Trezor's CTO on the Cold Card Hack: Randomness, Trust, and What Comes Next
Ep. 153 with
@tsusanka
Tomáš Sušánka is the CTO of
@Trezor, where he has worked since 2017. Tomáš joins Efrat for an urgent, unscripted conversation days after the Cold Card hardware wallet hack, in which a flawed random number generator left seed phrases vulnerable and resulted in more than 1,500 bitcoin stolen from affected users. Drawing on questions submitted directly by the Bitcoin community, Tomáš walks through what entropy actually is, how Trezor's own four-source random number generation works, why open-source visibility alone does not guarantee security, and what practical steps everyday self-custody users can take to reduce how much they have to trust any single piece of hardware.
→ Please like, comment, share & subscribe, to help me beat the suppressing algo's. Thank you!
00:00 - Introduction: Tomáš Sušánka, Trezor CTO
02:39 - What Happened with Cold Card: How Trezor Received the News
09:17 - Origins of Cold Card: Forks, Licensing, and the Bitcoin-Only Split
13:40 - Open Source vs. Source-Available: How the Bug Went Undetected for Five Years
20:20 - Trezor's Response: Security Reviews and R&D Changes Since the Incident
22:24 - How Trezor Generates Randomness: The Four Entropy Sources
23:29 - Dice Rolling for Seed Generation: Necessary?
28:30 - Reducing Trust: Practical Verification Steps
31:09 - Single Device vs. Multisig
32:45 -
@BTCsessions Clip: Ben and
@theBTCmentor on Air-Gapped Wallets
34:29 - Tomáš's Take: Why Air-Gapping Isn't What People Think
39:49 - How Trezor's Design Differs from Cold Card's
42:32 - 2026 Secure Element Laser Fault Injection Finding
47:46 - Responsible Disclosure: Trezor's Protocol for Reporting Vulnerabilities
49:29 - The Biggest Risks Facing Bitcoin Right Now
51:01 - Short-Term Damage vs. Long-Term Lessons for the Community
55:27 - Trezor Model One's 12th Anniversary and the Evolution of Hardware Wallets
57:57 - Closing Thoughts and a Call for Continued Security Research