1
00:00:00,000 --> 00:00:09,920
You've had a dynamic where money has become freer than free.

2
00:00:10,760 --> 00:00:15,680
If you talk about a Fed just gone nuts, all the central banks going nuts.

3
00:00:16,380 --> 00:00:17,860
So it's all acting like safe haven.

4
00:00:18,400 --> 00:00:23,500
I believe that in a world where central bankers are tripping over themselves to devalue their

5
00:00:23,500 --> 00:00:28,480
currency, Bitcoin wins. In the world of fiat currencies, Bitcoin is the victor.

6
00:00:28,480 --> 00:00:31,360
I mean, that's part of the bull case for Bitcoin.

7
00:00:31,800 --> 00:00:34,240
If you're not paying attention, you probably should be.

8
00:00:36,400 --> 00:00:43,740
Alex, the vibe has shifted from the last time we saw each other, which was a Thursday at the Galaxy event in D.C.

9
00:00:44,080 --> 00:00:45,360
Yeah, it was just shifting.

10
00:00:45,820 --> 00:00:55,180
I think you came maybe an hour before that PubKey event started and said there might be some issue with cold card.

11
00:00:55,180 --> 00:01:01,100
and I in my head I was like you know oh no but I was hosting that event so I got all

12
00:01:01,100 --> 00:01:06,980
tied up and I didn't realize that I didn't really see you the rest of the night until

13
00:01:06,980 --> 00:01:13,500
and then the next day I listened to your episode with James OB where you said that you were in a

14
00:01:13,500 --> 00:01:17,340
had to be in a corner on the phone the whole time which I of course now totally understand

15
00:01:17,340 --> 00:01:24,800
yeah pretty rough it's been a shitty week but uh I wanted to get you on because you and the team

16
00:01:24,800 --> 00:01:32,740
at Galaxy. I've done an incredible job of tracking the, um, the attackers. It looks like

17
00:01:32,740 --> 00:01:38,900
there's multiple waves of attacks of people, um, brute forcing private keys of those that were

18
00:01:38,900 --> 00:01:46,420
generated on cold card devices and contacting victims. And I think the knowledge you guys have

19
00:01:46,420 --> 00:01:51,380
gathered and the information that you've gathered over the last five days is important for people

20
00:01:51,380 --> 00:01:52,840
to understand what's going on.

21
00:01:52,980 --> 00:01:55,120
And so I have the chart here.

22
00:01:55,160 --> 00:01:56,060
Maybe we start there.

23
00:01:56,500 --> 00:01:56,660
Sure.

24
00:01:56,760 --> 00:01:58,360
Just what you guys have found

25
00:01:58,360 --> 00:02:00,700
based off of the information

26
00:02:00,700 --> 00:02:02,440
and the outreach they've gotten from victims.

27
00:02:02,560 --> 00:02:04,640
And I think you said so far, 94.

28
00:02:04,900 --> 00:02:05,500
Have you reached out to you?

29
00:02:05,800 --> 00:02:07,580
Yeah, it's in the mid-90s.

30
00:02:07,660 --> 00:02:10,560
I mean, it's growing.

31
00:02:10,860 --> 00:02:11,980
I mean, all the time.

32
00:02:12,060 --> 00:02:13,200
I mean, especially as I do,

33
00:02:13,720 --> 00:02:16,260
I did Nick Batia's show yesterday.

34
00:02:16,260 --> 00:02:17,980
I did Unchained yesterday,

35
00:02:18,120 --> 00:02:18,680
where, of course,

36
00:02:18,680 --> 00:02:25,060
I called for victims to not be ashamed. You did nothing wrong. You did not deserve this.

37
00:02:25,500 --> 00:02:31,320
Share. First of all, file police report. Well, first of all, secure. You haven't secured your

38
00:02:31,320 --> 00:02:36,480
funds on a potentially vulnerable cold card. Please do that immediately. But also share your

39
00:02:36,480 --> 00:02:41,860
drained addresses and the transaction IDs that drain them. I know, you know, it's hard for people

40
00:02:41,860 --> 00:02:47,300
to do it, but because I've been saying that people have been sharing and it's because of that sharing

41
00:02:47,300 --> 00:02:54,180
that we've been able to identify so many of the coins and where they are, what addresses they're sitting in.

42
00:02:54,520 --> 00:03:01,260
So, you know, it's also and sort of in exchange, although I don't think of it affected.

43
00:03:01,640 --> 00:03:09,400
Initially, I wasn't even doing it this way, but I can fulsomely trace anything in Bitcoin.

44
00:03:09,400 --> 00:03:17,720
I have a very powerful proprietary Bitcoin stack with some clanker sitting on top of it that helped me traverse.

45
00:03:17,880 --> 00:03:25,660
So I've been providing back like forensic reports to victims that they can then use to report to their local authorities, to the FBI,

46
00:03:26,080 --> 00:03:34,960
and that we can use as well to report to crypto exchanges and chain analysis and all that so that there's a chance that the funds get frozen.

47
00:03:34,960 --> 00:03:43,960
But please do continue to reach out and share those addresses with me so that we can keep building up the picture of the attack as it unfolds.

48
00:03:45,800 --> 00:03:49,340
And let's dive into the nature of these attacks.

49
00:03:49,420 --> 00:03:53,840
Obviously, it started late Thursday afternoon, early Thursday night.

50
00:03:53,840 --> 00:04:03,200
And I think it's become clear that AI was used to identify this vulnerability and then exploit it.

51
00:04:03,200 --> 00:04:09,460
And you can see that in the patterns of the waves of drainings that we've seen in the first wave.

52
00:04:09,600 --> 00:04:23,560
It seems apparent that the person who started draining the wallets of cold card users didn't really understand best practices or how to actually scope through a wallet.

53
00:04:23,980 --> 00:04:26,380
There was a very specific pattern to this first wave, correct?

54
00:04:26,620 --> 00:04:27,060
Yeah.

55
00:04:27,380 --> 00:04:31,140
So this pattern, I think they were the first.

56
00:04:31,140 --> 00:04:41,460
There's certainly where I learned of the pattern, which was the engineers at Block, Inc., obviously the guys behind Cash App, Aki, Spiral, etc., Square, right?

57
00:04:41,940 --> 00:04:45,180
They identified this pattern as a pattern, right?

58
00:04:45,200 --> 00:04:51,360
And a key piece of the pattern was a fixed 30 sat per V-byte fee on all draining transactions.

59
00:04:51,660 --> 00:05:00,1000
That was substantially higher than the median fee rate at the time, which being higher than the median is not in itself that surprising.

60
00:05:01,140 --> 00:05:05,440
right? Attackers are willing to overspend to make sure they, you know, get the funds. But,

61
00:05:05,440 --> 00:05:17,543
you know normal people with urgent transactions don have many bursts of transactions from previously unknown addresses with a fixed fee rate right

62
00:05:17,603 --> 00:05:24,183
Like your wallet, your typical wallets will suggest fee rates, you know, if you want to confirm in this amount of time.

63
00:05:24,303 --> 00:05:30,063
Fee estimation is actually a big thing Bitcoin Core itself has worked on in core, let alone all the other wallets, right?

64
00:05:30,063 --> 00:05:34,023
So that was a key feature of pattern of wave one.

65
00:05:34,023 --> 00:05:45,483
This is the only pattern of coins we have very high confidence in are stolen due to this vulnerability that was solely based on a pattern.

66
00:05:45,763 --> 00:05:47,623
And so they identified this pattern.

67
00:05:47,943 --> 00:05:50,043
It was very mechanical looking.

68
00:05:50,403 --> 00:05:58,183
There's a lot about it that looks like it was designed and then executed by automation, I'll say.

69
00:05:58,183 --> 00:06:03,703
And there are other patterns that also look like that.

70
00:06:04,023 --> 00:06:17,143
Right. These aren't they don't all look like that, but many of them have features in the topography of the movements and the design of the transactions themselves, the fee rates that look automated.

71
00:06:19,963 --> 00:06:28,583
What in terms of where these these coins are going to, I think the first wave had a lot of address for use, too.

72
00:06:28,583 --> 00:06:34,943
Yeah, so waves one and two, in effect, there's almost a better chart that I tweeted earlier.

73
00:06:36,363 --> 00:06:40,943
Well, I have a chart of wave one as a perfect example, wave one alone.

74
00:06:41,263 --> 00:06:47,243
These are called Sankey charts, and they show fun movements.

75
00:06:47,763 --> 00:06:51,183
This is just the highest level overview chart, right?

