Consider the moment when you first moved your bitcoin off an exchange. There was a ceremony to it, wasn't there? The offline laptop. The freshly printed seed phrase, handled with the reverence of a sacred text. The deliberate slowness of signing a transaction on that tiny monochrome screen with its insistence that you verify every single byte. You were not just moving money. You were making a declaration about who you trust. Not Coinbase. Not Binance. Not any corporate entity with a customer support portal and a terms-of-service agreement. Yourself β armed with a device the size of a USB stick that promised to keep your private keys in a vault that never touched the internet.
Now hold that feeling of certainty in your mind, and let me introduce a number: 1,367.
That is the number of bitcoin β worth roughly one hundred million dollars at current market prices β that Galaxy Research has identified as drained from addresses associated with Coldcard, the most respected name in Bitcoin's self-custody fundamentalist movement. Not through an exchange hack. Not through a smart contract exploit. Through the supposedly impenetrable wall that Coldcard users have built between their wealth and the world.

I want to be precise here, because precision matters when we are talking about people's life savings. Galaxy Research, the analytical arm of Mike Novogratz's Galaxy Digital, published the finding, but the details are frustratingly thin. We do not know the exact attack vector. We do not know the time window. We do not know whether this was one catastrophic event or β more likely, in my assessment β a slow, patient draining that took place over months. What we know is the number, and the brand name attached to it.
And the number should haunt every one of us who has ever told a friend, "Just get a hardware wallet. You'll be safe."
The first thing you need to understand is that the 1,367 figure is not just a statistic. It is a ledger of human decisions, each one made in good faith by people who believed they were following the best security practices their community could offer. I have spent nine years inside this culture, since the height of the ICO boom when I audited over fifty whitepapers to separate legitimate projects from scams, and I can tell you with complete confidence that Coldcard users are not the careless ones. They are, as a population, the most security-conscious segment of the entire cryptocurrency community. They are the people who read release notes. The people who verify checksums. The people who understand what a deterministic wallet is and why it matters. And if those people lost 1,367 BTC, then the rest of the ecosystem is not as safe as it believes.
The Coldcard Covenant: What We Believed About the Paranoid
To understand why this news cuts so deep, you need to understand what Coldcard represents in the Bitcoin ecosystem. It was never the most popular hardware wallet β that crown belongs to Ledger, with its sleek consumer products, and Trezor, the original open-source pioneer. Coldcard is something different. Coldcard is the wallet of the Bitcoin purist, the maximalist, the person who reads the Bitcoin whitepaper for fun and views fiat currency as a mildly offensive historical accident.
Everything about the device is engineered for paranoia. The firmware is fully open-source, which means its code can be audited by anyone. The device generates seed phrases entirely offline, never exposing them to a computer. It supports air-gapped signing via microSD card, so it never needs to connect to a computer at all. Its signature feature is the "duress PIN" β a backup PIN that, when entered, unlocks a decoy wallet while quietly wiping the real one. This is a device designed by people who genuinely believe that an attacker with a five-dollar wrench and your home address can extract anything from anyone, and who have therefore engineered their product to make even forced disclosure a potentially survivable situation.
In the community of Bitcoin self-custodians β a community I have been deeply embedded in since 2017 β Coldcard occupies an almost mythic space. It is not the wallet you buy because you want a nice accessory. It is the wallet you buy because you are making a statement about the nature of trust in a digital world. "Code is law" might be the movement's rallying cry, but for Coldcard users, the more operative sentiment is: "The code on this device is the only law I need."
Galaxy Research's report strikes at the heart of this covenant. If Coldcard addresses β specifically Coldcard addresses, identifiable as such on the public blockchain β can be systematically targeted and drained, then the entire narrative of self-custody as a superior alternative to exchange custody requires serious scrutiny. And because self-custody underpins the value proposition of the entire Bitcoin project, this is not just a product review. It is a stress test on the foundational security assumption of decentralized money.
