The Path to Bitcoin

Minimal line drawing of a long masonry wall of densely inscribed ledger blocks with one single cell left deliberately empty and measured

Episode #195 – The Gap

Bitcoin is a machine for remembering, and it works because of one deliberate hole in its memory. The Coldcard entropy failure filled that hole with facts the world had already written down somewhere, which turned a private key into an explainable object and cost people hundreds of millions of dollars without a single server being breached. Entropy is the size of the gap in the record, and the episode works out why nothing else in the system can do its job.


Episode Summary

Bitcoin is a machine for remembering. Every block, every transaction, every satoshi that has ever moved is written down in public, the writing is permanent, and it is checkable by anybody with a laptop and a small amount of compute. Fifty years from now a payment made in 2011 from some random bedroom in Helsinki will still be auditable, which is the whole of the invention, with one deliberate exception. There is a single fact recorded nowhere: not in any block, not on any node, not in any of the government databases tracking the network. That fact is the private key, and it has to be that way, because a system that remembered absolutely everything would also give everything away. Anything fully written down is something somebody can work out. Bitcoin therefore needs exactly one hole in its memory, and that tiny hole is the only thing standing between a person’s coins and every other person on the planet. Entropy, throughout this episode, means the size of that hole and nothing more elaborate. What happened at Coldcard was not a breach in any conventional sense. No servers were compromised, no houses were entered, nobody was manipulated into handing over their words, and nobody was attacked with a wrench. The people who lost money had by any normal standard done almost everything right: they bought a well-supported hardware wallet, generated a seed on it, wrote the words down, and put them somewhere safe, some of them doing exactly that correctly for five years. The failure sat underneath all of it. The firmware defined the flag for the hardware random number generator as zero, meaning off, and the library that needed to know whether the hardware generator was available asked whether the setting existed rather than whether it was switched on. Zero exists. The check passed, on every device and every time, for five years, and seed generation fell back quietly to a deterministic software algorithm, a thing that produces numbers which look random and are in fact worked out completely in advance.

That fallback was seeded from three values, and what those three have in common carries the entire episode: each of them is already written down somewhere in the world. The chip’s serial number is stamped on the chip. The boot counter is a number the device itself is storing. The time is the single most publicly recorded fact in the universe, with every satellite, every phone, every exchange, and every one of us agreeing about it continuously and for free. A search space intended to run to at least 128 bits collapsed to roughly 40 bits on the older Mark 3 devices and something closer to 72 on the Mark 4 and later. Forty bits is not difficult. Seventy-two is expensive, and expensive is relative when hundreds of millions of dollars sit on the other side of the calculation. The seeds had come to remember their own birth: made on chip number such-and-such, at this time, after this many boots. A key that carries memory is a broken key, and in the entire history of this technology that has always been the failure. Nothing about the seed’s appearance changed, which is why the problem sat undisturbed for five years. It was the same twelve or twenty-four words, the same length in bits, the same gibberish on inspection, and it restored perfectly. Handed the word list, nobody could tell by looking whether it came off dice rolls or off broken firmware, and there is no test that can be run on the words themselves. What changed is that the arrangement became explainable, and explainability is the only property that ever mattered.

Bitcoin needs two opposite objects welded into the same system, running side by side without ever touching. The time chain is a total history with zero secrets, public and permanent, each block connected to the one before it and verifiable by anyone. The key is the exact reverse, a total secret with zero history, a number drawn one time, witnessed by nothing, connected to nothing, leaving no trace anywhere except wherever its holder puts it. One object is unguessable and the other is undeniable, and the moment anyone confuses which is which, both properties begin to go. In framework language the word structure ends up doing double duty here, and separating the two uses is what makes the rest legible. Structure inside the key has to be zero, because any pattern in those bits is a road, and a road to a place will eventually be driven down. Structure holding the key has to be enormous: the steel plate, the second copy in another jurisdiction, the plan for what happens when the holder dies. The noise is the cargo and the memory is the ship carrying it. The word key is meanwhile covering three different objects, which the framework scores differently. First is the draw, the act of generation, energy committed to an irreversible process, a hundred dice rolls, one event, unrepeatable. Second is the value, the number that came out, contributing information and nothing else, its constraint quality obliged to stay at rock bottom forever, since constraint quality in this sense is structure and structure is a story. Third is the custody, the arrangement that keeps the number alive as it travels through time and across substrates, contributing all the testing, all the redundancy, and all the reach. Neither one is knowledge on its own. A key with no custody is noise, and noise evaporates the moment the paper is lost, or the house floods, or the children cannot find the word list. A custody scheme with no key is an empty box with no arrangement inside it to hold. The key becomes knowledge only through custody, and nothing else in Bitcoin works that way.

