Start Mining Free

Bitcoin

The Coldcard Disaster: Everything You Need to Know | Lloyd Fournier & Nick Farrow — Key Takeaways

YouTube

The Coldcard Disaster: Everything You Need to Know | Lloyd Fournier & Nick Farrow

What Bitcoin Did1h 23mAug 21, 2026

Watch the original

Move funds off Cold Card Mark III immediately — ~1,200 wallets holding ~2,000 BTC were compromised by entropy so weak (2²⁰ possibilities) that the attack runs on a laptop in hours.

Key takeaways

Cold Card Mark III entropy was ~2^20 bits, making brute-force feasible on a laptop

Cold Card Mark III entropy was ~2^20 bits, making brute-force feasible on a laptop

  • Initial estimates were 2^40 bits; Wizard Sardine analysis revised it to millions of possibilities, empirically verified.
  • Attacker swept ~1,000 BTC from 1,200+ wallets; researcher replicated the full attack overnight using Claude as coding assistant.

Yasmarang RNG is a toy 32-bit PRNG — cryptographically unsuitable, yet was Cold Card's entropy source

Yasmarang RNG is a toy 32-bit PRNG — cryptographically unsuitable, yet was Cold Card's entropy source

  • Yasmarang originated in MicroPython (hobbyist toolkit), has tiny state, and is not a cryptographic CSPRNG.
  • A secure CSPRNG needs ~256-bit secret key state; Yasmarang's state is so small it cannot absorb sufficient entropy.

Dark Skippy: a malicious device leaks your full seed phrase in just 2 signatures via nonce manipulation

Dark Skippy: a malicious device leaks your full seed phrase in just 2 signatures via nonce manipulation

  • Previous literature assumed ~50 transactions needed; Lloyd and Robin Linus reduced it to one transaction (two signatures).
  • Applies to any device that chooses its own signing nonce without anti-exfil protocol (Jade, BitBox, Frostnap implement anti-exfil).

This Dig holds 4 more insights, 4 flashcards, and 3 quotes — free with your trial.

Unlock this Dig free

Start free with 100 credits · No card, no expiry

In this video

  1. 1mIntroduction
  2. 1mThe Coldcard Disaster
  3. 3mHow AI Found the Bug Humans Missed
  4. 7mColdcard’s Fatal Randomness Failure
  5. 12m1,200 Wallets, Nearly 2,000 Bitcoin
  6. 18mMapping the Attackers On-Chain
  7. 19mReproducing the Attack With AI
  8. 32mHardware Wallets Are Trusted Third Parties
  9. 36mHow Frostsnap Removes Device Trust
  10. 41mIs Every Hardware Wallet at Risk?
  11. 48mOpen Source Security in the Age of AI
  12. 56mThe Human Cost of the Coldcard Hack
  13. 1h 4mHow Frostsnap Works
  14. 1h 11mProtecting Bitcoin From Physical Attack
  15. 1h 18mFrostsnap

This page is a partial, transformative summary produced by Homestake. All rights to the original content remain with its creator — please support them at the source link above.

Related in the Library