistake now of jumping too far into multi-sig because they're scared of this attack and actually

447
00:34:50,438 --> 00:34:55,498
add too much complexity to their own setups i think multi-sig is no longer that complicated

448
00:34:55,498 --> 00:35:01,118
i think this is not 2017 anymore um additionally if for whatever reason you want to do a single

449
00:35:01,118 --> 00:35:05,378
signature you could do single signature with a passphrase that effectively is a two of two

450
00:35:05,378 --> 00:35:11,178
multi-sig because you have to have both pieces to be able to constitute a spend if you were doing

451
00:35:11,178 --> 00:35:16,998
that with a reasonably strong passphrase going into today you're still safe i would still make

452
00:35:16,998 --> 00:35:23,838
a new wallet because if you fell under this and your initial 12 or 24 words were actually part of

453
00:35:23,838 --> 00:35:30,318
this hit of known possible seed phrases all that's keeping you safe now is your passphrase

454
00:35:30,318 --> 00:35:37,078
but uh i think there's a lot of opportunity for everyone to grow and learn from this to even

455
00:35:37,078 --> 00:35:44,518
further improve the user experience because this will this will be in the front mind of anyone

456
00:35:44,518 --> 00:35:51,758
who discusses self-custody for a very long time so this is the first like in the wild case that

457
00:35:51,758 --> 00:35:58,178
we've seen of ai essentially hacking and taking down a bitcoin self-custody solution um do you

458
00:35:58,178 --> 00:36:01,618
think this is the start of that era do you think we're going to see more and more attacks like this

459
00:36:01,618 --> 00:36:06,438
i think in general uh across the whole web there are going to be more and more attacks like this

460
00:36:06,438 --> 00:36:12,718
um the trivial ability for me to be able to open up to open router and use kimmy k3 and point at

461
00:36:12,718 --> 00:36:20,618
the cold card firmware and instantly read out everything everyone needs to be and we regularly

462
00:36:20,618 --> 00:36:31,254
do this at anchor watch i know most companies that i know of in the bitcoin industry are regularly doing this and kind of defensively trying to deploy these tools to find things

463
00:36:32,774 --> 00:36:36,434
We've always found, we've never found anything that was a money losing bug.

464
00:36:37,434 --> 00:36:40,794
Nothing in the universe of bad of what we're seeing here with the cold card.

465
00:36:41,994 --> 00:36:43,074
But you find bugs.

466
00:36:43,334 --> 00:36:44,194
The software has bugs.

467
00:36:44,414 --> 00:36:45,974
It always will have bugs, right?

468
00:36:45,974 --> 00:36:51,294
Like there is some emerging research around things like formal verification.

469
00:36:51,294 --> 00:36:56,394
So you can actually do formal mathematical proofs as to how code executes.

470
00:36:57,034 --> 00:37:00,894
That's an emerging field of research that I think may get more important over the coming decade.

471
00:37:01,694 --> 00:37:05,614
But software is written by humans and humans inevitably have bugs.

472
00:37:05,674 --> 00:37:07,234
And even LLM sometimes have bugs, right?

473
00:37:07,254 --> 00:37:14,034
You don't want to be blindly passing everything you've built to just have it go get figured out later by LLM.

474
00:37:14,054 --> 00:37:15,314
And the LLM may not be complete, right?

475
00:37:15,694 --> 00:37:19,694
The rapid development of these models, there's a kind of a funny software motif.

476
00:37:19,694 --> 00:37:27,254
If you like VibeCode a website and you launch it, in three months, the new model comes out and it says, wow, this code base is a mess.

477
00:37:27,314 --> 00:37:28,094
Let me fix this for you.

478
00:37:28,154 --> 00:37:30,354
And that's just been happening continually for two years now.

479
00:37:30,634 --> 00:37:46,394
So like we're at a place and a time where you need to be hypervigilant with your own individual judgment, with your ability to understand the nitty gritty details of risk and however it emerges to be able to keep you and people you work with safe.

480
00:37:47,254 --> 00:37:47,854
All right.

481
00:37:47,934 --> 00:37:48,874
Awkward question time.

