
What Bitcoin Did The Coldcard Disaster: Everything You Need to Know | Lloyd Fournier & Nick Farrow
44 snips
Aug 21, 2026 Nick Farrow, technical lead at Frostsnap who builds cryptographic tooling, and Lloyd Fournier, Frostsnap co‑founder and custody/security researcher. They dissect the Coldcard randomness failure, how AI and firmware complexity let an exploit slip by, the scale of seed collisions and stolen funds, and why threshold signatures and distributed key generation can replace fragile single-signature setups.
AI Snips
Chapters
Transcript
Episode notes
Toy RNG Undermined Hardware Entropy
- Coldcard mixed hardware TRNG output with a toy RNG named YASMARANG, creating tiny effective entropy states.
- The YASMARANG state was one 32-bit word, far too small for cryptographic seed generation.
Entropy Drop Made Seeds Searchable
- Effective seed entropy on many Mark IIIs collapsed into the 20s–40s of bits, leaving at-most millions to hundreds of millions of possible seeds.
- Kevin/Wizards' post empirically verified collisions and explains why multiple devices produced identical or guessable seeds.
Move Funds From Affected Coldcards Immediately
- Move funds immediately if you used a vulnerable Coldcard Mark III and monitor addresses for sweeps.
- Lloyd ran an attack simulation to enumerate affected wallets and found ~1,200 wallets and ~2,000 BTC impacted at peak.


