WEEKLY - Coldcard + BRCA
plus: assorted links, stunning photography and more...
Hello everyone! I hope you’re all well and taking care of yourselves.
Substack tells me I’m #15 rising in Crypto, which is weird but encouraging – I never expected to rank highly as I don’t give trading ideas, and my market overviews are weekly if that. But of course I’m chuffed, even if that rank disappears tomorrow.
You’re reading the free weekly send of the premium daily Crypto is Macro Now, where I re-share a couple of the week’s posts and add some non-crypto and non-macro links since it’s the weekend. 🌼
If you’re not a subscriber to the premium daily, I do hope you’ll consider becoming one! For $12/month, you’ll get ~daily commentary on how crypto is impacting the macro landscape, and vice versa. I talk about adoption, regulation, tokenization, stablecoins, CBDCs, market infrastructure shifts and more, as well as the economy and investment narratives.
PUBLISHED IN PARTNERSHIP WITH: ✨ ALLIUM ✨
When MiCA forced changes in Europe, the expectation was that capital would leave onchain. It mostly didn’t.
Our research follows the self-custody outflows from Binance and shows where the funds actually went. The onchain trail tells a different story than the headlines did.
→ Download the report: https://www.allium.so/reports/binance-mica-self-custody-outflows
And get weekly onchain data and analysis like this from the Allium Research team on Substack.
In this newsletter:
What the Coldcard blow means for Bitcoin
What is the BRCA?
Assorted links: Books, sci-fi, chips and a grab-bag of ideas
Weekend: aerial photography
Some of the topics discussed in this week’s premium dailies:
Coming up this week: US jobs data
Monday musings: The cost of geopolitical manipulation
What the Coldcard blow means for Bitcoin
Term of the day: BRCA
Why you should care about bank charters
Term of the day: OCC
Markets: a rhythm shift?
Term of the day: earnings revision breadth
What the Coldcard blow means for Bitcoin
It has been a bleak couple of weeks for the Bitcoin community, and for once it has nothing to do with the price.
Below, I’ll outline what happened, why this is such a big deal, what people are getting wrong, and what this could mean for Bitcoin and the broader market going forward.
What happened
Some background: Coldcard is a Bitcoin-only hardware wallet (a physical device with embedded software, as opposed to a wallet accessible via your browser or mobile phone).
It operates completely offline, generating private keys and signing transactions without touching the internet – known as “cold storage”, this is the most secure form of Bitcoin custody in that you don’t depend on third parties to keep your assets safe, and your holdings are not at risk from online hacks.
Coinkite – a Canadian company founded in 2012 to offer a Bitcoin web wallet and payment services – launched Coldcard in 2017 as an affordable cold storage solution. It came highly recommended by several industry leaders; the Human Rights Foundation even handed out Coldcards at a couple of their events.
One of the reasons Coldcard was trusted is that its firmware (software programmed directly into a hardware device) was open source – anyone could verify it. This changed in late 2020 when the firm announced its intention to migrate its firmware to a more restrictive license. The change became effective in March 2021 – only, it turned out that the software upgrade unwittingly introduced a flaw.
By now, all of you reading this will have had issues with passwords: either they’re incredibly secure but useless because you can’t remember them, or they’re easy to remember but useless because a hacker could figure them out in seconds. You can use password managers, but that still involves a layer of trust and a potential vector of vulnerability.
The most secure passwords are those that are long and totally random with a jumble of letters, numbers and symbols. For wallets, these are automatically created using a random number generator. Only, real randomness (also known as entropy) is not as simple as it sounds – it takes work. And an error in the 2021 Coldcard software upgrade contained a randomness error that went unnoticed until now. Put simply, the code generated keys that were not that random after all.
On Thursday of last week, a user on Reddit posted that their Coldcard wallet, untouched for years, had been drained. Word spread and, within hours, a wave of cold wallet attacks had been confirmed. As I type, they are still ongoing – latest data suggests that well over $100 million worth has been stolen so far, and that there are now several attackers exploiting the same vulnerability.
