Self Custody Is Dead. Long Live Self Custody
Key Takeaways
- •A firmware bug in Coldcard hardware wallets caused the generation of private keys with insufficient entropy, making them comparatively easy for attackers to guess.
- •Over 1,300 bitcoins have been stolen in the ongoing hack, with some estimates reaching as high as 2,000 coins.
- •An estimated 11,000 bitcoins were transferred to custodial exchanges last week as Coldcard users sought to move their funds away from the compromised device.
- •The entropy flaw remained undiscovered for years despite Coldcard's extensive security-focused design choices, including air-gapping and custom data transfer protocols.
- •Users who still control their private keys can protect their funds by migrating them to new wallets generated by unaffected devices or software applications.

The Coldcard hack delivered a damaging blow to segments of the Bitcoin industry last week, triggering a somber introspection that is now calling into question many of the practices and assumptions underlying retail-level Bitcoin security. The full consequences of this reckoning may not become visible for months.
Some observers have declared self-custody dead. Reports estimate that more than 11,000 bitcoins were moved to custodial exchanges last week as users fled one of the most popular hardware wallets in the industry. The hack, which remains ongoing and from which users can still protect themselves, has seen over 1,300 bitcoins stolen, with some estimates reaching as high as 2,000 coins. Users who still control their private keys can migrate funds to new wallets generated by unaffected devices or software, though doing so requires placing trust in an alternative tool at a moment when confidence in hardware security has been shaken.
Coinkite, and its most vocal founder NVK, held strong convictions about what it took to secure Bitcoin private keys from hackers. Their hardware wallets were airgapped to prevent malware from exfiltrating data through USB cables. They used low-resolution LED screens to avoid the complexity and attack surface of touch screens. The company developed protocols such as BBQR and integrated NFC so that information could be transferred between device and computer without a physical connection or shared SD cards. The catalogue of paranoid design choices that made Coldcards iconic is extensive.
Yet the hackers behind last week's theft of Bitcoin held in Coldcards did not employ methods reminiscent of a spy film. They exploited the one feature Coldcard should have had locked down absolutely: the generation of keys with sufficient randomness, also known as entropy — secrets that are, in other words, mathematically difficult to guess. While the devices were intended to draw on high-quality entropy sources, a firmware bug meant they did not, producing Bitcoin private keys that were comparatively easy to guess. The bug went undiscovered for years, even as the product's popularity steadily grew, until last week. The episode underscores a broader challenge in hardware security: even air-gapped, purpose-built devices can harbor implementation flaws in the most fundamental cryptographic operations, and no single layer of defense is sufficient on its own.
"Just buy the ETF bro"
The approval of U.S. spot Bitcoin ETFs in January 2024 has given retail investors a regulated, custodial avenue for Bitcoin exposure, lending new weight to the argument that institutions and fiduciaries may be better equipped to safeguard digital assets than individuals managing their own keys. Despite the losses — which wounded a cohort of some of the most committed Bitcoiners — the industry broadly maintains that Bitcoin cannot abandon self-custody without forfeiting its integrity. The rationale is rooted in the origins of the technology itself. Satoshi Nakamoto's white paper clearly envisioned Bitcoin as a solution to trusted third parties and intermediaries, making a forceful case against the trusted hierarchies of finance. The 2008 financial crisis exposed the deep systemic risks and structural flaws that legacy finance had produced — flaws that, in the view of many, were never truly resolved.
This may be unpopular, but we never escaped the 2008 financial crisis. We just shifted the pain. — Nayib Bukele (@nayibbukele) July 29, 2026
This may be unpopular, but we never escaped the 2008 financial crisis. We just shifted the pain.
