Today, Bitcoin Policy Institute and a broad coalition from across the digital-asset ecosystem are publishing an open letter calling on the world’s leading AI labs to provide qualified open-source defenders with trusted access to frontier AI models.
The past several weeks have made the need for this abundantly clear. The people defending digital-asset infrastructure and open-source software need access to the latest AI capabilities to perform comprehensive security reviews and stay ahead of increasingly sophisticated adversaries.
The coalition includes open-source development organizations, major custodians, treasury companies, payment services, security firms, capital allocators, and others whose businesses and customers depend on the integrity of open-source infrastructure and libraries.
Open-source defenders often occupy the least privileged position in the AI security landscape. They have limited access to the strongest internal cyber models and are frequently blocked by guardrails when using publicly available frontier systems for legitimate security research. As a result, they often resort to less capable open-weight alternatives.
We are urging frontier AI labs to establish a clear, trusted pathway for qualified open-source and digital asset defenders to access their strongest capabilities, with sufficient compute and secure environments to conduct meaningful security reviews. Frontier AI could become one of the most powerful defensive technologies ever developed, but only if defenders get fair access to those systems.
It’s time to give defenders the tools they deserve.
Read the open letter, add your organization, or sign as an individual on our website at https://t.co/cUTwQ5ugXJ
Those who wasted our time and energy with BIP-110 are not going to tell us what to focus on.
Bitcoin needs a great consensus cleanup and covenants. Possibly a few more optimizations.
Just because the most retarded update in Bitcoin's history has failed, doesn't mean we need to slow down.
The great crashout of the incompetent is over. The engineering mindset must take over now.
We are now mapping the ongoing Coldcard attack with a live dashboard - link below
I am deploying tripwire UTXOs that have varying levels of added entropy on top of the broken default seeds. We have different levels for 5, 10, 15, ... dice rolls, and 1, 2, 3, ... passphrase words.
This is so we can approximate the frontier of the confiscations that are actively happening.
The control UTXO with no added entropy was swept in an hour.
I took real measurements on an MK3 to calibrate a "good bad entropy" emulator in software. The control confiscation has proven it to work.
I am going to continue to deploy tripwire UTXOs along the bit curve.
Huge thanks to @Rob1Ham@otaliptus@PortlandHODL and other redteamers for the help.
The most common question I am getting right now in the fall out of the news of COLD CARD MK3, MK4, MK5 and Q having compromised entropy, is:
"Rob, what would you do right now if you were in my shoes? Where would you send your bitcoin to be safe?"
I will share with you my list of what I would do, but first, there is AN URGENT SECURITY ADVISORY IN THE BITCOIN ECOSYSTEM.
Below is my personal assessment of the situation.
If you or someone you know:
Uses an MK3, MK4, MK5, or Q in a single signature
OR
A multi signature wallet where the cold card devices can move the funds on their own (Example, 2 cold cards and a Ledger).
Please continue reading. You may be in danger. If this does not apply to you, keep on reading if you like, but you are not impacted by this issue.
If you are still here, there are three identified mitigations that protect you at the moment. They are all different forms in which you may have brought your own entropy.
A: DICE - This is done by either rolling dice from the start, or adding dice rolls to the generated seed phrase. At least 50 dice rolls would be my threshold at 128 bits of entropy.
OR
B: PASSPHRASE - You used a passphrase of sufficient entropy (128 bits).
128 Bits of entropy pass phrase examples include RANDOM combinations of the following:
- 12 BIP 39 seed words.
- 10 common words in the english language
- 25 mixed lower case letters and numbers
- 20 if you use ASCII characters
Note on pass phrases: This does not include the same word 12 times, 10 words in a sentence, etc. This combinations of characters/numbers OR words should never have been seen or spoken before in the total sum of all human knowledge and experiences. It needs to be RANDOM for it to be entropy.
OR
C: EXTERNAL ENTROPY - Your seed phrase was derived entirely outside of the cold card ecosystem. (It was imported into the cold card, not generated on it)
Now, if you are still reading, and you do not have any of these mitigations in place, you need to move your funds. The urgency of circumstances are as follows:
TIER 1: AS SOON AS POSSIBLE
Scenario A: If you are in a signature wallet with an effected device, and did not use any of the mitigations listed above. You need to move funds right now. Find someone to help you, any moment your funds can be stolen.
Scenario B: If you have an N of N (eg 2 of 2, 3 of 3, etc) multisig of just cold card devices that did not have mitigations listed above (dice and/or passphrase).
Attackers will be grinding all of the combinations of compromised keys. They know all your seed phrases. You are compromised. It is just a matter of time for them to assemble the puzzle pieces together and steal your funds.
If this scenario is you, I will have more below on how to mitigate risk when broadcasting your transaction.
TIER 2: URGENTLY
If you are in a single signature wallet with an effected device, and you used either less than 50 dice rolls OR a pass phrase less secure than what I shared above. The entire security of your bitcoin is reliant on how much of Dice AND Passphrases you applied to your wallet.
Attackers know your seed phrase. Your entropy from dice or pass phrase is the only thing protecting you. Did you add a pass phrase of 'bitcoin'? You are basically in tier 1. Did you use 6 words? You are not at tier 1, but you aren't safe. You need to make plans to move funds quickly.
TIER 3 SOON, BUT IMPORTANT CONTEXT:
You have a multi signature wallet where the compromised devices have sufficient ability to move the funds. An example is a 2 of 3 multisig where you have 2 cold cards and another signer.
The issue with Tier 3 is that an attacker may have already figured out your insecure seed phrases. This means when you broadcast your bitcoin transaction, an attacker in theory can then steal your funds.
NOTE: IF YOU ARE IN THIS SITUATION, AND YOU HAVE REUSED ADDRESSES, ALL REUSED ADDRESSES PUT YOU RIGHT BACK AT THE TIER 1 MOVE RIGHT AWAY YOUR FUNDS ARE AT RISK AT THIS VERY MOMENT
You should look into finding a way to use the @MARAFoundation_ slipstream service, which uses a private mempool. This means that by the time an attacker could see your attempted recovery, it is already in a block and not possible for them to steal funds.
TIER 4: KEY ROTATION. This is where you have an insecure cold card(s) in your multisig quorum, and you know that the other keys in your quorum are not impacted by this bug.
If there is a MK3,MK4,MK5 or Q in the quorum, BUT they either: 1. Rolled sufficient dice (50 min) 2. Have a strong pass phrase (as defined above). 3. Used entropy not sourced from the device, they are not impacted by this bug in the Cold Card (see notes earlier on mitigations).
You are in a position where a minority of your keys are compromised. Funds are safe, but you are at reduced security. Make plans when you are able to remove the compromised device from your wallet.
Now. With that security advisory out of the way, back to the question, what would I do in this situation?
Below is just my opinion, but you should not rely on only my opinion, you will have to make your own choices based on what you feel is best for you.
I want to be clear, if you are not on this list. It is not that I think your product/business is bad, insecure or at risk, I am directly answering the question of what I would do. This is my personal judgement given my decade of experience in bitcoin.
First, a disclaimer:
My bitcoin is at my company @AnchorWatch. I have full skin in the game in that if I'm offering a custody solution, there will never be another place I store large amounts of bitcoin long term for myself or my family, and it will be this way as long as I am here.
I was the first bitcoin that went on our Trident Vault platform. If the day ever comes, I will be the last bitcoin to leave the platform.
The years of what we built at AnchorWatch were for exactly moments like this. Avoiding catastrophic risk of ruin scenarios.
We offer 2 products:
1. Our Flagship Product where you as the customer can hold 1 or 3 keys, and we act as a cosigner. We leverage bitcoin native smart contracts which allow for your bitcoin to have different ways it can be spent across time.