76
00:06:51,243 --> 00:06:53,903
This shows the various waves.

77
00:06:54,043 --> 00:06:56,943
Waves one, two, and three are high confidence promoted.

78
00:06:56,943 --> 00:07:01,863
That's where people are getting this like 1356 type number.

79
00:07:02,223 --> 00:07:10,083
I've also promoted like a lot of what we call footprints A through N.

80
00:07:10,943 --> 00:07:15,303
Some of them are pattern matched.

81
00:07:16,583 --> 00:07:25,043
But what I should say is that wave one was designed and then later confirmed, but first designed solely by pattern matching from block.

82
00:07:25,043 --> 00:07:49,503
I took the pattern they described they saw. I set off across the entirety of not just confirmed blocks and their transactions, but also the entire UTXO history. So that's not the UTXO set. That's the UTXO set at every single state in Bitcoin ledger ever. Right. It's literally like 3.8 billion rows that I have.

83
00:07:49,503 --> 00:07:53,183
Yeah, so if you look at wave one here, this is all wave one.

84
00:07:53,283 --> 00:07:56,023
Now, like each of these four funnels, right?

85
00:07:56,763 --> 00:08:05,683
These are many addresses in each case being consolidated into four independent what we call collectors, right?

86
00:08:05,763 --> 00:08:10,643
They're collectors because they consolidate stolen funds into one step.

87
00:08:10,803 --> 00:08:17,743
And then that collector sent to three second hop holding addresses.

88
00:08:17,743 --> 00:08:23,323
And you can see for some reason, there's this little gray band that comes out of the first funnel here.

89
00:08:23,723 --> 00:08:24,743
That's not another secondhand.

90
00:08:25,383 --> 00:08:31,903
That's actually still sitting in the collector, but I put it on the right side here just to show that, like, the right side is where the funds sit.

91
00:08:32,343 --> 00:08:40,463
So this is actually a pretty typical looking siphoning topology or topography.

92
00:08:40,603 --> 00:08:41,663
I'm not sure which.

93
00:08:42,183 --> 00:08:43,483
I think people know what I mean.

94
00:08:43,483 --> 00:08:49,343
that you see in like other types of crypto hacks, right?

95
00:08:49,663 --> 00:08:52,343
It all gets drained immediately into an address the hacker controls,

96
00:08:52,483 --> 00:08:55,923
and then often they move it to like the proper setup that they want, right?

97
00:08:56,623 --> 00:08:58,483
Now, sometimes what you see,

98
00:08:59,263 --> 00:09:02,923
especially in a hacker determined to exfiltrate the funds,

99
00:09:03,043 --> 00:09:04,263
you know, into the fiat system

100
00:09:04,263 --> 00:09:07,043
or into whatever other chosen currency they want,

101
00:09:07,343 --> 00:09:09,823
then you start to see radical things like peel chains

102
00:09:09,823 --> 00:09:13,323
where they blow up the held coins into like,

103
00:09:13,483 --> 00:09:19,623
hundreds or thousands of different pieces. And then later they, they, you know, rejigger them

104
00:09:19,623 --> 00:09:24,263
into 20 pieces that don't look the same. They do it again and again, right. Just to make it really

105
00:09:24,263 --> 00:09:31,263
difficult to track. Um, also often they siphon them into like if stable coins are ever stolen,

106
00:09:31,743 --> 00:09:35,883
they often immediately transfer them into ETH, right? Because it's more immutable than the

107
00:09:35,883 --> 00:09:41,003
stable coin, um, or Bitcoin sometimes immediately get sent through Thor chain and then sent onto

108
00:09:41,003 --> 00:09:46,383
ETH and then sent through another bridge into this thing because bridges are harder to track funds

109
00:09:46,383 --> 00:09:51,903
through. Unlike those, all of the coins here in wave one are just sitting inert in these three

110
00:09:51,903 --> 00:09:56,803
addresses on the right. So they have not moved, right? And this is also true for waves two and

111
00:09:56,803 --> 00:10:01,563
three. But one of the other things that's interesting here about wave one, and I didn't

112
00:10:01,563 --> 00:10:06,123
in the thread where you pulled this, don't have the wave two. Wave two looks quite similar as well.

113
00:10:06,123 --> 00:10:11,703
and where it's many victim addresses consolidated into a holding address

114
00:10:11,703 --> 00:10:14,603
and then moved to a second address where they currently sit inert.

115
00:10:15,983 --> 00:10:18,283
That is a very clear pattern, right?

116
00:10:18,363 --> 00:10:34,586
Like wave three which is the other one that in that thread just maybe if you pull up as an example looks totally different And I will say also there is no co between waves one two or three attacker addresses

117
00:10:36,846 --> 00:10:39,606
There were co-spends between those bottom two funnels.

118
00:10:39,606 --> 00:10:43,266
So this is wave three. This is actually much more sophisticated.

119
00:10:44,226 --> 00:10:49,546
There is no common collector address. This is 293 chains.

120
00:10:49,546 --> 00:10:54,346
And by chains here, we mean like, you know, inputs like category groups of inputs.

121
00:10:54,346 --> 00:11:04,446
So three, 293 transactions funding, 293 staging addresses funding, 293 P2SWH vaults.

122
00:11:04,566 --> 00:11:18,726
Right. So each group of victim addresses was by itself moved into a staging one and then by itself moved into a vault, which could be a multisig.

123
00:11:18,726 --> 00:11:23,426
We wouldn't know until they spend transactions, but none of those have been spent.

124
00:11:24,086 --> 00:11:34,746
I think all but six of the 293 staging addresses only contained funds from one wallet.

125
00:11:34,986 --> 00:11:39,606
And now we can see that because of like co-spends of the wallets.

126
00:11:39,746 --> 00:11:45,206
And I also have a lot of victims that I've identified that are in these, right?

127
00:11:45,206 --> 00:11:54,966
And so the other thing is like wave one was a pattern that was described by block, which I expanded and later has been confirmed by many victim testimonies, reports.

128
00:11:55,846 --> 00:12:01,166
Waves two and three were identified by Galaxy Research solely by victim reports.

129
00:12:01,586 --> 00:12:04,146
Right. Like people started saying my coins were lost.

130
00:12:04,146 --> 00:12:10,046
And when I gathered like 10 from wave two or like 10 from wave three, it started to become apparent.

131
00:12:10,746 --> 00:12:15,006
It didn't actually take 10. It takes fewer than you realize, because once you get like two or three that look alike.

132
00:12:15,206 --> 00:12:29,686
You send the clankers off to look at all the blocks all around that and say, does anything else look like a bunch of addresses into a staging address into a, you know, paid a what script witness script hash was script witness that whatever into a vault.

133
00:12:29,686 --> 00:12:35,786
Right. Then you say, oh, my gosh, there's an entire burst of of transactions that look exactly like that.

134
00:12:35,966 --> 00:12:40,626
And that's how, you know. And then, of course, I start publishing about it.

135
00:12:40,726 --> 00:12:43,866
People start saying, I think I might be in wave three. They send me their stuff.

136
00:12:43,866 --> 00:12:46,546
If we get further corroboration, it becomes like high confidence.

137
00:12:47,406 --> 00:12:51,846
So, you know, one another interesting feature of one and two, I told you they look similar, right?

138
00:12:51,846 --> 00:12:57,306
Many victims into very few staging addresses, then into second hops where they're inert.

139
00:12:59,046 --> 00:13:06,706
The only two of one like of really there's a couple down talk about footprints, which are these smaller operators that have emerged.

140
00:13:06,706 --> 00:13:14,786
But there are a pretty sizable number of people who were drained in wave one that were not completely drained who were later fully drained in wave two.

141
00:13:15,286 --> 00:13:24,126
So there's a number of those that gives us some, I would say, medium to high confidence that wave one and wave two are the same attacker.

142
00:13:25,186 --> 00:13:26,686
Now, you know, someone could.

143
00:13:26,786 --> 00:13:34,166
And by the way, wave one, to your point, was all just after midnight, July 30th, UTC.

144
00:13:34,166 --> 00:13:50,386
So some people were like, oh, I was July 29th. And it was like, no, if you look, you were like, you know, West Coast, July 29th at night. That was actually early morning UTC, July 30th. We use UTC because that's like the default Bitcoin core and stuff. So it's just like easier to pick one.

