Go Back

Self-Custody Is a Right. It Was Never a Guarantee.

Security

August 3, 2026

Written by Joey Garcia

Holding your own keys has always been one of Bitcoin's defining rights. This past week showed why exercising that right may be more challenging than anticipated.
BTC Vault: Long-term storage for large Bitcoin balances Featured Image

Share this article

"Not your keys, not your coins" has been the moral backbone of the Bitcoin community since its earliest days, and for good reason. The ability to hold an asset that no government, bank, or intermediary can freeze, seize, or debase is one of the most important properties Bitcoin introduced to the world. That right — the right to self-custody, to genuine self-sovereignty over your own wealth — should be respected, defended, and preserved. I have argued for it in regulatory forums for years, and nothing in this article walks that back.

But a right is not the same thing as a recommendation. This past week, the Bitcoin community learned the difference between the two in the most painful way possible.

What happened with Coldcard

Coldcard hardware wallets, made by Coinkite, have long been regarded as among the most secure self-custody devices available — favoured precisely by the most security-conscious holders. A few days ago, that reputation collided with a flaw that had been sitting silently in the firmware for more than five years.

The vulnerability traces back to a firmware build from March 2021. A change in the code routed seed generation through a predictable software-based random number generator rather than the device's dedicated hardware chip — a build-time check that was supposed to enforce the secure setting simply failed to activate. The consequence was profound: the "random" keys generated by affected devices were drawn from a bounded, reproducible set. In practice, this means that anyone armed with the disclosure and sufficient computing power could regenerate those private keys entirely offline, without ever touching a device, without phishing a single victim, without breaching a single server.

Once the flaw became known, the draining began. And it came in waves:

  • The first wave swept roughly 1,083 BTC from almost 1,200 addresses in around 41 minutes.

  • Second and third waves followed within days, with the third alone draining a further ~208 BTC from more than 1,900 addresses — this time targeting smaller balances and using deliberately harder-to-trace transaction patterns.

  • A fourth wave, flagged by Galaxy Research over the weekend, moved a further ~389 BTC from 462 addresses in a scripted sweep lasting roughly two and a half hours.

Across all four waves, well over 1,750 BTC has now been drained from more than 5,000 addresses — comfortably in excess of $100 million at current prices. Tellingly, the stolen coins had sat untouched for an average of more than three years. These were not active traders taking known risks. The victims of this exploit were exactly the people the self-custody model is supposed to protect: patient, long-term holders who did everything "right" — bought a premium hardware device, generated their keys offline, and left their Bitcoin alone.

Why these funds are, in practice, gone

The hardest conversation now facing thousands of holders is that, for the overwhelming majority, recovery is not realistic. It is worth being clear about why:

There is no accountable counterparty. No exchange was hacked. No custodian failed. The attacker reproduced valid private keys and, from the network's perspective, simply spent coins they controlled. On-chain, a sweep is indistinguishable from a legitimate transaction. Bitcoin's finality — one of its greatest strengths — cuts both ways: there is no reversal mechanism, no chargeback, no administrator.

There is no one to claim against. When a regulated institution fails or is breached, the loss has somewhere to land: a legal entity, a balance sheet, insurance, courts, and rules requiring customer assets to be segregated and kept insolvency-remote. A self-custody loss lands nowhere. In a self-custody loss, the victim's only realistic counterparty is an anonymous attacker distributing funds across freshly generated addresses — with the latest wave deliberately routing each victim's coins to unique destinations using output types designed to frustrate clustering and tracing.

The manufacturer's liability is not the same as a bank's. Coinkite has, to its credit, acknowledged the fault, published patched firmware and taken public responsibility. But a hardware vendor is not a custodian. It does not hold the assets, does not owe you a deposit, and — unlike, say, the Trust Wallet incident years ago, where the company reimbursed roughly $12 million of losses from a near-identical weak-randomness bug — there is no regulatory or contractual obligation to make victims whole. Updating the firmware protects new seeds; it does nothing for anyone whose keys were generated on the flawed versions, who must now race the attackers to move whatever remains.

This is the sober reality of being "your own bank": you are also your own compliance department, your own security team, your own insurer — and your own resolution regime.

The right, and the responsibility

None of this is an argument against self-custody as a principle. The right to hold your own keys is non-negotiable, and any regulatory framework that tried to extinguish it would be both wrong and unworkable. This is work that we have been involved with and supported at the highest level for many years. For some holders — technically sophisticated, operationally disciplined, holding amounts they can afford to defend or to lose — self-custody remains a perfectly rational choice.

But the Coldcard incident exposes the uncomfortable assumption buried in "not your keys, not your coins": that your operational security will outperform that of a supervised, audited, professionally-run institution — forever, against a five-year-old bug you had no way of knowing existed. For most people, and certainly for wealth of any significance, that assumption deserves honest scrutiny. Holding a meaningful portion of your net worth on a single device is the digital equivalent of keeping your life savings in a home safe: defensible for small amounts, and a serious concentration of risk for anything more.

The more mature framing is not custody versus self-custody. It is imperative that we understand the importance of diversification of custody risk — just as we have always diversified every other kind of financial risk.

