r/Bitcoin: podcast transcript cited in criticism of nvk's AI-audit response
reddit-nvk-ai-audit-podcast
https://www.reddit.com/r/Bitcoin/comments/1vgj17y/coldcard_ceo_rodolfo_novak_confessing_2_moths_ago/
Latest reviewed change
source content difference between and
The post gained a separator line and a link to a WalletScrutiny GitLab work item.
Well, no one will say hardware wallets are bad, but it is time to make accountable hardware wallet vendors selling you unaudited shit and with no security in dept design. What is security in dept design or foolproof design? Well do not tell that rolling dice is optional but recommended, fucking do not allow the seed generation step to be completed without it. Specially if you ar going to say that AI reported bugs are crap and you have no external verified audit history of source code.
+_____
+https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340
+
comment: p1xm2dz
parent: t3_1vgj17y
First lines only. The complete diff is in the timeline below.
- Organisation
- Evidence role
- Community discussion
- Published
- not established
- Source changes
- 2
- Detected differences
- 2
- Unreviewed
- 0
- Copies held
- 3
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The post gained a separator line and a link to a WalletScrutiny GitLab work item.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 3 lines
Well, no one will say hardware wallets are bad, but it is time to make accountable hardware wallet vendors selling you unaudited shit and with no security in dept design. What is security in dept design or foolproof design? Well do not tell that rolling dice is optional but recommended, fucking do not allow the seed generation step to be completed without it. Specially if you ar going to say that AI reported bugs are crap and you have no external verified audit history of source code. +_____ +https://gitlab.com/walletscrutiny/walletScrutinyCom/-/work_items/340 + comment: p1xm2dz parent: t3_1vgj17y author: Few_Response_7028Extracted text as captured
post: 1vgj17y author: Fearless-Second-7230 created_utc: 1785961723 title: Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous" body: First this part, he recognizing is lame for bitcoin products to blame AI... Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something." Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. \*I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.\*" \_\_\_\_\_\_\_ There you have it. The guy in his own words impliying Coldcard has fucking bad security. But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing: Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?\[ ...\] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way" Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo \[laughter\] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff. Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap." \[ END OF TRANSCRIPT PART \] \_\_\_\_\_\_\_ Well, here is where things start to become a mess: He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them. But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/ They mention: "The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious. Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even analizing them carefully).Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
bobivy1234 edited their comment to add at the time to the claim about LLM audit tools flagging benign issues, and three new comments appeared, including first-hand reactions calling the developer criminally negligent and bobivy1234 replying that the podcast conversation proves little.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 30 lines
parent: t3_1vgj17y author: bobivy1234 created_utc: 1785965911 -edited: false -body: -Cmon man we can hate on them all we want but in the context of the conversation, he said some friend's random assessment tool scanned the ColdCard repo and marked a bunch of benign stuff as 'high risk' which they validated were mediocre small issues as a broader discussion of LLMs still not being strong for these use cases. +edited: 1786016462 +body: +Cmon man we can hate on them all we want but in the context of the conversation, he said some friend's random assessment tool scanned the ColdCard repo and marked a bunch of benign stuff as 'high risk' which they validated were mediocre small issues as a broader discussion of LLMs still not being strong for these use cases at the time. Yes missing the TRNG enablement in the codebase is a massive deal but also not worth putting out this conversation as some admission of intentional fraud of avoiding fixing discovered issues. sadly the sociopath devs rug pull in well ofuscated ways, by using shitcoin projects, icos, etc (x is enough evidence of his behavior and now he is deleting posts because he knows lawsuit is coming)....this guy knew the backdoor would be well covered by his "roll dice" narrative....those are the cover up to say "hey, look, but there were users not affected", but conveniently having a "bug" in its most critical component ..yeah, well implemented backdoor... + +comment: p21eya8 +parent: t3_1vgj17y +author: MasaiRes +created_utc: 1786015488 +edited: false +body: +The fact that people entrusted millions to this