Bitcoin's Worst Security Stretch: Coldcard, Boltz, BTCPay
Original title: 🟢 LIVE: Inside Bitcoin's Worst Security Stretch in Years w/ Foundation & Casa CEOs
Watch on YouTube Opens on youtube.com in a new tab. Playback here uses youtube-nocookie.com.
Summary
Bitcoin has just been through its worst stretch of infrastructure failures in years. On July 30, Coinkite disclosed a 2021 Coldcard firmware bug. The bug routed seed generation to a software randomizer instead of the device's hardware RNG. This left affected seeds guessable. Attackers have since drained roughly $130 million in BTC from more than 5,200 addresses. On Aug. 3, the swap bridge Boltz disabled its service indefinitely. Boltz said attackers now iterate faster than a team its size can find and patch. This followed months of automated, AI-assisted probing. On Aug. 7, BTCPay Server warned of a critical flaw under active exploitation. Merchant Lightning nodes were swept overnight. This included one belonging to hardware wallet maker Foundation. The bug was caught by a developer who lost money, not by the AI audits running across bitcoin's stack. The AI audits running across bitcoin's stack did not catch the bug. Foundation makes the Passport hardware wallet. Casa builds multisig self-custody for bitcoin.
This AI summary uses the title, description and tags. It may miss context from the full video. How summaries are checked
Key points
- On July 30, Coinkite disclosed a 2021 Coldcard firmware bug that routed seed generation to a software randomizer instead of the device's hardware RNG, leaving affected seeds guessable.
- Attackers have since drained roughly $130 million in BTC from more than 5,200 addresses.
- On Aug. 3, the swap bridge Boltz disabled its service indefinitely, saying attackers now iterate faster than a team its size can find and patch.
- On Aug. 7, BTCPay Server warned of a critical flaw under active exploitation; merchant Lightning nodes were swept overnight, including one belonging to Foundation.
- The bug was caught by a developer who lost money, not by the AI audits running across bitcoin's stack.
Questions
What was the Coldcard firmware bug?
A 2021 Coldcard firmware bug routed seed generation to a software randomizer instead of the device's hardware RNG, leaving affected seeds guessable.
How much BTC was drained from affected addresses?
Attackers drained roughly $130 million in BTC from more than 5,200 addresses.
Why did Boltz disable its service?
Boltz said attackers now iterate faster than a team its size can find and patch, after months of automated, AI-assisted probing.
A video appearing here is not an endorsement. Crypto assets can lose value. This page provides information, not investment advice.