Minimal line drawing of a layered engineering containment in section, its many armoured walls surrounding a completely featureless empty core
Structure inside the key at zero, structure around it enormous

The same 32 bytes sitting in the same drawer score two completely different numbers depending on the chair they are read from. To the holder, the value has enormous reach, unlocking everything they own, its constraint quality whatever the custody has earned for itself. From an attacker’s chair the identical object has no usable structure and unlocks nothing at all. The gap between those two scores is the security, and every custody decision widens it or narrows it. A brain wallet narrows it by handing the attacker structure. Losing the only backup narrows it by dropping the holder’s side to zero, which is why a great many of Bitcoin’s losses are self-inflicted. The attacker, though, is never scoring the key, for the simple reason that the attacker does not have it. What gets scored is a hypothesis about how the key came to be, and the hypothesis is a sentence: keys from this tool are drawn from such and such a space. Where a key comes off clean dice, the only true sentence available is that it came out that way. No mechanism, no bias, nothing connecting that key to anybody else’s key or to any fact about its owner. The attacker’s best hypothesis is that the value is uniform across two to the 256th, which is completely correct, survives every test anyone can throw at it, and does nothing whatsoever, shrinking the search space by not one bit. Its reach is zero, and the reason is worth stating carefully: the true explanation of that key has no consequences, and where there is nothing to understand, being clever buys nothing.

Run the same questions at the sentence the Coldcard attackers assembled and every score comes back high. Their claim was that the library checks whether the flag exists rather than whether it is on, so the real generator falls back to a predictable one, seeding from chip ID, boot count, and clock. On breadth, that claim was tested by things with nothing to do with each other: somebody reading the source, somebody reproducing it across four hardware models, somebody deriving addresses from the predicted seeds, and then those addresses going out to face the hardest verifier in the system, the thousands of independent nodes run by people who have never met. A node cannot be bribed and cannot be flattered; it either verifies or it does not. On depth, the explanation held across five years of firmware and every seed generated in that entire window, never once failing to predict. On reach, that one sentence reached every seed the firmware ever produced, retroactively and permanently, without the attacker needing a single name or country or any fact about any of the people involved. Hard to vary, deeply tested, enormous in reach: real knowledge, information with causal power, pointed the wrong way. The framework does not care what anyone does with it, and reach is reach. The attackers simply did better epistemology than everybody else, and did it to take hundreds of millions of dollars from people who had done almost everything right. The compute was cheap. The knowledge was the expensive part, brutally expensive to find and nearly free to apply, which is the shape the P versus NP episode described, and applying it does not tire or ration itself. What it produces looks less like a burglary than a harvest.

Then the coins were swept into a handful of addresses, and what that did to the attackers’ own position is the strangest part. Before the sweep they held an explanation with open reach across an unbounded population of victims. After it they held a pile of coins of one very specific size. The reach collapsed into inventory, and the explanation cannot pay out twice, because every affected seed that held money now holds none. That inventory has the exact opposite problem to a key: maximally structured, maximally remembered, welded into the most thoroughly verified ledger human beings have ever built, and likely the most watched addresses in Bitcoin for years to come. Anyone can go and look at them this afternoon. They exploited the absence of memory and now hold objects made of pure memory, winning on one axis and losing instantly on the other, in the same system and within the same hour. Anybody trying to hide would have peeled the coins apart across a hundred hops, so consolidating them in the open says concealment was never part of the plan. Perhaps the address is meant to stand as a monument, a permanent published proof that the explanation was real and complete, because a ledger that records a theft is also certifying it, and there is no more durable way to attest to exactly how far an idea reached.

