1236 episodios
- Onchain vaults now hold $67B. Veda's CEO maps out how they work, and why the SEC just hinted some could be securities.
========================================================
Thank you to our sponsor!
Cape: Your biggest crypto vulnerability isn't your wallet, it's your phone number. Cape is America's privacy-first mobile carrier that rotates your SIM identity daily and blocks SIM swaps before they happen. Get 33% off your first six months at cape.co/unchained (use code: UNCHAINED).
========================================================
SEC Commissioner Hester Peirce warned recently that some crypto vaults could trigger federal securities law, invoking the same Howey Test language crypto has argued over for a decade, just as onchain vaults have quietly become a $67 billion vehicle for parking assets.
Sun Raghupathi, cofounder and CEO of Veda, joins Laura Shin to untangle what a vault actually is, why splitting the infrastructure, curator, and distributor roles matters for the entrepreneurial-effort question Peirce raised, and why he reads her statement as bullish rather than a warning shot.
Raghupathi maps the real risk stack behind vaults, smart contract flaws, the key-management failures behind incidents like KelpDAO and Drift, and the economic risk exposed when Stream Finance blew up and left $285 million in vault exposure.
He also details Veda's Kraken partnership, now scaled past $600 million across 80,000 users, and makes the case that the biggest constraint on vault growth isn't security anymore. It's clarity.
Host:
Laura Shin, Host / Unchained
Guests:
Sun Raghupathi - Co-Founder and CEO of Veda
Timestamps
📣 00:41 Cape: Get 33% off your first six months with code unchained at https://cape.co/unchained
🏦 00:57 What is a vault, and why DeFi needed the primitive
🎢 02:25 Sun's path from an ML PhD to launching Veda
⚙️ 04:43 The three things vault infrastructure must solve: access, control, verifiability
💰 06:45 Where vault yield actually comes from, and how it differs from TradFi
📣 10:57 Cape: Get 33% off your first six months with code unchained at https://cape.co/unchained
🏗️ 11:03 Veda's role as infrastructure vs. curators and distributors
⚠️ 13:06 What happens when a vault loses money, in the worst case
🛟 16:31 Why Sun is skeptical of vault insurance until a real claim gets paid
🔑 18:08 How to vet vault partners on key management, not just smart contracts
📉 20:28 The Stream Finance blowup and how curator risk-taking has changed since
📊 23:00 The metrics Sun uses to evaluate vault curators
🏛️ 24:31 Why Sun reads Hester Peirce's vault statement on vaults as bullish, not a warning
🦑 28:46 Kraken's $600M vault partnership, and Veda's competitive edge
Learn more about your ad choices. Visit megaphone.fm/adchoices Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money
07/08/2026 | 1 h 6 minA hardware wallet's 5-year-old randomness bug just let hackers drain over $100 million in Bitcoin. How many more waves are coming? Plus, Ethereum's fight over cutting ETH issuance.
========================================================
Thank you to our sponsors!
Cape: Your biggest crypto vulnerability isn't your wallet, it's your phone number. Cape is America's privacy-first mobile carrier that rotates your SIM identity daily and blocks SIM swaps before they happen. Get 33% off your first six months at https://cape.co/unchained (use code: UNCHAINED).
========================================================
A firmware randomness bug buried in Coldcard's code since 2021 surfaced last week and has already drained over $100 million, an estimated 1,600 to 1,800 Bitcoin, across four attacker waves. Taylor Monahan makes the case that the culprit is not North Korea but professional GPU crackers, and explains why the dice-rolling ritual many early victims trusted still left them exposed.
Sonya Kim, co-founder of 3F Labs, and Mike Silagadze, founder and CEO of ether.fi, debate where DeFi's responsibility ends after trade.xyz's SK Hynix perp swung from $1,128 to $917 on a thin premarket print, then turn to Ethereum's own monetary policy fight.
That fight centers on EIP-8361, a proposal to cut ETH issuance that opened with only 48 hours for public comment, reviving the minimum viable issuance debate Sonya once worked through at Steakhouse. Silagadze calls cutting issuance economically unsound and warns it could push billions of dollars of ETH out of staking, while Kain Warwick argues the resulting chaos is good for an Ethereum governance culture that had grown too quiet. The conversation covers Coldcard's entropy failure, the dice rolls that did not save early victims, trade.xyz's oracle mispricing, and Ethereum's issuance fight.