482
00:37:48,874 --> 00:37:54,454
because i know you're friends with mvk but like the blame obviously ends with them but how

483
00:37:54,454 --> 00:37:59,034
incompetent was this because this has been five years that this firmware issue has been there

484
00:37:59,034 --> 00:38:08,774
uh not acceptable as a starting place like not like there is no yes i've i've known mvk for a

485
00:38:08,774 --> 00:38:18,594
long time um there is no excusable there's no set of circumstances that excuses this the the one job

486
00:38:18,594 --> 00:38:19,794
a hardware wallet has,

487
00:38:20,534 --> 00:38:22,014
if it were to have a single job,

488
00:38:22,454 --> 00:38:24,854
more important than all of the other jobs

489
00:38:24,854 --> 00:38:27,034
is that it can securely generate

490
00:38:27,034 --> 00:38:29,034
a sufficiently large random number

491
00:38:29,034 --> 00:38:31,154
with sufficient entropy.

492
00:38:31,534 --> 00:38:33,094
That is the entire game

493
00:38:33,094 --> 00:38:35,014
in which everything else gets derived from.

494
00:38:35,574 --> 00:38:37,934
There are bugs that have happened

495
00:38:37,934 --> 00:38:39,054
in hardware wallets in the past

496
00:38:39,054 --> 00:38:40,834
where maybe how they signed a transaction

497
00:38:40,834 --> 00:38:41,994
wasn't secure.

498
00:38:42,594 --> 00:38:44,014
And then basically,

499
00:38:44,134 --> 00:38:44,834
if you reused addresses,

500
00:38:44,914 --> 00:38:45,614
you could lose your funds.

501
00:38:45,874 --> 00:38:47,814
Or maybe you would have bugs

502
00:38:47,814 --> 00:38:50,494
where it wasn't checking the change address.

503
00:38:50,594 --> 00:38:51,614
So if I sent you Bitcoin,

504
00:38:51,774 --> 00:38:52,814
if I have 10 Bitcoin,

505
00:38:52,894 --> 00:38:53,774
I send you one Bitcoin,

506
00:38:53,914 --> 00:38:55,394
I have to send myself nine back in change.

507
00:38:55,694 --> 00:38:57,594
There were bugs in software and hardware wallets

508
00:38:57,594 --> 00:38:58,654
that didn't check the change,

509
00:38:58,714 --> 00:38:59,694
which was the most important part

510
00:38:59,694 --> 00:39:00,834
of the transaction in that sense, right?

511
00:39:01,654 --> 00:39:02,914
This bug is so foundational

512
00:39:02,914 --> 00:39:04,914
to the actual security of Bitcoin

513
00:39:04,914 --> 00:39:11,214
that it is a nuclear event, right?

514
00:39:11,214 --> 00:39:13,314
This is the most catastrophic thing.

515
00:39:13,394 --> 00:39:15,334
That is why someone could be entirely air-gapped,

516
00:39:15,714 --> 00:39:17,294
never have talked to the internet,

517
00:39:17,294 --> 00:39:21,634
and someone's able to peer through the vast space of randomness and get your Bitcoin,

518
00:39:21,914 --> 00:39:22,914
which should never happen.

519
00:39:25,554 --> 00:39:28,994
Do you think it's at the end of cold card?

520
00:39:29,054 --> 00:39:29,994
Do you think they'll be able to recover this?

521
00:39:30,014 --> 00:39:31,854
Because trust is everything when it comes to these devices.

522
00:39:32,394 --> 00:39:33,094
It is.

523
00:39:33,294 --> 00:39:36,274
I think it's too early to say.

524
00:39:36,434 --> 00:39:37,434
I don't know.

525
00:39:37,954 --> 00:39:38,714
I'm not a lawyer.

526
00:39:38,714 --> 00:39:44,534
I don't understand any of the liabilities or fallouts or all of these things.

527
00:39:44,534 --> 00:39:47,534
it's hard for me to say.

528
00:39:48,374 --> 00:39:48,734
Yeah, truly.

529
00:39:48,974 --> 00:39:49,574
I don't know.

530
00:39:50,214 --> 00:39:50,754
All right, Rob,

531
00:39:50,794 --> 00:39:51,694
I appreciate you doing this

532
00:39:51,694 --> 00:39:52,094
so last minute.