2. Multi Institution Custody, where we let you distribute your keys across 3 institutions of ourselves, @bitgo and @CoinCorner. 2 of the 3 institutions must sign off on the transaction, and you have to present a Yubikey signature before withdrawing to mitigate deepfake and compromised accounts.
For both products as, since we are a cosigner, we are able to enforce rules like whitelisted addresses, and velocity controls (how much bitcoin can you send how often). You can even disable the send button on the platform if you so choose!
We also offer 1:1 insurance backed by Lloyd's of London.
If you want to learn more about what we do, hit up @_joerodgers or @BeccaAmilee to learn more, or check out our website.
Now with that out of the way, places where I'd leave my bitcoin (besides @AnchorWatch) in no particular order:
Custodian:
I'd trust my life savings at @River under a duress situation. This is one of those times. @Leishman and the entire team at River are elite operators. It is my favorite bitcoin services business in the market today outside of my own.
They own their own custody infrastructure, and at times like this, you want those who have extreme ownership and control over how their customer's money is being managed.
@River does monthly proof of reserves, and you can turn on the force field feature which will freeze withdrawals of bitcoin. They have a world class custody team as well, and are making improvements regularly with a larger upgrade that has been planned for a long time, happening later this year.
Collaborative Custody:
1. The @Bitkey is an incredible product with an elite team of engineers supported by the @BlockEng organization. They have exceptional bitcoin developers across @spiral_xyz and @CashApp teams who deeply understand Bitcoin.
@jack has been a long time believer in bitcoin who has built an organization that has no peer in the resources they have not just understanding bitcoin, but building on bitcoin.
You can pick it up a Bitkey at best buy today!
I do want to add a disclaimer that all keys are managed within the Bitkey ecosystem. The Bitkey team has gone to great lengths to keep things secure, but in light of recent events, I want to call that out. At the moment, the Bitkey is my only exception to a purist ideal of multi vendor multisig (more below).
2. @CasaHODL - @Nneuman and @lopp have been on top of this incidence response, and have built a very clean user experience to let people be safe. You can either use a 2 of 3 or 3 of 5 multisig with a great mobile app. Casa is the best UX for soverign collaborative multisig that exists in the market today.
3. @uncahined - Unchained pioneered the collaborative custody model and the multi institution custody model. They have been working around the clock trying to support customers and have even been able to use slip stream going the extra mile on short notice to keep customers bitcoin safe.
Self Custody:
I have spent close to $5k on LLM tokens over the past 24 hours scanning over a hundred bitcoin related repositories. As of now, I have seen no vulnerability that has me concerned about any hardware device outside of the Cold Cards.
Even so, you can't be sure. So I would follow the @mflaxman "Bitcoin 10x security guide". Its how I held my bitcoin before I founded @AnchorWatch, and even though the guide is 6 years old, the principles are timeless. I would remove his suggestion of using the cold card and replace it with any other hardware wallet. I would replace the cold card with a @Ledger at this time if it were my decision. You can pick up a Ledger up at Best Buy in the US.
Michael pioneered multi vendor multisig as a concept, and if you want a fully sovereign solution, as of today there is no better mental model on how to think through this, he has advanced tabs to further increase the security. For his cold card guide he fairly calls out the added benefit of rolling dice, which would have saved you today.
I think the future is combining the tech we use at @AnchorWatch to move beyond the single signature/ multi signature paradigm of custody, with the principles of @mflaxman's 10x security guide and the support of collaborative custody.
More on that later, but I would check out @lianabitcoin from @Wizardsardine as well, they offer a fully open source wallet that enables these more advanced smart contracts and are security researchers in the bitcoin ecosystem.
With that, I'm going to get back to work. I will post a followup reply if I have additional information or any corrections or clarifications to make.