Why it’s a very big deal
First, I am beyond grateful to report that I have not been affected – I don’t have much BTC anyway, and I use a multisig custody service. My heart goes out to all those who have lost savings, and to those who have lost faith.
This attack is especially painful because it’s happening to people who thought they were doing everything right. They were taking the extra precaution of self-custody, via a trusted cold storage hardware wallet. They had no reason to suspect the firmware had a flaw. And yet many have lost their savings.
True, this is not as systemic a disaster as the Terra/Luna and FTX collapses, which caused untold harm to the industry and set back its development by years. This series of hacks won’t do that – but it hurts because it’s hitting those that largely reject the risk-happy “financialization” of the industry, that value self-sovereignty, that prefer to trust themselves.
The resulting losses have been enough to cause many to question the whole Bitcoin ethos – is secure self-custody even possible?
It’s as if you chose to hold your wealth in gold bars because you don’t trust banks, so you hire a firm to build a vault and to guard it. That firm then steals your bars. You thought your wealth was safe because you took steps. It is a shock to learn the hard way that’s not enough.
What people are getting wrong
Unsurprisingly, X surfaced a smattering of glee that Bitcoin has turned out to be vulnerable (“see?? the code isn’t so secure after all!”). This is nonsense – Bitcoin’s code is not at all involved, it is as secure as ever. The flaw was in the firmware of a hardware wallet.
There are also some that insist no custody is secure. This conflates custody infrastructure with custody processes – while it’s true that neither is infallible, a careful combination of the two can produce secure solutions.
Some have yelled that this is the worst thing to ever happen to Bitcoin. I’ll argue that the Mt. Gox crash was worse as it had the potential to really kill the nascent industry. This incident doesn’t.
And there are those who feel betrayed enough to abandon Bitcoin altogether, accusing its narrative of being a sham. That is pain speaking, and it’s understandable. But it’s short-term.
What’s ahead
The blow is bad, but the incident has highlighted the best of the ecosystem. Many experts immediately jumped in with offers of help in moving coins, tracing movements, running industry-wide scans, contacting law enforcement, etc. There was despair; there was also cooperation and kindness.
Hopefully, those who have lost funds will be able to recover some of them – blockchain forensics teams are on the job and the hackers will be identified. Yet again we are reminded of an intrinsic advantage of a transparent network that permits real-time tracing. It’s much harder in this case as stolen coins are not exiting from one source as in an exchange hack, and tracing depends to some extent on user reporting. But they’re on it.
We have also all been given a healthy reminder to check security, often. It’s so easy to forget, I know I do.
And we have been given a sobering glimpse at what’s ahead for all passwords – AI is coming for your access. If not AI, then quantum computing, or both. AI can also help shore up defences, but collectively we are just beginning to understand the nature of the security threat.
I am surprised the price was not more affected – you’d think expectations of the thieves cashing out would push BTC down, but it has been climbing for most of the week, and as I type it is approaching $65,000.
(chart via TradingView)
In sum, this incident touched a nerve and did some damage, both economic and psychological. But Bitcoin will recover. The community is strong. And while there are still many usability and security issues to resolve, the value thesis is intact.
I often get asked how I find something to write about every day for the newsletter.
My problem is more one of not having time to cover everything I consider relevant to the crypto-macro intersection. My backlog list is long.
But I’m good at surfacing the most relevant and also overlooked trends.
So, subscribe. 😎
What is the BRCA?
(There is so much jargon flowing around crypto and finance, so much “insider” language – so, most weekdays in the premium newsletter, I define a term that is often used but not well understood.)
In August 2023, Roman Storm – a blockchain developer and co-founder of cryptocurrency mixer Tornado Cash – was arrested in the US for conspiring to operate an unlicensed money-transmitting business, conspiracy to commit money laundering and conspiracy to violate US sanctions. Co-founder Alexey Pertsev was arrested in the Netherlands the previous year, and third co-founder Roman Semenov was charged but not arrested. Prosecutors alleged that Tornado Cash was used for processing criminal proceeds, that the developers knew this, and were therefore complicit.
