# EMERGENCY BITCOIN UPDATE: Coldcard Attack Explained | Rob Hamilton Page: https://stenobird.com/podcast/what-bitcoin-did-255500/emergency-bitcoin-update-coldcard-attack-explained-rob-hamilton Text version: https://stenobird.com/podcast/what-bitcoin-did-255500/emergency-bitcoin-update-coldcard-attack-explained-rob-hamilton.md Podcast: [What Bitcoin Did](https://stenobird.com/podcast/what-bitcoin-did-255500) Published: 2026-07-31T23:12:38+00:00 Episode link: https://fountain.fm/episode/D24j5CW1EOLb7pRfCAnV Audio file: https://feeds.fountain.fm/UZSKQcrOnhqYS1JopxGg/items/CDfHU2WcbeDRLx1z0EA9/files/VIDEO---DEFAULT---6be33c32-d8f8-46c3-a9ab-c8fce5e9921a.mp4/ORIGINAL.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/what-bitcoin-did-255500/episodes/emergency-bitcoin-update-coldcard-attack-explained-rob-hamilton Duration seconds: 2538 ## Resource “This is as code red as it can get for Bitcoin self-custody.” Rob Hamilton joins me for an emergency episode on the catastrophic Coldcard entropy bug that has exposed Bitcoin held in wallets generated on affected firmware. A firmware change introduced in 2021 prevented Coldcard devices from generating the level of randomness users believed they were getting. The result is that attackers may be able to reconstruct seed phrases and drain wallets, even when the device was air-gapped and the seed words never touched the internet. Rob explains which Coldcard models and setups are at risk, why updating the firmware does not repair an existing vulnerable seed, and what affected users need to do now. We also get into the risks facing single-signature and multisig wallets, whether passphrases and independently generated entropy provide protection, how attackers are finding and sweeping vulnerable wallets, and the role AI may have played in discovering the bug. THANKS TO OUR SPONSORS: LEDN SWAN ANCHORWATCH BLOCKWARE BITKEY CAPE FOLLOW: Danny Knowles: https://x.com/_DannyKnowles Rob Hamilton: https://x.com/Rob1Ham ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/what-bitcoin-did-255500/episodes/emergency-bitcoin-update-coldcard-attack-explained-rob-hamilton/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/what-bitcoin-did-255500/emergency-bitcoin-update-coldcard-attack-explained-rob-hamilton.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.