“Bitcoin is a clock with a new concept of time – block height – synchronously marking depletion of the most valuable resource in the universe, our time.” - Read the Stone Ridge 2024 Investor Letter from Ross Stevens, Founder and CEO https://t.co/ty5FwzVCZq
BITCOIN CORE'S LOSS OF FOCUS
The legacy technical leadership in bitcoin is becoming increasingly less effective.
--
Almost universally, Core and "graybeard" devs are not focusing on _the_ fundamental problem in bitcoin: preserving trustless UTXO ownership.
Instead they are distracted with valuable but secondary issues like mempool policy, Core code architecture, and minor IBD performance. These things are important in their own right, but they fundamentally don't matter if in times of trouble most users can't take possession of their own coins.
Core devs are exceptionally talented people. The brightest engineers. But the priorities of the project are out of whack.
The aggregate focus does not reflect the thing that makes bitcoin a unique asset: trustless custody.
--
Given the current limits of bitcoin, even upper-middle class Americans will not be able to self-custody, let alone the rest of the world.
If bitcoin doesn't figure out how to ensure that most users have a trustless way of owning and sometimes moving coins, it will become basically indistinguishable from a gold ETF. A row in some OFAC-compliant database. Another financial widget that is subject to the regulatory dictates of government.
In fact, if bitcoin does not scale UTXO ownership, gold will have the advantage that at least small amounts of it *can* be self-custodied and traded peer-to-peer. The same won't be able to be said for bitcoin. In a world where on-chain fees are in the thousands of dollars and there is not a workable, trustless layer two, most coins will be stuck with custodians.
Forget payments. I'm talking about savings. I'm talking about less than checking-account volume. 1-2 transactions a month.
If you think that most people should be able to DCA and withdrawal to self-custody once a month, maybe spend once every few years for big purchases, I've got news for you:
Given bitcoin's current limitations, only 18 million users can do that. A little over 5% of Americans.
--
Right now, the chain capacity is able to meet demand for self-custody because we are in a time of relative peace.
Most don't feel at risk keeping their bitcoin with a custodian. That can change very rapidly.
As bitcoin grows in value and challenges fiat currency, governments will increasingly want to control it. They won't ban it, which is now obvious, but almost certainly they will impose OFAC-like restrictions and possible wealth taxes.
When the regulatory hammer comes down, tens of millions will look to withdrawal their coins into self-custody. But they may not be able to.
--
Unfortunately this risk does not seem to be top of mind in the current Core culture.
One instance of a tone-deaf Core response to this kind of problem relates to CTV. As @JeremyRubin has been pointing out for years, CTV would be the most efficient way to guarantee that people can withdrawal coins from institutions in times of chain-panic and congestion, allowing exit to happen during crises without fully "unrolling" transactions. I wrote about this at length in 2023, and why it seems there is no more efficient way to do this (https://t.co/U2qqgZJYCt).
And yet technical figureheads like @TheBlueMatt and @murchandamus downplay the value of CTV, claiming that it has no compelling uses.
CTV is one of the primitive building blocks that we need to figure out UTXO scaling solutions. (Not to mention its use in applications like vaults.)
Some Core devs might argue "well okay, maybe we need that functionality - but CTV isn't the right way to do it. We need to think harder!"
The problem is that time is running out. As nation-states begin to enter the technical ecosystem, soft forks that promote scaling and self-custody will be more difficult to deploy. Powerful actors will not want bitcoin to change - they're perfectly happy letting regulated custodians act as the L2.
As the market cap grows, the stakes of change go up, and it will be much harder to get economically relevant actors to run new consensus.
Because Core devs aren't paying close attention to the covenants conversation, they may not realize that CTV is upgradeable, simple, and well-tested. It's good enough.
This gap in understanding partially reveals that those devs prefer to work on more smaller self-contained puzzle problems that are more tractable. Maybe this is understandable given the fraught Core development process and historical drama of soft forks, but neither of those are an excuse for abandoning the core challenge of realizing bitcoin.