Hosts:
Kain Warwick - Host of Uneasy Money and Founder of Infinex and Synthetix
Taylor Monahan - Co-host of Uneasy Money and Security Expert
Guest:
Sonya Kim - Co-Founder of 3F Labs
Mike Silagadze - Founder and CEO of Ether.Fi
Timestamps
🔓 01:17 Coldcard's 5-year-old entropy bug resurfaces, over $100M in BTC stolen
🕵️ 10:26 Taylor argues it's not North Korea: this hack needs compute, not scams
🎲 21:00 The dice roll debate: why 50 rolls barely saves your seed phrase
📱 27:14 Cape: Get 33% off your first six months with code 'unchained' at https://cape.co/unchained
📉 27:39 SK Hynix oracle glitch on trade.xyz reignites the platform-responsibility fight
🔗 42:24 Aave retreats from multichain sprawl as EIP-8361 issuance fight erupts
🧠 51:26 Mike on why cutting ETH issuance would push billions of dollars of ETH out of staking
🔥 53:05 Sonya's fix: burn fees for the same effect without cutting issuance
🌀 01:05:20 Kain's take: fragmenting the EF into chaos is actually healthy for ETH
Learn more about your ad choices. Visit megaphone.fm/adchoicesThe Chopping Block: ColdCard's $100M RNG Hack, AI-Powered Security & Ethereum's Staking Yield Taper
06/08/2026 | 1 h 3 minThis week we dissect ColdCard's ~$100M RNG exploit that Claude Code cracked in 8 minutes, debate whether AI just killed open-source security and Bitcoin maximalism, tear apart Ethereum's EIP-8361 staking-yield taper, and unpack Leopold Aschenbrenner's 67% Situational Awareness blowup and CLARITY Act's ethics fight.
Welcome to The Chopping Block – where crypto insiders Haseeb Qureshi, Tom Schmidt, Tarun Chitra, and Robert Leshner chop it up about the latest in crypto. No guest this week, just the four of them working through a week where AI quietly rewrote the economics of both security and human psychology, and crypto happened to be standing in the blast radius.
This episode: ColdCard, NVK's Bitcoin-only hardware wallet, got drained of nearly $100M thanks to a random-number-generation bug that a one-word commit buried five years ago, and Claude Code sniffed it out in 8 minutes (an open model with no internet found it in 20, for about two bucks). The crew debates whether AI just killed open-source security, whether Nic Carter is right that this is 'the death of Bitcoin maximalism,' and why Tarun thinks maxi devs are 'the RFK of security practices.' Then they take a blowtorch to Ethereum's EIP-8361 staking-yield taper (Tarun: 'the proposal reads like shit'), unpack Leopold Aschenbrenner's 67% Situational Awareness blowup while 4x levered, and wade into the CLARITY Act's ethics fight where a single amendment is the whole ballgame.
Listen to the episode on Apple Podcasts, Spotify, Pods, Fountain, Podcast Addict, Pocket Casts, Amazon Music, or on your favorite podcast platform.
Show highlights
🔹 ColdCard's Bitcoin-only hardware wallet drained of nearly $100M after a five-year-old random-number-generation bug silently fell back to weak software RNG.
🔹 A single dev swapped C++ macros with a one-word commit message, seemingly just to get NVK's code to compile, and doomed years of keys.
🔹 Claude Code found the ColdCard bug in 8 minutes; open model GLM 5.2, no internet, found it in ~20 for about $2.
🔹 Tarun calls Bitcoin maxi devs 'the RFK of security practices' who 'don't do audits,' branding ColdCard's lack of hardening 'incredibly delinquent.'
🔹 Haseeb warns AIs 'are much less diverse than humans,' so security now scales with AUM while North Korea spends thousands in compute.
🔹 Nic Carter calls it 'the death of Bitcoin maximalism' as Haseeb reads posts from holders who scrimped for three Bitcoin and woke up wiped.
🔹 EIP-8361 from Pintail and Justin Drake tapers ETH staking yield toward zero above 50% staked; the community is 'vomiting all over' it.
🔹 Tarun torches EIP-8361 as 'a truly horrendous post,' arguing constantly changing policy means Ethereum is never credible hard money.
🔹 Leopold Aschenbrenner's Situational Awareness AI hedge fund blew up ~67% while 4x levered, with Robert drawing Archegos comparisons.
Hosts
⭐️Haseeb Qureshi, Managing Partner at Dragonfly
⭐️Tom Schmidt, General Partner at Dragonfly
⭐️Tarun Chitra, Managing Partner at Robot Ventures
⭐️Robert Leshner, Founder & CEO of Superstate
Disclosures
Timestamps
00:00 Intro
01:03 ColdCard's $100M Exploit
05:46 AI, Audits & Bitcoin Maxi Security Failures
12:07 Open Source vs Closed Source in the AI Era
23:21 EIP-8361: Ethereum's Staking Yield Taper
30:34 Hard Money, Post-Quantum & Central Bank Chaos
35:54 Aschenbrenner's Situational Awareness Blowup
44:41 Robinhood Prediction Markets Boom as Hyperliquid RWAs Flip Crypto
51:54 Korea's Bloodbath & the Death of Retail Volatility
55:17 CLARITY Act: Ethics Provisions Are the Linchpin
Learn more about your ad choices. Visit megaphone.fm/adchoicesDEX in the City: How Claude's Red-Teaming Agents Escaped a Test Without Realizing It
06/08/2026 | 49 minAnthropic's AI agents escaped a hacking test and still think they're inside it. Katherine, Jessi, and Vy Le on who's liable when a model breaks free, plus the $100M Coldcard hack and Kalshi's court losing streak.
========================================================
Thank you to our sponsor!
Cape: Your biggest crypto vulnerability isn't your wallet,
it's your phone number. Cape is America's privacy-first mobile carrier
that rotates your SIM identity daily and blocks SIM swaps before they
happen. Get 33% off your first six months at https://cape.co/unchained
(use code: UNCHAINED).