What makes this report particularly unnerving is the source. Galaxy Research is not a Bitcoin maximalist outlet. It is the institutional research arm of a publicly traded financial firm, and it is not in the business of manufacturing panic. When Galaxy publishes an on-chain finding, it is because the data is demonstrably there. The firm's analysts are paid to be precise, because their reputation β and their parent company's balance sheet β depends on it. That is what makes the 1,367 BTC figure credible and also what makes the missing details so unsettling.
Here is where I must be honest with you about the limits of what we know. The report appeared to have provided a single aggregated number without the forensic depth that would allow the community to respond effectively. We do not know which addresses were targeted, how the funds were moved, or whether any of them were recovered. We do not know whether Coldcard has published a security advisory in response. This kind of information vacuum is precisely when fear, uncertainty, and doubt flourish. The self-custody community is left to fill the gaps with speculation at exactly the moment when it most needs clarity.
The Fingerprint Problem: How Attackers Found Their Targets
The most significant detail in the entire report, and the one that deserves far more attention than it has received, is the phrase "Coldcard addresses." This implies that the attackers were able to identify, through on-chain analysis, which addresses belonged to Coldcard users. This is not a trivial capability.
Every hardware wallet leaves a fingerprint on the blockchain. The way a wallet derives addresses, the structure of its change outputs, the specific script types it uses, the transaction fee behavior of its associated software β all of these create a pattern that a skilled chain analyst can use to cluster addresses and attribute them to a specific wallet implementation.

Coldcard, despite its privacy-conscious design, is not immune to this. Its address derivation follows BIP84 for native SegWit, and its addresses begin with the prefix "bc1q." But so do many other wallets. However, the UTXO management style, the interaction with companion software like SeedOR or Iris, and the typical spending patterns of Coldcard users β who tend to be long-term holders rather than frequent transactors β can create a distinguishing signature. When you combine this with the fact that Coldcard users often consolidate funds into fewer, larger UTXOs as they build toward a multisig threshold or a single large vault, the on-chain profile becomes increasingly recognizable.
There is also the matter of the unique "Coldcard style." The device's transaction signing process, when used via microSD, creates a specific pattern of input and output selection. The change addresses are generated with a deterministic path that, while standardized across many wallets, may have subtle behavioral telltales when combined with the device's default fee behavior. A trained analyst can look at a transaction and say, with measurable confidence, "This looks like a Coldcard user." Studies of address clustering have demonstrated that this kind of fingerprinting is not only possible, but is actively used by law enforcement and blockchain intelligence firms like Chainalysis and Elliptic.
Here is where my background in financial engineering kicks in, because this is ultimately an economics problem as much as a technical one. An attacker has a budget. They have infrastructure costs, operational security requirements, and the risk of exposure. When you are a criminal, you want maximum return per unit of risk. Attacking random addresses is noisy and inefficient. But if you can identify a cluster of addresses belonging to users of a specific hardware wallet β a wallet favored by high-net-worth bitcoiners who have carefully accumulated over years β you have just turned a scattershot heist into a precision operation.
The economics align brutally well. The Bitcoin blockchain is a public ledger, and the self-custody community has spent years celebrating this transparency. But that same transparency is a targeting database. Every large UTXO sitting in a cold address is a potential treasure chest with coordinates painted on the side. Coldcard users, by virtue of their commitment to self-custody and their tendency to accumulate and hold, are disproportionately likely to appear in the cluster of identifiable large balances. The very practices that make them good citizens of the ecosystem β long-term holding, consolidation of funds, careful security hygiene β also make them excellent targets.
This, in my judgment, is what makes the Coldcard case so different from previous hardware wallet concerns. In 2020, Ledger suffered a massive data breach that exposed customer email addresses and physical addresses, leading to a wave of physical threats and phishing attempts. That was a breach of a company's servers. This appears to be something more insidious: the systemic identification and targeting of a specific community of self-custodians through public blockchain data. I am marking this assessment as confident based on the report's language, but with the caveat that the underlying attack vector remains unpublished.
The fact that 1,367 BTC was drained strongly suggests this was not a single whale being targeted but rather a pattern of smaller drains accumulating over time. Each of those victims did everything right, by the gospel of self-custody. They bought the hardware. They verified the tamper-evident seals. They generated their seed phrase offline. They stored their backup in a fireproof safe. And still, their bitcoin is gone.
The Four Doors: Deconstructing How a Hardware Wallet Might Be Cracked
Since we do not yet have the official breach details, I want to walk through the four plausible attack vectors, because each leads to a different conclusion about what this event means. I am drawing here on my years of analyzing security incidents across the crypto ecosystem, including the fifty-plus whitepapers I audited in 2017 and the Resilience Rounds I hosted during the 2022 bear market, where we documented the failure modes of over fifty major protocols. Each door represents a different class of vulnerability, and each class requires a different response.
Door Number One: The Leaky Key
The most mundane explanation, and often the correct one, is that the private keys were never as offline as their owners believed. This can happen in several ways. A user might have typed their seed phrase into a wallet application on a computer that was not as clean as they thought. They might have taken a photo of the backup card and stored it in their phone's photo library, where a malicious app with the right permissions could access it. They might have tried to "test the backup" by importing the seed into software on a compromised machine. Or they might have fallen for a phishing page that masqueraded as the Coldcard companion wallet and asked them to "restore" a wallet, thereby capturing the entire seed.
None of these scenarios require any flaw in Coldcard hardware. They require only the ordinary fallibility of human beings who have been given a system with zero margin for error. A hardware wallet is a device for machines. The seed phrase is a secret for humans. The interface between the two β the moment when a human writes down twelve or twenty-four words, transcribes them into a backup tool, or types them into a verification utility β is where the entire security architecture is most vulnerable.
Through my TrustStack workshops in 2020, I taught over two thousand people how to navigate DeFi and self-custody. I cannot tell you how many times I saw the same pattern: a sophisticated person, capable of analyzing smart contract risks and arbitrage strategies, making a basic operational security error because nobody had ever explained the human side of the security model. We treat hardware wallets as if they were simply "plug in and be safe" devices, but they are actually protocols for human behavior. And protocols for human behavior fail when humans are involved.
The attack vector would look like this. An attacker identifies a Coldcard user through on-chain fingerprinting. They then send a carefully crafted email that appears to come from Coinkite, the manufacturer, warning about a "critical firmware vulnerability" and directing the user to a malicious download page. The page looks identical to the official one. The firmware image appears legitimate. But when the user connects their Coldcard to install the "update," the malware on their computer intercepts the communication and exfiltrates the seed phrase or signs unauthorized transactions. The user thinks they have just updated their security. In reality, they have just handed the vault key to the attacker.
This is not a cold-air-gapped theft. It is a social engineering operation that preys on the very thing that Coldcard users are most proud of: their vigilance about security. The attacker does not need to break the cryptography. They only need to convince the user that a normal security practice β checking for updates, verifying versions β is necessary and safe.
Door Number Two: The Tampered Package
The supply chain attack is the scenario that keeps security professionals awake at night. If an attacker can intercept a Coldcard during the shipping process β reassembling the device with a malicious chip, installing firmware that exfiltrates the seed phrase during the initial setup, or simply recording the generated private key before the user ever receives it β then the entire hardware security model collapses.
Coldcard has mitigations for this. The factory seals are tamper-evident and laser-etched with unique codes. The device's bootloader verifies the firmware signature before allowing any update. The design uses a "secure element" to store secrets, and the board can be visually inspected for signs of modification. The company publishes detailed guides on how to verify a device's authenticity, down to the microscopic engravings on the microcontroller.
But these mitigations are not absolute. A well-funded adversary with access to the supply chain can, in theory, defeat most of them, particularly if they are willing to invest in custom silicon and advanced hardware trojans. The attack would begin before the user ever holds the device. A maliciously modified unit would look identical, seal perfectly, and pass all visual inspection procedures. The malicious firmware would be indistinguishable from genuine unless a user performs a deep cryptographic verification that most consumers will never attempt.
