After Coldcard: A New Era for Self-Custody 

The events of recent days should – and, in our view, will – serve as a wake-up call for the wider Bitcoin community.

The successful exploitation of a large number of Coldcard devices as a result of weak entropy generation must lead us to fundamentally reconsider how we approach self-custody from here on out.

The incident has undoubtedly shaken many people who previously held their Bitcoin in self-custody and may now – understandably – be considering a return to third-party custody. At the same time, it has made self-custody appear even more intimidating to those who have not yet taken that step.

And honestly, one can hardly blame newcomers for being scared away when even many long-standing, active members of the Bitcoin community – with far greater than average technical knowledge and familiarity with the ecosystem – failed to anticipate and prepare for a disaster of this kind.

Yes, warning voices were there early on. We sincerely hope that their concerns will receive considerably more attention from here on out.

With that said, giving up on self-custody is the wrong response.

The answer must be to make secure self-custody more robust, more understandable and more accessible to a wider range of users.

First of all, centralized custodians have a considerably worse track record – one that stretches across essentially the entire history of Bitcoin. Exchanges and other custodial platforms have repeatedly been hacked, collapsed, frozen customer withdrawals, mismanaged customer assets or simply disappeared with the funds entrusted to them.

Concentrating large amounts of Bitcoin among a small number of custodians creates systemic risk and weakens the foundations of both the asset and the network itself. Nor does centralized custody have a better security record than self-custody – regardless of what those working for custodial service providers may have a strong financial incentive to tell you.

The type of guy who wants to protect you from holding your own money: Celsius founder Alex Mashinsky urged customers to entrust their crypto to his platform. In 2025, he was sentenced to 12 years for fraud
The type of guy who wants to protect you from holding your own money: Celsius founder Alex Mashinsky urged customers to entrust their crypto to his platform. In 2025, he was sentenced to 12 years for fraud

Second, holding “paper Bitcoin” rather than the real thing undermines the health of the wider system – and, with it, Bitcoin’s long-term value proposition.

If you are not comfortable holding Bitcoin in self-custody, there is ultimately little special about holding it in a brokerage account. You might as well hold Amazon, Microsoft or a gold ETF.

By holding only a paper claim, you outsource virtually all of the responsibility – and all of the work required to keep Bitcoin decentralized – to other people. At the same time, you direct fees and influence towards large traditional financial institutions whose incentives are to centralize custody and, ultimately, neuter the very properties that make Bitcoin valuable.

There is nothing inherently wrong with holding a conventional TradFi portfolio if it better suits your risk appetite and you understand its limitations. But you should not confuse purchasing a Bitcoin ETF with strengthening the Bitcoin ecosystem.

From the perspective of decentralization, you may be doing more good by not buying a Bitcoin ETF at all. Your money merely helps large custodial institutions bring even more Bitcoin under centralized control. If you want to support Bitcoin while keeping your own portfolio firmly within TradFi, allocate that capital to other traditional investments instead (and no – Bitcoin treasury companies are not the answer either…).

Yes, this incident was a devastating blow.

No, we must not give up on the mission of self-custody. If our response to its difficulties is simply to “trust the experts,” the entire system will gradually weaken and ultimately fail.

BitcoinVN Shop

We already know what some people will say:

“You sell hardware wallets in your shop – of course you want to keep promoting them!”

No.

BitcoinVN Shop has never turned a profit throughout its nine-year history. 

Keeping it operational has only been possible through subsidies and credit lines from our parent entity, BitcoinVN – a centralized exchange provider – which have accumulated to a mid-five-figure US-dollar amount over the years.

It is not a profitable business.

Yes, we charge a margin on every item sold. But those margins have – so far – never covered the losses and write-offs accumulated over the years – from products damaged in transit and warranty cases absorbed at our own expense to the many expected and unexpected logistical problems we have had to resolve.

And that does not yet account for our ordinary operating expenses: staff, logistics, inventory management, warehousing, accounting, deliveries, maintaining our online presence and everything else required to keep the service running.

We did not begin supplying hardware wallets to the Vietnamese market because we saw an easy opportunity to make money. Of course, we would eventually like BitcoinVN Shop to become profitable; otherwise, the operation will remain unsustainable and it simply cannot depend on subsidies forever.

But the original reason for establishing BitcoinVN Shop was very different.

When BitcoinVN – then known as “Bitcoin Vietnam” – launched Vietnam’s first Bitcoin exchange in early 2014, we deliberately chose a non-custodial model. We did not want to hold customers’ Bitcoin or assume responsibility for safeguarding it on their behalf.

Market realities soon caught up with us.

Immediate withdrawals worked well for people who knew what they were doing. 

For less experienced customers, however, they resulted in countless losses. Some sent their coins to dubious wallets, unreliable exchanges or outright scams. Others withdrew to their own wallets, only to lose access later because they had not properly understood self-custody or securely backed up their seed phrases.

We therefore began allowing a limited group of customers to keep their coins on the platform temporarily, while continually hammering home the importance of learning about self-custody and ultimately taking control of their own Bitcoin.

BitcoinVN Shop grew directly out of that experience. Our customers needed reliable access to self-custody tools, yet importing hardware wallets into Vietnam was – and remains – a cumbersome process.

Every additional point of friction means fewer people take the step into self-custody.

We therefore took it upon ourselves to handle the importation and domestic distribution of hardware wallets, making it as easy as possible for users to obtain the tools they need to get started.

Importing, storing and distributing hardware wallets is not a simple, low-overhead undertaking. It comes with all the constraints and complications of operating in the physical world with physical inventory – particularly when dealing with security-sensitive products for which the integrity of the supply chain is essential.

There are many easier ways to make money – or, in this case, to make any money at all. 

If we had not already been operating BitcoinVN Exchange and witnessing these problems firsthand, we would never have bothered becoming a hardware-wallet reseller.

So why did we bother?

There were two main reasons: one relatively self-interested, the other rooted in what we believe to be our responsibility towards the wider network and the long-term success of Bitcoin.

First, we do not want to be responsible for large amounts of other people’s Bitcoin. We do not want our customers to treat us as their bank.

That responsibility is enormous. A single mistake can wipe out another family’s life savings, alter its course for generations – or, in the most extreme cases, extinguish that family line entirely. 

And because we believe in the concept of karma – however you choose to name it – this is neither a risk nor a burden we are willing to carry on our shoulders. 

To the extent that we offer any custodial services, our communications are therefore filled with warnings and disclaimers not to entrust us – or any other third party – with an amount of money you cannot afford to lose.

The more assets we hold on behalf of customers, the greater the risk becomes. Accumulating more Bitcoin under our custody would make both the company and the people working for it considerably more attractive targets, because a successful attack would promise a much larger payoff.

Keeping the potential loot available to an attacker as small as possible is therefore a core part of our defensive posture. Making it easy for customers to withdraw and take control of their own Bitcoin is firmly in our own interest.

Then there is our responsibility towards the wider network.

Bitcoin can only succeed as an asset, a network and a project if a sufficiently large number of people hold their coins in self-custody.

The more Bitcoin custody becomes concentrated among a small number of institutions, the weaker the system becomes. The more widely control of the keys is distributed, the more resilient it is.

Yes, this also means that in an emergency there is no central operator who can simply force through an “easy upgrade,” reverse transactions or reshape the rules – as we have seen happen countless times with more centralized networks.

If you dislike a non-interventionist network that simply keeps chugging along regardless of anyone’s individual preferences, Bitcoin may not be for you.

But that is precisely the point.

The inability of centralized actors to bend the network to their will – an authority that can, and historically has, been abused to manipulate monetary systems for their own benefit – is what gives Bitcoin its value and makes it such a compelling alternative in the first place.

Where We Failed: Listing Coldcard

We must accept our share of responsibility here.

Several years ago, we added Coldcard devices to our product range. In doing so, we exposed customers who purchased those devices – and relied exclusively on their compromised random-number generator – to considerably weaker security than they reasonably expected to receive.

To be entirely clear:

We were not paid any “marketing dollars” or similar financial incentives – we decided to list the devices specifically because customers kept inquiring about them as they wanted a more Bitcoin-focused alternative to the more mainstream hardware wallet devices.

In all of this time, we did not make any profit from selling Coldcard devices. Our books show that supplying them to the Vietnamese market has already cost us several thousand US dollars in accumulated losses.

We must now write off a further US$10,000 or more in remaining inventory, as those devices are no longer suitable for sale to the public.

Continuing to sell devices with an RNG known to be weak – and thereby exposing customers to the risk of losing their funds – would be indefensible. We therefore stopped all sales and removed the devices from our shop as soon as we learned of the issue.

So how did we originally vet Coldcard?

Our assessment did not involve conducting an independent audit of the device’s hardware and firmware. Instead, one of the principal signals in our vetting process is whether leading specialist multisig software providers choose to integrate a device into their software stacks.

These teams have dedicated engineering talent, resources and technical focus, allowing them to examine the credibility and soundness of hardware-wallet devices far more closely than a small retailer reasonably could. Their integration decisions therefore provide us with an important – but never conclusive – signal when evaluating which devices to offer.

In this case, those signals failed to reveal the underlying weakness. The ultimate decision to list Coldcard remained ours, and we accept responsibility for that decision. 

At the same time, it is not realistic to expect a small hardware-wallet retailer to employ its own team of security engineers and independently audit every line of firmware running on every device it sells – particularly when the weakness remained undetected by the broader ecosystem for more than half a decade.

Various unknown Hardware-wallet manufacturers regularly approach us seeking a listing in our shop. Because we cannot independently audit each device from first principles, we rely on the assessments of technical teams and security researchers within the ecosystem whom we trust.

If a device earns their confidence, we may consider listing it. But that should not be mistaken for an independent security certification by BitcoinVN Shop. We do not possess the resources or technical capacity to provide one.

Future of self-custody

Pay close attention in the coming days and weeks to the people who use this incident to promote custodial solutions.

They are bad actors and should be marked as such – they have no interest in the success of Bitcoin.

We are already seeing a ramping-up of fearmongering on social media à la “Should have held it on an exchange, bro,” accompanied by flawed statistics about coins supposedly lost in self-custody – often counting Satoshi’s stack among them, which massively skews the numbers in what appears to be a deliberate fashion.

Jaffer Ali – rest in peace – wrote about this eternal dynamic many years ago.

Within the past month alone, we have once again seen several offshore CEX failures, accounting for tens of millions of dollars in depositor funds vanishing. Look into the stories of BitMart and AscendEX for a start.

Self-custody remains absolutely essential for Bitcoin to work – and to work out.

Despite this setback – from which we must all learn and draw our lessons – it remains the only way forward.

Solutions to the specific issue caused by Coldcard’s weak RNG already exist – and plenty of people, including those who used a Coldcard as part of their self-custody setup, were saved by them.

Furthermore, using a hardware wallet at all – despite the Coldcard fiasco – is already a step that protects users against 99% of the common threats that lead to the loss of digital assets.

Our team continues to document the evolving threat landscape here, and in the vast majority of cases, even a simple single-signature hardware wallet would have prevented the loss – whether caused by keeping signing capabilities on an internet-connected device or by outsourcing custody to a supposedly trusted third party.

A hardware wallet can prevent the vast majority of these threats from succeeding – and while a single-signature setup is, due to its inherent single-point-of-failure properties, not recommended for large savings, we must also be clear that, in the grand scheme of things, the Coldcard incident is a freak accident rather than the rule when it comes to how people lose their crypto savings. 

The situation is similar to the highly publicized plane crash that dominates media coverage – not the far more common fatal road accidents that, in purely statistical terms, devastate far more lives and families. 

Yes, if you are a Bitcoin OGand/or cypherpunk with a decade of experience, then sure – building your own custody setup using repurposed old laptops dedicated exclusively to running Linux and Bitcoin Core may be considerably safer.

For someone with your experience and capabilities, an off-the-shelf hardware wallet is likely unnecessary; your own setup is both cheaper and more secure – provided you know exactly what you are doing, which is the prerequisite here.

But this ignores the hurdles and friction such setups impose on more “normal people.” Tell them to build one, and many simply will not do it: they become overwhelmed and instead leave all their funds in a hot wallet or with a custodian.

Perfect is the enemy of good – and we continue to believe that the availability of hardware wallets is a net positive, making self-custody more accessible to a wider audience and, in the grand scheme of things, considerably safer.

What next?

One immediate change on our side is that our recommendations will shift far more strongly towards multi-vendor multisig as the required setup for any significant Bitcoin savings.

While we have promoted it for many years as the “gold standard” for securing funds once they represent a meaningful share of your overall net worth, we must hold ourselves accountable for the fact that our messaging was not as urgent or forceful as it should have been.

Essentially every article about self-custody covered the topic of multi-vendor multisig – but more as a suggestion for the extra-paranoid rather than as the required minimum bar to clear. 

This was a mistake. 

From here on out, we must and will communicate far more clearly that if you hold anything of significance in self-custody – for example, more than 0.1 BTC – you should get started with multi-vendor multisig.

The Coldcard/Coinkite incident was a tail-risk event: an edge case that was possible in theory and that many people had warned about over the years.. But:

As a function of time, every tail risk will eventually materialize with certainty. 

And in the age of highly capable frontier AI models, that time is compressing rapidly.

More tail risks and edge cases will materialize in faster succession than ever before, while single points of failure will be identified and exploited increasingly quickly unless they are mitigated in time.

In practical terms:

Once the immediate fires have been resolved, our team will begin offering dedicated multi-vendor multisig packages through our online shop.

We will also review and consider adding devices from additional manufacturers over the years to come, providing users with a more diverse range of independent entropy sources with which to eliminate single points of failure from their self-custody setups.

Furthermore, we will consider running smaller meetups dedicated to multi-vendor multisig setups, helping people get started and overcome the challenges involved.

These meetups are unlikely to be free of charge, as sharing this knowledge will require considerable time and resources from some of our senior team members. And the expectation that “somebody else will take care of things” for free is part of what brought us into this malaise in the first place.

Quality comes at a cost. If something is free, it is either worth very little – or, worse, you are the product.

The multi-vendor packages will likely begin taking shape during Q3 2026, while the smaller meetup series will be placed on our agenda for Q4 2026.

We will also strengthen our collaboration with industry peers working to advance multi-vendor multisig technology.

Now is the time to double down on promoting, implementing and funding the build-out of an ecosystem that makes multi-vendor multisig the non-negotiable standard for securing any significant amount of Bitcoin.

And why now?

Because – as bad as it was – the Coldcard fiasco was still, in the grand scheme of things, a “minor blip,” but also a loud warning shot.

The moment a similar incident affects a more mainstream manufacturer while the ecosystem has still failed to migrate sufficiently towards multi-vendor multisig, we will have a far larger catastrophe on our hands.

And yes, those manufacturers may follow more secure practices – but a single point of failure remains a single point of failure, and a freak accident can happen to any one of them.

This is a call to action for anyone who cares about Bitcoin’s long-term success.

Being committed to Bitcoin’s success means working to bring Bitcoin to more people – and providing them with the guidance, tools and knowledge they need to hold their own coins safely.

We have not given up on this mission – and we hope neither have you.

Let’s get to work.