Storm was found guilty by a federal jury in New York of the first count – conspiracy to operate an unlicensed money-transmitting business – but the jury was hung on the second two. The prosecutors are seeking a retrial.
The case is perhaps the most high-profile example of the dangers of being a blockchain developer. In 2019, FinCEN published interpretive guidance that anonymizing software providers are not money transmitters, unless they directly accept value from a customer. The Tornado Cash developers do not handle the tokens sent to the smart contract. And yet Storm was found guilty of being a money transmitter. Prosecutors insist he should be held accountable for the money laundering and sanctions evasion that happened in the smart contract he co-developed.
The Blockchain Regulatory Certainty Act (BRCA) hopes to protect blockchain developers from indirect liability. It specifically protects developers and providers of distributed ledger software who do not have the right or ability to control users’ assets from being treated as money transmitters and from being held liable for the way in which the tools they develop are used.
Of course, coding with intent to commit a crime would be punishable (“here’s a great program I wrote to help you avoid sanctions!”) – but making a neutral tool for anyone to use would not.
The Act was first introduced in the House of Representatives in 2018 by Tom Emmer (R-MN) and others, and has been reintroduced many times since then. A Senate version was introduced in January of this year by Senators Cynthia Lummis (R-WY) and Ron Wyden (D-OR), and has since been narrowed and incorporated into the CLARITY Act as Section 604.
It is bewilderingly controversial. Some argue that developers should be held more liable for consequences, especially as technology seeps into more areas of our lives. Others insist it would hinder law enforcement efforts when it comes to tracing funds, that it would weaken money-transmitter rules, and that it creates loopholes for criminals to exploit.
But we have to fervently hope it passes, as it is an essential pillar for not just blockchain development in the US, but open source development more broadly. And, the fundamental principle – responsibility for third-party use – could seep into other industries that manufacture tools criminals might use, pushing a broad spectrum of technological progress offshore.
ASSORTED LINKS
(A selection of reads I came across this week that I think are worth sharing, not about crypto nor macro. I try to choose links without a paywall, but when I feel it’s worth making an exception, I specify.)
The New York Times brings you a list of the 50 best thrillers of the 21st century, as submitted by hundreds of thriller writers. So much to peruse here, whether you’re a fan of the genre or not – I most certainly am, and now have a long bookshop list. (The 50 Best Thrillers of the 21st Century, New York Times – paywall)
More on books: Henry Farrell and Dan Wang of the Financial Times look at why the novels of Philip K. Dick feel so familiar: “He was not a good writer for his time. But he is a great writer for ours.” (Does Silicon Valley dream of Philip K Dick?, Financial Times – paywall)
I’m a fan of Derek Thompson’s occasional grab-bag sweeps of topics he’s interested in – he manages to keep the overwhelm off the page while triggering our desire to learn more. (The 9 Questions I’m Obsessed With Right Now: AI, Politics, Movies, Drugs, and Western Civilization, Derek Thompson)
An utterly charming interactive map of how chips are made, in the aesthetic of Rollercoaster Tycoon. (ChipTycoon)
HAVE A GREAT WEEKEND!
(in this section, I share stuff that has NOTHING to do with macro or crypto, ‘cos it’s the weekend and life is interesting)
Regular readers will know by now that I love gorgeous photography – the glimpse of other lives, other worlds, the breathtaking shape of light and colour.
It’s been a while since I came across a good competition to sift through, so you can imagine my gasp of delight when I found the International Aerial Photographer of the Year set – it invites you to enjoy stunning images while imagining yourself a bird.
Below are just a few of my favourites, but check out the other finalists here.
Kah-Wai Lin
Aleksandra Wilk
Azim Khan Ronnie
Max Horng
DISCLAIMER: I never give trading ideas, and NOTHING I say is investment advice! I hold some BTC, ETH and a tiny amount of some smaller tokens, but they’re all long-term holdings – I don’t trade. Also, I often use AI for research instead of Google, but never for writing.








