Self-custody security in a post-Coldcard vulnerability reality

A recent vulnerability in Coldcard hardware wallets has challenged the market’s previously held views on self-custody. Attackers have stolen more than $100 million worth of Bitcoin from wallets created on Coldcard devices with faulty firmware.

Self-custody security in a post-Coldcard vulnerability reality

Introduction

The root issue in the attack was weak random number generation during seed creation: affected devices produced roughly 72 bits of entropy instead of the expected 128. The fallout was that users had to migrate funds to new keys while Coldcard’s parent company,Coinkit, halted new device shipments.

The incident raises the difficult question: how safe is self-custody compared to alternatives, such as multisig and exchange custody? In this blog, we analyze the trade-offs and recent data on where Bitcoin is flowing to help individuals and institutions plan their security strategy post-Coldcard.

What we know

Coinkite’s advisory on July 30 confirmed that Coldcard Mk3 and some Mk2 seeds lacked full entropy unless users rolled at least 50 dice during setup. In practice, many users trusted the device’s RNG alone and unfortunately ended up creating vulnerable seeds.

Galaxy Research, a notable blockchain research firm, mapped large sweeps of more than 1,000 BTC drained in less than an hour. Subsequent waves brought the total to more than 18,000 BTC from more than 5,200 addresses.

Coinkite’s response was to force a migration. Its blog emphasized: “If your seed was generated without enough dice, migrate now.” The company shipped patched firmware on July 31 but noted it cannot repair existing seeds.

Single-sig vs. multisig vs. custodial

The Coldcard case highlights that no custody model is infallible. All single-sig wallets rely on a single RNG process. Here’s a simplified risk comparison:

image.png

 

Notably, Galaxy Research observed the thief targeted single-sig Coldcard wallets specifically. Galaxy cautioned that “multisig helps only when the quorum is not built entirely from affected devices.” This means that even multisig needs diversity because if all keys were generated on flawed Coldcards, the setup remains vulnerable.

A truly resilient multisig setup might use devices from different manufacturers or add host-derived keys. Some also use advanced schemes like Shamir Secret Sharing or seedless custody.

Regulated platform custody can be one part of a broader custody plan

Self-custody gives users direct control over their Bitcoin. But it also leaves every security decision in the user’s hands. A hardware wallet, seed phrase, firmware update, backup method, passphrase, and recovery process all become part of the same risk profile. If one part fails, the user may have limited options.

Even experienced self-custody users have now realized they are exposed to risks they may not have identified until after the fact. A single-signature wallet can work well when everything is set up correctly, but it still depends on one seed, one signing setup, and one recovery path.

Some users may compare regulated platform custody as one option while reassessing their self-custody setup.

Specifically, Ndax’s custody model is designed to reduce the single points of failure that can exist in a do-it-yourself setup. Client crypto assets are held through a hybrid custody framework that includes third-party custody arrangements subject to Ndax’s regulatory and operational controls. A significant portion of client crypto value is held in cold and warm storage with functionally independent custodians. A smaller portion may be held internally to support operational needs such as deposits, withdrawals, settlement, liquidity provider activity, and staking operations.

What this means is that risk is not concentrated in one personal device, one seed phrase, or one user-managed backup. Instead, platform custody relies on institutional custody processes, operational controls, compliance oversight, and defined procedures for handling client assets.

Ndax is a regulated crypto trading platform. Ndax provides an Order Execution Only (OEO) service. Ndax executes clients’ instructions but does not provide investment advice. Clients decide when and what to trade.

Regulation framework matters

Ndax operates within the Canadian regulatory framework and is registered as an Investment Dealer, is a CIRO member firm, and is recognized as a marketplace that operates as an Alternative Trading System across Canadian provinces and territories.

This means Ndax operates under a more formal standard than an unregulated venue or a purely self-managed wallet setup. A regulated platform may be one option users compare when reviewing how to hold, trade, or transfer assets during a custody review. Users do not need to immediately rebuild a multisig setup, test new hardware, generate new backups, or manage multiple keys before deciding what to do next.

This is not to say that self-custody is discouraged. Rather, it makes the case for having more than one custody option.

Many users choose to hold long-term assets in self-custody and use Ndax for trading, liquidity, or temporary custody during security events. Others may prefer to keep assets on a regulated platform because they value operational controls, Canadian oversight, and a simpler user experience over managing private keys themselves.

When a self-custody setup becomes uncertain, a regulated Canadian platform like Ndax may provide another custody option in a structured account environment while users assess the risks, controls, and responsibilities of each custody model. 


Don't forget to follow us on social media for more updates and join the conversation on our forums.

Disclaimer: This article is not intended to provide investment, legal, accounting, tax or any other advice and should not be relied on in that or any other regard. The information contained herein is for information purposes only and is not to be construed as an offer or solicitation for the sale or purchase of cryptocurrencies or otherwise.

Self-Custody Security After the Coldcard Vulnerability