145
00:13:50,386 --> 00:13:57,186
wave one happened in 41 minutes, very identifiable, right? Like you don't usually,

146
00:13:57,286 --> 00:14:02,926
because another big identifying feature is that not one of the high confidence, what I call

147
00:14:02,926 --> 00:14:07,226
promoted, meaning like we're saying these are drained, like these no longer a question,

148
00:14:07,766 --> 00:14:13,966
not one of those UTXOs was created before March 17th, 2021, when the, you know, cold card

149
00:14:13,966 --> 00:14:19,506
firmware bug was introduced. And I will say like, there's other patterns, like the median

150
00:14:19,506 --> 00:14:26,426
dormancy of all these coins is like four years. An enormous portion of the coins in waves one,

151
00:14:26,426 --> 00:14:32,806
two, and three, which are the majority still of high confidence victim addresses,

152
00:14:33,466 --> 00:14:39,286
the vast majority had never spent a coin. So these are just receiving coins,

153
00:14:39,606 --> 00:14:45,766
very indicative of people stacking sats into their cold card and in cold storage.

154
00:14:45,766 --> 00:14:54,886
so you know I think like there's co-spend which can help identify but again everything after wave

155
00:14:54,886 --> 00:14:59,806
one were patterned to the extent we found patterns there are some where I'm not seeing a pattern but

156
00:14:59,806 --> 00:15:06,466
I have a victim report it the one that I see it looks credible and drained and so we've

157
00:15:06,466 --> 00:15:12,226
incrementally added those two but also we found something like we're up to I think in the graphic

158
00:15:12,226 --> 00:15:17,246
the first graphic you showed, we're up to footprint N. That means we have multiple,

159
00:15:17,346 --> 00:15:22,546
the footprints are, we have multiple victims where the topography looks similar. They don't

160
00:15:22,546 --> 00:15:27,406
necessarily co-spend. A few of these co-spend, and so we're very confident and have promoted.

161
00:15:29,506 --> 00:15:42,969
But as you can see this graphic is everything that we haven yet confirmed This goes up well over 2 Bitcoin The shaded ones are I think not confirmed right by any owner right These are patterns that we found but haven yet

162
00:15:42,969 --> 00:15:49,249
gotten a confirmation at all. Some of those footprints are, they're identified by the fact

163
00:15:49,249 --> 00:15:54,428
that victims showed us. And we've, you know, said, is there anything else that looks like this? But

164
00:15:54,428 --> 00:16:01,928
we don't quite have enough confirmation that we should extrapolate it out to transactions that we

165
00:16:01,928 --> 00:16:06,309
don't actually have confirmed by a victim, right? Because there are plenty of transactions in waves

166
00:16:06,309 --> 00:16:11,209
one and two and three that we haven't actually gotten a victim report about, but we're very

167
00:16:11,209 --> 00:16:16,769
confident are part of the wave. So that's just up some background on the methodology that we've

168
00:16:16,769 --> 00:16:23,989
been doing. And just as background, like I have direct victim confirmation for about 400 Bitcoin

169
00:16:23,989 --> 00:16:28,069
of the 1500 or so that we currently call high,

170
00:16:28,249 --> 00:16:30,229
you know, value promote, promote.

171
00:16:30,428 --> 00:16:33,789
So a sizable amount have I've talked to.

172
00:16:34,649 --> 00:16:35,168
Yeah.

173
00:16:38,029 --> 00:16:40,369
It's so hard wrenching.

174
00:16:41,489 --> 00:16:42,009
Yeah.

175
00:16:42,229 --> 00:16:44,769
But I think explaining if you haven't,

176
00:16:44,829 --> 00:16:45,848
if you have a cold card,

177
00:16:46,289 --> 00:16:47,689
I don't care what your setup is.

178
00:16:47,869 --> 00:16:49,469
I mean, if you roll dice, you should be fine.

179
00:16:49,469 --> 00:16:52,548
But if you don't have confidence that you did it correctly,

180
00:16:52,548 --> 00:16:53,529
just get it off.

181
00:16:53,529 --> 00:17:23,289
I agree. Yeah. And I want another important thing to say, but again, and I have a cold card MK3, I believe with no password and no dice in a multi-sig quorum that cannot reach signing threshold. So it really can't be affected at the moment. And in that quorum, I've never spent. So there, the address isn't known to hold coins on chain, for example, because it's, you know, like a, it's a script hash address.

182
00:17:23,289 --> 00:17:25,629
that has never revealed its script, right?

183
00:17:26,629 --> 00:17:28,189
But I, and I haven't,

184
00:17:28,448 --> 00:17:31,569
because I know that that isn't vulnerable at the moment,

185
00:17:31,569 --> 00:17:34,369
I haven't actually rotated the cold card out yet,

186
00:17:34,769 --> 00:17:36,008
but I absolutely will.

187
00:17:36,929 --> 00:17:38,208
So, and I will say,

188
00:17:38,708 --> 00:17:42,188
I haven't updated this analysis since like midday yesterday,

189
00:17:42,188 --> 00:17:44,508
but I can say in waves one, two, and three,

190
00:17:44,609 --> 00:17:47,529
for sure there are zero multi-sigs identifiable.

191
00:17:48,089 --> 00:17:49,188
So as far as I'm concerned,

192
00:17:49,188 --> 00:17:51,589
there's no evidence that any multi-sig setup

193
00:17:51,589 --> 00:17:58,929
has been breached here. Now, of course, if you had like say a two of three multi-sig quorum

194
00:17:58,929 --> 00:18:04,769
where two of three are cold card MK3s like mine with no passphrase and no dice roll,

195
00:18:05,049 --> 00:18:11,109
that is vulnerable. I haven't seen one instance yet of it being attacked. It's probably,

196
00:18:11,349 --> 00:18:17,529
you know, Rob Hamilton and the red team working on this is probably more, and James OB are probably

197
00:18:17,529 --> 00:18:23,508
more apt to actually talk about that, but I understand that's probably lower on the tier

198
00:18:23,508 --> 00:18:28,669
of priorities that the black hats are looking at to search namespace for. It's more complicated.

199
00:18:29,488 --> 00:18:36,849
But all that being said, I am of the view that anything on a cold card at all, including my

200
00:18:36,849 --> 00:18:45,109
sub-threshold quorum key, should be rotated. I mean, there's just no reason to stick around if

201
00:18:45,109 --> 00:18:46,829
you have any doubt whatsoever, in my opinion.

202
00:18:46,829 --> 00:18:51,129
What's up, freaks? This rep was brought to you by our good friends at Square. If you run a business,

203
00:18:51,289 --> 00:18:54,609
you need payments. You need hardware, you need software, invoices, point-of-sale tools,

204
00:18:54,688 --> 00:18:58,909
and a system that does not turn every basic operational task into a headache. Square spent

205
00:18:58,909 --> 00:19:03,468
years making it easier for small businesses to get paid and keep moving. And now, with Block

206
00:19:03,468 --> 00:19:07,708
leaning deeper into Bitcoin, Square sits at an important intersection. Real-world merchants,

207
00:19:08,008 --> 00:19:11,688
payment infrastructure, and the future of Bitcoin commerce. We're making Bitcoin everyday money,

208
00:19:11,688 --> 00:19:16,289
freaks. You are starting or upgrading your business setup. You can get up to $200 off Square

209
00:19:16,289 --> 00:19:22,188
hardware at square.com slash go slash TFTC. All right, freaks, you know, I don't take sponsor

210
00:19:22,188 --> 00:19:25,829
money from products. I wouldn't use myself. So listen up. The Avon Bitcoin Visa card is one of

211
00:19:25,829 --> 00:19:29,329
the most interesting things I've seen in the Bitcoin lending space in a long time. Here's the

212
00:19:29,329 --> 00:19:33,948
deal. You can get a line of credit up to a million dollars backed by your Bitcoin without selling a

213
00:19:33,948 --> 00:19:39,349
single sat. No games, no annual fees, no minimum draws. And your Bitcoin is custodied by Bitco,

214
00:19:39,429 --> 00:19:43,429
one of the most trusted names in digital asset security. Avon never lends it out. There's no

215
00:19:43,429 --> 00:19:49,468
rehypothecation, you stay in control. You can lock in a fixed rate for up to 10 years. 10 years,

216
00:19:49,549 --> 00:19:53,968
that's 10 times longer than most lenders out there. We'll go interest only for up to five years.

217
00:19:54,488 --> 00:19:59,948
Rates start at 8.99% APR. For a product that lets you keep your stack and still access liquidity,

218
00:20:00,149 --> 00:20:04,809
it's hard to beat. On top of this, that's what, you also get 2% unlimited cash back every time

219
00:20:04,809 --> 00:20:09,988
you use the card. Spend fiat, keep your Bitcoin, that's the whole game. If you've been stacking for

220
00:20:09,988 --> 00:20:14,968
years and need liquidity without triggering a taxable event this is worth a serious look go to

221
00:20:14,968 --> 00:20:23,049
aven.com slash bitcoin that's aven.com slash bitcoin check it out yeah it's a timing thing

222
00:20:23,049 --> 00:20:28,329
that i mean bringing this back to the waves um obviously waves one and two at a very specific

223
00:20:28,329 --> 00:20:34,289
pattern but that is the game theory at play right now it's just a ticking time bomb if you have

224
00:20:34,289 --> 00:20:42,529
private keys generated with the affected versions of the firmware which started being released in

225
00:20:42,529 --> 00:20:49,968
march of 21 so i think version 4.0.0 and beyond are affected different models have different

226
00:20:50,011 --> 00:20:56,111
levels of entropy. Older models, I think, have more, pretty confident of more entropy,

227
00:20:56,251 --> 00:21:00,991
but still not a sufficient amount of entropy to protect you from a brute force attack. So

228
00:21:00,991 --> 00:21:04,391
move your coins if you haven't already. And the game theory is such that once

229
00:21:04,391 --> 00:21:09,151
the alarm bell was sounded last Thursday and it became obvious that this was exploitable,

230
00:21:09,151 --> 00:21:15,111
you just have to assume that other actors are going to enter the fray to try to exploit this

231
00:21:15,111 --> 00:21:22,071
too so the time bomb could be accelerating the pace of the clicking ticking of the talk can be

232
00:21:22,071 --> 00:21:30,691
accelerating so move with haste um and i think that's another weird factor that's entered the

233
00:21:30,691 --> 00:21:35,991
conversation too is there's i mean i've been listening to spaces and following this discussion

234
00:21:35,991 --> 00:21:39,411
since thursday night on the train right back people were already talking about this because

235
00:21:39,411 --> 00:21:44,351
So you had people like Wicked Bitcoin, Portland HODL, Rob Hamilton, Praveen,

236
00:21:44,711 --> 00:21:53,311
basically downloading the scripts to brute force private keys or seed phrases on their computers.

237
00:21:53,311 --> 00:22:02,531
And they were able to identify wallets and the ethical conundrum of do we sweep this as white hat hackers into addresses that we control and hope that we can get this back to.

238
00:22:02,851 --> 00:22:06,391
The original owner, that conversation started pretty early Thursday night.

239
00:22:06,391 --> 00:22:22,371
I think there has been confirmation that some people have engaged in white hat sweeping of these coins, but it gets into the, again, the ethical dilemma, but then the logistics of even if you do that, how do you get the coins back? And I think that's another important detail.

240
00:22:22,371 --> 00:22:31,591
Well, if there is a scenario in which we identify the attacker

241
00:22:31,591 --> 00:22:35,551
or white hats have swept funds and they want to return them,

242
00:22:35,911 --> 00:22:40,031
I think the ability to prove that you were the individual

243
00:22:40,031 --> 00:22:43,671
that actually created the private key initially

244
00:22:43,671 --> 00:22:46,451
depends on you actually having your physical device.

245
00:22:48,151 --> 00:22:51,951
Yeah, and you mentioned a couple people there too.

246
00:22:51,951 --> 00:22:53,391
You got a shout out to Wicked.

247
00:22:53,771 --> 00:22:54,051
Wicked.

248
00:22:54,251 --> 00:22:55,131
I think, what is he?

249
00:22:55,151 --> 00:22:56,031
Wicked Smart Bitcoin?

250
00:22:56,251 --> 00:22:56,431
Is that?

251
00:22:56,871 --> 00:22:58,411
And he doesn't even say that anymore.

252
00:22:58,411 --> 00:23:07,331
But that guy's been doing like spaces, just helping people do, you know, answering Q&A on self-custody at the most granular level.

253
00:23:07,551 --> 00:23:14,131
I have literally listened to him help dozens of people like move coins off their gold cards live.

254
00:23:14,671 --> 00:23:16,871
Reminds me of the old clubhouse days a bit.

255
00:23:17,891 --> 00:23:23,431
what um because i know you identified somebody i forget from which wave that sent it to

256
00:23:23,431 --> 00:23:31,011
a casino yeah this this one was pretty ugly like um not from waves one two or three

257
00:23:31,011 --> 00:23:36,231
those coins are inert they're not they haven't moved right and those are the key ones that we

258
00:23:36,231 --> 00:23:43,011
were watching um because they comprise the largest share of the known stolen coins one two and three

259
00:23:43,011 --> 00:23:52,971
yeah there was a victim that we traced and that i think seven or ten of their 17 bitcoin was

260
00:23:52,971 --> 00:23:59,251
instantly moved to thor chain which is a cross chain dex that lets you effectively send bitcoin

261
00:23:59,251 --> 00:24:05,711
into a multi-sig controlled by their validators and you can put an ethereum address for example

262
00:24:05,711 --> 00:24:12,651
and a trade order in an opera turn and then they spit out the equivalent eth on the other side

263
00:24:12,651 --> 00:24:17,711
in Ethereum. And so you enter your Ethereum address in the hop return, plus some other

264
00:24:17,711 --> 00:24:24,611
instructions about the trade that you want done. Luckily, the way it works is it's pretty easy to

265
00:24:24,611 --> 00:24:30,951
trace through there, at least in my limited experience tracing. And then it's a matter of

266
00:24:30,951 --> 00:24:37,071
using the Etherscan API to follow where it goes. And Etherscan has a lot of deposit addresses for

267
00:24:37,071 --> 00:24:45,071
exchanges and services labeled. These were something like, I don't know, $450,000 worth of

268
00:24:45,071 --> 00:24:52,651
the Bitcoin now ETH was deposited in an offshore casino that I'd never heard of called dual.com.

269
00:24:53,571 --> 00:24:59,831
And so I told the victim this and gave instructions on how to send a preservation

270
00:24:59,831 --> 00:25:03,931
request and a freeze request to the casino.

271
00:25:03,931 --> 00:25:09,611
And this was like at 1 a.m. on Sunday morning, so like late Saturday night, Eastern time.

272
00:25:10,611 --> 00:25:15,231
And they did get a response and it was like, we're not going to freeze until we get a police

273
00:25:15,231 --> 00:25:16,471
report demanding the freeze.

274
00:25:16,651 --> 00:25:23,151
And I found that to be offensive because it was midnight on weekend.

275
00:25:23,431 --> 00:25:29,591
There was literally zero chance that a police report was going to be sent anytime soon.

276
00:25:29,831 --> 00:25:53,351
And I thought the prudent measure for any sort of financial institution when receiving a credible cryptographic forensic report effectively proving that the funds emanated from a stolen address would be sufficient to just take the coins from the casino depositor.

277
00:25:53,471 --> 00:26:12,688
I saying don allow them to be withdrawn right until an investigation is complete I guess they declined to do that though They did promise me via DM that they would preserve the information about it which you know and I don know what jurisdiction this dual is actually registered in or if they are

278
00:26:12,788 --> 00:26:14,728
but that may be all that's required.

279
00:26:15,188 --> 00:26:22,328
And, you know, they wrote back on X that it was unreasonable to demand solely based on a report

280
00:26:22,328 --> 00:26:24,768
that their customers could not withdraw.

281
00:26:24,768 --> 00:26:32,388
all, it is an interesting thing about, it raises a lot of interesting ideas. One is that, you know,

282
00:26:32,488 --> 00:26:39,628
I have the victim report. The victim can prove they do possess the keys. But the nature of this

283
00:26:39,628 --> 00:26:48,388
exploit is that they are not the only one who now possesses the keys. And eventually, everyone

284
00:26:48,388 --> 00:26:50,948
might possess the keys to all of these coins, right?

285
00:26:52,528 --> 00:26:54,128
And that's tricky.

286
00:26:54,388 --> 00:26:56,708
That's one reason why we really encourage people

287
00:26:56,708 --> 00:27:00,448
to formally file victim reports with the local police,

288
00:27:01,488 --> 00:27:04,928
the FBI's IC3, Canada's Anti-Fraud Center,

289
00:27:05,208 --> 00:27:08,988
the Royal Canadian Mounted Police.

290
00:27:09,188 --> 00:27:10,348
I've got a whole list, by the way,

291
00:27:10,388 --> 00:27:12,648
if people need to know who to contact in their jurisdiction.

292
00:27:13,568 --> 00:27:15,128
These exist all over the world, right?

