Crypto Learning CenterSecurity

Does the Coldcard Hack Mean Self-Custody Is Broken? No — Here's Why

📖 Part of the Bitcoin555 Learning Center →

Every time self-custody suffers a disaster, the same argument resurfaces, and the Coldcard exploit has given it fresh ammunition: more than $116 million stolen from cold storage — hardware wallets can't be trusted, ordinary people can't do this safely, just buy the ETF or leave it on an exchange. You'll find versions of this take everywhere right now, some of them from people who should know better. Having watched this industry since 2013 — through Mt. Gox, through FTX, and now through this — I think the argument deserves a serious answer rather than a dismissive one. So let's take it seriously. And then let's take it apart.

The case against self-custody, steelmanned

Here's the strongest version: thousands of careful users bought a respected, open-source, Bitcoin-only device, followed the instructions, stored their backups properly — and were drained anyway, by a flaw they could not have detected (full timeline on our tracker). If doing everything right isn't enough, the argument goes, then the model itself is broken for normal people, and professional custody is the responsible choice. That's not a stupid argument. The people making it in good faith are reacting to real victims and real losses, and some of them are genuinely trying to protect newcomers from a skill they haven't built yet. It deserves better than a bumper-sticker rebuttal. It's still wrong — in four specific ways.

1. This was one vendor's bug, not the model's

The flaw was an implementation error in one firmware build from one manufacturer — a broken random number generator in code, not a crack in Bitcoin's cryptography or in the concept of holding your own keys. Seeds generated on other vendors' devices, seeds made with dice rolls, seeds from before the bug: all remain exactly as secure as they were. Condemning self-custody over this is like condemning aviation because one model had a defective part. The failure is real, the accountability should be brutal — and the category survives it, as the overwhelming majority of self-custodied Bitcoin, unaffected by this bug, quietly demonstrates.

2. Custodians have lost customers far more

The $116 million figure is painful. Now put it on the same chart as custody's track record: Mt. Gox lost roughly 850,000 BTC of customer funds — tens of billions at today's prices. FTX vaporized about $8 billion of customer money. Celsius, QuadrigaCX, Voyager, BlockFi — the list of custodians that took customer coins down with them is long, and the sums involved dwarf every hardware wallet incident in Bitcoin's history combined. The honest comparison isn't "self-custody risk versus no risk." It's "a bug that hit one vendor's users versus a business model whose failures are measured in billions." And those are just the spectacular endings — the slow variants are worse in aggregate: withdrawal freezes during the moments people most needed their coins, accounts closed by compliance decisions with no appeal, funds lent out and rehypothecated without meaningful consent. Every one of those users had done the "responsible" thing by the standards of this argument. Anyone citing this hack as a reason to trust custodians is arguing against the scoreboard.

3. The hack validated defense-in-depth — loudly

Buried in the wreckage is the strongest pro-self-custody evidence in years: the users who layered their security were untouched. Everyone using a BIP39 passphrase kept their coins, because the reproduced seed alone couldn't reach them. Everyone using multisig kept theirs, because one compromised seed out of several isn't enough. The tools designed for exactly this failure worked exactly as designed, at full scale, under a real attack. That's not a broken model. That's a model whose safety features passed a live-fire test.

4. Custody doesn't remove risk — it relocates it

Moving coins to an exchange or an ETF doesn't eliminate the possibility of loss; it converts key risk into counterparty risk — the precise risk Bitcoin was invented to remove. A custodian can be hacked, can freeze withdrawals, can be seized, can rehypothecate, can simply lie about reserves until the day it can't. You trade a risk you can engineer around for one you can only hope about. For some people — genuinely uninterested in learning, holding small amounts — that trade can be rational. But call it what it is: reintroducing the trusted third party, not upgrading security. The ETF version deserves special mention, because it's marketed as the grown-up option: what you own there is a share tracking Bitcoin's price, held through layers of brokers and custodians, with no ability to withdraw a single satoshi, transact on-chain, or exit the financial system the asset was designed to route around. It may be a fine price-exposure product. It is not Bitcoin ownership in any sense this hack has anything to say about.

What the critics get right

Two things, and they deserve saying plainly. First, self-custody does demand more from the user than a brokerage account — real attention at setup, real discipline about backups, and now, evidently, some awareness of firmware provenance. Second, this event proved that single points of failure are not theoretical: one invisible flaw in one component silently undermined thousands of setups for five years. Anyone who claims self-custody is idiot-proof is selling something. It is a skill, and skills have a floor.

The actual lesson: self-custody with redundancy

The rational response to this hack isn't retreating to custodians — it's removing the single points of failure the hack exposed. Add a passphrase, so no reproduced seed can stand alone. Graduate to multisig as your stack grows, so no single device or vendor can sink you. Take entropy into your own hands with dice rolls if you want the manufacturer's RNG out of your trust equation entirely. If you're affected or unsure, start with our step-by-step check-and-migrate guide; if you're building from scratch, our self-custody starter guide lays the foundation. Concretely, redundancy looks like this: no seed guards serious money alone (a passphrase or a second signature stands behind it); no single vendor's correctness is load-bearing (mix devices, or take entropy into your own hands); and every backup is tested before it's trusted, not after it's needed. None of that requires a computer science degree — it requires an afternoon and the humility to assume something in your stack will eventually fail. Sixteen years in, the principle that emerged from every custodial collapse still holds — and this incident, properly understood, reinforces rather than refutes it: your keys, your coins. Just hold them with redundancy now.

Free 7-Day Bitcoin Course

Everything you need to start with Bitcoin — one lesson per day, from someone who's lived on it since 2013.

No spam. Unsubscribe anytime. Free forever.