What Bitcoin Did

The Coldcard Disaster: Everything You Need to Know | Lloyd Fournier & Nick Farrow

44 snips
Aug 21, 2026
Nick Farrow, technical lead at Frostsnap who builds cryptographic tooling, and Lloyd Fournier, Frostsnap co‑founder and custody/security researcher. They dissect the Coldcard randomness failure, how AI and firmware complexity let an exploit slip by, the scale of seed collisions and stolen funds, and why threshold signatures and distributed key generation can replace fragile single-signature setups.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Toy RNG Undermined Hardware Entropy

  • Coldcard mixed hardware TRNG output with a toy RNG named YASMARANG, creating tiny effective entropy states.
  • The YASMARANG state was one 32-bit word, far too small for cryptographic seed generation.
INSIGHT

Entropy Drop Made Seeds Searchable

  • Effective seed entropy on many Mark IIIs collapsed into the 20s–40s of bits, leaving at-most millions to hundreds of millions of possible seeds.
  • Kevin/Wizards' post empirically verified collisions and explains why multiple devices produced identical or guessable seeds.
ADVICE

Move Funds From Affected Coldcards Immediately

  • Move funds immediately if you used a vulnerable Coldcard Mark III and monitor addresses for sweeps.
  • Lloyd ran an attack simulation to enumerate affected wallets and found ~1,200 wallets and ~2,000 BTC impacted at peak.
Get the Snipd Podcast app to discover more snips from this episode
Get the app