The Gap
Bitcoin is a machine for remembering, and it works because of one deliberate hole in its memory. The Coldcard entropy failure filled that hole with facts the world had already written down, which turned private keys into explainable objects.
The one-minute version
The narrative that the Coldcard exploit was a hack, and the wipe-restore-spend ritual as proof that a seed is sound.
Bitcoin is a machine for remembering.00:43
That's also a failure. Most, not most, a lot of Bitcoin's losses are self-inflicted.16:20
What you want to think about doing when you're generating a private key in Bitcoin is you are putting a hole in the record that no one can ever fill in.36:24
Every passage, on the record.
- 00:43Quote
Bitcoin is a machine for remembering.
- 01:33Idea
There's one thing that the system deliberately does not know, one fact that isn't recorded anywhere in any block, on any of the nodes, in any of the government databases tracking the Bitcoin network: your private key. It has to be that way, because the system that remembered absolutely everything would also give everything away. You can think of it like entropy, which is just the size of the hole.
- 02:42Claim
Somebody showed us what happens when you take that little hole and fill it with what the world had already written down somewhere. Nobody was hacked, there were no servers breached, no houses broken into, nobody got wrench attacks, nobody was manipulated into giving away these novel arrangements.
- 03:18Event
The people who lost the money had done almost everything right. They bought a well-supported hardware wallet, generated a seed on it, a unique piece of information, wrote the words down, put them somewhere safe. Some of them had been doing it correctly since 2021.
- 03:55Claim
Bitcoin needs two opposite things at the same time: one object that means absolutely nothing, and one object that means everything, welded together in the same system without ever touching or mingling. If you get that backwards the whole thing falls over.
- 04:28Event
The Coldcard wallet had a firmware setting that turns on the hardware chip whose job is to produce real noise from a real physical process. The firmware set that flag to zero. There was a library that checked whether the setting existed, not whether it was switched on, so the check passed even though the value was zero, and seed generation quietly fell back to a deterministic software algorithm, and it passed every single time, for five years, on every device.
- 05:21Claim
The fallback algorithm was seeded with three things: the serial number of the chip, how many times the device had been switched on, and the clock. The chip's serial number is stamped on the chip. The boot counter is a number the device stores itself. The time is the single most publicly recorded fact in the universe, every satellite, every phone, every exchange is agreeing all the time about what time it is, continuously and for free.
- 06:14Claim · condensed
The device was building these keys on facts that already existed in the world, so the intended search space, at minimum 128 bits, became closer to 40 bits on the older Mark IIIs and 70 to 72 bits on the Mark IVs and later. 40 bits is not difficult. 72 is expensive, but expensive is relative when we're talking about hundreds of millions of dollars.
- 07:05Quote
The seed remembered its own coming into being, its own birth. A key that carries information, a key that carries memory, is a broken key. Always, every single time in the entire history of this technology, that has always been the problem.
- 07:50Claim · condensed
Notice what didn't change: the seed itself didn't get any shorter, it was the same 12 or 24 words, the same length in bits, it still looked like gibberish, it still restored perfectly. There's no test you can run on the words themselves to tell whether they came off dice rolls or a broken firmware build. What changed is that it became explainable, and explainable is the only thing that actually matters.
- 09:35Quote
One is unguessable, the other is undeniable, and the moment that you confuse which is which you start to lose both properties.
- 09:35Idea
The time chain is a total history with zero secrets, permanent, verifiable by anyone. The key is the exact reverse: a total secret with zero history, a number drawn one time, witnessed by nothing, connected to nothing, that leaves no trace anywhere in the world except wherever you put it, a memory of an event that as far as the universe is concerned never happened.
- 11:01Idea
Structure inside the key has to be zero, that's what makes it unguessable, because structure is a memory, any pattern in those bits, and structure holding the value has to be enormous: the steel plate you back your seed up with, a second copy in another jurisdiction, a plan for what happens if you die.
- 11:01Analogy
You can think of it like a road: if there is a road to a place, ultimately someone will drive down it. Structure is a road.
- 11:01Analogy · condensed
Think of the noise that is the key as the cargo, and the memory, the custody arrangement, as the ship that is carrying that cargo.
- 11:01Idea
When I say key I'm actually talking about three different things, and K equals Ic squared will score them all differently: the draw of the key, which is the active generation, committing energy to an irreversible process, a hundred dice rolls; the value, the number that actually comes out; and the custody, the whole arrangement that keeps that number alive as it moves through time and substrates.
- 13:15Claim
The draw is one event, unrepeatable, you do it one time. You do a hundred dice rolls, you can never roll the dice the same way again. It's unrepeatable, the energy was spent, the outcome occurred, and then you have to keep that a secret.
- 13:47Quote
A key with no custody is just noise.
- 13:47Quote
A custody scheme without a key is nothing, it's an empty box.
- 13:47Claim
The value only contributes information, those 256 bits, that's all. Its constraint quality has to stay at rock bottom forever, because constraint quality is structure, and structure in this sense is death, it's a story, a road that someone will drive down. The custody contributes everything else, all the testing, all the redundancy, all the reach.
- 14:42Claim
The key only becomes knowledge through custody, that's the relationship, and nothing else in Bitcoin works that way.
- 15:37Analogy · condensed
Take one seed, 32 bytes, sit it in a drawer, nothing is happening to it, and it has a completely different score depending on who's looking: from the owner's chair that value unlocks everything they own and its constraint quality is whatever their custody has earned for itself; from an attacker's chair the same bytes have no structure they can use, it's not even a fraction of a Bitcoin, it's zero.
- 16:20Idea · condensed
The gap between those two scores, that's your security. Everything you do in custody is widening that gap, every mistake narrows it. A brain wallet narrows it by handing the attacker structure. Losing your only backup narrows it by dropping your own side to zero.
- 16:20Quote
That's also a failure. Most, not most, a lot of Bitcoin's losses are self-inflicted.
- 17:18Claim
The attacker in this case isn't scoring your key at all, because they don't have it. What they have is a hypothesis about how your key came to be, a story, and that's the thing that gets scored. Run the framework's questions at that sentence instead: how many independent things have tested it, how long has it held up, what does it let them do that they couldn't do yesterday.
- 17:51Claim
If your key comes off clean dice, the only true sentence available about it is that it came out that way. There's no mechanism, no bias, no story connecting your key to anybody else's key or to any fact about you, so the attacker's best hypothesis is uniform across two to the 256, which is completely correct but does absolutely nothing for them; the reach of that information is zero, because the true explanation of your key has zero consequences.
- 18:46Claim
This wasn't brute force, nobody sat there guessing. What somebody had was one sentence: the library checks whether the flag exists rather than whether it's on, and that means the real generator is falling back to a predictable story, seeded from a chip ID, a boot count, and a clock.
- 19:24Idea · condensed
That claim got tested by things that have nothing to do with each other: reading the source, reproducing it across four different hardware models, deriving addresses from the predicted seeds, then going looking for them on chain, and facing the thousands of independent Bitcoin nodes run by people who've never met, who can't be bribed or flattered, who either verify or don't.
- 20:01Idea
Depth: the explanation held across five years of firmware, and every seed generated in that window, it never once failed to predict. Reach: that one sentence reaches every seed the firmware ever produced, retroactively and permanently, without the attacker needing to know a single name or country or anything about the people.
- 21:10Quote
The attacker just did better epistemology than everybody out there, and they did it in order to steal hundreds of millions of dollars from people who did almost everything right.
- 21:40Reference
Remember back to the episode that we did on P versus NP: this explanation was brutally expensive to find and it ends up almost being free to apply, and once you have it there's no rationing.
- 21:40Idea
It was brutally expensive to find and it ends up almost being free to apply. Once you have it there's no rationing, you don't apply an explanation to one wallet and then get fatigued, this is why the exploit looks like a harvest rather than burglary.
- 22:10Claim
Look at what happens to the attacker's knowledge the moment they sweep those addresses: before the sweep they held an explanation with open reach across an unbounded population of victims; after the sweep they hold a pile of coins in a very specific number, so the reach collapsed into inventory, and the explanation can't pay out twice because every affected seed that had money on it now doesn't.
- 23:41Quote
They exploited the absence of memory and now they're holding objects made of pure memory. They won on one axis and then lost instantly on the other, in the same system, in the same hour.
- 23:41Claim · condensed
Consolidating everything into one address, in the open, says the concealment was never part of the plan, possibly because they want it up as a monument: a permanent published proof that the explanation was real and complete.
- 25:01Claim
Nobody can delete your coins, the ledger only gets added to, no one can go back and erase you. The only threat is an unauthorized next entry, somebody producing a valid signature that moves your coins somewhere else. Protection isn't a wall around your money, it's exclusivity over who gets to write the next line.
- 25:47Analogy · condensed
In the fiat world you can think of protection like a wall around your money. That's not how it works in Bitcoin: Bitcoin doesn't have any gatekeepers, there's nothing that checks whether you're you, the network will accept a valid signature from anybody on earth, so exclusivity has to be manufactured out of thin air.
- 26:21Idea
Entropy protects your memory from being the one thing that isn't remembered. You cannot protect memory using more memory, and more memory is exactly what those Coldcard seeds were made out of: the chip ID, the boot count, the clock, all facts the world had already saved a copy of, and that pattern allowed the things to be found.
- 27:53Quote
The only thing that does not degrade is entropy. A properly drawn number leaks no partial information ever, you can watch the chain for a hundred years and you're gonna learn exactly zero bits about a properly derived private key. It's the one fixed point in a system where everything else is eroding. It's not just another layer, it is the root.
- 28:27Claim · condensed
When you're generating a key, you're not generating knowledge at all, you're generating unguessability, a different job with different physics. Everything else in Bitcoin, the protocol, the code, the ledger, the incentives, is built to be understood by anybody who looks. Your key is the single object in the whole stack that is deliberately built to be ununderstandable.
- 29:03Idea
The entropy you generate with a hundred dice rolls is a one-time commitment that shouldn't have any memory to it, except that you guard the memory of that one thing having happened, because you are the only one who has ever seen that specific pattern. You can roll a hundred times again but you'll get a completely different key, you can't recommit to the same one, and you can't run the dice backwards. It's the pawl at the scale of one person.
- 29:50Idea
Knowledge is a state that transfers, and that has the ability to travel. Where does that arrangement travel to, to what substrate? You become the substrate, that's the weirdest bit.
- 30:23Analogy
The arrangement has to travel and you are the channel: dice to your brain, your brain to paper, paper to steel, paper to the device you use to generate the transaction, on to the device you use for your signature. Those are all substrate changes, and it has to keep its exact shape through every single one, because if you get one wrong word, one wrong bit, the whole thing is dead. Perfect fidelity carrying zero meaning.
- 31:07Claim
The proper ritual: you roll the dice, get the numbers, plug them in, get your words, put them in a device, send a small amount of Bitcoin to it, wipe the device completely, restore it from your backup, and spend the coins. If you're able to spend the coins you sent to the wallet you wiped, you've done it all correctly, you've managed to constrain that information for long enough to make it useful.
- 31:39Claim
The network, thousands of independent nodes, verifies that you restored your key and control those coins, and not one of those nodes learns anything about your key. The signature proves you hold it without revealing it. Normally being tested costs you exposure, here you get the harshest class of verification that has ever existed, checking you indefinitely, for free, and it never gains a single bit of information about the thing it's checking.
- 32:14Idea · condensed
Back to K equals Ic squared: the breadth times depth, it isn't one, it felt like one when you generate a seed, because you're the only verifier who knows the secret, but the number of blind verifiers is effectively unlimited, and that's what lets you build up constraint quality on something you can never show anybody.
- 33:21Claim
That ritual wouldn't have saved anybody in the Coldcard exploit. Every victim could have run it perfectly, wiped, restored, spent, and gotten a 40-bit seed that restores perfectly. Every step of that ritual is downstream of the draw, and the draw is the one act in this entire process that nobody ever tests, not you, not the network, not anybody, ever.
- 34:01Claim · condensed
What you've confirmed with the wipe-and-restore ritual is that your backup and your wallet, copy A and copy B, match each other. That's worth doing, it'll catch a misspelled word or two words swapped, but if the original number is rotten, copy A and copy B are both rotten, and they'll still match each other perfectly.
- 34:43Analogy
You can inspect a house's wiring, plumbing and roof any day you want, as often as you want, for as long as you want. The one thing you can't inspect is the foundation, it only gets poured once and then it gets sealed, and the only thing that mattered to the foundation was the quality of the concrete on the day.
- 35:31Claim
The draw is your foundation, everything else is the house. If depth can't reach the draw, everything falls on breadth, and breadth means genuinely independent sources, things that don't share a failure mode. One vendor is a breadth of one, no matter how good the vendor is, no matter how many years, no matter the reputation. Everybody who got drained had one source of entropy and one firmware, and that was the entire problem, and it would be the whole problem for any manufacturer.
- 36:24Claim
Rolling dice, with all our technology, is still the best thing we can do, because the universe has never seen that number, there is no story to it, no rhyme or reason, no structure. AI does not break entropy, it's an explanation-finding machine; point it at an object engineered to have no explanation and it does nothing forever, no matter how good it gets. But point it at a wallet generator with a clock in it, and it's gonna eat everything.
- 36:24Quote
Those seeds were compromised in 2021, all of them, the moment they were created, and for five years they looked completely fine. They weren't surviving anything, they were just sitting there in the open, waiting for someone to notice, and when somebody did, that safety evaporated.
- 36:24Quote
What you want to think about doing when you're generating a private key in Bitcoin is you are putting a hole in the record that no one can ever fill in.