Is Self-Custody Still Such a Good Idea?

The Coldcard hack wasn't the biggest ever, but it left a deep crater in the bitcoin world: is self-custody still such a good idea for safeguarding your wealth?

Is Self-Custody Still Such a Good Idea?
Contribution by Erik

More than a week after the Coldcard hack, the shockwaves are still rippling through the bitcoin community. It has hit everyone hard that the roughly five thousand victims weren't the reckless type, nor were they gambling on quick profits.

In the latest episode of Satoshi Radio we take a deep dive into how the hack unfolded, who the key players are, and what it stirred up among bitcoiners

Compare the current group of victims with, say, those caught up in the Celsius bankruptcy in 2022. The latter took a deliberate risk by handing their crypto over to a company that lent it out. But the victims of the Coldcard hack were bitcoiners who chose a bitcoin-only hardware wallet and engraved their seed phrase on a steel plate; or followed similar practices that were doing the rounds in the bitcoin world. Sure, some could have done more, but they certainly weren't careless.

Plenty of prominent figures in the international community are owning up to their part in this. Just read this:

“The fact that I occasionally praised Coldcard as ‘the best,’ while I could in no way back up that claim, is unacceptable to me.”

That's what the well-known bitcoiner American HODL wrote, with a hefty dose of self-reflection and, further down in his post on X, remorse.

Even sovereignty-minded bitcoiners, who swear by the adage ‘Don't trust, verify,’ have been forced to confront the fact that they too sometimes blindly trusted a company that didn't have its house in order.

That's what makes the Coldcard fiasco more painful than a hack of an exchange or DeFi project. The loss comes with the dawning realization that total financial sovereignty simply doesn't exist. Of course the risk of a problem with hardware wallets was already on the list of potential risks, but for the first time that risk is now being felt in the gut.

And that's a bitter pill to swallow. There's a limit to your own ability to verify what a counterparty is doing. Beyond a certain point of complexity, you have to rely on the competence of other parties. That's life.

Putting your own security firm under the microscope

All of this raises a question for ‘ordinary’ crypto holders: if some seasoned bitcoiners got burned, what makes us think we can pull it off?

That's a fair question. If you want to take custody of your own crypto, you become your own security firm. It means thinking about fire, loss and theft, about phishing and fake updates, extortion and death. And therefore thinking about weak links in the security chain, including the manufacturer of your wallet… What a hassle!

That doesn't mean self-custody is no longer a good option. But for many bitcoiners it will lead to a ‘recalibration’ of their approach. Do I perhaps want to park part of my holdings with a custodian, so that there's no ‘single point of failure’?

Have you decided, after weighing it all up, that you want to keep doing self-custody? Then it makes sense to take fresh stock of your setup. What do I know about the manufacturer of my hardware wallet? Should I add a passphrase on top of my private key after all? Should I make the move to multisig? Those last two are best practices that Bitcoin Alpha has always advocated, and they still stand. As does the tip to regularly practise sending coins. Taking custody of your own crypto isn't a one-off action but a skill you have to maintain.

Not everyone has the time or the inclination for that. For many people, the conclusion will be that it's a good idea to simply deposit their BTC with a reputable custodian, and/or buy a BTC ETF.

A self-cleansing effect

So some good things will come out of this hack. Once the dust has settled, a portion of bitcoin holders will leave self-custody for what it is. Another portion will improve the quality of their self-custody.

And you can bet that every hardware wallet manufacturer will take a fresh look at their firmware and re-examine other risks. The manufacturers who can demonstrably get this right will benefit in terms of market share.

This incident will have a self-cleansing effect. A forest fire is a disaster, but it renews the landscape.

More Alpha

Are you a Plus member? Then we'll continue with the following topics:

  1. Coldcard manufacturer ignored the warnings
  2. Is Ethereum suffering from too much staking?
  3. Clarity Act gets a shot... in September

Below that come the news snacks, a handy overview of the news that really mattered this past week.

1️⃣ Coldcard manufacturer ignored the warnings

Contribution by Erik

The hack of Coldcard wallets has now cost bitcoiners well over a hundred million dollars. A frequently asked question is why this bug could sit in open-source software for years without being noticed. The answer is twofold: the software wasn't really open source, and the bug was actually spotted; at least, the risk of it was flagged. There were developers who warned Coinkite, and they were brushed aside.

