What Happened Last Week
On March 1, 2021, a single commit changed the way Coldcard firmware asked for randomness. Seed generation had been calling the dedicated hardware random number generator on the device’s main chip. The new code called a software routine instead, and the build flag meant to route it back to hardware was written to check whether a setting existed rather than what it was set to, so the hardware path was quietly compiled out. Every seed created on affected builds was drawn from a software generator seeded with non-secret chip data.
The effect was a collapse in the size of the search space. A properly generated twelve-word seed carries 128 bits of entropy, a 39-digit number of possibilities that is permanently out of reach. Seeds created on affected Mk2 and Mk3 builds (versions 4.0.1 through 4.1.9) carried roughly 40 bits, about a trillion possibilities, which a rented GPU cluster can work through in hours. Mk4, Mk5, and Q seeds made before the patched releases carried roughly 72 bits. Nothing about the device was compromised and no physical access was required. An attacker could generate the candidate seeds offline, derive the addresses each one produces, and check them against the public blockchain. Coinkite’s advisory notes one exception: seeds hashed together with at least fifty dice rolls, or protected by a strong BIP-39 passphrase, were never exposed.
On July 30, someone finished that reconstruction. Roughly 594 BTC, about $38 million at the time, left close to 500 dormant addresses in under 30 minutes. By August 5 the running tally from Galaxy Research had reached roughly 1,816 BTC, close to $116 million, drained from more than 5,200 addresses across four waves, with broader estimates putting total losses above $130 million. The attack remains ongoing. Coinkite published an advisory and shipped patched firmware within two days. Patched firmware does not repair a seed that was already generated weakly, so the guidance is to create a new seed on updated firmware or on a device from another manufacturer and move the coin to addresses that new seed controls. A strong passphrase buys time; it does not fix the seed underneath it.

These holders bought the most security-obsessed device in the industry, generated their seeds offline, and left their bitcoin untouched for years. Following best practices that many recommended as the gold standard for custody led to loss of funds.
The Wrong Lesson, Again
CoinDesk reported an immediate behavioral response: holders moving coin back onto exchanges. The industry has seen this pendulum before. The Mt. Gox collapse created the consumer hardware wallet category, with the Trezor Model One shipping in July 2014 as a direct market answer to it. FTX, BlockFi, Voyager, and Prime Trust pushed a second wave off exchanges in 2022. That column is familiar enough to recite: Mt. Gox, then FTX where roughly $8 billion in customer deposits funded Alameda Research, then Celsius, whose Earn terms of service transferred ownership of deposited coin to the company and turned what customers believed were savings accounts into unsecured loans to a leveraged trading desk. As we have written before, the names have changed and the architecture has not. Now a hardware failure is pushing holders back toward the custodial pole, where the last $8 billion loss originated.

For fifteen years holders have been swinging their wealth between single counterparty exchanges, where malice and incompetence have taken more than $20 billion, and self-custody, where poor hardware, user error, and physical coercion have taken roughly 1.57 million bitcoin, worth something near $100 billion at today’s price. The self-custody column gets less press because the losses are unreported and arrive one at a time. The two failure modes look different on the surface and share a root cause underneath: too much depending on one key, one device, one company, or one person.
An Honest Word About Self-Custody
The ability to self-custody is absolutely crucial to bitcoin’s value proposition, and the people building better tools for it are doing necessary work. For most holders, though, the real question is not whether they can self-custody but whether their core wealth should depend on it. Our team takes a barbell approach: a minority of holdings in self-custody under sole control, with the majority in multi-institution custody. That split comes from years of using nearly every option available and keeping what held up.
The reason is scope rather than competence. A single signing setup has to keep working through firmware updates, device discontinuations, moves, and estates, and it has to keep working when the person operating it is no longer the person who set it up. The drained Coldcard addresses were dormant for a reason: almost nobody revisits the setup on coin they have not touched since 2021. That is a maintenance discipline measured in decades, and it is a reasonable thing to hand to people who do it for a living.
“Not your keys, not your coins” was the right rebellion against Mt. Gox and FTX. As a universal prescription for every holder, it has cost real families real wealth, and last week it cost the most careful ones. We prefer to eliminate single points of failure, including yourself.
Why Careful Wasn’t Enough
The deeper issue runs past this particular bug. Any custody setup with a single point of failure, whether that point is one device, one vendor’s hardware across several devices, one company, or one person, gives that point the power to lose everything. Careful holders can and do compensate, and Coinkite’s advisory confirms that seeds built with fifty dice rolls or wrapped in a strong passphrase were never at risk. The people who did that work were right to. But it took specialist knowledge to know that it mattered, and the holders who were drained were not careless. They followed the device’s defaults. When a setup depends on one device, one firmware build, and one person’s judgment about which optional features to turn on, being careful is not the same as being safe.
Key generation and key management are expert disciplines, and the fix that holds is structural: distribute the keys. But last week also showed that multisig alone is a half-measure when the implementation concentrates risk somewhere else. Collaborative custody users holding two of their keys on Coldcards spent the weekend scrambling to move funds right alongside the single-sig holders, because a quorum drawn from one vendor’s hardware inherits that vendor’s failure modes. The same logic holds at institutional scale: an exchange like Coinbase secures customer coin with multisig, yet every key sits inside one company, one security program, and one legal perimeter. Three signatures behind one door is still one door.
