RSS Amplifier

Bitcoin Katie · Aug 15, 2026

I Survived the Celsius Bankruptcy and the Coldcard Exploit - Here's Why I Still Self-Custody my Bitcoin

0
Sign in to vote or save

Katie Mestre · Bitcoin Katie

On the 30th of July, 2026, it took just over 40 minutes for around 1,200 Bitcoin addresses to be swept, resulting in the loss of all their Bitcoin. In this first sweep, losses were estimated at around US$70 million.

In the subsequent days, Bitcoin Twitter (X) and crypto media outlets were full of many prominent voices suggesting that self-custody is dead, that ordinary people should not try to self-custody, that self-created entropy is not for 99% of people, and that the obvious answer is to use an ETF or a custodian instead.

All affected addresses were associated with Coldcard Mk3 hardware wallets. 30 hours after the first sweep, Coinkite - the Canadian manufacturer of the Coldcard hardware wallets - publicly disclosed the risk posed by its firmware.

In a nutshell, the Coldcard seed phrase generation process had been compromised by a firmware error, and the resulting seed phrases had nowhere near the level of entropy (randomness) required to prevent a computer from guessing them.

So it was relatively straightforward for the Bitcoin thieves to reverse-engineer the seed phrase generation process and thus guess the seed phrases created by the ColdCard Mk3 model.

To avoid belaboring the point, I have written more about the Coldcard incident here.

In this article I cover:

  • The day I woke up to find out my Bitcoin was gone

  • The parallels with the current self-custody ‘crisis’

  • The choice facing all Bitcoiners

  • The risks of using a custodian vs the risks of self-custody

  • Which risks I choose, and why

  • Self-custody checklist in a post-ColdCard landscape

Before I continue with the recent Bitcoin events, I want to take you back to 2022.

On the morning of June 12th, I woke up to an email from the Celsius Network, advising customers that all withdrawals had been paused until further notice.

To say that I felt sick to my stomach is an understatement. It was pure gut-wrenching, accompanied by immediate, overwhelming regret. I couldn’t eat properly for a week.

Celsius customers had no way of knowing if or when any of their savings would be returned. For some people, everything they owned was in Celsius. They had sold their houses, all their shares, everything they owned to put it all on the Celsius platform to earn yield.

Even writing that sentence makes me deeply saddened for those people. I know some even entertained or possibly carried out self-harm as a result. This event destroyed dreams, destroyed lives.

If you were not in Bitcoin at the time, Celsius was not the only platform to go down, taking customers’ funds with it. There was also the TerraLuna de-peg. The FTX collapse. The BlockFi bankruptcy…just to name a few.

This was the era of ‘not your keys, not your coins’. The narrative was extremely anti-custodian, and for good reason. The risks of entrusting your Bitcoin or crypto to a third party became as plain as day.

This was the time when many rushed off into self-custody - myself included. I bought a popular hardware wallet and used it to secure what remained of my Bitcoin. Now, it was ‘my keys, my coins’. Problem solved.

Not so fast.

You hold your own keys. Your Bitcoin is yours. You bought one of the best wallets out there - a Coldcard. You have removed all counterparty risk, exactly as you were supposed to.

Except on the last day of July, you wake up to the news that the seed phrase you generated using your ColdCard has been potentially compromised.

So as it turns out, your keys and the coins attached to them may not be exclusively yours after all.

On July 31st, once Coinkite had publicly confirmed the entropy flaw, it began to dawn on all Coldcard users - myself included - that their Bitcoin may be at risk.

In this article, I explain that I had used a Coldcard Q with a passphrase and, as a result, was not immediately at risk of having any funds stolen.

However, out of an abundance of caution, I moved all my Bitcoin to addresses associated with a fresh seed phrase and changed to a Seedsigner - I was not willing to take any risk.

I know that the people who had been the victims of this sweep, those who had lost hundreds of thousands or millions of dollars worth of Bitcoin, had likely woken up on that Friday with the same awful, sick feeling that I experienced when I received that Celsius email.

We can never know the individual stories of all victims. Maybe that Bitcoin was their life savings. Perhaps they were months away from retirement. Some of them may have needed the money to pay for their children’s education, or their partner’s cancer treatment. We don’t know.

They had all done what they were supposed to do. None of them did anything wrong.

In the wake of the 2022 bankruptcies, the smart, sensible thing we were all told to do was to self-custody our Bitcoin. To not trust anyone else with it. And yet the outcome was the same, if not worse.

Their Bitcoin was gone, and nobody could help them.

If you use a custodian, you are adding multiple layers of trust that are supposed to be eliminated by Bitcoin.

If you self-custody, however, an unforeseen flaw or hack may expose your Bitcoin to bad actors who will steal it without the slightest hesitation.

So what is the lesser of two evils?

Some prominent voices in the Bitcoin space will have you believe that it is the former. Trust a custodian. Trust Wall Street to wrap your Bitcoin in regulated financial products. Anything but self-custody!

How do I say this delicately? They believe that you are too stupid to be in charge of your own money. And now they are openly telling you what they think.

Now imagine these same people saying this in the wake of the 2022 bankruptcies. Bitcoin Twitter would have had them for breakfast. Who would have been willing to shill custodians when billions of dollars belonging to ordinary people had just been lost?

Bitcoin custody is not a case of ‘this is the one best option for everybody at all times'.

Custody spans a spectrum of options, each with its own benefits and trade-offs. It is the job of every Bitcoiner to figure out which option they are most comfortable with, at a given point in time.

To put it simply, all Bitcoin custody can be separated into two categories: full self-custody, with no third parties involved, or a custody setup that involves at least one custodian or other third party.

Full self-custody includes any kind of setup where you ONLY hold the keys - whether it is single- or multi-sig.

Custody setups range from a 2-of-3 multisig, where a custodian holds one key, all the way through to exchange custody or even holding Bitcoin in an ETF or at a treasury company.

Every one of these options has benefits, risks, and trade-offs. I am not saying the benefits and risks are equal, because, in my opinion, they are not. Many of these options, for example, have risks and trade-offs that far outweigh the benefits.


Some risks of self-custody:

  • Generating weak seed entropy with a flawed device (i.e. Coldcard)

  • Losing a seed phrase that was properly backed up

  • Accidentally exposing a seed phrase

  • Relying on a setup with a single point of failure

  • Being socially engineered and scammed

  • Wrench attacks

  • Failing to learn how to transact, i.e. doing a ‘set-and-forget’ setup

  • Losing a passphrase

  • No recourse for theft or mistakes

  • Not having an inheritance plan in place

Some risks of custodial services

  • The custodian can stop withdrawals at any time

  • Limitations can be placed on transactions

  • Exchanges want to know who owns the addresses you transact to

  • Full KYC puts your private data at risk

  • All your transactions are processed by a third-party node

  • Exchanges or custodians can go bankrupt (i.e. FTX, Celsius)

  • In many cases, you don’t own any Bitcoin, just an IOU

  • Multiple layers of custodians may be involved, some hidden

  • Custodians can suffer exploits and hacks

You may also like…

As they say, you have to choose your hard. Bitcoin self-custody is not easy. It does

Read the original on bitcoinkatie.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.