The Bitcoin Nova PodcastThe Bitcoin self-custody disaster that rocked the space — and what it reveals about trust, verification, and the future of crypto security
A catastrophic vulnerability in one of the most trusted Bitcoin hardware wallets has caused over $100 million in losses, catching even the most diligent self-custody advocates off guard. In this urgent episode, seasoned security researcher Josh (secsovereign) shares an insider’s perspective on how a series of seemingly small technical choices led to the worst disaster in Bitcoin’s self-custody history — and why it’s a wake-up call for everyone holding Bitcoin today.
You’ll discover:
How a firmware switch from open source to a murky “verifiable” label concealed serious security flaws
The overlooked risks of relying solely on source code and community reputation instead of actual audits
The role of license changes, internal retaliation, and insufficient vetting in enabling a multi-million dollar theft
Whether AI played a part in uncovering or hiding vulnerabilities — and what future automation might mean for Bitcoin security
Practical steps to protect your Bitcoin through minimal trust setups like passphrase separation and multi-sig strategies
How the community is responding, what’s being destroyed, and what this reveals about governance in the Bitcoin ecosystem
This episode is a must-listen for anyone serious about true security and sovereignty — whether you’re a seasoned hodler or new to Bitcoin self-custody. With raw insights, technical deep-dives, and a call for greater oversight, Josh guides us through a painful yet vital lesson: in Bitcoin, trust must be verified. If you want your Bitcoin to stay safe amid rolling vulnerabilities, don’t miss this essential discussion.
Guest: Josh (secsovereign) is a respected Bitcoin security researcher, always digging into the intricacies of consensus and hardware wallet safety, and offering practical advice to build a more resilient ecosystem.
Stay informed, protect your assets, and build a future where trust is earned, not assumed. Hit play now.
This episode is perfect for those who want to understand the real risks behind seemingly secure hardware wallets — and how to stay a step ahead.
As the disaster unfolds, one thing is clear: true sovereignty in Bitcoin requires relentless verification.
00:00 Background of Cold Card and its open source history
04:59 Cold Card’s open-source origins
09:51 License change and security review gaps
21:06 Self-custody, entropy, and accessibility
31:26 Warning signs and missed opportunities
51:54 How the wallet drain unfolded
01:03:54 Protecting funds: single-sig and multisig
01:18:37 Bitcoin governance, audits, and accountability
01:30:12 Closing reflections: rebuilding trust
Topics: Coldcard vulnerability, self custody security, don't trust verify, Bitcoin security audits
Subscribe for more real conversations on Bitcoin, sovereignty, and the incentives shaping our world.
Guest: Josh, Secure Sovereign
https://microseed.io/ Code: Nova