Zach Herbert is Co-founder and CEO of Foundation, building Passport Prime, an open-source device that moves your digital authority onto dedicated, secure hardware:one device built to be held, verified, and trusted.

https://x.com/zherbert


PARTNERS

🔐 The Bitcoin Way is your personal Bitcoin security team. Schedule a free, 30-minute consult: http://www.thebitcoinway.com/bram?utm_medium=podcast&utm_source=partner-bram-kanstein

🤝 Firefish is the open market for Bitcoin-backed loans. Find offers and get 30% off your first loan’s fees with code BRAM: http://firefish.io/?ref=BRAM


PRODUCTS I ENDORSE

› Get 10% off a Bitaxe open-source Bitcoin home miner using code BRAM at https://shop.powermining.io/?ref=BRAM

› Heat your home and Earn Bitcoin with Heatbit - Get 5% off with code BRAM https://heatbit.com/?ref=BRAM

› Stamp Seed: The safest way to backup your hardware wallet - Get 15% off with code BRAM at https://stampseed.com


🔔 SUBSCRIBE TO GET NOTIFIED

https://youtube.com/@bramk⁠⁠

https://x.com/bramk


🕑 TIMESTAMPS

00:00 - Coldcard exploit, what likely happened

02:29 - Negligence vs conspiracy theories

04:54 - Why basic entropy checks failed

06:30 - Source available vs open source

08:13 - Closed source scenario, why panic

09:25 - Why FOSS still wins long term

12:58 - Ledger, audits, and verification limits

16:30 - Why this bug was the worst case

19:23 - AI changes wallet threat models

21:56 - Best practice, rerun audits per model

24:56 - Self-custody backlash, convenience vs control

32:34 - Designing happy path vs advanced mode

36:54 - Do you need a phone?

37:45 - QR air gap limits and Quantum Link

57:04 - Hardware wallet cooperation, not infighting

1:04:24 - Biggest takeaways for average users


ℹ️ EPISODE SUMMARY

Bram Kanstein and Zach Herbert discuss the Coldcard entropy failure and why it smells like negligence, not a nation state plot. They confront how “don’t trust, verify” often stops at a slogan, even when seed generation is the whole game. They map the trade-offs between closed source, source available, and true FOSS, especially now that AI can audit firmware fast. Zach reveals why Foundation moved past pure QR air gaps, and how Quantum Link uses QR to bootstrap an encrypted Bluetooth tunnel. They zoom out to the real damage: self-custody adoption, UX vs hardcore OPSEC, and an industry that needs a rapid response loop.

Podden och tillhörande omslagsbild på den här sidan tillhör Bram Kanstein. Innehållet i podden är skapat av Bram Kanstein och inte av, eller tillsammans med, Poddtoppen.