293
00:27:15,508 --> 00:27:17,928
Some of them share information with each other and all that.

294
00:27:18,388 --> 00:27:25,428
is to establish victimhood early because there could be a time if funds are recovered where many people use keys to claim that they're theirs, right?

295
00:27:25,488 --> 00:27:26,488
And it becomes a whole cluster.

296
00:27:27,028 --> 00:27:33,868
That's why I also tell people not to destroy their cold cards even after they've moved funds off of them or had their funds drained

297
00:27:33,868 --> 00:27:42,888
because there might be forensic evidence on the cold card that can be used to establish that they're the primary owner in the chain.

298
00:27:42,888 --> 00:27:48,308
And another thing that it raises is the question of hold authority.

299
00:27:48,308 --> 00:27:57,568
This came up once recently with a hack, a DeFi hack, and I'm forgetting which one it is.

300
00:27:58,048 --> 00:28:16,768
There's been many where ZaxxBT and others notified very early to Circle that funds were being exfiltrated and bridged over Circle's sort of, I think it's called CCTP, cross-chain stablecoin bridge,

301
00:28:16,768 --> 00:28:22,528
which is an interesting version of a bridge, by the way, that's more secure than some of the lockup funds on one side,

302
00:28:22,628 --> 00:28:26,748
reissue them on the other, because it goes through Circle, but it goes through Circle.

303
00:28:26,888 --> 00:28:31,668
So Circle is the issuer of USDC, just cancels them on one chain and reissues them to you on the other,

304
00:28:32,108 --> 00:28:40,108
which is actually safer in a lot of ways because it's not like locking them up to create a honeypot on one side of the chain,

305
00:28:40,168 --> 00:28:43,708
which is how so many DeFi bridges are exploited.

306
00:28:43,708 --> 00:28:48,928
anyway they didn't they'd circle declined to stop this even though they'd been warned for like six

307
00:28:48,928 --> 00:28:52,748
hours loudly on twitter that this was happening and they said that they needed what was called

308
00:28:52,748 --> 00:28:59,248
hold authority um this is now in clarity this idea of hold authority it says that you know if you

309
00:28:59,248 --> 00:29:04,688
credibly know that or have reports that there's you know this type of fraud whatever going through

310
00:29:04,688 --> 00:29:12,068
your centralized platform you you can hold it uh freeze it on your platform for some amount of

311
00:29:12,068 --> 00:29:18,068
time, I think in clarity, it's 48 hours while you investigate and you are totally immune from civil

312
00:29:18,068 --> 00:29:22,708
liability. So I understand, you know, I think there's an argument to be made in the case of

313
00:29:22,708 --> 00:29:27,788
the duel.com with this one that I talked about, like, you know, are they worried about being sued

314
00:29:27,788 --> 00:29:32,528
by their client who they promised, you know, their user, you know, instant withdrawals? I,

315
00:29:32,528 --> 00:29:37,768
you know, I get that it's a little tricky, but I'm becoming a little bit like, you know,

316
00:29:37,768 --> 00:29:43,268
Tevano, if people follow her, who used to was like head of security at Metamask and had my Ether wallet.

317
00:29:43,608 --> 00:29:49,168
Big, big, I think, participant in the SEAL rapid response crypto hacks team.

318
00:29:49,628 --> 00:29:52,148
She is just zero patience for this type of behavior.

319
00:29:52,148 --> 00:30:04,208
And just the more people I've talked to from the cold card hack and seeing this type of thing and just like knowing the funds are there and not being able to get them to act is incredibly frustrating.

320
00:30:05,148 --> 00:30:13,708
So, yeah, we haven't, I got to say, the vast majority of coins, we have not seen that type of exfiltration behavior from.

321
00:30:15,888 --> 00:30:16,848
Maybe there's luck.

322
00:30:16,968 --> 00:30:19,728
Maybe they do have KYC at dual.com.

323
00:30:19,888 --> 00:30:24,328
And, you know, with the police report, maybe they'll be able to identify that hacker.

324
00:30:24,468 --> 00:30:26,328
But that's the other part of the story, Marty.

325
00:30:27,008 --> 00:30:28,248
That is definitive.

326
00:30:28,548 --> 00:30:30,548
Well, it could also be, but very doubtful.

327
00:30:30,548 --> 00:30:35,288
So I would say definitively not the same hacker from Waves 1, 2, and 3.

328
00:30:36,128 --> 00:30:45,428
Well, didn't Block report that Waves 1, 2, and 3, the hacker was obviously using some chain analysis tool that was a paid service?

329
00:30:45,748 --> 00:30:52,528
Yeah, I think this is Wave 1 in particular, which is the one that they really blogged about where I got that first pattern to work with.

330
00:30:52,528 --> 00:30:56,308
they said that, and I don't know how they figure this out,

331
00:30:56,628 --> 00:31:01,088
but I think Clay from Block said that they,

332
00:31:01,448 --> 00:31:02,868
from BitKey, I believe, right,

333
00:31:03,188 --> 00:31:04,948
said that they confirmed this

334
00:31:04,948 --> 00:31:07,628
with the blockchain infrastructure provider.

335
00:31:08,428 --> 00:31:24,504
I don know the details but what I do know and what they said was and what I assume is a blockchain infrastructure provider is like a in this case a party that you can connect to their RPC right

336
00:31:24,544 --> 00:31:30,644
And pull blockchain data from. Potentially for many chains, right? They have APIs or RPC providers.

337
00:31:30,644 --> 00:31:35,564
There are many of these, to be clear. It's a great service, especially for, you know, blockchains

338
00:31:35,564 --> 00:31:40,524
like Ethereum and Solana, which are even more cumbersome to run than Bitcoin, right?

339
00:31:41,044 --> 00:31:44,624
Many people use these for many, obviously, to be clear, obviously, totally legitimate

340
00:31:44,624 --> 00:31:45,044
reasons.

341
00:31:45,624 --> 00:31:51,744
But somehow, Block said that they had identified that the same entity they believed to, this

342
00:31:51,744 --> 00:31:59,084
pattern they observed that, what I now call Wave 1, had queried, like, I guess, a lot

343
00:31:59,084 --> 00:32:03,804
of the addresses that they ultimately attacked through this blockchain provider, and that

344
00:32:03,804 --> 00:32:09,244
in talking with the blockchain provider, they learned that this entity had used a paid account

345
00:32:09,244 --> 00:32:16,244
at the blockchain provider. So I think this is very promising as potentially the ability and

346
00:32:16,244 --> 00:32:23,844
that authorities have been notified. So potentially the wave one attacker could be identified. And

347
00:32:23,844 --> 00:32:28,984
that could be very, very promising, you know, knock on wood. I don't want to, you know,

348
00:32:28,984 --> 00:32:35,584
get ahead of ourselves here but um you know you know say run your own node verify your own

349
00:32:35,584 --> 00:32:41,524
transactions in the blockchain apparently wave one hacker did not do that so even though it would

350
00:32:41,524 --> 00:32:46,764
have been pretty trivial to do so yeah he didn't spin up his own node and that i mean that that

351
00:32:46,764 --> 00:32:51,424
begs the question too like what what can these attackers do now if they have the coins obviously

352
00:32:51,424 --> 00:32:56,944
you mentioned like thor chain and split there are things i i think yeah i've seen some bitcoiners who

353
00:32:56,944 --> 00:33:02,304
aren't as, haven't, you know, followed or been as close to like, most of these hacks are like

354
00:33:02,304 --> 00:33:07,824
centralized exchanges or like smart contracts and DeFi, right? Historically, bridges, DEXs,

355
00:33:08,484 --> 00:33:13,764
obviously centralized exchanges, you know, many such instances.

356
00:33:15,784 --> 00:33:21,524
It doesn't happen very often in the Bitcoin ecosystem directly outside of centralized

357
00:33:21,524 --> 00:33:26,644
exchanges because there is no DeFi on Bitcoin, right? It's a pretty simple protocol, which

358
00:33:26,644 --> 00:33:31,744
makes it a lot more secure, in my view, at the protocol level than many of these others,

359
00:33:31,784 --> 00:33:37,624
which are much more complicated. And it doesn't have the generalized scripting that others do.

360
00:33:37,624 --> 00:33:42,044
So you don't have people creating novel new programs and stuff like that. Multisig is native

361
00:33:42,044 --> 00:33:46,944
on Bitcoin, whereas it's not on Ethereum, et cetera, et cetera. So people have been saying,

362
00:33:47,064 --> 00:33:53,944
well, what can they do? We can track it everywhere. The hackers can themselves be

363
00:33:53,944 --> 00:34:00,104
expert money launderers. They can pay money launderers. These people exist. They have

364
00:34:00,104 --> 00:34:06,884
methods. It is possible for them to exfiltrate these coins. It is hard. It's definitely hard.

365
00:34:07,564 --> 00:34:14,104
There are mixers and tumblers in the Bitcoin world that they could use, but those are very

366
00:34:14,104 --> 00:34:22,284
watched targets by law enforcement. You can bridge to another network that has privacy protocols.

367
00:34:22,284 --> 00:34:30,504
Right. The fact that the one we talked about, the one to dual dot com didn't go through like tornado cash first on ETH before going to dual dot com is surprising.

368
00:34:30,944 --> 00:34:37,824
Suggests they really were not very sophisticated, even even though this attack seems so sophisticated and it is pretty sophisticated.

369
00:34:38,484 --> 00:34:43,664
That shows you like how it's degrading, like waves one and two and three are more sophisticated.

370
00:34:43,664 --> 00:34:46,504
And who knows why they're sitting inert on Bitcoin?

371
00:34:46,504 --> 00:34:54,604
I can tell you it's not because it's impossible for them to exfiltrate the funds, but it is difficult to do so without getting caught.

372
00:34:54,984 --> 00:35:06,164
And that is a silver or potential positive that it isn't easy, but I would caution, don't hang your hat on that.

373
00:35:06,204 --> 00:35:08,624
It is possible to launder money out of Bitcoin.

374
00:35:09,264 --> 00:35:09,744
Freaks, look at me.

375
00:35:09,784 --> 00:35:10,204
I'm glowing.

376
00:35:10,504 --> 00:35:12,844
I've got like an angel's halo going around me.

377
00:35:13,064 --> 00:35:13,824
You know why that is?

378
00:35:13,844 --> 00:35:14,664
I feel good.

379
00:35:14,724 --> 00:35:15,604
I feel taken care of.

380
00:35:15,604 --> 00:35:17,364
I feel blessed, healthy, happy.

381
00:35:17,644 --> 00:35:19,064
And that is because I'm a CrowdHealth member.

382
00:35:19,344 --> 00:35:23,204
My family and I have been CrowdHealth members for five years now, literally this month.

383
00:35:23,364 --> 00:35:24,544
Five years ago, we joined CrowdHealth.

384
00:35:24,644 --> 00:35:25,464
We've had two babies.

385
00:35:25,744 --> 00:35:29,204
We've had multiple health events, and we're never going back to health insurance.

386
00:35:29,544 --> 00:35:31,444
CrowdHealth is crowdfunded healthcare.

387
00:35:31,784 --> 00:35:36,304
So you sign up for CrowdHealth, you pay a monthly fee, you help out with other people's bills.

388
00:35:37,124 --> 00:35:40,004
And it's significantly cheaper than health insurance.

389
00:35:40,004 --> 00:35:40,704
We were on COBRA.

390
00:35:40,824 --> 00:35:41,664
It's a family of three.

391
00:35:42,044 --> 00:35:45,184
When I left my last job before I went full-time with CFTC,

392
00:35:45,604 --> 00:35:52,544
went on the crowd health. Now as a family of five, we pay, I believe $700 a month. It's significantly

393
00:35:52,544 --> 00:35:57,484
cheaper. They're going to negotiate prices lower for you. They've consistently negotiated healthcare

394
00:35:57,484 --> 00:36:03,504
prices as much as 50, 60, 80%. In many cases, they help out with babies. If you have a pregnancy,

395
00:36:03,724 --> 00:36:09,004
you pay the first $3,000 and the crowd covers the rest. If you have a regular health event,

396
00:36:09,004 --> 00:36:13,744
you pay $500 and the crowd pays the rest. Go to joincrowdhealth.com. Sign up today,

397
00:36:13,744 --> 00:36:18,824
use the code TFTC, opt out of health insurance. I'm an insured baby and I love it. Use the code

398
00:36:18,824 --> 00:36:36,100
TFTC at joincrowdhealth and you get a month for the first three months that you on the CrowdHealth platform in the community Bitcoiners you found sovereign money now find sovereign health and sovereign healthcare What up freaks When you take Bitcoin seriously you start with custody You want to control your keys avoid single points

399
00:36:36,100 --> 00:36:39,820
of failure, and make sure your savings cannot disappear because you or someone else screwed up.

400
00:36:39,900 --> 00:36:43,900
That is what Unchained has been focused on since 2016. Unchained is the leader in collaborative

401
00:36:43,900 --> 00:36:48,260
multi-sig custody and Bitcoin financial services that keep you in control. They secure over $12

402
00:36:48,260 --> 00:36:52,900
billion dollars in bitcoin for more than 12 000 clients that means about one out of every 200

403
00:36:52,900 --> 00:36:57,420
bitcoin sits inside an unchained vault their model is simple you hold two keys they hold one key it

404
00:36:57,420 --> 00:37:01,700
always takes two keys to move bitcoin meaning their single key can't access your bitcoin on its own

405
00:37:01,700 --> 00:37:05,400
just resilient shared custody that gives you institutional grade security while keeping you

406
00:37:05,400 --> 00:37:08,960
sovereign unchained also lets you trade straight from your vault access bitcoin-backed commercial

407
00:37:08,960 --> 00:37:13,600
loans open a bitcoin ira where you hold your own keys and set up personal business trust or

408
00:37:13,600 --> 00:37:18,360
retirement vaults. They even offer inheritance solutions built for long-term hodlers. Or opt for

409
00:37:18,360 --> 00:37:22,020
the highest level private client service with Unchained Signature and get a dedicated account

410
00:37:22,020 --> 00:37:26,500
manager, discounted trading fees, exclusive access to events and features, and much, much more.

411
00:37:26,600 --> 00:37:29,920
If you want a partner that helps you secure and grow your Bitcoin without giving up control,

412
00:37:30,060 --> 00:37:35,220
go to unchained.com and use the code TFTC10 at checkout to get 10% off your new Bitcoin

413
00:37:35,220 --> 00:37:40,980
multisig vault. That's TFTC10 at unchained.com. I mean, there's been a massive reaction. Obviously,

414
00:37:40,980 --> 00:37:48,700
you and your team are tracking this but it seems like um there has been somewhat of a immune response

415
00:37:48,700 --> 00:37:57,720
to not only obviously for um cold card victims but it has incited this urgency across the industry

416
00:37:57,720 --> 00:38:03,280
to begin auditing every system and that's yeah something that's been fascinating to watch unfold

417
00:38:03,280 --> 00:38:10,260
over the last five days is the speed with which um rob hamilton the new ceo of bitcoin and uh

418
00:38:10,260 --> 00:38:18,660
the red team that are working on, um, uh, basically auditing as many projects as possible,

419
00:38:18,660 --> 00:38:23,660
um, are uncovering, I mean, they haven't disclosed any, but, and Rob did come out and

420
00:38:23,660 --> 00:38:29,580
confirm that all the vulnerabilities that they have found so far do not put funds at risk

421
00:38:29,580 --> 00:38:35,000
immediately. Um, or funds at risk at all. I believe he said, um, don't quote me on that.

422
00:38:35,000 --> 00:38:44,200
double check that but uh i think it's i said this yesterday on rhr like by no means

423
00:38:44,200 --> 00:38:52,280
is this something that uh this cold card hack um this cold card vulnerability was human error

424
00:38:52,280 --> 00:39:01,980
um it seems like ai was used to discover from these these attackers and they've exploited it

425
00:39:01,980 --> 00:39:06,620
but there have been reports of others in the past that we've all been made aware of now

426
00:39:06,620 --> 00:39:12,680
that were reporting that they had collisions and their coins were getting out there.

427
00:39:12,840 --> 00:39:18,280
So this has objectively been possible for five years.

428
00:39:18,920 --> 00:39:23,800
It seems like there were some users reporting that they went to their wallet and funds were swept.

429
00:39:24,880 --> 00:39:26,540
Maybe that wasn't an attacker.

430
00:39:26,540 --> 00:39:35,860
It was just a coincidence of somebody creating a private public key pair using a cold card and sweeping the funds once they noticed there were some there already.

431
00:39:36,700 --> 00:39:47,480
But AI is a very, very big and is becoming a larger sub theme to all this, both the exploit side and the reaction to it as well.

432
00:39:47,480 --> 00:40:01,220
Yeah, absolutely. And it's worth noting, I think, and I'm not going to cite any of the names because I forget them, but bugs in the entropy, random number generators in crypto wallets have existed before and have been found without AI.