--
Segwit and Taproot were massive changes, and I can almost understand why so much drama was spent on them. They both basically reinvented how locking scripts are stored and executed in bitcoin.
But to make significant headway on finding a scaling solution for self-custody, it may only take a few opcodes - much more narrowly scoped bits of functionality. Changes that are much easier to test and reason about, and don't reinvent the engine of bitcoin.
--
As I continue campaigning for a renewed focus on scaling coin ownership, some may compare me to the "big blockers" of the 2017 scaling wars.
The big-blockers camp wanted to raise the blocksize for the sake of housing the world's P2P payments. They resisted the use of Lightning and other second layer solutions.
The reality is that they have been partially vindicated. Lightning has not solved our problems, and given the on-chain footprint that existing channel constructions require, it categorically cannot. Lightning certainly helps reduce on-chain payment volume once someone has opened a channel - but to do that for most people will require a layer 1 innovation.
I don't share the big blockers' objectives.
I don't think that trying to fit the world's P2P payments on the base chain is a reasonable target.
But the ability to resist near complete capture of UTXO custody by third-party financial institutions - *that* is intertwined with the core purpose of bitcoin.
In Satoshi's whitepaper, the first sentence claims
"A purely peer-to-peer version of electronic cash would allow online payments to be sent directly from one party to another without going through a financial institution."
If most users become unable to even take possession of their own coins a few times a year, we have failed on the objective.
--
I am not writing this out of any sense of antagonism. Yes, I am frustrated that after numerous attempts, Core devs are not engaging more productively with the few people trying to translate scaling strategies to the base layer.
But I'm hoping that by calling attention to this issue, we can get some of these great minds to refocus on bitcoin's critical mission, and to realize that ossification will come sooner than we thought.
The existing (and well-funded) power structures *want* stasis.
The recent show of rapid institutional affinity should make you suspicious that bitcoin in its current form isn't a threat to the fiat order.
The lack of "ivory tower" attendance in the recent OP_NEXT and the broader covenants discourse demonstrates that, like many of America's elite institutions, there has been mission drift in bitcoin's technical elite. I hope this changes.
--
The risk of merging many of the opcodes proposed during the last few years is limited.
OP_CAT, OP_CTV, lnhance, probably OP_CCV, some others; they're all fine. If sufficiently tested, great additions to bitcoin.
We can pretty easily mitigate what risk there is with comprehensive testing and analysis, provided the focus is there.
The upside is almost infinite: a reasonable attempt to continue the preservation of bitcoin's unique function - trustless self-custody that is practically available to most.
OP_VAULT is likely the softfork proposal that has received the most public attention from companies concerned with custodying bitcoin:
- writeup from River (https://t.co/WTK2sBFpbw)
- presentation from @kodylow at @fedibtc (https://t.co/s597Srslgv)
- Sean Ryan from Anchorage (https://t.co/gIoKqqUO2V)
- a talk from @darosior (Wizard Sardine) about how OP_VAULT would help Liana (https://t.co/NnZi8CO49U)
- support from @Rob1Ham at @AnchorWatch (https://t.co/vHcfeIQjJT)
- @reardencode, a former employee at BitGo and Casa, is a big supporter of the functionality
- @lopp (Casa) wrote about OP_VAULT in his essay on covenants (https://t.co/aoorA3BzBU)
The companies above know a lot about what it takes to custody bitcoin safely. I think their support says a lot.
Privately, a number of large custodians not mentioned above have told me that, yes - they would absolutely make use of OP_VAULT if it were available. In fact its development was partially motivated by experience in this kind of an industrial environment.
Longterm, fully featured and efficient vaults are absolutely necessary for bombproof custody, both for individual users and large commercial holders.
While vaults might be technically possible with other, more granular opcodes like OP_CAT, I think the inherent complexity of "hacking" OP_VAULT like behavior using these low-level tools will make it very difficult for industrial users to have confidence that their vault implementations don't have bugs.