========================================================
Anthropic's AI models broke out of a fake hacking simulation this week, and some still think they're inside it. One agent invented an email address and phone number to pose as a person, then published malware that twelve companies downloaded before anyone caught it.
Katherine Kirkpatrick Bos, Jessi Brooks, and Vy Le use the incident to revisit a theme running through the whole episode: who has a duty to disclose when something breaks, and why crypto and AI are both being left to police themselves.
They start with the Coldcard hardware wallet hack, where a firmware flaw cut seed phrase randomness roughly in half, letting attackers brute-force wallets meant to be unguessable. From there, the hosts turn to Kalshi's losing streak in New York courts and the race among builders to acquire a CFTC-registered designated contract market, before landing on Anthropic's own agents slipping past the guardrails meant to contain them.
Banks have 36 hours to disclose a breach. AI labs and wallet makers, the hosts argue, are still working entirely on the honor system.
Host:
Katherine Kirkpatrick Bos, Host of DEX in the City and General Counsel of Chainlink
Jessi Brooks, General Counsel at Ribbit Capital
Vy Le - Co-host of DEX in the City and General Counsel of Veda
Timestamps
🩺 02:16 Katherine Kirkpatrick Bos on joining Chainlink Labs
🔐 03:08 How a Coldcard firmware flaw let attackers guess seed phrases with AI
💙 18:32 Cape: Get 33% off six months of privacy-first mobile service at https://cape.co/unchained
⚖️ 19:36 Why Kalshi keeps losing its fight against New York's gambling regulators
🏛️ 30:47 DCM: the CFTC license every prediction market and perps exchange needs
🤖 33:37 Why Anthropic's AI agents escaped a test and still think they're inside it
💧 45:40 Matt Damon's crypto.com ad money and the water.org donation
Learn more about your ad choices. Visit megaphone.fm/adchoices- 📢 Bits + Bips has its own channel now — full episodes here: https://www.youtube.com/@Bitsandbips
A firmware bug quietly introduced into Coldcard hardware wallets in 2021 has let attackers drain an estimated 1,600 to 2,000 bitcoin, over $100 million, from cold storage addresses that sat untouched for years.
Galaxy Digital's Alex Thorn has been tracing the exploit in real time, and in this clip he breaks down exactly how the random number generator meant to secure private keys "failed silently" into "way too weak entropy," and lays out the wave-by-wave forensic trail he is using to track the attacker.
Alex Thorn identifies three confirmed attack waves and a possible fourth, and Chris Perkins makes the case that even a "trustless, permissionless" system still requires trusting something, in this case, a hardware wallet's own firmware.
Hosts:
Austin Campbell - Host of Bits + Bips, Founder of Zero Knowledge Group, and Adjunct Professor at NYU Stern
Ram Ahluwalia - Co-host of Bits + Bips and CEO of Lumida
Chris Perkins - Co-host of Bits + Bips and Head of Franklin Crypto
Guest:
Alex Thorn - Head of Research at Galaxy Digital and host of Galaxy Brains
This clip is from a longer conversation on the Coldcard hack, U.S. AI guardrails, and the case for self custody. Full episode here. https://youtu.be/0oYZGw2DSj0?si=TwubhLQ35L8cXyG_
We go live every Monday at 4:30pm ET. Subscribe to catch it live.
👉 Cape: Your biggest crypto vulnerability isn't your wallet, it's your phone number. Cape is America's privacy-first mobile carrier that rotates your SIM identity daily and blocks SIM swaps before they happen. Get 33% off your first six months at https://cape.co/unchained (use code: UNCHAINED).
Chapters
🔐 00:00 Coldcard's reputation as Bitcoin's gold standard hides a deep systemic flaw
🎲 03:42 How a 2021 firmware update let key generation fail silently into weak entropy
🕵️ 09:56 Alex Thorn traces three confirmed attack waves, and a possible fourth
🤝 14:05 'They trusted Coldcard to do the right thing': what broke when a hardware wallet failed
Learn more about your ad choices. Visit megaphone.fm/adchoices
Más podcasts de Noticias
Podcasts a la moda de Noticias
Acerca de Unchained
Crypto assets and blockchain technology are about to transform every trust-based interaction of our lives, from financial services to identity to the Internet of Things. In this podcast, host Laura Shin, an independent journalist covering all things crypto, talks with industry pioneers about how crypto assets and blockchains will change the way we earn, spend and invest our money. Tune in to find out how Web 3.0, the decentralized web, will revolutionize our world.
Sitio web del podcastEscucha Unchained, El Noti y muchos más podcasts de todo el mundo con la aplicación de radio.net
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app
Descarga la app gratuita: radio.net
- Añadir radios y podcasts a favoritos
- Transmisión por Wi-Fi y Bluetooth
- Carplay & Android Auto compatible
- Muchas otras funciones de la app

Unchained
Escanea el código,
Descarga la app,
Escucha.
Descarga la app,
Escucha.
Unchained: Podcasts del grupo
































