The Bitcoin Nova PodcastColdcard incident explained with Swan engineer Steve Keider
Staci is joined by Steve Keider, an engineer at Swan, to break down the ongoing Coldcard incident, what appears to have gone wrong, and why the recommended response is broader than just affected devices. They also dig into how AI-assisted red teaming is changing both
Bitcoiners just got a brutal reminder that self-custody is only as safe as the code behind it. Swan engineer Steve Keider breaks down the Coldcard incident, how a seed-generation flaw opened the door to compromise, and why this is pushing the entire Bitcoin security stack into a new era of AI-assisted red teaming.
Staci and Steve trace what happened in the first hours after the issue surfaced, why the recommendation is still to move funds off affected Coldcard-generated seeds, and how a vulnerability in wallet firmware can create risk long after a device is updated. They also dig into the scale of the blast radius, the likely timeline of the attack, and why the on-chain behavior suggests a small, highly motivated actor rather than a nation-state operation.
You'll hear how open-weight AI models are changing defensive security work, why frontier models with safety guardrails can be a bad fit for legitimate audits, and how engineers now need to think like attackers to protect Bitcoin infrastructure. Steve explains the concept of adversarial reviews, why bug bounties matter more than ever, and what this incident reveals about the tension between privacy, usability, and extreme self-custody rituals.
The conversation also widens into the bigger picture: what open source and source-available code mean for security, why multi-sig and multi-manufacturer setups are becoming more attractive, and how collective Bitcoiners using AI may become the best line of defense against future exploits. If you care about Bitcoin security, hardware wallets, AI safety, or the real-world consequences of one hidden bug, this episode is essential listening.
Steve Keider is an engineer at Swan, where he works on Bitcoin security and technical analysis. He helped investigate the Coldcard vulnerability and has been actively involved in the community response and red-teaming effort.
Perfect for Bitcoiners, self-custody users, engineers, and anyone trying to understand how AI is reshaping both attacks and defenses in crypto.
Steve Keider:
Swan Bitcoin:
Chapter List:
(00:00) Coldcard Incident
(00:37) The First Night
(01:06) AI Finds the Flaw
(01:45) Swan Responds
(03:28) Old Seeds at Risk
(05:00) Open Models for Audits
(07:12) Limits of Restricted AI
(08:30) Adversarial Review
(09:58) Media & Narrative Risk
(11:48) Early Theft Totals
(13:07) Auditing Other Wallets
(15:13) Open Source vs. Source Available
(16:59) Sponsorships & Trust
(18:57) Auditing Cryptography
(20:24) Better Self-Custody
(22:23) Paranoia & Multisig
(24:22) AI Speeds Up Exploits
(26:29) A Mass Wallet Attack?
(29:11) Was Frontier AI Needed?
(30:38) Tracking the Attacker
(32:24) Why the Coins Can’t Move
(34:37) The Attacker’s Paper Trail
(35:38) Small Team or Nation-State?
(37:14) Next-Gen AI Audits
(40:38) Bug Bounties Matter
(43:09) AI Tracks the Attacker
(45:14) Defensive vs. Offensive AI
(47:14) Everyone Felt Safe
(49:37) AI Guardrails & Defenders
(52:00) AI Custody & Kill Switches
(54:03) Think Like an Attacker
(54:53) Closing Thoughts