chancer is staggering. + +comment: p21hswg +parent: t1_p1xyd24 +author: bobivy1234 +created_utc: 1786016544 +edited: false +body: +I don't disagree in general but we have no clue what that report said or what they fixed and didn't fix. It's just some random conversation on a podcast and it isn't an out-of-left-field sentiment that LLMs and some of these new tools aren't quite hitting the mark yet. The release of Fable and other pioneer models were a monumental leap but that has all been more recent. + +comment: p21v811 +parent: t3_1vgj17y +author: ItsAlwaysThemBooBoo +created_utc: 1786020918 +edited: false +body: +at worst hes a criminal who is behind this, and at best, hes a criminally negligent cunt who allowed a critical security flaw to be there for 5 years in a row without correcting.Extracted text as captured
post: 1vgj17y author: Fearless-Second-7230 created_utc: 1785961723 title: Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous" body: First this part, he recognizing is lame for bitcoin products to blame AI... Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something." Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. \*I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.\*" \_\_\_\_\_\_\_ There you have it. The guy in his own words impliying Coldcard has fucking bad security. But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing: Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?\[ ...\] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way" Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo \[laughter\] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff. Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap." \[ END OF TRANSCRIPT PART \] \_\_\_\_\_\_\_ Well, here is where things start to become a mess: He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them. But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/ They mention: "The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious. Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even analizing them carefully).Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
post: 1vgj17y author: Fearless-Second-7230 created_utc: 1785961723 title: Coldcard CEO Rodolfo Novak confessing 2 moths ago in a podcast regarding AI audit bug reports: "Everything was like high like they said everything is like 'high high so it's like 'super dangerous" body: First this part, he recognizing is lame for bitcoin products to blame AI... Interviewer: "...The BIsq announcement thread mentioned that it is likely an AI powered attack. So maybe people using you know is it some North Korean group using Claude or Cursor or Mythos or something." Rodolfo Novak 'nvk'(18:53): "Yeah, but that's like you know that's that's like saying that they just encounter an adversary that's a little bit better than they are. \*I mean like you know the reality is people are trying to break stuff all the time and if you have like Bitcoin to be taken you know it just means that they had you know bad security.\*" \_\_\_\_\_\_\_ There you have it. The guy in his own words impliying Coldcard has fucking bad security. But the interesting part is this one, where he arrogantly is downplaying the bug reports an AI audit tool is throwing: Interviewer (19:08): "Yeah, but I guess the point would be is there has the game changed, right? Is there a you know now this is a big new threat that people need to start thinking about which is basically AI assisted hacking?\[ ...\] like well there's AI assisted hacking and now we need AI assisted defense and you need to find you need you need to defend it uh and um that way" Rodolfo Novak 'nvk'(20:03): "so it's already happening we we got a preview a friend got a preview of the codec cyber or whatever they call it the KYC NDA version of their uh uh security assessment tools y uh you know the first thing he did was run after run it on the code card repo \[laughter\] And uh you know honestly like we we saw the the bug reports they're all like you know extremely mediocre stuff. Uh everything was like high right like they they said everything is like high high so it's like super dangerous and everything was like completely false reporting. The tools are still abhorent. The quality of this this this hacking uh AI hacking is still ultra ultra crap." \[ END OF TRANSCRIPT PART \] \_\_\_\_\_\_\_ Well, here is where things start to become a mess: He is confessing they have extremely dangerous findings through AI but he just arrogantly is downplaying them. But here in Jul 30 2026: https://blog.coinkite.com/entropy-technical-backgrounder/ They mention: "The COLDCARD source code has always been open and publicly available, so we have to assume that someone used AI to review previous versions of our firmware and stumbled upon this issue. A few weeks ago, we used one of the best available AI models to review our code for security issues, and it did not find this bug or anything serious. Both attackers and defenders have the same AI tools, but today it did not help us, and only helped the bad guys." (No you idiot, you are confessing an AI showing you dangerous bugs and just arrogantly maybe not even analizing them carefully).Excerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.