0:00
/
Generate transcript
A transcript unlocks clips, previews, and editing.

Trezor's CTO on the Cold Card Hack: Randomness, Trust, and What Comes Next - Tomáš Sušánka | Ep. 153

Tomáš Sušánka is the CTO of Trezor, where he has worked since 2017. Tomáš joins Efrat for an urgent, unscripted conversation days after the Cold Card hardware wallet hack, in which a flawed random number generator left seed phrases vulnerable and resulted in more than 1,500 bitcoin stolen from affected users. Drawing on questions submitted directly by the Bitcoin community, Tomáš walks through what entropy actually is, how Trezor's own four-source random number generation works, why open-source visibility alone does not guarantee security, and what practical steps everyday self-custody users can take to reduce how much they have to trust any single piece of hardware.

Please like, comment, share & follow — to help me beat the suppressing algo’s. Thx!


Follow Tomáš: Twitter | LinkedIn

— Support my work —
I was recently banned from Stripe, so I cannot have paid memberships on Substack… but there’s always another way!

Click here to support me!

Takeaways:

  • A single root failure destroys everything built on top of it. If entropy is broken at the very beginning of key generation, no amount of good design downstream can save you, because every key that follows inherits the same flaw.

  • Open source is necessary but never sufficient. Code being visible does not mean anyone is actually looking at it. Security requires incentivized eyes doing the work, not just accessible code sitting in a repository.

  • Licensing quietly shapes an entire industry’s incentive structure. When a company forks free and open code but locks its own derivative down, it loses the very community review that made the original trustworthy.

  • A vulnerability can sit untouched for five years, and the silence itself is never proof of safety. Absence of disclosure just means absence of attention, not absence of risk.

  • The instinct to add more security friction often trades away the usability that keeps people safe in the first place. Security that nobody can use correctly becomes its own kind of vulnerability.

  • Physical security gets disproportionate attention because it is dramatic and visible, while remote and software-level risks quietly do far more damage. We fixate on the exotic threat and underinvest in the mundane one.

  • Transparency has a cost that companies rarely get credit for. Publishing a finding that ultimately posed no real risk to funds still reads as a headline, and honesty can be mistaken for weakness.

  • Every wave of institutional entry into Bitcoin, through ETFs and custodians, reintroduces the exact intermediary that Bitcoin was built to remove. Convenience quietly recreates the system people thought they were escaping.

  • A crisis inside a trusted brand tends to produce both short-term flight to convenience and long-term improvement in rigor, and a community can hold both reactions true at the same time.

  • Bug bounty programs are a quiet admission that no company, however competent, can find all of its own flaws. Declining to pay for vulnerability reports is a decision about priorities, not a sign of confidence.

  • Multisig across different vendors protects against a category of failure that multisig within one vendor cannot touch. Redundancy only works when the redundant parts can actually fail independently of each other.

  • Technologies inherit reputations from years-old failures long after the underlying weaknesses have been fixed. A protocol’s old bad name can persist even after the real problem has quietly been solved.


Connect with me:
Twitter | YouTube | Instagram | Nostr | My podcast | All other links


Sponsors:

Expat Money

→ Download the free report on second citizenships & setting up a plan B in another country with Expat Money: https://expatmoney.com/efrat

Watch my episode with Mikkel for more:


Ledn

Access liquidity without selling your Bitcoin, get 0.25% off your first loan: https://ledn.io/Efrat


Trezor

→ Get your TREZOR wallet & accessories, with a 5% discount, using my code at checkout (get my discount code from the episode - yep, you’ll have to watch it)


Abundant Mines

→ Have you tried mining bitcoin? Stack sats directly to your wallet while saving on taxes with Abundant Mines. A month of free hosting for my followers:


Special offers:

→ Get 15% off “Born To Be Free” all-natural, tallow-based skincare products on a bitcoin standard, using code EFRAT: https://oshi.link/1nvZYq

→ Join me at any of these conferences or events:

Get 10% off on Augmented NAC to detox the Spike protein, using the code: YCXKQDK2, and this link. (Please note, this is not medical advice and you should consult your MD). Watch the episode with Tina below.

Watch “New Totalitarian Order conference with Prof. Mattias Desmet & Efrat - use code EFRAT for 10% off

— Support my work —
I was recently banned from Stripe, so I cannot have paid memberships on Substack… but there’s always another way!

Click here to support me!

Discussion about this video

User's avatar

Ready for more?