Total sovereignty is a total single point of failure: you're trusting someone either way
26-08-01

Coinkite disclosed that a firmware integration error stopped the hardware random number generator from feeding seed creation on Coldcard devices, falling back to a deterministic software path instead. The bug went in with a single commit in March 2021 and sat there for roughly five years. Affected Mk3 devices produced seeds with around 40 bits of effective entropy against a 128-bit target. Chainalysis has linked the flaw to more than $38 million in drained Bitcoin, and the estimates are still moving.
Read that again. Not a phishing site. Not a fake Ledger email. Not a $5 wrench. The device sold specifically to be the paranoid option was quietly generating guessable seeds for five years, and nobody noticed, including the people who wrote it.
If you own one, go read the advisory first. Seeds made with a passphrase or with 50-plus private dice rolls aren’t considered at risk. Anything else generated on affected firmware needs to move to a fresh seed.
There is no trustless option
The self-custody pitch has always been that you remove counterparty risk. You don’t. You relocate it.
- You trust the wallet company to build hardware that isn’t backdoored and to survive long enough to patch it.
- You trust the wallet software to generate your seed from real randomness, which is exactly what failed here.
- You trust the supply chain that put the device in your hands.
- You trust yourself to store 24 words for decades, not lose them in a house fire, not get socially engineered, and not die without your family being able to recover them.
That last one is the biggest risk in the list and nobody wants to price it.
The exchange version is narrower: do you trust a licensed, audited, capital-buffered institution holding client funds in segregated accounts? It’s the same class of question you already answer every time you leave money in a bank. Nobody frames a checking account as reckless.
What I actually recommend doing
Treat a MiCA-regulated exchange like a bank. That’s where the bulk sits, because that’s where the security budget, the HSMs, the round-the-clock defense team and the legal inheritance path are. Spread it across three of them, so no single failure, freeze, outage or bankruptcy takes the whole position. That’s diversification, the same reason you don’t keep every euro at one bank.
Then keep a hardware wallet for the smaller amount. Not because it’s safer, but because it’s the part you can move without asking permission, and because having some coins fully outside the regulated perimeter is worth something on the day it matters.
Yes, that’s handing over a piece of sovereignty, and I’m fine with the trade. Total sovereignty is also a total, undiluted single point of failure: one seed, one device, one firmware bug you had no way of knowing about, and it’s gone. No appeal, no insurance, no recovery, no support line. I’d rather give up some control to institutions that answer to a regulator than keep every last bit of it and carry the entire downside of one bad event alone.
Eggs across baskets, and that’s the whole strategy. Three regulated custodians, a small amount on the wallet, nothing that goes wrong in any single place being fatal. Then stop thinking about it.
What about multisig
The obvious objection is that it doesn’t have to be one seed. Run a multisig instead: two of three keys, different vendors, different firmware, so no single device and no single bug like this one can drain you. That genuinely removes the single point of failure, and if you’re holding enough to justify it, it’s the correct answer.
But it isn’t free. Now it’s three devices to buy, verify and keep alive, three backups in three places, a wallet descriptor that’s as critical as the seeds and that almost nobody stores properly, and a recovery you have to rehearse rather than assume. The odds of losing everything to one catastrophic event go down. The odds of losing it to your own mistake go up, because the complexity went up and the error surface with it. You’ve traded one big failure mode for a wider spread of small ones, and small ones are what people actually hit.
The alternative
Going all the way deep means not just the multisig, but everything around it. Dice rolls for your own entropy instead of trusting the device’s RNG. A passphrase on top of the seed. Geographically distributed metal backups. Test recoveries every year. A written inheritance plan your spouse can actually execute.
All of that is legitimate, and if your threat model calls for it, do it properly. But be honest about what you’re signing up for: a permanent second job, a setup you’ll be too nervous to touch for years at a time, and the exact anxiety the whole thing was supposed to eliminate. Then a disclosure like this one lands and you spend a weekend checking whether your seed was in the affected batch anyway.
You were never choosing between trust and no trust. You were choosing who to trust, and how much of a personal security operation you wanted to run. Pick the split that lets you sleep.
For the longer argument on why regulated custody stopped being a compromise in Europe, see Not your keys, not your worry.