Minimal line drawing of a house in section with its wiring, plumbing and roof annotated for inspection above a sealed unannotated foundation
The draw is the foundation, poured once and sealed

How entropy protects anything is a mechanism almost nobody states. Nobody can delete coins, since the ledger only ever gets added to and no one can go back and erase an entry. The only threat is an unauthorised next entry, somebody producing a valid signature that moves the coins elsewhere. Protection here means exclusivity over who gets to write the next line, which is a different object from the wall around the money that fiat custody provides. Bitcoin has no gatekeepers and no guards, and the network will accept a valid signature from anybody on earth, which is the entire design, so exclusivity has to be manufactured out of thin air, and exactly one material does that job: a fact that exists nowhere else. It is not hidden, not encrypted, not stored somewhere clever. It is absent. Memory cannot be protected using more memory, and more memory is precisely what those seeds were made out of. There is a second property here that gets very little attention. Every other component of Bitcoin security degrades with time and use. Addresses grow more linkable every year, chain analysis improves every year, identity leaks a little more with every exchange touched, firmware accumulates bugs, and discipline slips as people get busy and older and distracted and move house, and the steel plate ends up in a box in the garage. Entropy alone does not degrade, because there is nothing for it to degrade toward. A properly drawn number leaks no partial information, ever. Watch the chain for a hundred years, run every analysis anyone invents between now and then, and learn exactly zero bits. It is the one fixed point in a system where everything else is eroding, which is why it is the root rather than another layer.

Which is what the dice are for. A hundred rolls is a one-time commitment carrying no memory, an arrangement that exists because energy was committed once and that nobody else has ever seen, and it cannot be made twice: roll again and a completely different key comes out, and the dice cannot be run backwards. That is the pawl at the scale of one person. From there the arrangement has to travel, and its holder is the channel, from dice to brain, brain to paper, paper to steel, steel to the signing device, every one of those a substrate change that has to preserve the exact shape, since one wrong word or one wrong bit kills it. Perfect fidelity carrying zero meaning. The ritual that follows is well known: put the words in a device, send a small amount of Bitcoin to it, wipe the device completely, restore from the backup, and spend the coins. If they spend, the arrangement survived, and the verdict is delivered by thousands of independent nodes confirming that the restored key controls those coins while not one of them learns anything about the key itself. Being tested normally costs exposure, and to be examined a thing has to be seen; here the harshest class of verification that has ever existed runs indefinitely, for free, and never gains a single bit about what it is checking. Every spend is another cycle survived.

That ritual, however, would not have saved a single Coldcard victim. Each of them could have run it perfectly, because a 40-bit seed restores perfectly, and their custody was probably as good as it gets. The test confirms that copy A matches copy B; it will catch a misspelled word or two words in the wrong order, and it can say nothing at all about where the seed came from. Every step of it is downstream of the draw, and the draw is the one act in the whole process that nobody ever tests: not the holder, not the network, not anybody, ever. A house can have its wiring and plumbing and roof inspected any day, as often and as long as anyone likes. The foundation gets poured once and sealed, and all that ever mattered was the quality of the concrete on the day. Since depth can never reach the draw, everything falls to breadth, and breadth means genuinely independent sources that do not share a failure mode. One vendor is a breadth of one, however good the vendor and however many years of reputation stand behind it, and everybody who got drained had one source of entropy and one firmware. Dice remain the best available answer for the reason that the universe has never seen that number and there is no story attached to it. Nor does artificial intelligence change this: an explanation-finding machine pointed at an object engineered to have no explanation does nothing forever, no matter how good it gets, while the same machine pointed at a wallet generator with a clock in it will eat everything. Those compromised seeds were compromised in 2021, at the moment of their creation, and for five years they looked completely fine, sitting in the open and appearing to survive every attacker on earth while surviving nothing at all, waiting for somebody to notice. Generating a private key is putting a hole in the record that no one can ever fill in.