433
00:40:01,220 --> 00:40:04,100
so it's not that

434
00:40:04,100 --> 00:40:06,320
AI was needed to find

435
00:40:06,320 --> 00:40:08,260
this bug

436
00:40:08,260 --> 00:40:09,960
in the implementation

437
00:40:09,960 --> 00:40:12,260
of Coldcard's random

438
00:40:12,260 --> 00:40:14,160
number generator but it is pretty

439
00:40:14,160 --> 00:40:16,420
likely that it was used and it's definitely

440
00:40:16,420 --> 00:40:18,320
being used by attackers to

441
00:40:18,320 --> 00:40:19,800
operationalize the vulnerability

442
00:40:19,800 --> 00:40:22,360
Rob and the red

443
00:40:22,360 --> 00:40:24,320
team there's a bunch

444
00:40:24,320 --> 00:40:26,420
of efforts going on right I'm focused on

445
00:40:26,420 --> 00:40:28,300
on chain tracing of funds because

446
00:40:28,300 --> 00:40:29,340
that's what I'm good at

447
00:40:29,340 --> 00:40:43,500
Rob and many others are just burning tokens, like evaluating, doing code review with Frontier Cyber enabled models, but also like Kimmy and GLM, the open source models.

448
00:40:44,060 --> 00:40:48,180
I'm like basically anything they can get their hands on in the Bitcoin community.

449
00:40:48,180 --> 00:40:58,420
So other hardware wallet code bases, like libraries that underlie important Bitcoin infrastructure, like everything you can think of, which is a huge effort.

450
00:40:58,420 --> 00:41:03,180
There's also, like we said, people like Wicked literally helping individuals migrate coins.

451
00:41:03,700 --> 00:41:11,540
There's people that are trying to replicate the attack in order to determine how many addresses are still at risk.

452
00:41:11,780 --> 00:41:15,020
And you need substantial compute for that.

453
00:41:15,120 --> 00:41:16,240
People are chipping that in.

454
00:41:16,760 --> 00:41:22,460
There is a huge immune response from the Bitcoin community in reaction to this exploit.

455
00:41:22,460 --> 00:41:31,800
But to your broader point, Marty, about attacking and defending with AI, that's been a huge problem, right?

456
00:41:31,800 --> 00:41:33,780
Like, you remember there's the opening.

457
00:41:33,780 --> 00:41:39,960
I know you guys covered this, the open AI lab leak that hacked into Hugging Face, which itself is an AI.

458
00:41:39,997 --> 00:41:45,597
model repository, Hugging Face said they couldn't use frontier models to defend themselves.

459
00:41:45,757 --> 00:41:47,257
They kept hitting all the cyber safeguards.

460
00:41:47,357 --> 00:41:50,677
And so they had to fall back on Chinese open source models.

461
00:41:50,677 --> 00:41:58,017
To me, the idea that American companies have to rely on Chinese AI models to defend themselves

462
00:41:58,017 --> 00:41:58,957
is absurd.

463
00:41:59,657 --> 00:42:01,457
And something needs to give here.

464
00:42:01,837 --> 00:42:09,437
I don't know if it's just the sort of safetyism emanating from the frontier labs or if it's

465
00:42:09,437 --> 00:42:15,877
reaction to the US government's midnight phone call to Anthropic that halted the release of

466
00:42:15,877 --> 00:42:25,937
Mythos. But something needs to change. And I wrote this on X. To the extent that I have any reach,

467
00:42:26,097 --> 00:42:31,417
I'm escalating that to the highest levels I have access to because it's absolutely insane.

468
00:42:31,417 --> 00:42:44,197
Even myself, I primarily am using cloud code and codex and even asking again on a database that's local of Bitcoin data, which is public.

469
00:42:44,397 --> 00:42:50,657
Right. Even saying, hey, I have a report from a victim that they were drained, you know, in this transaction ID.

470
00:42:50,957 --> 00:42:55,397
Can you like pull the transaction information out of my own computer?

471
00:42:55,897 --> 00:42:59,557
And I'm hitting Fable 5 safeguard and getting downgraded to Opus.

472
00:42:59,557 --> 00:43:07,137
right like it's insane it's just insane um something's got to give here no it does to think

473
00:43:07,137 --> 00:43:14,617
that i mean it's a try i mean it's something that we've been saying in bitcoin just in the concept

474
00:43:14,617 --> 00:43:21,257
of like trying to throw kyc aml restrictions on bitcoin bring it to the chain level or prevent

475
00:43:21,257 --> 00:43:27,517
people from accessing privacy preserving tools it's like well yeah you can you can try to prevent

476
00:43:27,517 --> 00:43:31,877
people from using Bitcoin in a peer-to-peer fashion or using it in a private way, but

477
00:43:31,877 --> 00:43:36,537
criminals don't care. They're going to use it that way no matter what. They're criminals because they

478
00:43:36,537 --> 00:43:40,197
do not have a high regard for the law in the first place.

479
00:43:40,197 --> 00:43:43,937
When it comes to this discussion around AI

480
00:43:43,937 --> 00:43:48,157
and defending against attacks and being proactive to

481
00:43:48,157 --> 00:43:52,277
secure your systems and make them more robust from a security

482
00:43:52,277 --> 00:43:56,257
posture, it's insane that we have to fight this battle,

483
00:43:56,257 --> 00:43:57,597
particularly in the U.S. right now.

484
00:43:58,077 --> 00:44:00,097
Everybody's using Kimmy.

485
00:44:00,297 --> 00:44:04,217
I believe Gwen came out with a new model just yesterday that's in the mix.

486
00:44:04,757 --> 00:44:12,537
I think the red team, I saw Rob or Callie say that they did get access to OpenAI's

487
00:44:12,537 --> 00:44:15,857
sort of edge enterprise frontier model.

488
00:44:16,537 --> 00:44:21,257
Yeah, and I can just say I know of some big crypto companies

489
00:44:21,257 --> 00:44:27,257
that have access to either Glasswing or OpenAI Frontier Cyber Models

490
00:44:27,257 --> 00:44:31,717
and have been doing work on code-based review and vulnerability reporting,

491
00:44:31,717 --> 00:44:48,842
responsible disclosure stuff like that and stuff that also helps Bitcoin And also I think there I don know if it pronounced like this you know when you only read something you never heard it said out loud Project Lupe is an open source like LLM security vulnerability project

492
00:44:49,002 --> 00:44:51,602
And I don't know who runs it, but I know Steve Lee is involved.

493
00:44:52,202 --> 00:44:54,262
And they're also working on this.

494
00:44:54,302 --> 00:44:55,622
So there are a lot of efforts.

495
00:44:56,162 --> 00:44:59,162
It's not just Bitcoin or even blockchains.

496
00:44:59,162 --> 00:45:02,322
Like this is a global question.

497
00:45:02,322 --> 00:45:19,042
Like every company needs to upgrade. We're in an arms race right now. I do think like it's going to be episodic and we'll get to a, you know, it'll plateau where the defenders have caught up to the attackers. And so there's a little bit of a detente.

498
00:45:19,042 --> 00:45:30,042
I think governments will impose some actual like pausing and safeguarding as these things get better and better for better or worse.

499
00:45:30,042 --> 00:45:38,742
I think they will. Even I think the Chinese government will eventually not allow like the most dangerous because, you know, the open source models can be used by their people as well.

500
00:45:39,602 --> 00:45:46,682
And so, like, I think you'll see. But we are definitely still in early innings where it is like attackers are outpacing defenders.

501
00:45:46,682 --> 00:45:51,482
And so defenders, and by the way, that's true for every weapon on Earth.

502
00:45:51,602 --> 00:45:54,482
You know, like the Mongols defeated whomever because they had horses.

503
00:45:54,662 --> 00:45:58,382
They were shooting arrows from horses that had never been seen before, right?

504
00:45:58,462 --> 00:46:00,102
Like we're kind of in that era, right?

505
00:46:00,162 --> 00:46:03,202
Like the American Revolution, they kind of invented guerrilla warfare.

506
00:46:03,562 --> 00:46:06,682
And that was overwhelming to the British's column warfare.

507
00:46:06,902 --> 00:46:13,902
So we're still in that stage, but I think it'll be episodic where you reach plateaus

508
00:46:13,902 --> 00:46:19,602
And then who knows, maybe step function increases cause another episodic arms race and blah, blah, blah.

509
00:46:19,702 --> 00:46:24,162
But we're definitely still in a period where the defenders don't have access to good enough defensive tools.