For example, see @rot13maxi's _very_ clever purrfect_vault implementation: https://t.co/C2neyuj3jt. It's awesome, but hard to understand, probably hard to test, and not feature-complete with OP_VAULT.
A dedicated opcode like OP_VAULT makes it easier to deliver and test what would be a huge improvement in custodial security.
With PayPal and Stripe both heavily invested in making stablecoins a payment method for e-commerce, it feels like federal legislators should really get their act together on whether they want stable coins to be a thing and if so what federal regulation they need.
Influence: the central skill of great product managers.
But how does one build this mysterious skill?
Through years of trial, error, and mentorship, @julesdwalt has honed his ability to align difficult stakeholders on the gnarliest projects in record time. A top Google leader once told him that he “bends people to alignment.”
In his now instant classic guest post, Jules shares five proven tactics to influence leaders and drive alignment on complex initiatives at @SlackHQ, @YouTube, and now at Google's @GeminiApp.
Jules' five tactics for increasing your influence:
1. Seek intel on how each stakeholder makes decisions
2. Frame your message from their POV (not yours)
3. Prime detractors and champions alike in the “meeting before the meeting”
4. Make people feel heard and validated
5. Manage the clock
Tactic 4 will likely make the biggest immediate dent in your ability to influence others.
Here's Jules's on how to practice this skill:
Managing emotions in the meeting is another critical aspect to driving alignment. People often won’t listen to you until they feel that you’ve fully heard them. When people don’t think you deeply understand their POV, they often become obsessed with repeating their points more forcefully instead of hearing yours.
That’s because psychologically, people who feel dismissed or misunderstood are likely to go into a stress response state (fight, flight, freeze, or fawn) and become more defensive. They are also less likely to let you influence them if they feel you’re not willing to let them influence you (e.g. to listen to their POV). People want reciprocity.
The most common way I try to make people feel heard is by playing back their statements in my own words, especially when they raise concerns. I use statements such as [see first attached image].
I seek various points in meetings to synthesize the conversation to make various people feel heard and to ensure that everyone is following along and on the same page. I can surface any misunderstandings quickly and bring people back to the crux of the issue so we can make progress. This also helps me secure progressive alignment, which de-risks the decision-making process. Instead of waiting until the end of the meeting to confirm full alignment, during the meeting I might say something like this: [see second attached image].
When Slack’s CEO had concerns about my team’s proposal to drive self-serve revenue growth, we made sure he felt heard by acknowledging his feedback through statements along the lines of: [see third attached image].
Don't miss the full post with all five tactics: https://t.co/ldwOaPiIVX
It's satisfying to find a brand that resists dark patterns their competitors are now infamous for (because it's good for short-term business).
I've "converted" a lot of people asking for printers to choose Brother because they get no funny business like sleazy subscriptions.
1/🧵 Since my first review of #bitcoin hardware wallets / signing devices, new ones have been released and I've snatched them up as quickly as possible and tested them. The testing was carried out the same way as last time, using mostly @SparrowWallet and @SpecterWallet.
Excellent post. B2B/custodial Lightning has a bright future. But consumer non-custodial LN has major challenges. The key insight as to why is put perfectly by @benthecarman: "Lightning lets us move payments off-chain but what it doesn't do is let us move ownership off-chain."
“If you don’t have a stablecoin solution in the world of money movement, I think you are going to miss the boat”
Love this prediction from @fintechjunkie
The power to create money – via printing (central banks) or credit creation (commercial banks) – is simply too intoxicating to relinquish […].
To bitcoiners, the hysterical wails “ban it!” or “close it down” are as boringly predictable as they are, Conute-like, irrelevant.
Highlights from Ross Stevens annual shareholder letter, a 🧵
https://t.co/bi401vLg4r
“In April 1933, FDR gave Americans less than thirty days to “turn in” their gold or face up to 10 years in prison. The price of gold is ~100x higher today. And legal.”