What secure, regulated infrastructure actually offers

This is the model Xapo has spent more than a decade building — first as one of the earliest Bitcoin custodians, dubbed the "Fort Knox of Bitcoin", and today as a fully regulated bank alongside a separately licensed virtual asset services provider.

Xapo’s security architecture is designed specifically to remove the single points of failure that the Coldcard incident has just made vivid:

No single key, ever. Bitcoin held with Xapo is protected using Multi-Party Computation (MPC): the full private key never exists in one place, at any moment, on any device. Encrypted key shards are distributed across HSM-protected environments in geographically dispersed, military-grade facilities. An attacker would need to compromise multiple independent systems simultaneously — there is no equivalent of one flawed firmware build silently undermining everything.

No seed phrase to lose, leak, or have regenerated against you. The entire class of vulnerability behind the Coldcard incident — a compromised seed-generation process — simply does not exist in this model.

Security features that put friction where it belongs. Hardware security keys (such as a YubiKey) can be linked to an account, so that even if a phone is stolen, the account remains locked — addressing the "physical device" security instinct without carrying the key-management burden. The BTC Vault adds a mandatory 48-hour withdrawal delay: a two-day window to detect and cancel any transaction you did not authorise. Contrast that with the 41 minutes it took to drain over a thousand Bitcoin in the first Coldcard wave.

Assets that work, and assets that outlive you. Bitcoin sitting on a hardware wallet in a drawer is inert. Within regulated infrastructure, BTC can be put to work — deployed for yield, borrowed against for USD liquidity without triggering a sale — and, critically, structured for what comes after you. Xapo's inheritance framework allows members to designate beneficiaries so that Bitcoin passes on as intended. Self-custodied Bitcoin, by contrast, dies with its key-holder more often than the industry likes to admit: an estimated fortune in BTC is already permanently stranded because seed phrases were lost, hidden too well, or never shared.

Segregation and insolvency remoteness. Customer Bitcoin is held in segregated, insolvency-remote structures, off Xapo's balance sheet, through a regulated VASP entity. It is not lent, not rehypothecated, not exposed to leverage.

The honest conclusion

The lesson of the Coldcard incident is not "self-custody is dead." That would be as glib as the maximalist position it replaces. The lesson is that self-custody is a demanding discipline whose risks are silent, uninsured, and unforgiving, and that the community owes newcomers honesty about that, rather than a slogan.

Hold your own keys if you choose to — that right must always exist. But hold them knowing what risks you are actually taking on. And for the portion of your wealth you cannot afford to lose to a five-year-old bug, a house fire, a forgotten passphrase, or your own mortality, there is now a genuine alternative that did not exist in Bitcoin's early years: regulated, supervised, institutionally secured infrastructure, built by people who have been protecting Bitcoin since 2013.

Sovereignty includes the freedom to choose your fortress.

Disclaimer

We provide this article for general information only. It is not legal, financial, or professional advice, and you should not treat it as a substitute for advice tailored to your specific situation. While we strive for excellence Xapo Bank does not guarantee that the information in this article, or any content linked within it is always accurate, complete, or up-to-date. We provide this “as is” without any formal warranties.

Crypto services are provided by Xapo VASP Limited, a Distributed Ledger Technology Provider regulated by the GFSC (Permission No. 26061). These are not provided by Xapo Bank Limited. Banking services are provided by Xapo Bank Limited, which is regulated as a Credit Institution by the GFSC (Permission No. 23171) for fiat (traditional currency) balances only. Important: Crypto asset deposits are not covered by the Gibraltar Deposit Guarantee Scheme (GDGS).

When we use terms like “guaranteed”, “protected”, or “secure” regarding crypto, we are referring only to our technical and operational security features. These terms do not imply any form of government deposit protection or regulatory financial safeguard for your crypto assets.

Crypto is high-risk and its value can go up as well as down - you may get back less than you put in. For more information on risks see our DLT Risk Disclosure Statement.

Approved by Xapo Bank Limited on 03.08.2026.

Share this article

Be in the know.
Unlock the future of money.

Get the latest Bitcoin news, product updates, and exclusive insights from Xapo Bank.

The Xapo
Insider

Catch up on the latest crypto news, and get the inside scoop on our products and services.

How Xapo Bank secures Bitcoin: MPC custody, human oversight, and the 48-hour Vault timelock
Security
Article - Jul 23, 2026

How Xapo Bank secures Bitcoin: MPC custody, human oversight, and the 48-hour Vault timelock

The Bitcoin loan strategy: Get liquidity without selling
Loans
Article - Jul 16, 2026

The Bitcoin loan strategy: Get liquidity without selling

Xapo Bank: The Gold Standard for Regulated Crypto Off-Ramping
Xapo Bank
Article - Jul 14, 2026

Xapo Bank: The Gold Standard for Regulated Crypto Off-Ramping

How to manage a 50+ BTC position like a pro
Bitcoin
Resource - Jul 02, 2026

How to manage a 50+ BTC position like a pro

The smart Bitcoin accumulator strategy: How to grow your Bitcoin wealth in 2026
Grow
Article - Jun 30, 2026

The smart Bitcoin accumulator strategy: How to grow your Bitcoin wealth in 2026

What is the 'risk-free rate' for Bitcoin?
Bitcoin
Resource - Jun 30, 2026

What is the 'risk-free rate' for Bitcoin?