Coldcard Exploit - Is Bitcoin Self-Custody At Risk?

Смотреть на YouTube ↗  |  05 августа 2026, 10:35  |  54:54  |  The Block
Спикеры
Tim Copeland — Соведущий и руководитель отдела развития, The Block
Zach Herbert — Co-founder & CEO, Foundation
Jameson Lopp — Co-founder & CTO, Casa
Zach Herbert and Jameson Lopp analyze the Coldcard hardware wallet entropy bug that led to over 1,700 BTC stolen. They discuss the role of AI, the open‑source vs closed‑source debate, and reject the idea that self‑custody is dead. The conversation highlights the need for multi‑vendor multisig setups and better industry security practices. - A critical entropy bug in Coldcard devices allowed attackers to derive seeds and drain over 1,700 BTC. - The vulnerability, introduced in early 2021, affected all Coldcard models, especially the MK3. - AI advancements likely accelerated the discovery and exploitation of the bug. - Both guests emphasize that open-source code enabled a faster community response and is not the root cause. - Jameson Lopp stresses that “don’t trust, verify” is impractical for most users and advocates for distributed trust via multi‑vendor multisig. - The speakers push back against the narrative that self‑custody is dead, reaffirming its importance for Bitcoin sovereignty. - The industry is urged to improve security audits, user experience, and collaboration to prevent future failures.
Далее