Self-custody is still the point
On July 30th, someone swept roughly 594 bitcoin, about $38 million, out of some 500 wallets in 25 minutes. Every one of those seeds was born on a Coldcard. Block's security researchers traced it to a one-line build error that shipped in March 2021: the firmware silently skipped its hardware random number generator and fell back to software randomness seeded by the chip's serial number and a timer. Seeds that should have been unguessable were drawn from a pool of about four billion. The bug sat in open-source firmware for five years, and analysts now suspect related losses closer to $116 million and still growing.
If you generated a seed on a Coldcard Mk2 or Mk3 running firmware 4.0.1 or later (or any other version of the product or firmware for that matter), deal with that before you read anything else, this post included. Move your funds to a fresh seed created on an unaffected device (not a Coldcard, even with the new firmware). Updating the firmware repairs nothing that already exists. Coinkite's advisory has the steps.
Now for the part that worries me more than the bug.
Every custodian's sales deck just got a new slide. "Self-custody is dangerous. Let the professionals hold it." And plenty of people will nod along, because in 2026 you can get all the NGU you want without ever touching a key. Buy the ETF, watch number go up (NGU), sleep fine.
Here's the problem: NGU is the marketing, not the product. The product is money that nobody can freeze or debase, and that no custodian can quietly lend out from under you. That property does not live in the price. It lives in the keys. Bitcoin held by a custodian is a great ticker symbol attached to somebody else's promise, which is precisely the arrangement we were all trying to leave. Self-custody is the entire difference between bitcoin and everything else on the screen.
So the answer to the Coldcard incident cannot be surrendering keys. But I'll say the uncomfortable second half out loud: the answer isn't defending the Coldcard paradigm either.
I never owned one. However, I did recommend it to someone I “orange pilled”, who bought much more Bitcoin than I could ever have, because he needed the “good stuff” to secure his bigger bag. Most of the bitcoin maxi echo chamber loved the product and talked about that translucent calculator like the ugliness was a virtue: no design budget meant every dollar went to security, and the hostility (from NVK) meant seriousness.
With hindsight, it was just ugly.
The ugliness did no security work at all. A predictable random number generator shipped anyway and lived there for half a decade while we admired the exposed circuit board. What the ugliness did accomplish was keeping normal people out (thankfully, I guess now).
The Coldcard, patched or not, is the purest expression of a direction we should never have taken: tools built by mechanics, for mechanics, in love with their own machinery. The direction we need runs the other way.
I wrote a long essay about that direction a few months ago, and this incident is exactly why it exists: Why Bitcoin Needs a Design Revolution
The short version. Buckminster Fuller argued that good technology buries its complexity; nobody should ever meet a seed phrase, for the same reason no driver ever meets a camshaft. Sagmeister and Walsh proved that beauty is functional; an experience that signals danger gets avoided no matter how sound the math underneath, and nearly every touchpoint of self-custody today signals danger.
Thankfully, Coldcard was the ugliest experience of all and kept most people away. Pascal explains what happens next: anxious people flee into distraction, which is how savers end up on custodial casino apps watching candles at 2am. And Rory Sutherland's psycho-logic: gold feels valuable partly because it is heavy, and we have given bitcoin and self-custody no weight at all.
What does self-custody look like if we start over? In the essay I sketch one possibility, a thought experiment called Hearth: keys kept inside a heavy, beautiful object that sits openly in your home like an heirloom, transactions expressed as intent rather than fee rates and change outputs, an interface that rewards patience instead of panic. That exact idea is certainly wrong for many reasons. The point is that almost nobody is exploring this space seriously, because the culture decided fifteen years ago that suffering was proof of sovereignty. It never was. Suffering was just suffering, and last week it wasn't even safe.
To be fair, Block is actually rethinking this with the Bitkey. It's a giant step in the right direction, in my opinion. And its important to point out, the Bitkey wasn't just better designed, it was unaffected by this specific ColdCard issue. So were Trezor and Ledger. Every other major hardware wallet generates its entropy a different way, and not one of them shipped this bug.
So what do you do if you never touched a Coldcard? You still have one job today. Know where your randomness comes from. Pull up whatever device you use, confirm it's running current firmware, and make sure you actually understand how it generates a seed (if you can't find that out in a few minutes, well, that's information too). This isn't a reason to sprint to a custodian. It's the opposite. It's the reminder that self-custody is a practice, not a purchase, and the practice is boring on purpose: hold your own keys, keep your tools current, verify instead of trust. The whole point of this money is that you don't have to take anyone's word for it. So don't. Not even your hardware's.
NGU will keep bringing people to the door. Millions of them, every cycle. What happens at the door is up to us. Either they meet self-custody tools a human being can love, or they hand their coins to a custodian on day one and bitcoin slowly becomes one more asset in one more vault. The most important property of this money is the one only its holders can exercise, and right now we have it wrapped in the worst experience in the industry.
The Coldcard pointed the wrong way. Read the full essay here: https://bitcoinwell.com/blog/why-bitcoin-needs-a-design-revolution
Carl Frisko is the Head of Marketing at Bitcoin Well, helping people escape the fiat matrix one sat at a time. At Bitcoin Well, Carl leads growth across Canada and the U.S., focusing on Portal adoption, ATM expansion, and making “not your keys, not your coins” impossible to ignore.