Matt Odell and Marty Bent discuss #Coldcard's 4.0.0 firmware shortly after it's release. This release is now known to have distributed the vulnerability Coinkite CTO authored under an alias that later lead to the theft of $100m+ of #Bitcoin in July/August 2026. The following clip is taken from their podcast titled "Rabbit Hole Recap: Bitcoin Week of 2021.03.29" from timestamp 1:25:09 to 1:26:21.

Replies (40)

.'s avatar
. 2 days ago
exactly
.'s avatar
. 2 days ago
Also the screenshot says "unreleased 4.0.0"
.'s avatar
. 2 days ago
I took the "don't dissect my fucking statement" as - shut up Marty - "i have one piece of knowledge.. I'm not allowed to share" and the fact that his add dice rolls guide points to only one thing.
What do you mean by points to only one thing? I just don't believe Marty or Odell have any culpability with this coldcard shit, they promoted a product that by all accounts was very good and it wasn't their responsibility to verify the code, etc. If people had to underwrite every product they were paid to endorse, there would be no such thing as advertising. I dunno, im hurting a lot over all of this and just thank God that those Im responsibile for are safe.
How could they verify the code if it wasnt open source? That should have been the obvious first red flag that should have made them hesitate... For most people who avoided coldcards Im assuming that was the main reason!
.'s avatar
. 2 days ago
All I am pointing out is that in 2021 Matt was clearly told information by Novak that made Matt aware that his own guide protects users from the bug. What about the guide protects users as we now know: dice rolls Matt knew that dice rolls or being below a the new "big release" made users not vulnerable. That logically points to the entropy bug. NVK and Matt had foreknowedge and didn't say anything.
We can't say that actually. So far I don't see any reason to believe that Odell had prior knowledge. My only observation is that NVK might have accidentally slipped that *he* knew about it. nevent1qqsqqqpf62hzfjvcpz9jzeypthpu8wasu44j2tm8m2cd96pwg77r4cgpzfmhxue69uhk7enxvd5xz6tw9ec82cszypj2eaq9t75zd09ts3t7ynhclwn5jz4mremdh2m24p6j55aqadx55my2le5
Chain Signal's avatar
Chain Signal 2 days ago
Interesting timing. The 4.0.0 firmware was released on June 29, 2026. 30 days later, ~14.5k blocks at 2 sat/vB would cost ~0.29 BTC.
acronym's avatar
acronym 2 days ago
They were aware of their bug, thought they had it fixed in 4.0.1 and then opted to recklessly take the chance on the numbers. 1. Maybe they thought too few actually generated seeds with 4.0.0 2. Maybe they thought many of them used good pasphrases anyway 3. Maybe they thought most big hodlers already had established wallets and they could weather a few reports of lost funds (and they did) 4. Maybe they thought (as most shysters and criminals do) that they were technically astute and they had this Strike 3 already but somehow they were allowed to stay at the plate to keep swinging. Now that this is known to be said by Matt (in the presence of Marty) bullshit has to be ruled on their little Rabbit Hole Recap cry session.
.'s avatar
. 2 days ago
Not here for any credit, just the truth. I wanted to verify the AI pulled clip and stumbled on the remainder of the conversation.
.'s avatar
. 2 days ago
This is my reasoning: If because of what Novak said to Matt about unreleased 4.0.0 resulted in (A) Matt knew being below 4.0.0 was not vulnerable + (B) Matt knew his guide was not vulnerable ie dice rolls + (C) Matt says he can't say why and to not dissect why Then (D) Are we to believe he never reasoned why? What else other than low entropy seeds fits A, B & C ? Even if he thought 4.0.1 fixed "him being able to steal all your bitcoin" he knew coldcard had created a serious issue that meets A, B, C in 2021. I don't see how the unreleased 4.0.0 usb issue meets these conditions.
Two things. 1. Odell's investment company, the sole investor of Coinkite, should be supeoneoad for discovery. 2. They probably can be held partially liable for damages. I am not an attorney. 3. There isn't any public data so far that implicates them in an inside job.
KoreanCat's avatar
KoreanCat 2 days ago
There seems to have been a $125K seed round investment by another party closer to the coinkite founding, well before 2020 when 1031 became an investor. SO likely those seed investors will get pulled in too.
Yes. Being financially liable when your startups CTO commits fraud is not the same thing as being criminally convicted for fraud. Greg has problems, and depending on how much NVK, Coinkite, and investors knew... they might have their own.
I am guilty and caved due to doubting myself. Lucky/unlucky, I received the cold card the day of the announcement lol No refund, but atleast I got a glow in the dark calculator and DECOY! 😄 I've always been a Trezor guy, but will be migrating my seed to a dice roll for that too, just in case. dont trust, even if its fully open source! Wherever we have sovereignty we should use it!
.'s avatar
. 2 days ago
He may have thought 4.0.1 fixed it. But that means he knew something met the conditions in unreleased 4.0.0 If you knew the company made such an error would you continue to advocate for it?
acronym's avatar
acronym 2 days ago
It is clear from this clip he was totally willing to cover for Coinkite then. For him to say now he had no idea Coldcard was a total piece of shit and he always had the interest of the freaks top if mind is wishful thinking. He was let in on a little secret and knew they were covering it up and didn't think hmmm.....maybe these guys are not as straight up as I thought. He went on recommending Coldcard wholeheartedly.
Only thing clear is that NVK knew and revealed it implicitly/explicitly to Odell. nevent1qqsqqqp6vzpmwx0xnw55jwze6gt92j5any4a2n92xxyhka63d0adudspzfmhxue69uhk7enxvd5xz6tw9ec82cszypj2eaq9t75zd09ts3t7ynhclwn5jz4mremdh2m24p6j55aqadx55yxpytz
Fucking hell! The trick is old as world where you ship vulnerability then ask users to upgrade but you still keep the vuln!!
.'s avatar
. 2 days ago
Appreciate that.
It was introduced in 4.0.0 which IIUC was never released. 4.0.1 fixes an unrelated physical access bug that Matt wouldn't give two shits about because it's not a remote theft vulnerability like the 4.0.0 RNG one