Timestamps

00:00 – The Coldcard exploit as an occasion to run the framework

00:52 – Bitcoin as a machine for remembering

02:02 – The one fact the system deliberately does not know

02:36 – Entropy as the size of the hole in the record

03:18 – No servers breached, no houses entered, nobody wrench-attacked

04:25 – Two opposite requirements welded into one system

05:14 – The firmware flag set to zero

05:47 – The check that asked whether the setting existed

06:20 – Chip serial, boot count, and clock: three facts already written down

07:19 – From 128 bits to 40 on the Mark 3 and 72 on the Mark 4

07:44 – The seed that remembered its own birth

08:09 – A key that carries memory is a broken key

08:35 – Nothing visible changed; the seed became explainable

09:30 – Total history with zero secrets, total secret with zero history

10:45 – Structure doing double duty

10:54 – Zero structure inside the key, enormous structure around it

12:22 – The noise is the cargo and the memory is the ship

12:51 – Three things called the key: the draw, the value, the custody

13:54 – Scoring the value and the custody separately

15:07 – The key becomes knowledge only through custody

16:14 – The same object read from the attacker’s chair

16:28 – The gap between the two scores is the security

16:39 – How a brain wallet narrows the gap

17:24 – The attacker scores a hypothesis, never the key

17:47 – Clean dice and the sentence with zero consequences

19:26 – Scoring the attacker’s sentence: breadth

20:06 – The thousands of independent nodes that cannot be bribed

20:23 – Depth across five years of firmware

20:40 – Reach across every seed the firmware ever produced

21:25 – Better epistemology, pointed the wrong way

22:20 – A harvest rather than a burglary

22:33 – Why the sweep went to so few addresses

23:15 – Reach collapsing into inventory

23:58 – Coins made of pure memory

24:29 – Consolidation in the open, and the monument reading

25:15 – How entropy actually protects anything

25:39 – The only threat is an unauthorised next entry

26:12 – Exclusivity manufactured out of thin air

26:39 – Memory cannot be protected using more memory

27:31 – Everything else degrades: linkability, analysis, discipline

28:22 – Entropy as the one fixed point

29:05 – Why everyone keeps talking about rolling dice

30:06 – The pawl at the scale of one person

30:29 – The arrangement travels and the holder is the channel

31:29 – The ritual: fund, wipe, restore, spend

32:19 – The harshest verifier that has ever existed, working for free

33:15 – Why the ritual would not have saved anybody

33:30 – A 40-bit seed restores perfectly

34:38 – The foundation gets poured once

35:23 – One vendor is a breadth of one

35:52 – Dice, and a number the universe has never seen

36:05 – Why AI does not break entropy

37:16 – A hole in the record no one can ever fill in

Timestamps are approximate.


Topics Discussed

  • Bitcoin as a machine for remembering, and the single fact it deliberately does not record
  • Entropy defined as the size of the hole in the record
  • The Coldcard failure: a library that checked whether the RNG flag existed rather than whether it was switched on
  • Chip serial number, boot counter, and clock as three facts the world had already written down
  • The collapse from an intended 128 bits to roughly 40 bits on Mark 3 devices and around 72 on Mark 4 and later
  • Why a seed that remembers its own birth is broken even though it restores perfectly
  • Explainability as the only property that changed, and the only one that matters
  • Total history with zero secrets against total secret with zero history, welded into one system
  • Structure inside the key at zero, structure holding the key enormous, and why they look like opposites
  • The draw, the value, and the custody as three separate objects the framework scores differently
  • Why a key with no custody is noise and a custody scheme with no key is an empty box
  • Two scores for the same 32 bytes, and the gap between them as the definition of security
  • Scoring the attacker’s hypothesis rather than the key, and why clean dice produce a true sentence with no consequences
  • Breadth, depth, and reach applied to the exploit itself, and knowledge pointed the wrong way
  • Why the sweep collapsed open reach into fixed inventory, and coins made of pure memory
  • Protection as exclusivity over the next ledger entry, not a wall around the money
  • Entropy as the only component of Bitcoin security that does not degrade with time
  • Why the fund-wipe-restore-spend ritual verifies custody and can never verify the draw
  • Breadth of one: a single vendor and a single firmware as the shared failure mode
  • Why AI finds missing entropy rather than breaking real entropy

Links & References


Related Episodes


Notable Pull Quotes

“Bitcoin is a machine for remembering.”*”

“A key that carries memory is a broken key.”*”

“The gap between those two scores. That’s your security.”*”

“You cannot protect memory using more memory.”*”

“The draw is your foundation. Everything else is the house.”*”

Post a comment:

Comment