Breaking down the Coldcard exploit & ramifications for self-custody

Watch on YouTube ↗  |  August 03, 2026 at 12:36  |  1:08:10  |  The Block

Summary

The episode covers the Coldcard hardware wallet exploit that compromised seed generation on devices since 2021, leading to over 1,700 BTC stolen. Guests Zack Herbert (Foundation) and Jameson Lop (Casa) discuss the bug's discovery, role of AI, implications for self-custody, and the need for open-source best practices and multi-vendor multisig.

  • Discussion of the Coldcard exploit: a bug in the entropy/seed generation code introduced in 2021 weakened randomness, making seeds crackable.
  • Over 1,700 BTC drained from Coldcard devices, with attackers using scripts to derive and sweep funds.
  • AI frontier models (like GPT 5.6 Soul) are believed to have accelerated discovery and exploitation of the bug.
  • Zack Herbert emphasizes that open-source remains critical for detection and community response, while closed-source would have prolonged the fog.
  • Jameson Lop notes that no single vendor or codebase is infallible; multi-vendor multisig and distributed trust mitigate single points of failure.
  • Self-custody is still valid but requires understanding trade-offs; responsibility scales with the size of holdings.
  • The event has prompted industry-wide code audits and a re-evaluation of 'don't trust, verify' in a world of complex hardware/software.
Up Next