Historical Precedent: Executive Order 6102
Looking further back to the birth and proliferation of the modern banking system and its fiat currency, Executive Order 6102, signed by President Franklin D. Roosevelt in 1933, resulted in the persecution and confiscation of gold from both centralized trusted third parties and ordinary citizens. Over $300,000,000 in gold was surrendered after the order threatened owners with heavy fines and jail time if they did not sell their bullion to the banks at $20.67 per ounce. More than 14 million troy ounces of gold were turned in as a result. An additional 200 million troy ounces are estimated to have been held within the American banking system at the time.
The global banking system of that era was built atop the gold standard, and the United States — the world's largest economy — held the biggest concentration of gold within its borders. The nation's abandonment of the gold standard dealt a death blow to gold as a free-market pricing mechanism for goods and services. Governments worldwide, freed from the discipline of sound money, quickly fed on and fattened from the hidden tax of inflation.
At the time of the executive order, the price of gold was artificially fixed at $20.67 per ounce. Less than a year later, it was repriced to $35 with the passage of the Gold Reserve Act in 1934 — a 69% devaluation of the dollar.
The fiat standard was thus handed to governments across the world through an alliance between the banking system and politicians, granting central banks the legal authority to create money at will. This was soon followed by World War II, funded by fiat currency, in which tens of millions of lives were sacrificed at the altar of state power.
A century later, U.S. government debt demands nearly one trillion dollars per year in interest payments alone, with total obligations approaching $40 trillion and a debt-to-GDP ratio of 123%. These are, arguably, the inevitable and predictable consequences of the gold standard's demise. The purchasing power of the dollar has collapsed over the ensuing century, even as technology has achieved parabolic efficiency gains — something only possible with money that has steadily lost value for decades. And the dollar remains the strongest of the fiat currencies.
The confiscation of gold in a rising power like the United States effectively murdered the gold standard. Yet it could not have succeeded if civilian custody of gold had been wider and more distributed. Many of the civilians who surrendered millions in gold following EO 6102 had only recently withdrawn it from their accounts during bank runs. Their identities were known; the amounts they held were tallied. If gold had been easier to move in large quantities, if private gold ownership totals had been more ambiguous, if halting the free flow of gold had not been as simple as the state knocking on bankers' doors under threat of force — perhaps the world's economies would not have been able to sustain such a vast and destructive conflict as WWII in the decade that followed.
Bitcoin Is Gold, Engineered to Survive a 6102 EO
Bitcoin presents an alternative to gold, purpose-built to learn from gold's inadequacies. It possesses superior properties for resisting and surviving confiscation. Bitcoiners envision and aspire to bring about a world that adopts Bitcoin as a global monetary standard — a future in which a large minority or even a small majority of the global economy uses Bitcoin as its primary store of value. In that scenario, Bitcoin would take gold's place and restore sound money to the economic order.
To achieve and defend the status of a global reserve currency, Bitcoin must be better than gold — and it can be, precisely because of its digital nature. The control of private keys, as daunting as it appears in the wake of the Coldcard hack, can ultimately prove far more powerful than any physical vault. Multi-signature scripts alone enable distributed storage of Bitcoin private keys, requiring a threshold of approvals before coins can be moved. This means multi-jurisdictional, multinational vaults can exist — structures capable of resisting or escaping the grasp of a large state attempting a modern-day 6102-style takeover.
The digital nature of Bitcoin also means that large amounts of value can be moved with ease, without dispatching a navy to transport gold and without constructing a trusted hierarchy of banking custodians to facilitate transfers. Civilians, equipped with tools available today and improved tools yet to come, may be able to conceal their Bitcoin holdings — as has already been demonstrated in war-torn countries like Ukraine — thereby escaping an authoritarian state's grip on public wealth.
Ultimately, a major hardware wallet manufacturer has failed the Bitcoin industry. But the fundamental qualities of money remain unchanged, and among them all — as identified by Aristotle and those who followed — Bitcoin remains king.
"Bitcoin vs gold vs fiat — One is not like the others." – @BITCOINARCHIVE
This article first appeared on Bitcoin Magazine and is written by Juan Galt.