Skip to content
TrackPodcasts
technologySep 3, 20268:08

Coldcard, Trezor, SafePal hacks... Is Crypto Self-Custody Dead Now?

About this episode

This story was originally published on HackerNoon at: https://hackernoon.com/coldcard-trezor-safepal-hacks-is-crypto-self-custody-dead-now.
The Coldcard hack, plus recent Trezor and SafePal attacks, raises big questions about crypto self-custody. Here's what they teach us.
Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #crypto-hacks, #coldcard, #trezor-hardware-wallet, #hardware-wallet, #crypto-exchanges, #obyte, #crypto-security, #good-company, and more.

This story was written by: @obyte. Learn more about this writer by checking @obyte's about page, and for more stories, please visit hackernoon.com.

The Coldcard hack, plus recent Trezor and SafePal attacks, raises big questions about crypto self-custody. Here's what they teach us.

Get every episode summarized

Each time The Good Tech Companies publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

86 searchable segments. Every word is indexed and playable.

Coldcard, Trezor, SafePal hacks... Is Crypto Self-Custody Dead Now?

The Good Tech Companies

0:00
8:08

Full transcript

The Good Tech CompaniesColdcard, Trezor, SafePal hacks... Is Crypto Self-Custody Dead Now?. Machine-transcribed; use the interactive transcript above to jump the player to any line.

This audio is presented by Hacker Noon, where anyone can learn anything about any technology. Cold Card, Trezor, Safe Pal Hacks. Is Crypto Self-Custody Dead now? By O-Bite. August 2026 was a roller coaster for the crypto space. Kind of a bad one. Just before the start of that month, some unknown attackers managed to take advantage of a bug in the Cold Card hardware wallets to steal up to $2,055 BTC, till $1,130 million, directly from users. This is being considered the largest hardware wallet exploit to date, and it was followed by more attacks on Trezor and Safe Pal, two other major hardware wallet providers. Self-Custody is thus caladinto question for many. We've been told, repeatedly, that our private keys must remain offline, out of reach for hackers and scammers. Therefore, numerous crypto users have chosen Toe Invest in more security and purchase specialized hardware devices to safeguard their coins. Now, among those who chose a Cold Card as this specialized device, several have lost their funds without even

doing anything about it, because the attack was completely remote and out of their control. It feels unfair, but wait, because there are still things to unpack before losing faith in self-custody. So, what happened to Cold Card and company? The first thing we must understand is that no, crypto networks aren't just insecure now. The recent attacks weren't against strong distributed ledgers, but against specific companies and their products. Let's start with the Cold Card case. The problem came from the way certain devices generated wallet seeds are private keys. In an average crypto wallet, just, guessing, seeds by applying brute force, many repetitive attempts, is impossible. A 12-word phrase alone has about 340 undiscillion possibilities. This implies, as knowing Bitcoin explains, that, I.F. every computer on earth tried a billion seed phrases per second, it would take trillions of times the current age of the universe to try them all. Unfortunately, it wasn't like that for some Cold Card devices. A software change introduced

in 2021 caused certain devices to use a software-based pseudo-random number generator instead of the hardware-based random number generator intended for creating secure seeds. In other words, the wallet security relied on insufficient randomness. Attackers were able to guess the private keys when they should never have been able to. Even after applying a firmware fix, those seeds are just not suitable to use anymore. Anyone who has generated seeds on a Cold Card between 2021 and 2026 IS advised to withdraw all their funds to a more secure wallet. What about Trezor and SafePow? At the very least, no funds were compromised in these two attacks. However, they John be considered equally serious, because personal data and physical addresses were, indeed, leaked. On August 12, Trezor informed that ShipMonk, one of their shipping providers, suffered a severe data breach that exposed the full names, phone numbers, email addresses, and physical addresses of almost 12,000 of ITS customers. In the same fashion, barely some days later, SafePow announced the discovery of a bug

that could let someone access or track customer order information without having the proper permission. Which some hackers did, confidential data like names, phone numbers, emails, and physical addresses from almost 40,000 customers with stolen. It seems better than having funds or private keys taken away, but it isn't. With all this information, hackers can easily find customers, carry out targeted attacks, phishing, and even plan, wrench attacks, or physical break-ins at their homes. Indeed, according to CERDIC, violent physical attacks against crypticers have increased by 33% in 2026, compared to the previous year. Should we rush to crypto exchanges, then? According to CMC, ColdCard HECK sends Bitcoiners scrambling for sexes. So, Arithi's safer for us, after all? Is that a real solution in the long term for crypto users? The answer isn't that simple. Centralized exchanges, even withtons of investment and security, can and have been hacked. In 2025, Coinbase, one of the largest exchanges worldwide, suffered the same type of leak as

Trezor and SafePal. In previous years, other firms like Liquid, KeepChange, Celcius, and OpenC faced major data breaches, too. Beyond that, numerous crypto exchanges have been robbed or bankrupted over the years, or they were just scams from the beginning. Mount Gox, Quadrigas CX, Cryptopia, and FTX are only some of them. Thousands of users globally suffered massive losses from these cases. That's why this motto is so common in crypto. Not your keys. Not your coins. However, now that self-custody appears to be threatened, what is the alternative? Where do we run to? You may think that, well, the flaws were limited to certain brands, so we just change brands and that's it. And that's still not the answer. The answer is that nothing in no one is exempt from failure. Self-custody requires more responsibility, while external custody presents a different set of risks. That's the thing, though. Neither arrangement removes risk. They put different risks on different sides of the table, and you need to choose which of these risks is, less risky,

for your own circumstances. Which benefits do you prefer? I.E. Full ownership versus convenience, and what are you willing to risk for them? Even Fiat currencies and banks have their own risks and disadvantages, and their pitfalls are the whole reason why cryptocurrencies exist. Sad, but true, new lesson. Don't put all your eggs in one basket. Decentralize, like crypto networks themselves. If one device, one manufacturer, one backup, one company, or one process can determine whether your entire stash survives, that's a single point of failure you need to fix ASAP, no matter how secure you believe it is. There are several solutions for this. A simple starting point is backup redundancy, with copies stored in separate locations so one fire, flood, or defective device doesn't wipe out everything. In O-Bite, you can create several text coins with different amounts in them, and store them offline. However, you'll have to take care of noting down your text coins, seeds, copying them to different secure locations, and taking care of them to the best

of your ability. The only way for self-custody is higher responsibility. For stronger protection, multi-signature wallets can require two or more separate keys before coins can be moved. A two of three setup, for example, uses three keys but requires any two to approve a transaction. That means losing one key doesn't automatically lock you out, while compromising one key doesn't give an attacker enough control. You can also spread keys across different devices or manufacturers, reducing dependence on one technology. In O-Bite, you can create a multi-signature, multi-device, account in just a few steps to increase your security and, if you wish, include other people asco-signers, not just your own devices. There's also value in testing recovery. A backup that has never been checked ESSA plan on paper, a successful recovery test provides evidence that the plan works, and complexity deserves its own warning label. Every extra passphrase, device, location, and backup adds another thing to remember and maintain. So, as crypto self-custody dead,

no, if anything, the bumps along the road make the idea more mature. Self-custody avoids potential financial censorship and can give people full control, but control comes with homework, from understanding how keys are created to knowing where backups live and what happens when a device fails. Toby prepared for a device to fail, even. Self-custody means taking ownership of the entire security model, not just buying a device with the words, hardware wallet, on the box. Do your own research, dy-or, on every brand, every software, and every process. This is worth repeating. The only way for self-custody is high responsibility. Thank you for listening to this Hackernoun story, read by artificial intelligence. Visit Hackernoun.com to read, write, learn, and publish.

More episodes

More from The Good Tech Companies

View all episodes →