If this is the attack vector, then the implications extend far beyond Coldcard. Every hardware wallet, from Ledger to Trezor to BitBox, relies on the integrity of a global supply chain that spans multiple countries, multiple contractors, and an almost infinite number of potential interception points. The response to a supply chain attack cannot be "switch to a different brand." It must be a fundamental rethinking of how hardware wallets are manufactured, distributed, and verified. The lesson would be that no hardware wallet can be trusted on receipt, and that users must either construct their own devices from verified components or rely on additional layers of verification that render the hardware question academic.
I am marking this vector as speculative, because there is no published evidence that confirmed it, and attributing a supply chain compromise without proof would be deeply irresponsible. But the possibility must be on the table, because the cost of dismissing it entirely is far higher than the cost of considering it.
Door Number Three: The Physical Proximity Problem
Side-channel attacks β extracting private keys through the physical measurement of a device's electromagnetic emissions, power consumption, or even its internal temperature β have been demonstrated in academic laboratories against various hardware wallets. In 2020, researchers from the University of Florida and the University of Texas demonstrated a side-channel attack on a popular hardware wallet that recovered the seed phrase from the device's power consumption during the signing process. Similar attacks have been shown against Trezor and other devices, usually requiring physical access, specialized equipment, and custom analysis software.
These attacks are real, but they require physical access to the device, sophisticated equipment, and considerable technical expertise. The attacker must either steal the device briefly and return it, or maintain access without the user noticing. That is a high-risk operation for a criminal because physical access to a user's home is already a serious crime, and the window for extracting the key is often very narrow.
While plausible for a nation-state adversary or a highly organized criminal group targeting a specific high-value individual, side-channel attacks are an inefficient mechanism for draining 1,367 BTC across what appears to be multiple addresses. Mobilizing the equipment and expertise to perform a side-channel attack on dozens of victims would be prohibitively expensive, and each extraction would risk detection. I am putting this vector near the bottom of the probability list. Not zero, because this is an adversary-in-the-loop scenario, but substantially lower than the social-engineering and supply-chain possibilities.
Door Number Four: The Fingerprint and the Faithful
This is where I believe the truth lies, and it is the most troubling possibility. The attackers did not crack Coldcard's cryptography. They did not intercept a single package. They identified a population of Coldcard users through on-chain fingerprinting, and then they went after the humans in that population. They used phishing attacks calibrated for a specific user's holdings. They deployed social engineering that spoke the language of Bitcoin self-custody. They stood up rental phishing sites that offered a "security update" download for Coldcard's companion software. They created malicious versions of legitimate tools, delivered through compromised update channels or convincing clones, and they engineered their delivery with the patience of a dedicated adversary who knows that the target is waiting for the next chance to verify their security.
The beauty of this attack, from the criminal's perspective, is that it does not require any vulnerability in Coldcard at all. It requires only a target list, and the tools to build that list are freely available to anyone with basic blockchain analytics skills. If you can identify a Coldcard user with a meaningful balance, you can direct your effort at the softest part of their security system: the human being who owns the device. The device could have foolproof cryptography. The human being still has to trust something. The attack is on the trust, not the device.
The reason I rank this vector most likely is not because I have inside information, but because it is the only vector that scales naturally to the observed pattern. A single compromised package would yield one victim. A side-channel operation would yield a handful of victims, at enormous effort. But a well-crafted phishing campaign, targeted at a list of addresses identified through fingerprinting, can be repeated indefinitely, across hundreds of victims, with a consistent and efficient cost structure. The 1,367 BTC figure is consistent with an operation that has been running for months, honing its message, refining its targeting, and quietly draining the accounts of people who thought they had retired from the risk surface.
The fingerprinting itself is the strategic weapon. In traditional finance, even if an attacker knows that you have a bank account at a certain institution, they cannot read your balance directly from public records. In Bitcoin, the entire ledger is available, and every user's balance is resolutely knowable. The combination of on-chain transparency and human vulnerability forms the perfect conditions for a predatory market.
