Forced Capitulation: I was Hacked
Quick Housekeeping
Disclaimer: nothing in this post should be taken as financial advice. I don’t know how you would take something in this post as financial advice, but if you do, that’s entirely on you.
Another thing: while I may use AI to help build ideas, these words are my own.
Sobering Realities
Do well in school. Get a job. Put some money toward your future. Conventional wisdom.
But what’s the conventional wisdom for getting hacked? How are you supposed to respond when your net worth is slashed >50%? “Everybody has a plan until they get punched in the mouth.”
Starting on 7/29 at 9:36pm EST, the “ultra-secure” Coinkite Coldcard Mk3 was breached. In the next 7 minutes, 1082 Bitcoins were stolen worldwide because of a failure in proper entropy when generating these Bitcoin wallets. 1082 Bitcoins, the equivalent of nearly $70M, stolen in 7 minutes.
The hack has since spread to further Coldcard models, with the Mk4 and Mk5 also affected. The Coldcard Q might also be affected. If you kept funds on a Coldcard, regardless of model, check immediately if they’re still there. MOVE THEM ASAP.
At this point, Galaxy Research estimates ~1600 BTC (>$100M) has been stolen. Everyone in Bitcoin, affected or not, is watching the wallets where these stolen funds have landed. What’s the hacker’s next move?
How Did I Get Here?
In a recent post outlining my bullish outlook on Robinhood ($HOOD), I alluded to my entry into crypto. Allow me to expand.
In 2017, after graduating from college, my parents let me keep the $500 security deposit they’d graciously loaned me for the duplex I rented with one of my closest friends. Bitcoin was starting to garner headlines and becoming slightly more mainstream. “Screw it, I’m buying.” 1 Bitcoin was ~$5000, so I became the owner of ~0.1 BTC (or 10,000,000 sats) after dumping that $500 into it. My understanding of the asset was rudimentary, and that’s being generous.
In the 9 years since, I’d become an advocate for not only Bitcoin but the entire crypto asset class. I’ve grown an affinity for the simplicity of Bitcoin. Each transaction starts its confirmation process when it’s included in a newly mined block. It takes ~10 minutes for a block to be mined. After 210,000 blocks (~4 years), the reward for the miners maintaining the security of the network is cut in half. There’s a fixed maximum supply (21M). Disregarding the volatility in USD terms (understandably difficult), there’s no subjectivity. You know exactly what the Bitcoin network is going to do, and when it’s going to do it. And in large part because there’s no single entity who can change the rules.
Outside of Bitcoin, of course, there are an endless supply of other cryptocurrencies, each with their own tokenomics (supply, confirmation methods, utility, etc.). There are no shortage of opinions of Bitcoin and these altcoins. Maybe another time I’ll write on some of these, but the general consensus is that Bitcoin is the “safest” bet of the bunch. It might not always gain the most in USD value against these altcoins, but it almost always maintains its value better than altcoins in a downturn.
Like many in the space, Bitcoin was a small speculative investment when I first participated in the frenzy. Since that initial purchase in 2017, Bitcoin has accrued more value than any other asset that I’ve held for the same period. And thus, I’ve continued to gain more and more confidence in it. I’ve had some larger purchases ($1000+) but for the most part, I’d accumulated my position through dollar cost averaging (DCAing). $0.25/hour, $10/day, $20/week, whatever fit my budget at the time—I’d set and forget and 9 years later that sum had turned into a sizable nest egg for my future. And despite BTC being down 27% YTD (and 50% from its ATH), my conviction was only growing stronger each and every day.
….And It’s Gone
This past Saturday, I finally saw the news on the Coldcard Mk3 hack. I’m in the middle of moving to a new apartment. I was out grabbing coffee and a breakfast sandwich, I needed to bring the heat to unpack everything I brought with me to my new place. I came home, and immediately pulled up my Sparrow wallet (the software that I used to interact with my Coldcard). It took a minute to load the entirety of the Bitcoin network’s transactions from the last time I had interacted with Sparrow. Nearly everything had loaded, and I was in the clear. But right as it was finishing, the dreaded outbound transactions appeared on my screen.
I had been wiped. 9 years of stacking was undone in that 7 minute window on 7/29. 2 and a half days had passed before I even knew. The BTC balance I had accumulated (as well as the balances of hundreds of others) is now siting in this wallet, and I can’t access it.
If you’ve never been hacked, I’ll spoil it for you. Think of the most embarrassing moment of your life. Multiply that by 100. Add a couple sucker punches for good measure. That’s how it feels.
The blood rushes from your face. Time stops. You try to hit the back button. CTRL + Z. But the deed is done. You’re fucked.
Instantly you think about where you went wrong. It wasn’t a phishing attempt that I got baited on. It wasn't a sketchy exchange that I trusted. It wasn’t a loss of my Bitcoin keys. It was putting my whole stack into a wallet and not verifying that the wallet was as secure as it said it was.
If you’d asked me where I thought the most secure Bitcoin wallet was on 7/28, I would’ve told you Coldcard. Not even close. The thing is air-gapped. It never even touches the internet. Both receiving and sending transactions takes a few minutes, even for experienced users. I overlooked what I now realize was the most important part—the seed generation.
