What the Coldcard blow means for Bitcoin
plus: what is the BRCA and why should we care?
“It has been said that man is a rational animal. All my life I have been searching for evidence which could support this.” – Bertrand Russell ||
Hello everyone! I hope you’re all taking care of yourselves.
👀 You’re reading Crypto is Macro Now, which covers the role crypto is playing in the changing plates of finance, economics, politics, culture and markets. 👀
Production note: this newsletter will skip production this coming Friday. 🐟
PUBLISHED IN PARTNERSHIP WITH: ✨ ALLIUM ✨
A futures market on compute?
GPU rental prices are starting to trade months ahead. Take Nvidia’s B200, its flagship AI chip: It costs about $6.58 an hour to rent today.
Kalshi and Polymarket now let traders take positions on what that hourly rate will be months from now.
→ Download the report: https://allium.so/reports/gpu-rental-prediction-markets
Get weekly onchain data and analysis like this from the Allium Research team on Substack.
IN THIS NEWSLETTER
What the Coldcard blow means for Bitcoin
Term of the day: BRCA
Crypto is Macro Now offers ~daily commentary and updates on the overlap between the crypto and macro landscapes. Plus links and more.
If you’re a premium subscriber, thank you so much!! ❤
WHAT I’M WATCHING:
What the Coldcard blow means for Bitcoin
It has been a bleak few days for the Bitcoin community, and for once it has nothing to do with the price.
Below, I’ll outline what happened, why this is such a big deal, what people are getting wrong, and what this could mean for Bitcoin and the broader market going forward.
What happened
Some background: Coldcard is a Bitcoin-only hardware wallet (a physical device with embedded software, as opposed to a wallet accessible via your browser or mobile phone).
It operates completely offline, generating private keys and signing transactions without touching the internet – known as “cold storage”, this is the most secure form of Bitcoin custody in that you don’t depend on third parties to keep your assets safe, and your holdings are not at risk from online hacks.
Coinkite – a Canadian company founded in 2012 to offer a Bitcoin web wallet and payment services – launched Coldcard in 2017 as an affordable cold storage solution. It came highly recommended by several industry leaders; the Human Rights Foundation even handed out Coldcards at a couple of their events.
One of the reasons Coldcard was trusted is that its firmware (software programmed directly into a hardware device) was open source – anyone could verify it. This changed in late 2020 when the firm announced its intention to migrate its firmware to a more restrictive license. The change became effective in March 2021 – only, it turned out that the software upgrade unwittingly introduced a flaw.
By now, all of you reading this will have had issues with passwords: either they’re incredibly secure but useless because you can’t remember them, or they’re easy to remember but useless because a hacker could figure them out in seconds. You can use password managers, but that still involves a layer of trust and a potential vector of vulnerability.
The most secure passwords are those that are long and totally random with a jumble of letters, numbers and symbols. For wallets, these are automatically created using a random number generator. Only, real randomness (also known as entropy) is not as simple as it sounds – it takes work. And an error in the 2021 Coldcard software upgrade contained a randomness error that went unnoticed until now. Put simply, the code generated keys that were not that random after all.
Last Thursday, a user on Reddit posted that their Coldcard wallet, untouched for years, had been drained. Word spread and, within hours, a wave of cold wallet attacks had been confirmed. As I type, they are still ongoing – latest data suggests that well over $100 million worth has been stolen so far, and that there are now several attackers exploiting the same vulnerability.
Why it’s a very big deal
First, I am beyond grateful to report that I have not been affected – I don’t have much BTC anyway, and I use a multisig custody service. My heart goes out to all those who have lost savings, and to those who have lost faith.
This attack is especially painful because it’s happening to people who thought they were doing everything right. They were taking the extra precaution of self-custody, via a trusted cold storage hardware wallet. They had no reason to suspect the firmware had a flaw. And yet many have lost their savings.
True, this is not as systemic a disaster as the Terra/Luna and FTX collapses, which caused untold harm to the industry and set back its development by years. This series of hacks won’t do that – but it hurts because it’s hitting those that largely reject the risk-happy “financialization” of the industry, that value self-sovereignty, that prefer to trust themselves.
The resulting losses have been enough to cause many to question the whole Bitcoin ethos – is secure self-custody even possible?
It’s as if you chose to hold your wealth in gold bars because you don’t trust banks, so you hire a firm to build a vault and to guard it. That firm then steals your bars. You thought your wealth was safe because you took steps. It is a shock to learn the hard way that’s not enough.
What people are getting wrong
Unsurprisingly, X has surfaced a smattering of glee that Bitcoin has turned out to be vulnerable (“see?? the code isn’t so secure after all!”). This is nonsense – Bitcoin’s code is not at all involved, it is still as secure as ever. The flaw was in the firmware of a hardware wallet.
There are also some that insist no custody is secure. This conflates custody infrastructure with custody processes – while it’s true that neither is infallible, a careful combination of the two can produce secure solutions.
Some have yelled that this is the worst thing to ever happen to Bitcoin. I’ll argue that the Mt. Gox crash was worse as it had the potential to really kill the nascent industry. This incident doesn’t.
And there are those who feel betrayed enough to abandon Bitcoin altogether, accusing its narrative of being a sham. That is pain speaking, and it’s understandable. But it’s short-term.
What’s ahead
The blow is bad, but the incident has highlighted the best of the ecosystem. Many experts immediately jumped in with offers of help in moving coins, tracing movements, running industry-wide scans, contacting law enforcement, etc. There was despair; there was also cooperation and kindness.
Hopefully, those who have lost funds will be able to recover some of them – blockchain forensics teams are on the job and the hackers will be identified. Yet again we are reminded of an intrinsic advantage of a transparent network that permits real-time tracing. It’s much harder in this case as stolen coins are not exiting from one source as in an exchange hack, and tracing depends to some extent on user reporting. But they’re on it.
We have also all been given a healthy reminder to check security, often. It’s so easy to forget, I know I do.
And we have been given a sobering glimpse at what’s ahead for all passwords – AI is coming for your access. If not AI, then quantum computing, or both. AI can also help shore up defences, but collectively we are just beginning to understand the nature of the security threat.
I am surprised the price was not more affected – you’d think expectations of the thieves cashing out would push BTC down, but yesterday it started climbing and earlier today briefly poked above $64,000.
(chart via TradingView)
In sum, this incident touched a nerve and did some damage, both economic and psychological. But Bitcoin will recover. The community is strong. And while there are still many usability and security issues to resolve, the value thesis is intact.