What This Does and Does Not Prove
Let me be very clear about something, because it matters for how we calibrate our response to this event. This attack does not prove that Coldcard's cryptographic implementation is broken. There is, as of now, no evidence that BIP39 seed generation, BIP32 hierarchical derivation, or the device's signing algorithms have been compromised. I have seen no reports of a firmware zero-day that allows remote extraction of private keys. If such a vulnerability existed and were being exploited at this scale, we would expect to see a far more rapid and dramatic series of disclosures.
What this attack does suggest β and here I am speaking with medium confidence based on the report's language β is that the security model of "buy a hardware wallet and you are safe" is incomplete. The hardware wallet protects your keys from a compromised computer and from internet-borne attacks. It does not protect you from a compromised you, from a compromised supply chain, or from an attacker who knows you hold a Coldcard and can build their entire operation around separating you from your seed phrase.
This is a distinction that most security coverage fails to make, and the consequences of that failure are devastating. When a story like this breaks, the typical response from well-meaning Bitcoiners is to reassure each other: "It was probably user error. Coldcard is fine." And indeed, it might have been user error, in the same way that a bank robbery committed by an employee who knows the vault combination is "user error." But that framing lets the industry off the hook.
The security model that Coldcard and every other hardware wallet sells is not just the device. It is the entirety of the system in which the device is used β including the human operating it, the software surrounding it, and the supply chain that delivers it. When we tell people that a hardware wallet makes them "financially sovereign," we are making a much larger claim than the device can possibly deliver.
The On-Chain Forensics: What the Blockchain Tells Us
If Galaxy Research has released a partial finding, there is likely more evidence on the public ledger that a capable analyst can piece together. The drain of 1,367 BTC did not happen in a single transaction. It would have required a series of outputs, each with its own signature, change, and routing. Those transactions are still sitting in the blockchain for anyone to examine.
A careful analyst would look for the following patterns. First, the destination addresses: are they clustered into a single wallet that consolidates the stolen funds, or are they scattered into hundreds of distinct destinations? If consolidation has occurred, the case begins to resemble a protocol theft rather than scattered consumer fraud. Second, the time distribution: if the thefts occurred in a short, coordinated burst, it suggests a compromised batch or an automated exploit. If they occurred over many months without a distinct cluster, it supports the patient-social-engineering theory. Third, the fee structures and transaction timings can reveal the operational sophistication of the attacker β a sophisticated actor uses batch transactions and privacy-enhanced routing, while a lower-tier thief may reveal patterns that enable tracking.
Blockchain intelligence firms like Chainalysis and Elliptic have decades of combined experience in tracing stolen funds. If Galaxy Research has identified the thefts at all, those firms are likely already building the full picture. The question is not whether the analysis is possible but whether it will be made public. In the past, such findings have often been held for law enforcement purposes until the trail goes cold. If we are lucky, a detailed post-mortem will eventually emerge. But the community should not hold its breath. The most likely outcome is that the findings remain in the hands of regulators and investigators, and public knowledge stays at the level of the 1,367 figure.
The Economics of Scale: Why One Hundred Million Is Both a Lot and a Little
Before we descend into either panic or complacency, let me put the scale of this in context. 1,367 BTC, even at a conservative price of $75,000 per coin, is approximately 102.5 million dollars. That is a substantial amount of money by any human standard. It is the lifetime savings of dozens, perhaps hundreds, of individuals. But in the context of the broader Bitcoin market, it is a rounding error.
Bitcoin's daily spot trading volume consistently exceeds twenty billion dollars across global exchanges. The market capitalization of bitcoin is over one and a half trillion dollars. A one hundred million dollar drain, while catastrophic for the victims, represents roughly 0.0067% of bitcoin's total market capitalization. The price barely moved on the news, which is exactly what I would expect. This is not a market-moving event. It is a trust-moving event.
And trust, not price, is the variable that matters most in this industry. I have seen the numbers play out again and again over my years in this space, from the Mt. Gox collapse in 2014 to the FTX implosion in 2022, and the pattern is consistent: price recovers far faster than trust. The reason regulators keep circling the crypto industry with proposals that would gut self-custody is not because they care about price. It is because they see stories like this and ask a very reasonable question: "If people cannot protect their own assets with supposedly professional-grade security tools, what exactly is the argument against mandated custody?"
The regulatory risk hiding inside this story is arguably more dangerous to the ecosystem than the direct loss of the bitcoin itself. Every high-profile self-custody failure becomes ammunition for the argument that ordinary people cannot be trusted to manage their own keys. The Travel Rule, increased KYC requirements for hardware wallet purchases, and proposals requiring cold storage services to register as money transmitters all become easier to sell when the response to "not your keys, not your coins" is "and still, 1,367 BTC disappeared."
Be careful what you wish for when you celebrate the regulatory arbitrage of self-custody. The freedom that Bitcoin offers is also a freedom that can be lost in the name of consumer protection. And a well-publicized hardware wallet theft is precisely the kind of story that consumer-protection advocates will use to justify restrictions.
A Culture Problem Disguised as a Technology Problem
Here is where I must contradict the dominant conversation around this event. The overwhelming tendency on crypto Twitter, when such news breaks, is to treat it as a purely technical problem. Someone will find the specific exploit. A patch will be issued. A firmware update will be distributed. The story will recede, and the industry will move on, slightly wiser but fundamentally unchanged.
But this is not primarily a technical problem. It is a cultural problem that has manifested as a technical one. Culture eats blockchain for breakfast, as I have learned through years of watching brilliant protocols fail not because the code was flawed but because the human systems around them could not sustain the burden.
The culture of self-custody has developed a mythology that is both its greatest strength and its most profound weakness. The mythology says: if you hold your own keys, you are sovereign. You have escaped the surveillance state, the fractional-reserve bankers, and the corporate custodians. You are, in the words of the movement's most passionate evangelists, "your own bank." This mythology has driven the adoption of hardware wallets among politically conscious bitcoiners, and it has genuine power. For many people, it is the first time they have truly owned an asset in a way that no government can seize and no intermediary can deplete.
But mythologies have blind spots, and the blind spot here is that sovereignty is a team sport. The self-custody mythology emphasizes individual responsibility to the point of isolating people from the communal structures that could actually protect them. It tells people to be their own bank, but banks have compliance departments, fraud detection systems, insurance, and armies of lawyers. When you are your own bank, you are also your own compliance department, your own fraud detective, your own insurance policy, and your own legal team. And when the bad guys come β sophisticated, patient, well-funded bad guys who have studied your species for years β you are also your own last line of defense.
In my TrustStack workshops, I saw the same question emerge every single time: "How do I protect my assets without becoming a full-time security engineer?" The honest answer is that you cannot, not entirely. You can delegate portions of that responsibility β to the hardware wallet manufacturer, to a multisig service, to a trusted network of peers. But each delegation is itself a trust decision, and we have created a culture that treats delegation as betrayal and self-custody as the only pure path.
This is not sustainable. And the 1,367 BTC drain is the price of that unsustainability.
There is also the question of blame. Every security incident of this magnitude produces a predictable blame cascade. The victim is blamed for being careless. The manufacturer is blamed for a flawed product. The concept of self-custody itself is blamed for being too complex for ordinary users. In the end, the only entity that escapes blame is the attacker, which is precisely the wrong outcome. We should not be parsing who "deserved" the theft any more than we should be asking whether a burglar who chose a house with a weak lock had a point. The only relevant fact is that a criminal act occurred, and the community's job is to make the next attack harder, not to litigate victim behavior.
The Multisig Reckoning: What Security Professionals Do with Their Own Money
It is a revealing exercise to ask what security professionals β the people who run the infrastructure that projects like this depend on β actually do with their own bitcoin. I have asked this question in private conversations for years, informally and through my research, and the answers are remarkably consistent. They almost never rely on a single Coldcard, or a single Trezor, or a single Ledger. They use multisignature wallets with keys distributed across multiple devices, multiple vendors, and multiple physical locations.