510
00:46:24,262 --> 00:46:24,802
I don't think.

511
00:46:25,842 --> 00:46:31,322
No, I mean, obviously, Bitcoin is being affected right now.

512
00:46:31,382 --> 00:46:40,262
But there was a report out of Minneapolis, I believe, or Minnesota a couple of weeks ago about a water treatment plant being affected by some virus and shutting down.

513
00:46:40,262 --> 00:47:00,282
If you think of how antiquated the software around grid systems are today, energy systems, this is, I mean, when it comes to the broader discussion about getting access to frontier models to people that need to defend these systems, I think it's an imperative.

514
00:47:00,462 --> 00:47:02,582
It is a national security issue at this point.

515
00:47:03,922 --> 00:47:05,842
Yeah, it is.

516
00:47:05,842 --> 00:47:12,702
And I have to say, like, I don't have the answer on what the policy should be exactly.

517
00:47:13,042 --> 00:47:16,242
I just know that current status quo isn't good enough.

518
00:47:17,262 --> 00:47:17,742
No.

519
00:47:18,322 --> 00:47:19,242
I know you got to jump here.

520
00:47:19,322 --> 00:47:21,702
Thank you for taking some time to hop on.

521
00:47:22,942 --> 00:47:31,522
I really wanted to get you on so that anybody who may be a victim out there isn't aware of the research that your team is doing and the data gathering.

522
00:47:31,522 --> 00:47:49,387
Yeah you can see we publish a fair amount on GLXY research on X but so you can get all the info on how to contact me and us through that but that accounts DMs are not open so you can DM me on X at intangiblecoins

523
00:47:49,767 --> 00:47:56,427
I would love to help. And Marty, I just wanted to say thank you for being in this community.

524
00:47:56,427 --> 00:48:04,047
I know it's been a really tough time for, you know, you guys as longtime users of ColdCard as well.

525
00:48:04,207 --> 00:48:05,567
I've used ColdCard.

526
00:48:05,867 --> 00:48:13,067
I think the first rap I ever did on Galaxy Brains had a line about using ColdCard keys because we hold hard cheese.

527
00:48:13,067 --> 00:48:26,807
So and also I've been explaining this attack to journalists, to institutional investors who are interested but not affected because, you know, they use custodians and stuff like that.

528
00:48:26,807 --> 00:48:46,407
And one of the things I've been saying about why this is so demoralizing and such a tragedy, though I believe anyone having their money stolen for basically any purpose is terrible, is that these victims didn't do anything wrong and they didn't even do anything risky.

529
00:48:46,407 --> 00:48:57,087
In fact, if like I said, the vast majority of the coins being stolen, their addresses had never spent their coins and they'd only received.

530
00:48:57,787 --> 00:49:03,727
And the average of the median dormancy of the coins being stolen is like three point eight years.

531
00:49:04,247 --> 00:49:13,007
These are long term DCA Bitcoin believers, the cultural demographic of people that use CoinKai.

532
00:49:13,007 --> 00:49:18,907
I mean, I've got a block clock over my shoulder the last 250 episodes of Galaxy Brains.

533
00:49:19,687 --> 00:49:25,227
The people that use these are largely the most philosophical believers in Bitcoin.

534
00:49:25,767 --> 00:49:33,027
And this sort of strikes at the core of the self-custody, you know, work hard and save in Bitcoin.

535
00:49:33,507 --> 00:49:36,047
You know, again, nobody deserves to have their money stolen.

536
00:49:36,207 --> 00:49:41,067
But these people didn't put their coins on a shady crypto exchange to speculate.

537
00:49:41,067 --> 00:49:49,107
They didn't accidentally, which, you know, leak their coins, didn't drop their hardware wallet unlocked on the ground.

538
00:49:49,227 --> 00:49:51,687
They didn't accidentally upload their seed phrase.

539
00:49:51,767 --> 00:49:57,107
Not that those, you know, those are mistakes, but these people didn't make any mistakes.

540
00:49:57,447 --> 00:50:04,627
And that's what makes it so upsetting and why people are worried about sort of the future of the self-custody movement.

541
00:50:05,067 --> 00:50:06,827
And I would just say self-custody is not dead.

542
00:50:07,367 --> 00:50:09,487
This was a poorly implemented thing.

543
00:50:09,487 --> 00:50:23,527
Random number generators do work. They are proven to work. This one is not proven to work. And that's why Rob and the red team and many others, Portland and Calais and others who are helping are so essential.

544
00:50:23,527 --> 00:50:41,431
I think the wake up call for us in the Bitcoin world is that you know verifying and auditing codes not like a checkbox like it something we got to be doing you know 24 7 365 But I personally do believe this will damage the single SIG

545
00:50:43,231 --> 00:50:48,191
keep your hardware wallet under the bed and put your seed in a seed plate. I think the future of

546
00:50:48,191 --> 00:50:53,571
self-custody is multi-SIG collaborative custody. I do believe that firms like Casa and Unchained

547
00:50:53,571 --> 00:51:00,131
and Nunchuck and the Miniscript-based ones like Liana Wallet and Anchor Watch and others. I'm

548
00:51:00,131 --> 00:51:01,251
Sorry if I'm forgetting others.

549
00:51:01,891 --> 00:51:14,151
There are ways to provably and to really diversify the exposure to hardware wallets or specific key generation mechanisms that might sound difficult when I say multi-sig collaborative custody.

550
00:51:14,151 --> 00:51:18,951
But actually, there are many strong companies that provide this as a relatively cheap service.

551
00:51:19,631 --> 00:51:25,991
So, you know, if you are hellbent like I am in doing self-custody, look into those.

552
00:51:25,991 --> 00:51:32,731
I think we need to be a lot more deliberate about the risks that people take.

553
00:51:32,891 --> 00:51:37,431
I do think telling people to roll 100 dice is just not going to work for the majority of people.

554
00:51:38,131 --> 00:51:39,951
But there are easier ways.

555
00:51:40,051 --> 00:51:43,651
You don't have to be permanently demoralized about self-custody.

556
00:51:45,731 --> 00:51:46,631
I agree there.

557
00:51:46,851 --> 00:51:48,711
I'm not going to give any advice at the moment.

558
00:51:49,051 --> 00:51:55,691
But I think the only advice I will give is if you have a cold card, if you're for some reason just becoming aware of this, just move.

559
00:51:55,991 --> 00:51:58,971
your funds ASAP. Alex, thank you, brother.

560
00:52:01,071 --> 00:52:03,891
If you aren't following Alex and the team at Galaxy Research,

561
00:52:04,611 --> 00:52:08,931
if you're a victim, make sure you're following them. Make sure you're reaching out. Again, I think

562
00:52:08,931 --> 00:52:13,211
police reports, if there is a chance of recovery of funds,

563
00:52:13,531 --> 00:52:16,811
having that police report and holding onto your device will be

564
00:52:16,811 --> 00:52:20,931
critical. So make sure you follow that advice. And this is

565
00:52:20,931 --> 00:52:25,031
obviously a developing situation. So make sure you follow the teams

566
00:52:25,031 --> 00:52:29,171
that are on top of this, which Alex and the team at Galaxy is very much on top of this right now.

567
00:52:29,991 --> 00:52:33,211
Thanks a lot, Marty. Good to be here. Yeah. Please reach out if you're affected.

568
00:52:34,091 --> 00:52:34,811
Peace and love, freaks.

569
00:52:35,151 --> 00:52:39,811
Thank you for listening to this episode of TFTC. If you've made it this far,

570
00:52:39,811 --> 00:52:44,691
I imagine you got some value out of the episode. If so, please share it far and wide

571
00:52:44,691 --> 00:52:47,931
with your friends and family. We're looking to get the word out there.

572
00:52:48,771 --> 00:52:52,751
Also, wherever you're listening, whether that's YouTube, Apple, Spotify,

573
00:52:52,751 --> 00:52:59,291
make sure you like and subscribe to the show and if you can leave a rating on the podcasting

574
00:52:59,291 --> 00:53:05,131
platforms that goes a long way last but not least if you want to get these episodes a day early and

575
00:53:05,131 --> 00:53:11,631
ad free make sure you download the fountain podcasting app and go to fountain.fm to find that

576
00:53:11,631 --> 00:53:18,371
five dollars a month get you every episode a day early ad free helps the show gives you

577
00:53:18,371 --> 00:53:24,911
incredible value. So please consider subscribing via fountain as well. Thank you for your time.

578
00:53:24,911 --> 00:53:26,331
And until next time.