The property that actually does the work is independence. In a 2-of-3 multisig vault held across three independent institutions, each key is generated by a different team, on different hardware, in a different location, against different firmware. And the hardware itself belongs to a different class than the device that failed last week. Institutional custodians generate keys inside purpose-built, airgapped signing infrastructure, with audited entropy sources, hardware security modules, and sharded key material, systems engineered and maintained for exactly this job rather than consumer devices produced at retail scale. Each institution procures, configures, and audits its own stack independently of the other two, so there is no shared firmware build, no shared vendor, and no shared failure mode to find. One breached data center and one failed or seized institution moves nothing, because the remaining quorum still controls the bitcoin and will swap out the other key.
That structure also flips the economics of attack. An attacker who finds one flaw in a popular consumer device can rob every holder who shares it, which is how one firmware bug reached more than 5,200 addresses. An attacker facing multi-institution custody has to compromise several hardened, unrelated organizations simultaneously, a job we have previously argued exceeds the practical reach of even the most sophisticated nation-state attackers.
The Primitive Was Here All Along
None of this requires new technology. Multisig is part of the Bitcoin protocol itself (OP_CHECKMULTISIG): open source, deterministic, and battle-tested across more than a decade of production use. A 2-of-3 locking script cannot be upgraded into malicious code, and every cosigner can verify a transaction’s inputs, outputs, and fee in open software before signing. Bitcoin is the only asset in history that ships distributed custody at the protocol layer. Proprietary multi-party computation schemes, by contrast, reintroduce exactly the complexity and opacity the protocol was designed to avoid.
This matters for the industry because nobody owns the primitive. It is an open standard, available to any custodian willing to build on it.
An Opportunity to Be Stronger Together
We think custody converges on this architecture, and that it becomes the standard for any wealth not held in self-custody. Each new failure at either pole strengthens the case for the middle, and no symmetric event exists to discredit it, because a single institution failing inside a 2-of-3 vault is an operational inconvenience rather than a loss. The model also scales with the balance it protects, moving from 2-of-3 to 3-of-5 and beyond, with the holder choosing which institutions hold which keys. That redundancy is what makes the structure insurable: underwriters can price a loss condition that requires several regulated entities to fail at once, and custody that underwriters will stand behind is custody that trusts, estates, and retirement accounts can hold for decades.
The claim attaches to the architecture, deliberately, and to no single firm, because the model is positive-sum by construction. Multi-institution custody requires multiple independent institutions; that independence is the security feature. Every credible custodian that adopts the standard adds key diversity, hardware diversity, and jurisdictional diversity, and each addition strengthens every vault built on the model. This should become an industry position rather than a vendor position: custodians, collaborative custody firms, and hardware makers converging on the shared primitive, with interoperable key management, independently generated entropy, and published audits. The 5,200 drained addresses are the reason to start the work before the next incident, and they will not be the last reason.
There is a second-order effect worth naming carefully. Coercion against an individual holder works because one person, under enough pressure, can produce an entire balance. A quorum held across independent institutions changes that arithmetic, because no single person can move the coin alone and there is nothing to be gained by pressuring one. The digital version follows the same logic: an attacker who compromises one vendor cannot sweep every customer at once. As more of the industry’s wealth sits behind structures where no individual and no single company is a complete answer, the expected payoff from going after any one of them falls. That is a safety improvement that reaches holders who never adopt the model themselves, giving air cover for the rest of the industry.
Closing
Self-custody is not the problem, and institutional custody is not inherently bad either, especially if each is done the right way. Bearer assets are not new; gold has been held in vaults and under floorboards for millennia. What is new is a bearer asset that is fully digital, one that can be held, secured, and moved with a set of keys rather than a set of armored trucks, divided across parties without being physically split, and verified without an assayer.
For fifteen years, the choice of how to hold that asset has been presented as a binary: trust an exchange with everything, or trust yourself with everything. That framing was always false. The real choice is concentrated keys versus distributed ones, and distribution is no longer a theoretical preference.
That is why multi-institution custody runs through so much of our portfolio. Onramp built the model for individual holders. Onramp MENA is extending it into the Gulf. Aureo and Stables apply the same principle of distributed control in adjacent markets, and there is more coming. The pattern is deliberate rather than incidental.
Our partner Michael Tanguma likes to say that multi-institution custody makes no one fully happy: hardcore bitcoiners want the device in hand, and the large trust banks would prefer to hold everything themselves. After a week in which the device failed at scale and the reflex was to run back toward the banks, the uncomfortable middle looks less like a compromise and more like the standard.
If you are building on this architecture, whether as a custodian, a key holder, a hardware maker, or an application layered on top of it, we want to hear from you. The primitive is open and nobody owns it, which means the standard gets written by whoever shows up to build it. There is room for every serious institution inside it, and we would rather help build it than watch it get built.
Subscribe to Keep Reading
Get the full piece, plus all the latest Early Riders research, letters, and the Open Range weekly, delivered directly to your inbox.
Subscribing is free, and this device stays unlocked once you do.