In May 2025, Bitcoin Core developer James O'Beirne dove into the Coldcard firmware on his own initiative. He wanted to understand how the device generated a seed, the recovery phrase that grants access to the stored funds. O'Beirne told Coinkite, the company behind Coldcard, that he doubted whether the correct so-called random number generator was actually being used. The response he says he received: if something were wrong, “we'd know by now.”

A screenshot surfaced, from a Telegram exchange in April 2021, a month after the introduction of the fatal bug. “Do we really want to replace Trezor's software, which has been in use and extensively audited for years?”

Coinkite hasn't responded to these specific messages and it's too early to draw conclusions on this precise point about their negligence.

But we can already draw broader conclusions. A recent look at the section of the software containing the bug shows that a major software change in March 2021 (4.0.0) was very poorly documented and justified by the responsible developer. This was unprofessional.

From open source to a dusty corner

A mistake can happen, but the fact that it slipped through the cracks needs more explaining. That broader context of where things went wrong is now clear too. The origins of Coldcard's firmware lay with hardware wallet manufacturer Trezor.

Coldcard began as a fork of the Trezor firmware, which was covered by a full open-source license. When competitor Foundation in turn used Coldcard's code as its starting point, Coinkite, out of displeasure, switched the license to source available: the code can be viewed, but not reused. As a result, Coinkite could no longer use the proven Trezor components, including the way it generated seeds, and had to replace them. It was precisely in that replacement, in March 2021, that the bug crept in.

Another consequence was that the software was no longer open source, and thereby became less interesting to external parties, who could otherwise have found bugs. Although, as mentioned, there were a couple of cases of interested people who put their finger close to the sore spot, but found no ear.

🧠
Having second thoughts about (self-)custody?
On Thursday, Bart and Peter held a live Q&A on Discord about the Coldcard hack and self-custody. Among other things, they covered the ways you can store your bitcoin, the responsibilities you take on (or hand off), and what makes for a sensible setup for most people.

Have you started to have doubts about using hardware wallets? About the way you've set things up for yourself? Let us know. If there's enough interest, we'll put together the key takeaways from the Q&A in a standalone update.

You can respond by email, by replying to this message, or by sending Peter an email at peter@bitcoinalpha.nl.

2️⃣ Is Ethereum suffering from too much staking?

Contribution by Peter

Anyone who locks up ETH in staking helps secure the network and receives a reward for it. By now roughly a third of all ether, some 40 million ETH, is locked up in that system. The more capital that stands behind ethereum this way, the more expensive it becomes to attack the network. So far, then, more staking mainly sounds like good news.

Except that reasoning breaks down at some point. A group of six researchers, including Justin Drake, argues that beyond a certain point every extra ether that gets staked adds hardly anything to security. By then the network is already extraordinarily expensive to attack.

The group argues that above a certain level, more and more staking can be counterproductive. Newly locked-up ether has a low marginal security contribution, while the side effects only grow. More and more ETH ends up with custodians, exchanges and so-called liquid staking providers. Individual stakers are pushed to the margins as a result, and power concentrates in a smaller number of large players. The network thus becomes economically slightly more secure, and at the same time more vulnerable to centralization and outside influence.

The researchers want to do something about this. Their proposal is called Tapered Issuance Burn. As a larger share of all ETH is staked, an ever-larger portion of the reward that validators receive gets burned. Around a staking ratio of 50%, the reward from new ETH eventually disappears altogether. Other income, for example from transaction fees and MEV, remains in place. To avoid a sudden blow to stakers, the change would be phased in over eighteen months.

The proposal is far from settled. It was put on the table for the first time this past week to the core developers as a candidate for a future ethereum upgrade.

The reactions to it are mixed. Some are optimistic, because the intervention puts a ceiling on ether inflation; conditions could then actually become deflationary, a long-cherished dream of Drake's. But it's precisely the staking yield that makes ETH attractive to investors. Squeeze the reward and some of the capital may go looking for returns elsewhere.

It's hard to predict in advance which of the two effects will have the biggest impact on, say, the ether price; that's ultimately where the interest lies for the investors who care about this. For now, they're not enthusiastic about the idea.

The group will take a position later on the direct and indirect consequences of the proposal. That will also reveal to what extent the researchers connect with the concerns at play, or whether they keep pontificating from their ivory tower.

