Joe Burnett, MSBA|Aug 01, 2026 12:50
This was possibly one of the worst weeks in the history of Bitcoin.
Many people believed they had done virtually everything right. They bought a respected hardware wallet, generated their seed offline, followed established best practices, and still lost significant amounts of Bitcoin because of a vulnerability affecting @COLDCARDwallet seeds generated on or after March 2021.
The vulnerability went undetected for 5+ years.
I think this will permanently change confidence in self-custody.
Over the years, I experimented with many different hardware wallets. I intuitively never trusted any one of them enough to store a serious amount of Bitcoin.
These are all startups manufacturing small $200 devices that people use to secure life-changing amounts of wealth. Most users have never audited the code. I have never audited the code in sufficient detail. I do not have the time or technical expertise to independently verify every component of a device, its firmware, its entropy generation, and its supply chain.
There are also many potential points of failure.
The software could contain an accidental bug. An insider could intentionally introduce a vulnerability. A supplier could compromise part of the device. A firmware update could create an issue. The random-number generator could fail in a way that almost nobody notices.
Everyone purchasing the device is signaling that they may eventually store significant wealth on it. That makes the entire hardware and software supply chain an extremely attractive target.
Something like this always felt inevitable.
I have always believed that attempting to store a meaningful amount of Bitcoin on your own requires multi-vendor multisig, with keys generated independently using different hardware and different software. The keys should also be stored in different physical locations.
One device should be able to be completely compromised without causing you to lose your Bitcoin.
Even with that architecture, I have always felt some level of uncertainty. I have also owned MSTR, ASST, GBTC, and IBIT in significant size. Self-custody is an incredible tool, but its risks were clearly greater than many people understood.
I believe self-custody will survive, but it has permanently changed.
The current wave of Bitcoin adoption is happening through ETFs, treasury companies, and institutional custodians. It is largely coming from people who have no interest in becoming experts in private-key generation, hardware security, firmware, backups, inheritance planning, and physical storage.
That makes complete sense.
Securely holding your own keys is so complicated that even the experts building these devices failed to prevent this vulnerability, and the broader technical community failed to detect it for 5+ years.
Free markets naturally produce specialization. Bitcoin remains an incredibly valuable tool. Most people who lack deep expertise in securely generating and protecting private keys will outsource that responsibility to people and institutions that specialize in it.
For someone who wants direct sovereignty over a significant portion of their Bitcoin, the standard should be multi-vendor multisig. If you are uncomfortable with that, use an institutional-grade custodian.
A large amount of Bitcoin secured by one key generated by one hardware wallet carries far too much concentrated risk.
I think that is where Bitcoin custody is heading.
The obvious concern is that institutional custody could eventually concentrate too much Bitcoin in the hands of large firms. That would create censorship, seizure, and confiscation risks.
However, Bitcoin’s portability and settlement properties provide the critical check and balance.
Anyone can spin up a wallet and demand that their Bitcoin be sent to them. Settlement can happen globally, quickly, and cheaply. A person can move from counterparty exposure to direct ownership in a matter of minutes.
Gold never had that property.
Most people did not hold physical gold. Their gold sat in a vault somewhere. You could not rapidly move the gold from New York to Tokyo. You could not easily demand immediate global settlement into an asset you could personally verify and hold.
Gold’s lack of portability and the inability to quickly demand physical settlement helped cause it to fail as money.
Bitcoin solved that problem.
You can leave a custodian, acquire actual Bitcoin, spin up a wallet, demand settlement, and move your wealth into cold storage. You always retain the ability to remove counterparty risk.
That optionality is what matters.
Bitcoin gives every person the ability to hold their own wealth. It gives every person the ability to exit a custodian. It gives every person the ability to demand final settlement into an asset they can personally control.
That ability to hold your own keys is what keeps custodians, governments, and financial institutions accountable.
It is one of the fundamental properties that makes Bitcoin work.
I think we may look back on this moment as one of the darkest periods in Bitcoin’s history. Coins have been lost. Confidence has been shaken. Many of the people with the highest conviction in Bitcoin have been forced to reconsider assumptions they once viewed as guaranteed.
I also would not be terribly surprised if this marked a turning point.
As long as Bitcoin itself remains secure, the failure of one custody method does not invalidate the underlying monetary system. It forces the market to develop better tools, stronger standards, and more resilient custody architectures.
It is often darkest before the dawn.
This week may ultimately mark the end of one era of Bitcoin custody and the beginning of the next major wave of Bitcoin adoption.(Joe Burnett, MSBA)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink