Skip to content
PodcastsBusinessThe Café Bitcoin Podcast

The Café Bitcoin Podcast

Swan Bitcoin
The Café Bitcoin Podcast
Latest episode

661 episodes

  • The Café Bitcoin Podcast

    Café Bitcoin | Slay Your Heroes, the Fourth Turning, and Certainty Lowers Your Guard | Day 17 of 50

    06/08/2026 | 1h 25 mins.
    Suze's Forbes piece, and the question under it. Her Telegram reporting found a persistent identifier that survives restarts, network changes and borders, with the credible risk being targeted surveillance rather than mass tracking. Her real question: why is don't-trust-verify never applied to companies and personalities inside Bitcoin?

    The confessions, and Cory's calibration. American HODL admitted he bought a Coldcard largely as a badge of Maxi Club membership, and Odell described being pulled into a cult of personality. Cory's distinction: someone who bills himself as a technical expert and reviews products carries responsibility a self-described bullshitter does not.

    He also warned against the new bad heuristic. Treating abrasiveness as a proxy for bad code fails immediately: Core and Blockstream are full of people who read as cocky and their code is sound. He credited NVK as a genuinely good educator while calling the outcome inexcusable.

    Brandon Quittem: deep in it, not at peak. Maximum wealth inequality is a classic Fourth Turning signpost, and the post-war institutions are a shell of themselves without anyone needing to be malicious. He held his own confidence low throughout, calling the framework a rough way to squint at the world.

    His bet on the climax. Not a head-to-head with China, which a hyperglobalized economy makes unlikely, but a Cold War 2.0: proxy and economic war, trade policy, supply-chain fights, plausible deniability, and zero-day attacks on each other's infrastructure.

    AI through the Fourth Turning lens. The authors would say technology is always arriving and the variable is how the generational mood receives it. Facebook landed because millennials were the sharing archetype; Gen X would have refused it. He calls AI pure leverage with no clear direction.

    Horseshoe theory, and Bitcoin as the through line. Answering Suz on where left and right even are now: both extremes arrive at authoritarianism from the same wealth-inequality catalyst, which is why Bernie and Trump were popular at once. Bitcoin is what pushes back on both.

    He retracted his own timeline live. Five years ago he would have called a Bitcoin standard likely by 2030 and now says that was far too aggressive. A First Turning looks like exhaustion, inequality easing, culture getting more boring, and it may only be visible in hindsight.

    The libngu decision, traced. An audience question surfaced that the firmware was rewritten off a GPL library partly out of anger at being cloned, producing an in-house source-available replacement and fewer eyes. Of 300-plus repos the red team has scanned, the one that came back completely clean was libsecp256k1.

    The synthesis, and the way out. Suz: Bitcoiners who believe they saw through the system struggle to admit deception, because it means admitting they were fooled. Brandon: that lowers the guard rather than raising it. His prescription is local, not global. Be the sewer rat yourself.
  • The Café Bitcoin Podcast

    Café Bitcoin | Guy Swann and Yan Pritzker on Coldcard, the Asymmetry of Defense, and Privacy | Day 16 of 50

    05/08/2026 | 1h 12 mins.
    Guy Swan on learning the wrong lessons. The takeaway circulating is "go with the biggest company," which forgets Mt. Gox and FTX and everything else proving size is not safety. His analogy: when a libertarian politician betrays you, libertarianism didn't break, you got scammed.

    He wants a rule that works forward. His sharpest point: "I don't want a rule that only works in hindsight." Anyone can now point at the source-available license. The useful question is what indicator predicts the next failure before it happens.

    His own heuristic broke in both directions. He had trained himself not to dismiss builders for being abrasive, and now concludes that for security specifically, a maintainer who attacks people reporting problems is telling you something. Yan Pritzker paired it with the engineering version: without a culture of safety, people stop surfacing mistakes.

    James O'Beirne's tripwires. He seeded wallets on-chain carrying graduated entropy over broken Coldcard seeds, five dice rolls, ten, fifteen, one and two-word passphrases, as bait. The bare seed was swept within an hour and nothing else has moved, mapping attacker capability live.

    The red team's numbers. Rob Hamilton and Calle have scanned over 300 repos and spent roughly $40,000 on tokens in two days, finding critical vulnerabilities at about one per person per hour. OpenSats is now funding most of that budget.

    Every company needs an agentic security pipeline. Yan's argument: agents are non-deterministic, so one scan proves nothing. The real work is harnesses that find, test, distill and reproduce on a loop. Swan has been building this for six to twelve months.

    The asymmetry is the whole problem. Attackers need one vulnerability, defenders need all of them, and the economics favor the attacker. Some have been paying up to 90% of stolen funds in fees to get transactions mined quickly.

    A fake Coldcard desktop app is circulating. No such application has ever existed. Trezor reported a phishing spike since disclosure, and a counterfeit Wasabi wallet reached an app store. Nobody legitimate asks for recovery words, and unsolicited migration instructions are always hostile.

    Yan's read on whether this repeats. He calls the bug exotic: entropy wasn't weak, it was switched off entirely. Scans across the popular hardware wallets show correct and consistent entropy use, so he thinks this specific failure is unlikely to recur elsewhere.

    Government overreach, the other half of the show. Suz on Liechtenstein's beneficial ownership register, roughly 31,000 entities, built in 2021 for EU anti-money-laundering compliance and now breached and offline. Yan on the Bank Secrecy Act's 1970 threshold, never inflation-adjusted, capturing dramatically more data for near-zero measured effect.
  • The Café Bitcoin Podcast

    Café Bitcoin | Self-Custody Is Not Dead, the Custody Spectrum, and Owning Is Not Operating | Day 15 of 50

    04/08/2026 | 1h 17 mins.
    Dice rolls are now confirmed safe. Portland HODL published a full verification, independently cross-checked by James O'Beirne, Block's engineering team and Rob Hamilton: the Coldcard did use dice entropy rather than falling back to the pseudo-random generator. Fifty or more rolls was sufficient.

    Still rotate anyway. The prevailing view on the show was that dice-generated seeds are safe but worth rotating as hygiene. Separately, no other hardware wallet firmware vulnerability has surfaced yet from the red-team sweep.

    The red team is scaling. Rob Hamilton's group, now joined by other Bitcoin developers, is pointing Kimi K3 and other frontier models at repos across the ecosystem. Critical vulnerabilities have been found and responsibly disclosed, none in hardware wallets so far.

    Cory rejects the "always more to learn" framing. He argued that line doesn't apply here: the entire point of code securing assets is that there can be no mistakes that put those assets at risk. He gave two press interviews on the exploit.

    The custody spectrum, with a chart in the nest. Cory laid out five positions: solo self-custody, guided self-custody via Swan Sovereign at $25 a month, collaborative multisig, delegated custody with OCC-chartered custodians, and multi-institutional custody, which Swan has been building since December.

    The real gap is knowing how to use your wallet. Alec, who spent the weekend on client calls, found people holding large amounts in setups they could not operate. Getting Bitcoin off an exchange is not enough. Practice moving it more than once.

    Jason on the false binary. People have been taught there is one right way to hold Bitcoin, and that it's the most esoteric one. His question: what is self-custody worth if you cannot move your coins in an emergency?

    Zach Herbert of Foundation. Self-custody is not dead, and he framed this as negligence by a single vendor rather than an indictment of every maker. His takeaway is free and open source software, shared libraries and engagement with auditors. He calls it the worst event for committed Bitcoiners since Mt. Gox.

    Boltz went dark. The Lightning swap provider shut down entirely, hit by automated attacks faster than a small team could patch, taking swaps in Zeus, Aqua and Blockstream's app with it. No user funds lost. Brady drew the line from Kimi K3's release through Coldcard to this.

    The AI incentive argument. Phillip's case: calls to regulate AI harder are moat-building, not safety, and defenders keep having to reach for open-weight models because the US frontier models refuse legitimate security work. Steve noted five figures a day in tokens is not a sustainable audit model.
  • The Café Bitcoin Podcast

    Café Bitcoin | The Coldcard Timeline, Joe Nakamoto on the Fallout, and Open Source Must Win | Day 10 of 50

    03/08/2026 | 2h 30 mins.
    A full forensic timeline. Brady traced it end to end: a 2018 MicroPython software fallback sat harmless for three years until March 2021, when Coinkite moved to Bitcoin Core's math library and silently bound seed generation to that fallback. Lopp notes the bug lived in the build system, not the main code.

    Firmware 4.0.0 is the dividing line. Shipped March 17, 2021. Seeds generated before roughly March 1 are fine, and MK3 releases 3.2.1 and 3.2.2 were the last safe ones. Every default seed after that was weak.

    It was flagged in 2021 and dismissed. Four months after the bad firmware shipped, someone publicly raised Coldcard entropy concerns. NVK's reply called it FUD and demanded a line in the code. That post is deleted; an archived screenshot survives.

    The scope widened over the weekend. Coinkite added MK2 alongside MK3 and MK4, and confirmed Q and MK5 at roughly 72 bits rather than the expected 128. Independent analysis put the MK4 class nearer 50 to 60 bits in practice.

    Dice rolls and passphrases do not cover everything. Nine other Coldcard features draw from the same broken generator, including message signing and deriving keys for other purposes. BTC Sessions confirmed an MK4 with a one-word passphrase was drained.

    Scale, and Cory's proportion. Roughly 1,300 Bitcoin total, 594 in the first wave, with Chainalysis showing the highest-balance wallets targeted first. Cory noted centralized exchanges and lenders have lost about a thousand times more.

    The chip-ID recovery hope is gone. Holders were told earlier in the week to keep their devices because a chip signature might prove ownership. Brady reported that has since been shown not to work as hoped, narrowing recovery further.

    Vendor indictment or self-custody indictment? An audience question that framed the hour. Brady argued it is a challenge to upgrade toward multi-vendor multisig rather than a verdict on self-custody. One listener pushed back that the indictment already landed.

    Joe Nakamoto from Europe. He found almost nobody in his circle affected, since Coldcard's loudest advocates were largely American and circular economies mostly run on Lightning. Bloomberg was the only genuinely mainstream outlet, and its coverage was fair.

    Open source, and the AI asymmetry. Researchers keep reaching for Moonshot's open-weight Kimi K3 because US frontier models refuse legitimate security work. Rob Hamilton's decentralized effort to pentest Bitcoin repos received grant funding during the show.
  • The Café Bitcoin Podcast

    Café Bitcoin | Coldcard Emergency: What Happened, Who's Affected, and What To Do Now

    31/07/2026 | 5h 10 mins.
    The event. A firmware flaw in Coldcard seed generation, disclosed the night before, let an attacker recompute private keys outright. By airtime, 594 Bitcoin, put at roughly $38 million on the show, had been swept from about 500 wallets.

    The mechanism. Yan Pritzker and Swan engineer Steve: the device's true random number generator was present and working, but a March 2021 library change meant the firmware silently stopped using it, falling back to software randomness seeded from device ID and clock.

    Why five years passed. The code looked correctly wired, the failure hinged on a build-time variable, and the output still looked random. Zach Herbert of Foundation said a researcher flagged something adjacent in 2022 without unraveling it.

    Who is exposed. Only seeds the Coldcard generated itself. Imported seeds are safe, dice rolls are safe, a long passphrase saved people. MK3 is worst hit. MK4, MK5 and Q sit near 72 bits, costly to attack but not impossible.

    Updating firmware does not fix it. Coinkite patched, including MK3, but the vulnerable seed is the problem, not the device. You must generate a new seed and move funds. The dice function was never affected and has now been audited.

    Multisig is not automatically safe. If most keys came from affected devices, an attacker can try permutations, and spending publishes your public keys and invites an RBF race. Wicked pointed people to Portland.HODL for private broadcast through Slipstream.

    The attacker looks unsophisticated. The sweep ran roughly 25 minutes into a handful of addresses, stopped at shallow address gaps, and queried a public node instead of running one. Block researchers identified that service, so there may be a lead.

    The industry reckoning. American HODL called it a Paul Revere moment and demanded podcasters and former sponsors broadcast immediately. Reardon argued the industry spent three years arguing over the wrong priorities and got caught by an entropy bug.

    Self-custody versus diversification. Wicked held that multi-vendor multisig with your own entropy beats any custodian. Joe Carlasare countered that every system rests on assumptions that eventually fail. Yan declined to preach one model, calling self-custody still very early.

    Swan's status and the scam wave. Yan confirmed Swan Vault is built on Blockstream Jade and unaffected, and reported an influx of deposits. He flagged a devious scam variant where attackers send you working seed words and ask you to deposit into them.
More Business podcasts
About The Café Bitcoin Podcast
It's 50 Days for Freedom - 50 Days of Café Bitcoin. Every weekday at 10am ET on Bitcoin Twitter.
Podcast website

Listen to The Café Bitcoin Podcast, Inside Business with Ciaran Hancock and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features
The Café Bitcoin Podcast: Podcasts in Family