Hard Money. Higher Standards.
Friday August 7th, 2026 - Issue # 140
(Any views expressed below are the personal views of the author and should not form the basis for making investment decisions, nor be construed as a recommendation or advice to engage in investment transactions.)
Good morning!
Hope you’ve all had a great week. It’s been a lot since I last posted. I actually had what I thought was a really great 80% completed letter that was meant to go out this time last week but was not able to complete it because the COLDCARD incident was still unfolding. And it was way too soon to pivot to try and speculate about what happened or use a very real tragedy for convenient clickbait.
If you were not aware of the incident, or only heard about it after seeing this headline in The Globe and Mail earlier this week, you are not alone. COLDCARD was a relatively niche hardware wallet used primarily by a small, technically sophisticated segment of Bitcoin holders, which is part of why the incident remained largely contained within Bitcoin circles before mainstream outlets began picking it up.
In the simplest terms possible, think of a Bitcoin wallet as a safe protected by an extraordinarily long combination. A properly generated 24-word recovery phrase is selected from 2²⁵⁶ possible combinations, a number containing 78 digits. For context, that puts it in roughly the same almost unimaginable neighbourhood as the estimated number of atoms in the observable universe. If the combination is generated properly, guessing it is effectively impossible.
When a new COLDCARD was set up, the device was supposed to select one of those combinations completely at random. But because of a mistake in the software, some devices were selecting combinations from a much smaller and more predictable corner of that enormous universe of possibilities. The safe itself still worked, but the combination protecting it was nowhere near as random as its owner believed.
The attackers eventually discovered the weakness and used AI and powerful computers to work through the possible combinations. They did not need to steal the physical devices, break into anyone’s home, trick people into sharing their recovery words or hack the Bitcoin network. Once they found a combination connected to a real wallet, they had the same ability to move the bitcoin as its rightful owner.
The result was that people who had done nearly everything right could still lose their coins because the device they trusted had created weak keys from the start. That is what makes this incident both so tragic and so important. Bitcoin itself did not fail, but the incident exposed how much trust still exists in the products we use to secure it, and why self-custody involves far more than simply buying a hardware wallet.
Jonathan’s story is what made this incident feel so different. This was not someone leaving bitcoin on a questionable exchange, clicking a phishing link or sharing his recovery phrase with a stranger. His COLDCARD was sitting offline in a safety deposit box and had never been connected to the internet. By nearly every conventional measure, he had taken security more seriously than almost anyone, and yet the vulnerability had been built into his wallet from the moment it was created.
It would be easy to look at that story and conclude that self custody does not work. I think that would be exactly the wrong conclusion. The ability to hold bitcoin directly, without needing permission from a bank, broker, government or any other intermediary, is one of the most important things that separates bitcoin from every financial asset that came before it. Self custody is not some fringe feature of Bitcoin. It is fundamental to what Bitcoin is.
But self custody is a capability, not a guarantee of safety. When you take possession of your own keys, you eliminate one category of risk and personally assume several others. You are no longer relying on an exchange or custodian to remain solvent, honour your withdrawal or protect your assets, but you are now responsible for the device, the firmware, the randomness used to create the seed, the physical backup, the recovery process and every decision made along the way. That tradeoff can still be absolutely worthwhile, but it should be understood honestly.
That is the larger lesson from COLDCARD. The risk was not that somebody broke into a safety deposit box or connected remotely to an offline device. The risk existed upstream, inside the software used to create the wallet in the first place. It is a reminder that even when you remove the obvious middleman, you are still placing some degree of trust in hardware manufacturers, software developers, standards, supply chains and your own ability to operate the setup correctly.
My co-founder Jon wrote about this exact point yesterday. As artificial intelligence makes cyberattacks faster, cheaper and more sophisticated, the standard for protecting valuable digital assets has to rise with it. You can read his full piece here.