This is not because they have access to secret information about vulnerabilities in any specific device. It is because they understand a fundamental principle of security architecture, a principle that is almost entirely absent from mainstream self-custody advice.
Single-device custody, whether that device is a hardware wallet, a mobile phone, or a piece of paper, is a single point of failure. Not necessarily a single point of technological failure, but a single point of human, logistical, and procedural failure. If your security model depends on one device and one seed phrase, then you have effectively placed the entirety of your wealth behind one door. The door might be very strong. It might be made of the best steel known to humanity, protected by the most sophisticated lock ever designed. But it is still one door.
Multisignature setups β where a transaction requires approval from multiple independently controlled keys β change this architecture. An attacker must now compromise not one device but several, not one human decision-maker but several, not one physical location but several. The security moves from the realm of a single strong fortress to the realm of a network of interdependent outposts. This is not a guarantee of absolute safety. A sufficiently determined adversary can eventually compromise anything. But it changes the economics of attack in ways that strongly disfavor the criminal.
The tragedy is that this knowledge is not secret. It is openly discussed in the technical communities, in the Bitcoin developer forums, and in the security conferences that have been part of my world since the 2022 crash, when I studied the failure modes of fifty major protocols and published The Ethics of Failure. And yet, the mainstream narrative continues to be: "Buy a hardware wallet. Sleep soundly." We are doing people a disservice by oversimplifying a deeply complex security landscape into a consumer product purchase.
The cost of multisig is real, of course. It is more expensive. It requires more education. It introduces new failure modes, such as the risk of losing one of your keys and being locked out. But the cost of a single point of failure has now been measured in hundreds of millions of dollars. The insurance premium of a multisig setup has never been cheaper.
The Collaboration Imperative: Unchained, Casa, and the New Architecture of Trust
There is a world already being built that understands all of this. Firms like Unchained and Casa have spent years advocating for a hybrid approach: collaborative custody, where a user's bitcoin is held in a multisignature wallet with keys distributed between the user and a professional service provider, sometimes with a third key held in reserve for inheritance planning or loss recovery.
I have been skeptical of these services for years. My instinct, shaped by the foundational values of the decentralization movement, was to resist any reintroduction of a trusted third party into a system designed to eliminate them. But the events summarized in this report have been a powerful teacher. When I think about the seventy-year-old retiree who must pass bitcoin to her children, the founder who must manage a treasury while traveling to high-risk jurisdictions, or even the sophisticated twenty-five-year-old who has just inherited a significant balance and does not yet have the operational security training to protect it β I have to admit that the pure self-custody model, as currently practiced, is not serving these people.
Code binds, but people break or build. I have watched the crypto community build extraordinary technical systems and then, with breathtaking naivety, place those systems in the hands of ordinary people without ever building the human infrastructure to support them. The result is a predictable cycle of catastrophic losses, each of which provides another argument for the regulators who would rather see everyone's keys in a bank vault.
The Coldcard drain, if nothing else, should force a serious conversation about this cycle. It should force the self-custody maximalists to acknowledge that hardware wallets are not a panacea. It should force the services like Unchained and Casa to articulate their value proposition with more honesty about their own trade-offs. And it should force all of us β myself included β to stop pretending that there is a frictionless path from "buy Bitcoin" to "be your own bank."
What the Industry Should Do Now, and What You Should Do Now
I want to close the analytical portion of this piece with concrete recommendations, because I have learned that fear without direction is just a more sophisticated form of paralysis.
For the industry, the first priority must be disclosure and transparency. Coldcard's parent company, Coinkite, has a strong reputation for security communication, and it needs to use that reputation now. The community needs to know: which attack vector was involved? Was any Coldcard hardware or firmware actually compromised? Were any companion software tools implicated? If the answer is that this was a sophisticated phishing campaign targeting identified Coldcard users, the industry needs to say so clearly and provide actionable guidance for how users can harden their operations.
