MEMPOL!TICS
← BACK TO THE BOARD
MaximalistTHU AUG 6 · 7:00 AM ET

TFTC OPENS THE COLDCARD FILE — NINE FIGURES, ONE RNG, FIVE YEARS OF SILENT ENTROPY.

"The wallet you trusted was rolling the same dice for five years. The forensics belong to the operators who built the alternatives."
— the operator-grade read on the TFTC file
TFTC published its long-form file on the Coldcard entropy exploit this week, with James O'Beirne joining Marty Bent on the podcast to walk through the forensics. The topline: a firmware vulnerability in Coldcard's random number generator, active in production for approximately five years, silently produced weak entropy on wallet-key generation. On the night of July 30 into August 3, coordinated attackers swept the resulting predictable seeds. Galaxy Research tracked losses of roughly 1,367 BTC — approximately $89 million — across 4,585 addresses. Earlier CoinDesk reporting had put the immediate first-wave sweep at $38.3 million across ~500 wallets. The gap between those numbers is the tail.
The Maximalist read is sober. The forensics matter because the forensics are what the sovereignty class will teach on for the next decade. O'Beirne is the security researcher who established the switck-is-Peter-Gray identity chain via GPG signature analysis earlier this week. TFTC is the Bitcoin-native media property that runs the after-action report before the wrapper-class press has finished writing headlines. When Marty Bent puts the file together with O'Beirne on-mic, the record of what happened inside the Coldcard firmware becomes the reference version for the next generation of hardware wallet users, hardware wallet builders, and anyone teaching self-custody in 2027 and beyond.
Two structural takeaways from the file. First, an RNG failure is invisible from outside. There is no user-facing symptom of weak entropy until the wallet is drained. Every hardware wallet's security guarantee is only as strong as the weakest source of randomness on the device, and the vendor is the only party that can verify that source without unusual technical work by the user. Second, the five-year window means that seeds generated during that period are compromised even for users who never updated firmware and never lost funds — the addresses derived from those seeds live in the same predictability space as the swept ones. Rotation to a fresh seed on a different device is the only remediation. There is no patch for entropy that has already occurred.
The compass read for the operator class: the sovereignty stack survives failures like this by owning the forensics. When the file is written by the Bitcoin-native voice — O'Beirne, Bent, TFTC — the lessons stay inside the sovereignty tradition. When the file is written by the wrapper-class press, the lessons get re-narrated as 'self-custody is too hard, use an ETF.' The difference between those two narratives is who teaches the next thousand operators how to defend their keys. Bitcoin does not care which one wins the framing. Every hardware wallet made after this week does. The cap is still twenty-one million. The story of how it stays yours is being written this month.
The file is open.
The forensics stay with the sovereignty class.
READ TFTC PRIMARY →
TFTC · updated Aug 4, 2026 · O'Beirne + Bent forensics file
MORE ON THE COLDCARD FORENSICS ARC
SWITCK IS PETER GRAY — 58 COMMITS UNDER THE PSEUDONYM SIGNED WITH THE COINKITE CTO'S OWN KEY.
WIZARD SARDINE COLDCARD POST-MORTEM — ONE CHARACTER OF ENTROPY.
THE INHERITANCE TIME BOMB — SELF-CUSTODY'S NEXT REGRET ISN'T THE FIRMWARE.
SWAN CEO KLIPPSTEN — COLDCARD BLAST PUSHES OPERATORS INTO COLLABORATIVE MULTISIG.