For most holders, the decision does not need to be all or nothing. Someone can believe deeply in self custody and still decide that an entire life changing position should not depend on one device, one recovery phrase or one location. Holding some BTC directly while keeping another portion in a multisignature arrangement or with a reputable institutional custodian is not a rejection of Bitcoin’s principles. It is simply diversification applied to custody.
Each approach comes with tradeoffs. Self custody offers the greatest direct control, multisignature reduces reliance on any single key and institutional custody places more of the operational responsibility with a professional provider. There is no universal answer, and the right structure will depend on the size of the position, the owner’s technical ability, their family situation and how much responsibility they genuinely want to carry. The important thing is that the setup is chosen deliberately.
For anyone who continues to self custody, the fundamentals matter. Never photograph or digitally store a recovery phrase, and never enter it into a computer, phone, website, cloud service or online form. Only download firmware and wallet software from verified official sources, confirm receiving addresses directly on the hardware device and send a small test transaction before moving a meaningful amount. It is also worth recording which device and firmware originally generated the wallet, maintaining secure offline backups and testing the recovery process before it is actually needed.
The incident will also create an opportunity for scammers. Phishing emails and fake support messages work best when people are frightened and feel pressure to act quickly.
No legitimate wallet manufacturer, custodian or Satstreet employee should ever ask for a seed phrase or passphrase. If someone does, stop immediately and verify everything through a separate trusted channel.
As the incident unfolded, this became very real for our team. Through the night and into the early morning, we helped clients move millions of dollars worth of bitcoin from their own setups into Satstreet’s institutional cold storage by quickly providing secure deposit addresses and hands on support. Unfortunately, we have since learned that some of our clients were affected by the vulnerability. We are doing everything we can to support them, while also helping other clients review their setups and protect their holdings.
That experience has not changed our belief in self custody at all. Some clients may ultimately decide to create a new independent setup, some may prefer institutional custody and others may choose a combination of the two. Our role is not to push everybody toward the same answer. It is to help people understand the tradeoffs and avoid allowing one unexpected failure to compromise their entire position.
As tragic as this event has been for the small number of Bitcoiners who lost coins, the response has me feeling incredibly optimistic. Developers and security researchers are working around the clock to find vulnerabilities and make the ecosystem hard AF. That is Bitcoin’s game theory at work. Attackers have an enormous incentive to find weaknesses, but the people protecting the ecosystem have an even greater incentive to fix them, and because so much is built in the open, every lesson can quickly benefit everyone.
AI will accelerate that contest for both sides, but Bitcoin will ultimately benefit from being tested first and hardened first among many other areas of technology. The network itself continued to operate exactly as designed, while the failure occurred in a product built around it. If there is a beacon of hope in an otherwise tragic event, it is that the losses suffered by a very small number of Bitcoiners may lead to materially safer custody for millions of people in the future. Bitcoin is already the hardest money on the planet, and this relentless process of attacking, learning and hardening is how the infrastructure surrounding it becomes worthy of protecting it.
The takeaway is not to fear self custody. It is to respect custody in all of its forms and recognize that the right answer may change as a bitcoin position becomes more meaningful. Review the setup, understand the tradeoffs, remove unnecessary single points of failure and make sure the people who matter can recover the assets if they ever need to. Bitcoin gives us the ability to take direct ownership of our wealth, and that freedom is worth protecting thoughtfully.
If this incident has made you question your current setup, my team and I are here to help. Whether you want to remain entirely in self custody, move some bitcoin into insured institutional cold storage or simply get a second opinion, give me or anyone on our team a call. We can walk through the tradeoffs with you and help you land on a setup that makes sense for your circumstances.
This was not a failure of Bitcoin. It was another test, and Bitcoin passed. If this proves to be the black swan event of this cycle, it will be remembered as a tragic but relatively contained incident that forced every serious wallet provider, custodian and developer to raise the bar. Bitcoin gets attacked first because it is the biggest honeypot, and it gets hardened first because the incentives to protect it are enormous. After watching the network perform exactly as designed and the community respond in real time, I have never been more bullish.
Signing off for this week 🫡








