Unchained
Unchained

Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

A hardware wallet's 5-year-old randomness bug just let hackers drain over $100 million in Bitcoin. How many more waves are coming? Plus, Ethereum's fight over cutting ETH issuance. ======================================================== Thank you to our sponsors! ⁠⁠⁠⁠⁠⁠Cape⁠⁠⁠⁠⁠: Your big

Topics Discussed

Episode Summary

Executive Summary: The episode centered on two major risk-management stories in crypto: a severe Coldcard hardware wallet entropy bug that has exposed users to ongoing thefts, and a contentious Ethereum issuance proposal that critics say was rushed and may backfire. The hosts also discussed a Trade.xyz oracle incident and broader DeFi responsibility for UX guardrails and price safety.

Main Topics: Coldcard entropy bug and ongoing wallet thefts (Priority: 5/5): Taylor Monaghan explained that a five-year-old randomness flaw in Coldcard’s seed generation has enabled attackers to brute-force private keys over time, making this a prolonged, high-severity non-custodial wallet failure affecting hardened Bitcoin users. Who is behind the Coldcard attacks and why attribution is hard (Priority: 4/5): The panel argued the activity is unlikely to be North Korea, instead resembling professional crackers or possibly a first-wave discoverer using AI, followed by later waves of optimized brute-force attackers mining weak keys. Hardware-wallet safety, audits, and user guidance (Priority: 5/5): The speakers emphasized that cryptographic randomness failures are among the worst vulnerabilities, urged users to verify audits and organizational maturity, and criticized teams that lack peer review or security processes. Trade.xyz oracle failure and DeFi venue responsibility (Priority: 4/5): A thin pre-market SK Hynix print caused a major perps incident; the hosts debated whether venues should stop obviously abusive or nonsensical trades rather than merely warn users, comparing DeFi UX to brokerage risk controls. Aave’s strategic pullback from everywhere expansion (Priority: 3/5): The conversation noted Aave is reducing its multi-chain footprint as certain deployments become negative-EV, reflecting a broader rethink of operational risk and overextension in DeFi. Ethereum issuance debate and EIP-8361 backlash (Priority: 5/5): The hosts criticized a rushed proposal to reduce ETH issuance, arguing it was introduced without sufficient consultation and could harm staking economics, security budget, and ETH price if staking yields collapse. Mechanism design, incentives, and unintended consequences (Priority: 4/5): Across the Ethereum discussion, the speakers argued that monetary-policy tweaks and oracle fixes create second- and third-order effects, so rough consensus and caution are preferable to precise but brittle optimization.

Key Arguments: Entropy failures in wallets are uniquely dangerous because they allow attackers to brute-force weak keys over weeks or months, turning a single bug into a long-tail, ongoing theft event. Coldcard’s problem was exacerbated by its small team, weak process, and lack of security audits; the hosts said users should look for organizational red flags, not just hidden code flaws. North Korea is an unlikely culprit because this attack pattern requires specialized compute and brute-force cracking, whereas DPRK operators are described as favoring social engineering. Trade venues and wallet apps have a responsibility to prevent obviously destructive user actions, not merely display warnings, because permissionless interfaces still shape outcomes and bear ethical duty. Reducing Ethereum issuance could reduce staking yield so much that it may push ETH out of staking and into the market, potentially worsening, not improving, price and security. A more efficient or lower-issuance Ethereum is not obviously better; many crypto networks benefit from higher staking participation, and fees burned can already create monetary tightness without changing issuance. The issuance debate shows that fragmenting Ethereum governance into separate organizations increases agitation and public conflict, which may be healthy because it forces broader consultation. Oracle design is inherently trade-off driven: preventing one bad case can create worse tail-risk elsewhere, so mechanism design should be treated as a high-stakes systems problem.

Data Points: Coldcard attack timeframe: 5 years - The bug was said to have existed in the code base since 2021 and been used for about five years before discovery. Estimated theft total: over $100 million - Current loss estimates discussed for the Coldcard entropy attack. Bitcoin stolen: 1,600-1,800 BTC - Approximate amount referenced in the Coldcard incident. Coldcard attack waves: 4 waves - Galaxy Research’s cluster analysis was described as identifying four distinct waves of activity. ETH staking yield: about 2.5% - Described as the blended rate from MEV plus staking rewards in the Ethereum issuance debate. Proposed post-cut yield: about 20 basis points - Used to argue that lowering issuance further could collapse staking incentives. Proposal comment window: 48 hours - Criticism of the Ethereum issuance proposal centered on how little time was given for feedback. Trade.xyz price event: $11.28 to $9.17 - The SK Hynix perps oracle issue on Trade.xyz involved a sharp real-trade dislocation before recovery. Potential recovery amount: all users made whole - Trade.xyz reportedly said it would reimburse affected users, while stressing it would not be precedent-setting. ETH issuance debate reference: EIP 8361 - The episode’s Ethereum governance segment focused on this issuance-related proposal. Older issuance debate reference: MVI in 2024 - Mike referenced prior discussion about minimum viable issuance and stakeholder consultation. Staking concentration example: 5 validators - Aave/Lido discussion mentioned collapsing many validators into a smaller number for operational simplicity. Fee-market burn narrative: EIP-1559 - Referenced as the mechanism that burns fees and can reduce effective supply without changing issuance. Ethereum owner earnings estimate: north of $7 billion - A Ribbit Capital thesis was cited to argue the network already produces substantial economic value.

Pivotal Quotes: "if your code cannot get the randomness necessary or initialize the process like with any amount of confidence, then it should barf and catch fire." — Taylor Monaghan: Used to argue cryptographic systems must fail hard rather than fall back silently. "The strongest thing is just don't fuck with it." — Mike: Summarizing the case against changing Ethereum issuance via monetary-policy tinkering. "This is just not, frankly, the most important thing by a long shot." — Mike: A critique of prioritizing issuance reduction over more material Ethereum issues.

Implications: Users should urgently audit hardware-wallet risk, demand stronger security processes, and treat DeFi interfaces as safety-critical. For Ethereum, governance and issuance changes need broader consultation because poorly judged monetary tweaks can create larger security and market distortions than they solve.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained