Cypherpunk’d

← Cypherpunk’d11 Aug · 55 min

Is Bitcoin Self-Custody Broken? Coldcard Flaw & The Future of Security

Is Bitcoin Self-Custody Broken? Coldcard Flaw & The Future of Security11 Aug55 min

<p>Over $100M in Bitcoin vanished from hardware wallets — no phishing, no malware, nobody touched a device. Just a broken random number generator that sat in open-source code for five years.</p>

<p>Matty sits down with Dr. Francesco Madonna — physician, former military medical officer, and founder/CEO of BitVault — to break down exactly how the Coldcard entropy failure worked, why "random" wasn't random, and what it means for the future of self-custody.</p>

<p>Francesco also walks through his own near-miss with a physical attack scam, and how it led him to build a wallet where a stolen seed phrase still can't drain your funds — using on-chain time-locks and 2-of-3 multisig that always give the real owner priority over the attacker.</p>

<p>In this episode: </p>

<p>• How a single build flag turned "random" seeds into guessable ones </p>

<p>• Why hardware wallets were never the whole story </p>

<p>• Time-locked vaults, explained (the 80-year-old bank tech behind them) </p>

<p>• Open source vs. closed source after a 5-year public bug </p>

<p>• Francesco's Dubai-diamond-dealer scam story (and why he moved countries) </p>

<p>• The 60/20/20 self-custody debate: are you a self-custody maxi?</p>

<p>⏱️ Chapters</p>

<p>00:00 Cold open </p>