If the Coldcard was Fort Knox, and my Bitcoin was in the middle of it, the hacker didn’t evade the security cameras, armed guards, or alarm system. They didn’t blow up the vault door. They realized the key to unlock the vault door looked something like this. They spent a few moments trying to replicate it, and once they did, they walked right in.
I think the only thing I’ve felt since Saturday morning is a constant numbness. And quite honestly, it’s been less to do with the loss of funds. It’s more the last 9 years of growing conviction has now been flushed down the drain. Not with Bitcoin or the crypto network as a whole, but the conviction I had with interacting in the space.
Decisions, Decisions
I am not an investor in gold, not currently anyway. But if I were to invest in gold, I’d want a physical gold bar. I wouldn’t want to buy an ETF or an IOU that says someone somewhere is holding the gold for me. I’d want what I purchased! That’s how I’ve interacted with Bitcoin and crypto.
If you know me, you know that I believe in freedom of choice. There are tradeoffs in pretty much any decision one can make. Who am I to make a decision on your behalf? I take pride in doing my own research to make my own decisions on behalf of my own convictions. If you disagree with my decisions or opinions, that’s no sweat off my back. I’ll champion the right to your own decisions, because I believe that I should have the right to mine.
In Bitcoin/crypto, if you want to invest because “number go up” and you don’t want to self custody the asset, I’ll encourage you to do so. Anyone who knows me knows that I always have. But I’ve preferred to play with these assets by attaining self custody. I’ve seen exchanges get hacked (Mt. Gox). I’ve seen exchanges act in bad faith and rehypothicate coins (BlockFi and FTX). I’ve seen exchanges freeze coins of users because they wouldn’t comply with KYC or because they were in trouble with the law. I didn’t feel comfortable keeping my stack on an exchange for these reasons. Again, I didn’t want a Bitcoin IOU. I thought I understood the risks of self custody and where that could fail. I thought the biggest risk I faced by custodying my own coins was losing my seed phrase and never being able to interact with my wallet. I took measures to ensure that would not happen. The likelihood that Coldcard would fail me was 0%. Not 0.0000001%. It was simply not an option.
And to be fair, I have to eat a sizable portion of the blame pie. I had consolidated my entire position into a Coldcard Mk3. I didn’t use sufficient dice rolls (I used some, but not enough) to enhance the entropy of the seed generation. I didn’t have a multi-sig setup (where I’d need multiple devices to gain access to one single wallet). I didn’t store portions of my BTC in different hardware manufacturers’ wallets (Coldcard vs. Trezor vs. Ledger vs. Bitkey etc). I didn’t setup a passphrase to further my own security. Again, I will champion the right to make your own decisions. I made mine. And now I have to live with it.
Thought Experiments and Closing Thoughts
There are so many thoughts that have gone through my head over the past couple days. “If you had your BTC returned to you right now and had to make a decision in the next hour for what you’d do with it for the next 5 years, what would you do?” Honestly, I have no clue. I’d probably send it to an exchange out of sheer panic. Once there, I don’t think I’d keep it in BTC out of my aversion for letting someone else custody this asset for me. But if I took that BTC and converted it to USD, I’d feel like a coward for snubbing the conviction I’ve built in the asset.
Which brings me to my next thought experiment: “what do I now feel most comfortable parking my long term savings in?” I understand what society calls the “risks” of Bitcoin and crypto. I put risks in quotes because I still have loads of conviction in the Bitcoin network itself. If Bitcoin went to $0 overnight, that was a ship I was willing to go down with. And gosh, that option would be so much better than getting hacked—at least I’d have a community to share that experience with. Getting hacked is incredibly isolating.
But what do I feel most comfortable with for the long haul now? The working theory is that an LLM (Kimi K3?) helped generate the seed phrases to the compromised wallets. In the age of AI, and in a mostly unregulated casino (dammit! that’s what I love about Bitcoin and crypto), I venture this won’t be the last of its kind. Everyone in the Bitcoin space spent all weekend trying to secure their setup and/or trying to find bugs to fix before a bad actor finds them. I have no clue where I feel most comfortable parking my money. Again, Bitcoin is simple at its core. I appreciate its transparency. I just have no trust right now that I’ll be able to interact with the ecosystem with confidence.
Ultimately the decisions I’ve made that have brought me to where I am stem from a reluctance to trust just anything. My trust is hard-earned. And with this act of embarrassment, my trust will be even more constricted.
I doubt I’ll ever see those funds returned to me. I’ve come to grips with the loss. I’ll be following the hacker’s movements, as there’s a chance they mess up and dox themselves. But there’s no crying in baseball.
In 2011, Brian Wilson blew a save against the Tigers and went apeshit on the water cooler. Afterwards he said “Well, you know, give myself 30 seconds to absolutely lose it, then come back and be part of the team”.
I’ve had my 30 seconds of losing it. That big ball of fire we call the sun will still rise tomorrow. And along with it is a growing fire within me. We get up off the mat. Why? Because in this house we make our own decisions. We live (and die) by them. But we always move forward. We control our own future. Yea, I don’t know much of what I can trust right now. But if you think for one second that I’ll ever stop trusting myself, well then you just don’t know me. Momma ain’t raise no bitch. We prevail.
TL;DR
Life is a series of tests. How will you respond?