3️⃣ Clarity Act gets a shot... in September

Contribution by Peter

On Friday, the Clarity Act seemed to be slowly sinking into the American political swamp. The Senate was about to break for summer recess and Majority Leader John Thune had already set the procedure in motion for all sorts of other bills. The most important American crypto law was missing. On Satoshi Radio we summed it up somewhat gloomily: in this case, no news is not good news.

The Clarity Act is meant to finally provide clear rules of the game for the American crypto market, among other things by establishing when a crypto asset falls under the SEC or the CFTC. In May the law still got enough support in the Senate Banking Committee; there it cleared the procedure with 15 votes in favor (and 9 against).

Since then, the trickiest political files have been left on the shelf. Democrats want stricter ethics rules because of the crypto interests of President Trump and his family. There's also disagreement over stablecoin rewards, partly because banks fear such products could pull deposits away from them. What's more, sixty votes are needed for the final vote; the Republicans can't do it on their own.

On Friday, an early sign became visible of a development the Democrats are hoping for: the separation between Trump (and his family) and parts of the crypto world.

During the recording of Satoshi Radio, it looked as though the Senate wouldn't take another look until September. That's uncomfortably late. After the summer recess, only a small political window remains before the campaign for the midterm elections claims all the attention.

But just before the senators headed home, there was movement after all. Thune arranged for the Clarity Act to come to the table right after the summer recess. On September 15, the Senate will first vote on whether the law is officially taken up for consideration.

A law that on Friday was in danger of dropping off the agenda is now ready as one of the first files when Washington returns. Before then, conversations in the corridors will no doubt make it clear(er) whether it's possible to rally enough Democrats behind the bill.

🍟 Snacks

To wrap up, a few quick snacks:

  • Wells Fargo, too, is bringing bank balances on-chain. This fall the American bank is introducing so-called tokenized deposits, initially for US dollars and British pounds. With them, customers can transfer programmable money around the clock. The system runs on its own private, permissioned blockchain, though. With that, Wells Fargo stays deep in traditional Wall Street territory: it's using new technology to make existing banking services more efficient. But: the step toward an open, decentralized financial infrastructure isn't ruled out.
  • Samsung is deepening its relationship with the crypto world. The South Korean conglomerate has taken a stake in Dunamu, the company behind crypto exchange Upbit. Analysts link that investment to Samsung's earlier plans to make stablecoins available through its smartphones. With hundreds of millions of devices in circulation, Samsung could in theory grow into a major distribution layer for digital money. Just how concrete that link becomes is still unclear.
  • Quarterly figures show that Strategy is taking an increasingly defensive stance. In the past quarter it still managed to grow its bitcoin position, by 11%. At the same time, its use of convertible debt was reduced and its dollar reserve increased. This week Strategy even sold bitcoin to build up extra liquidity and buy back STRC. The thinking behind it: less dependence on debt and sufficient cash on hand should demonstrate that the company will stay financially afloat even in a weak bitcoin market. Some analysts link that to the desire to be included in the S&P 500.
  • BTCPay Server has patched a critical vulnerability after bitcoin was stolen. Attackers were able to obtain LND's so-called macaroon files without login credentials and thereby gain control over Lightning nodes. Only installations using LND were vulnerable; BTCPay's regular on-chain wallets were unaffected. All versions before 2.4.2 contained the flaw. BTCPay is urging users to update immediately and is still investigating how many victims there are and how much bitcoin was taken.
  • Cloudflare is building payment infrastructure for AI agents. With Cloudflare Wallets, agents will soon get their own virtual wallet with which they can independently purchase access to APIs, data and other online services. Payments run via stablecoins and the x402 protocol. The owner can set limits on spending and on the size of transactions. For now, users can only reserve a wallet name; full access will follow in the coming months.
  • MetaMask is giving AI agents their own crypto wallet. With the new Agent Wallet, AI systems can independently carry out on-chain actions, such as swaps, staking and trading perps. Users keep control of their own money and decide, for example, how much the agent may spend and which protocols it may use. According to MetaMask, additional safety checks are built in on top of that. The trend: AI agents are shifting more and more from advising to actually acting.

Thank you for reading!

To stay informed about the latest market developments and insights, follow our team members on X:

We appreciate your continued support and look forward to bringing you more comprehensive analysis in our next edition.

Until then!

Subscribe to Bitcoin Alpha

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe