"Not your keys, not your coins" has been the moral backbone of the Bitcoin community since its earliest days, and for good reason. The ability to hold an asset that no government, bank, or intermediary can freeze, seize, or debase is one of the most important properties Bitcoin introduced to the world. That right — the right to self-custody, to genuine self-sovereignty over your own wealth — should be respected, defended, and preserved. I have argued for it in regulatory forums for years, and nothing in this article walks that back.
But a right is not the same thing as a recommendation. This past week, the Bitcoin community learned the difference between the two in the most painful way possible.
What happened with Coldcard
Coldcard hardware wallets, made by Coinkite, have long been regarded as among the most secure self-custody devices available — favoured precisely by the most security-conscious holders. A few days ago, that reputation collided with a flaw that had been sitting silently in the firmware for more than five years.
The vulnerability traces back to a firmware build from March 2021. A change in the code routed seed generation through a predictable software-based random number generator rather than the device's dedicated hardware chip — a build-time check that was supposed to enforce the secure setting simply failed to activate. The consequence was profound: the "random" keys generated by affected devices were drawn from a bounded, reproducible set. In practice, this means that anyone armed with the disclosure and sufficient computing power could regenerate those private keys entirely offline, without ever touching a device, without phishing a single victim, without breaching a single server.
Once the flaw became known, the draining began. And it came in waves:
The first wave swept roughly 1,083 BTC from almost 1,200 addresses in around 41 minutes.
Second and third waves followed within days, with the third alone draining a further ~208 BTC from more than 1,900 addresses — this time targeting smaller balances and using deliberately harder-to-trace transaction patterns.
A fourth wave, flagged by Galaxy Research over the weekend, moved a further ~389 BTC from 462 addresses in a scripted sweep lasting roughly two and a half hours.
Across all four waves, well over 1,750 BTC has now been drained from more than 5,000 addresses — comfortably in excess of $100 million at current prices. Tellingly, the stolen coins had sat untouched for an average of more than three years. These were not active traders taking known risks. The victims of this exploit were exactly the people the self-custody model is supposed to protect: patient, long-term holders who did everything "right" — bought a premium hardware device, generated their keys offline, and left their Bitcoin alone.
Why these funds are, in practice, gone
The hardest conversation now facing thousands of holders is that, for the overwhelming majority, recovery is not realistic. It is worth being clear about why:
There is no accountable counterparty. No exchange was hacked. No custodian failed. The attacker reproduced valid private keys and, from the network's perspective, simply spent coins they controlled. On-chain, a sweep is indistinguishable from a legitimate transaction. Bitcoin's finality — one of its greatest strengths — cuts both ways: there is no reversal mechanism, no chargeback, no administrator.
There is no one to claim against. When a regulated institution fails or is breached, the loss has somewhere to land: a legal entity, a balance sheet, insurance, courts, and rules requiring customer assets to be segregated and kept insolvency-remote. A self-custody loss lands nowhere. In a self-custody loss, the victim's only realistic counterparty is an anonymous attacker distributing funds across freshly generated addresses — with the latest wave deliberately routing each victim's coins to unique destinations using output types designed to frustrate clustering and tracing.
The manufacturer's liability is not the same as a bank's. Coinkite has, to its credit, acknowledged the fault, published patched firmware and taken public responsibility. But a hardware vendor is not a custodian. It does not hold the assets, does not owe you a deposit, and — unlike, say, the Trust Wallet incident years ago, where the company reimbursed roughly $12 million of losses from a near-identical weak-randomness bug — there is no regulatory or contractual obligation to make victims whole. Updating the firmware protects new seeds; it does nothing for anyone whose keys were generated on the flawed versions, who must now race the attackers to move whatever remains.
This is the sober reality of being "your own bank": you are also your own compliance department, your own security team, your own insurer — and your own resolution regime.
The right, and the responsibility
None of this is an argument against self-custody as a principle. The right to hold your own keys is non-negotiable, and any regulatory framework that tried to extinguish it would be both wrong and unworkable. This is work that we have been involved with and supported at the highest level for many years. For some holders — technically sophisticated, operationally disciplined, holding amounts they can afford to defend or to lose — self-custody remains a perfectly rational choice.
But the Coldcard incident exposes the uncomfortable assumption buried in "not your keys, not your coins": that your operational security will outperform that of a supervised, audited, professionally-run institution — forever, against a five-year-old bug you had no way of knowing existed. For most people, and certainly for wealth of any significance, that assumption deserves honest scrutiny. Holding a meaningful portion of your net worth on a single device is the digital equivalent of keeping your life savings in a home safe: defensible for small amounts, and a serious concentration of risk for anything more.
The more mature framing is not custody versus self-custody. It is imperative that we understand the importance of diversification of custody risk — just as we have always diversified every other kind of financial risk.
What secure, regulated infrastructure actually offers
This is the model Xapo has spent more than a decade building — first as one of the earliest Bitcoin custodians, dubbed the "Fort Knox of Bitcoin", and today as a fully regulated bank alongside a separately licensed virtual asset services provider.
Xapo’s security architecture is designed specifically to remove the single points of failure that the Coldcard incident has just made vivid:
No single key, ever. Bitcoin held with Xapo is protected using Multi-Party Computation (MPC): the full private key never exists in one place, at any moment, on any device. Encrypted key shards are distributed across HSM-protected environments in geographically dispersed, military-grade facilities. An attacker would need to compromise multiple independent systems simultaneously — there is no equivalent of one flawed firmware build silently undermining everything.
No seed phrase to lose, leak, or have regenerated against you. The entire class of vulnerability behind the Coldcard incident — a compromised seed-generation process — simply does not exist in this model.
Security features that put friction where it belongs. Hardware security keys (such as a YubiKey) can be linked to an account, so that even if a phone is stolen, the account remains locked — addressing the "physical device" security instinct without carrying the key-management burden. The BTC Vault adds a mandatory 48-hour withdrawal delay: a two-day window to detect and cancel any transaction you did not authorise. Contrast that with the 41 minutes it took to drain over a thousand Bitcoin in the first Coldcard wave.
Assets that work, and assets that outlive you. Bitcoin sitting on a hardware wallet in a drawer is inert. Within regulated infrastructure, BTC can be put to work — deployed for yield, borrowed against for USD liquidity without triggering a sale — and, critically, structured for what comes after you. Xapo's inheritance framework allows members to designate beneficiaries so that Bitcoin passes on as intended. Self-custodied Bitcoin, by contrast, dies with its key-holder more often than the industry likes to admit: an estimated fortune in BTC is already permanently stranded because seed phrases were lost, hidden too well, or never shared.
Segregation and insolvency remoteness. Customer Bitcoin is held in segregated, insolvency-remote structures, off Xapo's balance sheet, through a regulated VASP entity. It is not lent, not rehypothecated, not exposed to leverage.
The honest conclusion
The lesson of the Coldcard incident is not "self-custody is dead." That would be as glib as the maximalist position it replaces. The lesson is that self-custody is a demanding discipline whose risks are silent, uninsured, and unforgiving, and that the community owes newcomers honesty about that, rather than a slogan.
Hold your own keys if you choose to — that right must always exist. But hold them knowing what risks you are actually taking on. And for the portion of your wealth you cannot afford to lose to a five-year-old bug, a house fire, a forgotten passphrase, or your own mortality, there is now a genuine alternative that did not exist in Bitcoin's early years: regulated, supervised, institutionally secured infrastructure, built by people who have been protecting Bitcoin since 2013.
Sovereignty includes the freedom to choose your fortress.