533
00:39:52,214 --> 00:39:52,994
I wanted basically

534
00:39:52,994 --> 00:39:53,874
just to get this out there.

535
00:39:53,934 --> 00:39:55,154
If one person listens to this show,

536
00:39:55,254 --> 00:39:56,454
they're not permanently

537
00:39:56,454 --> 00:39:57,214
on Bitcoin Twitter

538
00:39:57,214 --> 00:39:57,774
like you and I

539
00:39:57,774 --> 00:39:58,634
and they haven't seen this news,

540
00:39:58,754 --> 00:40:00,794
like that makes it 100% worth it.

541
00:40:01,334 --> 00:40:02,314
Any closing words

542
00:40:02,314 --> 00:40:03,034
for everyone who's listening?

543
00:40:04,134 --> 00:40:05,074
Closing words again.

544
00:40:05,994 --> 00:40:07,814
If you or someone you know

545
00:40:07,814 --> 00:40:11,794
has used an MK3, MK4, MK5, Q,

546
00:40:12,194 --> 00:40:13,614
any of those cold card products,

547
00:40:13,614 --> 00:40:18,194
without either rolling your own dice

548
00:40:18,194 --> 00:40:20,014
or having a sufficiently strong passphrase.

549
00:40:20,494 --> 00:40:21,314
And if your question is,

550
00:40:21,414 --> 00:40:22,754
is my passphrase strong enough?

551
00:40:22,934 --> 00:40:24,694
It means you don't understand the entropy,

552
00:40:24,874 --> 00:40:26,454
which means you need to go fix this immediately,

553
00:40:26,594 --> 00:40:27,414
even if it is, right?

554
00:40:27,494 --> 00:40:30,414
You just, if you don't know for a fact,

555
00:40:30,514 --> 00:40:32,654
oh yes, I have this many bits of entropy in my passphrase

556
00:40:32,654 --> 00:40:34,394
because you are super in the details.

557
00:40:34,654 --> 00:40:36,214
Your passphrase is not strong enough at the moment.

558
00:40:36,314 --> 00:40:39,534
You need to immediately make any moves and plans.

559
00:40:39,534 --> 00:40:41,094
You need to cancel your weekend plans.

560
00:40:41,474 --> 00:40:43,094
You need to get on a plane if you have to.

561
00:40:43,094 --> 00:40:45,934
You need to call a loved one who may be able to help you out remotely.

562
00:40:46,914 --> 00:40:51,454
This is a full five alarm fire.

563
00:40:51,714 --> 00:40:52,894
This is all hands on deck.

564
00:40:53,314 --> 00:41:03,154
I think everyone in the Bitcoin community has been trying to help through back channels and through direct messages, through being able to have people call you, find people, get connected to people.

565
00:41:03,354 --> 00:41:04,434
My DMs are open on Twitter.

566
00:41:04,554 --> 00:41:07,234
Like I said, I've talked to dozens of people across the whole ecosystem.

567
00:41:08,054 --> 00:41:11,594
None of them even Anchor Watch customers because Anchor Watch customers don't have an issue at the moment.

568
00:41:11,594 --> 00:41:18,454
Like this is not related to anything of how your funds are being kept safe at Anchor Watch.

569
00:41:18,714 --> 00:41:31,734
So all of that to be said, like reach out to those you may know, people you've ever referred to using a cold card and do what you can to try and help them out.

570
00:41:31,734 --> 00:41:39,934
And I think there's going to be an opportunity in the coming week, two weeks, to when the initial...

571
00:41:39,971 --> 00:41:47,351
race is over. We can focus on triage. We can focus on, well, once we move beyond triage,

572
00:41:47,391 --> 00:41:52,411
we can start focusing on where does the industry go from here. All right, Rob, I appreciate you,

573
00:41:52,411 --> 00:41:56,651
man. Thank you for all the work, helping people out on this terrible, terrible event, but

574
00:41:56,651 --> 00:41:59,991
Bitcoin will get through it, man. Thank you. Thank you.

575
00:42:09,971 --> 00:42:39,951
Thank you.