The second priority must be education. Hardware wallet manufacturers and self-custody advocates have been collectively negligent in teaching users about the human layer of security. We teach people about seed phrases and air-gapped signing, but we do not teach them about spear phishing, supply chain verification, or the dangers of operational security fatigue. Every hardware wallet box should come with education that treats the user as a trusted system component that needs maintenance, not just as a buyer of a product.
The third priority must be advocacy for a security posture that is genuinely resilient. That means promoting multisig as the standard for meaningful balances. It means encouraging the use of multiple wallets from multiple vendors, so that no single device or single company's supply chain represents a catastrophic single point of failure. And it means destigmatizing collaborative custody for users who are not prepared to take on the full burden of self-custody.
For individuals reading this, the recommendations are more personal. If you are holding a significant balance β and by "significant," I mean an amount whose loss would materially change your life β you should be using multisig. If you are not technically comfortable with multisig, you should be using a collaborative custody service. You should not be holding your entire net worth behind a single PIN and a single seed phrase. I say this not to frighten you but to release you from the mythology that individual sovereign security is a binary state: either you are a perfect self-custodian or you are a fool.
The freedom that Bitcoin offers is not freedom from responsibility. It is freedom to design your own risk architecture. And the first design decision you should make is one of humility.
Every four years, the Bitcoin ecosystem has a halving that reminds us that the supply is capped and the value proposition is designed for the long term. The 1,367 BTC drain is an arbitrary event that has no halving schedule, but it has the same effect on the trust that underpins the network. Every value transfer in Bitcoin depends on trust in the cryptographic assumptions that secure the chain, and every individual adoption of Bitcoin depends on trust in the tools that secure the keys. When that trust is compromised, the network is weaker even if the code is unchanged.
This is why the current incident is not merely a product recall story. It has reached deep into the psyche of the community to ask whether self-custody β the ideal on which the entire project is built β can actually be achieved at human scale. The answer, I believe, is yes, but only with a significantly more honest and mature approach to the human architecture around the technology.
The Uncomfortable Question
Let me end with a question that I have been sitting with since the Galaxy Research report crossed my desk. We have built an entire movement around the idea that individual self-custody is both a right and a responsibility. We tell people, with complete sincerity, that they must not trust any intermediary, that the technology has finally made it possible for the individual to be completely sovereign over their own assets. And then, when people follow this advice and their assets are stolen by sophisticated criminals who identify them through public blockchain analysis and defeat them through social engineering, what do we say?
Do we blame the victim for not being paranoid enough? Do we blame the hardware manufacturer for not being perfect enough? Do we blame the very concept of self-custody for promising more than the human condition can deliver?
The answer is yes. We should blame all three, in equal measure. We should demand that manufacturers take responsibility for the full lifecycle of their products, including the human ecosystem around those products. We should demand that the self-custody community mature beyond a culture of blame and embrace a culture of collective learning. And we should demand that the industry stop selling security as a product and start treating it as a practice.
Trust is the only currency that matters, and right now, the self-custody ecosystem is spending it recklessly. Every time a story like this breaks, the trust account diminishes. The victims lose their savings. The larger community loses a little bit of its confidence in the fundamental premise of holding one's own keys. And the regulators, watching from the seats they have reserved for themselves at the table of consequence, see their arguments validated.
We are building the future, together. That sentence has been the first principle of my work in this industry since I distributed my fifteen-thousand-word manifesto, The Human Layer of Blockchain, to five thousand early adopters in 2017. But building the future together means acknowledging that the future of self-custody is not a single device in a sock drawer. It is a resilient architecture of overlapping protections, honest conversations about trade-offs, and a community that holds one another up rather than waiting for the next headline to reveal whose fortress had a window.
The window has been found. The question is whether we will have the courage to look through it, see the landscape clearly, and begin building differently. The number 1,367 is a tuition payment. We cannot afford to waste it.