Skip to content
TrackPodcasts
technologySep 16, 20261:07:00

Institutional Custody, Multisig & the War on Cash | Mike Belshe SLP773

About this episode

Mike Belshe, co-founder and CEO of BitGo, walks through how institutional Bitcoin custody actually works in 2026: qualified custody, self-custody co-signing, and why BitGo still centers a 2-of-3 model after pioneering P2SH multisig in 2013.

BitGo now operates as a US-regulated qualified custodian and public company, while still offering the same wallet stack individuals can run in self-custody mode. The conversation covers what “institutional security” means in practice — HSM-backed co-signing, open-source recovery paths, multi-jurisdictional key storage (including how BitGo moved WBTC when US regulation looked hostile), and why on-chain multisig still beats vendor-locked MPC for cold ops.

They also dig into the political and operational risks around large Bitcoin holdings: KYC and PII as honeypots, France tying names to amounts, the war on cash reaching Bitcoin, and whether an EO 6102-style confiscation risk still belongs in the threat model. On the institutional side, Belshe pushes back on multi-custodian setups that add failure modes, explains insurance limits versus the size of the Bitcoin market, and why splitting wallets matters after events like Bybit.

Timestamps

00:00 — Intro: Mike Belshe of BitGo

00:59 — Don't Lose Self-Custody's Power

05:41 — Retail Deserves Institutional Security

07:16 — Humans Are Terrible at OpSec

09:56 — 2-of-3 Protects Theft and Loss

14:35 — Retail Pays 160 Basis Points

19:22 — Why People Drift Toward Banks

20:35 — Self-Custody Is Never Trustless

23:39 — Why BitGo Sticks to 2-of-3

30:31 — A Public CEO Holds Zero at Home

31:27 — KYC Leaks Are Government Honeypots

39:28 — France Doxed Bitcoin Holdings

41:30 — War on Cash Reaches Bitcoin

43:45 — Multi-Jurisdictional Key Storage

45:29 — Executive Order 6102 Could Return

47:43 — Quantum-Resistant Wallets Today

49:27 — Multisig Beats MPC

53:33 — Splitting Custodians Adds Failures

58:29 — 2-of-2 MPC Can't Recover Loss

01:00:57 — $5–7B Insurance vs $1.6T Bitcoin

01:03:35 — Bybit Lost 10x by Not Splitting

01:05:21 — Multi-Institution vs Qualified Custody

Links: 

Stephan Livera links:

Get every episode summarized

Each time Stephan Livera Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

1,101 searchable segments. Every word is indexed and playable.

Institutional Custody, Multisig & the War on Cash | Mike Belshe SLP773

Stephan Livera Podcast

0:00
1:07:00

Full transcript

Stephan Livera PodcastInstitutional Custody, Multisig & the War on Cash | Mike Belshe SLP773. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Hi everyone, welcome back to Stefan Levera podcast. Rejoining me on the show today is Mike Belchie CEO and founder of Bitgo. Mike, I think it's been maybe six or seven years since your last appearance on the show. So welcome back. Well, thanks for having me back. I guess you probably took a pause for the last five years or something, huh? That's right. Well, who knows. But obviously, I thought there's lots of things going on in the world of Bitcoin and security and AI. Thought it would be a good time to get you on to talk about it. Obviously, hearing a range of views across the industry, whether that's relating to people who are doing like full self-custody stuff or obviously like yourself running one of the largest Bitcoin custodians. So let's just start there. I mean, obviously, this recent round of hacks and attacks in the Bitcoin world has got a lot of people concerned. Do you have any initial reaction on that? I have a lot of things to say.

So let's see. For anybody who doesn't know who Bitgo is, we've been around since 2013, started as a technology play for how do you secure Bitcoin better? That was like the original thing. And we helped pioneer the use of multi-sig and the Bitcoin wallets. We didn't invent it. You know, as built into the Bitcoin protocol, you know, as part of P2SH way back when, but basically made a usable form of what's now known today as multi-sig. We do a two out of three variant and help push that forward. I think what's going on right now is actually we're at a transition, which frankly, I think we talked about all the way, you know, 10 plus years ago as a community, as an ecosystem, which is how much of this belongs in banks and how much of it belongs in self-custody. And before anybody thinks I'm going to just go pitch the bank thing, look, I am a huge huge fan of self-custody. And I think that if we ultimately lose self-custody, and by the way, it's not a guarantee that regulators

won't come and ban it. But if we lose self-custody, we lose the power. We will end up with a system where there's a set of gatekeepers that control the banks, and they get to decide whether you're in or you're out. And most of the time, that probably works more or less okay, and sometimes it really doesn't work okay. And then you're really sad that you didn't have self-custody. So Biko offers a full complement, although we're known for custody, or license, or US, regulated, federally regulated bank here. I think we're the largest independent bank in crypto of any other player, although we're known for that, everything we do we offer in custody and self-custody modes. And in fact, you can come to Biko, you can come right now, you get full free access for individual users of all the self-custody, you can upgrade to custody if you want, etc. All right. And the transition I think that's happening is the asset class has gotten big enough, and the security requirements, you know, to secure assets of that value has now reached a level where people are like, wait a minute, can I secure this myself?

So first off on the thesis and the premise, a lot of people are really excited about self-sovernty. The ability to hold it on your own, have your own control, nobody can take it from you. It's a really important thing. But then that's got to trade off of like, well, wait, what lengths am I willing to go to? To secure my assets. And then also, who can I trust? Now 10 years ago, there was nobody you could trust because none of the banks were touching it, none of the traditional players that had built up all these layers from regulatory to security, etc. were there. These days, I think that part is definitely changed. But you still have the issue of like, what goes into securing your own money, how much you're comfortable with. And I think here's an interesting question for you, for me, for anybody. What percentage of your net worth would you be comfortable having responsibility to secure yourself? And it's an important question you're going to have to grapple with, even if you're the biggest believer in Bitcoin. At some point, you know, Bitcoin way bigger than ever in the market.

Maybe it's 98% of your net worth. How much are you comfortable holding on to yourself? I mean, for me, I am one of those dice roll multivander, multiseg guys. But even for me, I certainly do believe that you can spread it around. Like in earlier years, and don't forget, I think many of us have grown up in this, like, at the time many of us first got into Bitcoin, especially like I'm 38 and a lot of other Bitcoiners are kind of similar bracket. When we first got into it, we were single, no kids. It's like now, you know, married with children, like your life, you know, risk profile changes. Yeah. Like what the risks you're willing to take when you're, you know, 25 or 24 or whatever, like versus now, I get to call every month. I get to call every month from somebody that's had Bitcoin. They've been holding it 10 plus years and they're like, you know, it's enough value. It's enough of my net worth. I got to figure out like what's going to happen. I think my spouse could handle it if I disappeared, but maybe not. I'm the technical one.

And you know, how do you pass that on? It turns out to be tough. So it's a real challenge. Yeah. And of course, there's no one size of it's all. It's all kind of like, what's your net worth? What percent of your net worth is Bitcoin? And if it's a very large percent of your net worth, then yeah, you do need to be extremely careful about how you do that, whether that's like doing, going full DIY self custody, or you kind of use a guided solution or use a custodian such as yourself or use, you know, a bit go wallet, this kind of thing. So I guess all of these questions are going to happen. Is the same thing that happened with traditional finance, you know, I mean, you know, there was a time when people held on to their own assets. You had it in your house, right? It was the wild, wild west. And then banks did start to emerge. And then you had this problem of like, well, that looks like a reputable guy that's going to hold my money. He says he's a bank, but like, what if he runs away? And were there rug poles in the 1800s? Absolutely. There were rug poles from folks posing to be banks. You know, obviously nothing to do with digital assets. This happens.

And eventually, you know, you build up layers of systems and you build up some regulation, you build up some laws and you build up some insurance. Okay. So I think it's a destiny that of course we're going to have a mix of the two. And as a, as an individual, you're going to have a choice. What do you want to put where? So just like you have some cash in your wallet, and probably you wouldn't want to lose that cash in your wallet, you probably also wouldn't mind terribly. And it probably wouldn't completely destroy your life if you did. But as you go forward with all of your assets, and remember, it's not just Bitcoin, right? Your stocks are moving, tokenize your stable coins are moving tokenized. Everything is moving tokenized. So there's going to be more than just Bitcoin in terms of assets that you're going to need to figure out how to protect either at a bank or not. And then lastly, as the value goes up, I think individuals need to start thinking a little bit more like institutions have it. At BICCO, we have the saying we say retail deserves what institutions demand. And BICCO started back in 2013. And at the time, the people that gravitated towards what we built, the people that had

lots of amounts, lots of amounts of asset. And so they were willing to pay some for security. So we quickly found ourselves down this institutional path. But at the end of the day, why is the security of institutions somehow better or more advanced than individuals? Well, humans are good at some things, but security is probably not one of them. In particular, opsec, we are terrible. I am, you are, I call everybody out. There's not an elitism here. Like humans just are not very good at opsec. And so the structure that we built with multi-sig, you know, two out of three, the number one principle of securing your asset is don't have a single point of failure. So if you have a single person that's responsible for your money, hey, make it so that there's two. If you have it in one location, hey, make it so there's two. If there's one private key, make it so that there's two. If you have a single machine that can have malware on it, make it so that there's two.

So this is a problem that we solved literally over 10 years ago. The ease of use of multi-sig has been perceived to be hard. I would argue that we have this solved at BICO and please, like try it, love feedback, like there's things we can do to make it easier, absolutely always open to that. What are you doing this for a long time? At the end of the day, when you're using a multi-sig wallet at BICO, you really can't tell much difference between that and a single-sig wallet. But I'll tell you one big difference. When you get malware on your single-sig wallet machine, whether that's your phone or whether it's your desktop, and we see these posts on X every single day, I opened up a new wallet, I just provisioned it, I deposited $10,000, and now it's gone five minutes later. Why did that happen? You had malware on your machine. That's why it happened. And with multi-sig, much, much harder. Now, there's still more to be done than just multi-sig. I'm not trying to say there's a panacea here. But we do put all of that multi-user like you and your spouse both want to be on the account. Pretty simple. You want to have like a spending policy. Hey, spend $1,000, who cares?

Spend it. You want to spend $1,000,000? Maybe I'm going to get a second person to approve that. And I'm going to do that through a high security mobile app, which got another application level programming key around it. Anyway, all these bells and whistles that we've been building for institutions for the last 12 years, I guess, 13 almost. We make them available to individuals as well and try it. It's not hard. So it talks to us a bit about the suite you offer then. So on the Pico wallet side or the self-custody side, can you talk to us about how that's working? Is there, can you use like a hardware wallet with that or is it more just like a phone and a server or what's the model there? When you provision the wallet, it gives you a few choices about how you make your keys. So we use what we call a two out of three model. It protects against both theft and loss. So theft is like no single point of failure. You can't have a single machine breach and lose all your money. Loss. We worry about it less, but we probably ought to worry about it more. This is where you, me as a user, we forget our passwords, we lose our keys, we forget

our seed phrases, our house burns down and we didn't realize, oh shoot, I have my ledger and my seed phrase, both in the same house. Loss is the backup key. And the challenge with backup keys is that you can recreate the single point of failure problem. So first you devise a system so that there's no single point of failure, but then you create a backup, well, that can't be a single point of failure, really. Just giving a key to a lawyer or whatnot, well, he can steal all your money. And of course, this has happened many, many, many times in history. So we use this two out of three model, which protects against both. I think we're the only ones to do it. We do it on every chain we support. We think it is a fundamental underpinning that you absolutely have to have. The alternative is to create a secondary backup, which has a single point of failure problem. All right, so in this model, we hold one key and you hold two keys. So when you provision a wallet with us, that one key we provision on our servers, it's in HSMs, we've been doing, there's a hardware security modules, we've been doing that longer than anybody, because we're the first, kind of into the space that they were in generation four or something like that now.

And then the other two keys, you get some flexibility of how you create. If you just created through the browser, one will get created in your browser. Another one you can use like a coin cover is a third party service that we use. They've got a provisioning system that they've done completely separate. Or if you want, you can bring your own third key, you can provision that however you wish. So you've got a lot of flexibility. And of course, all of this is available programmatically, although individual users use that less, it's probably more for businesses. But you can, so you get total flex in terms of how this does. Then we give you some backup materials in terms of a key card, which by itself, you know, doesn't, doesn't create any single breach point. And there's a couple of other security features that we build around it. But you get a lot of flexibility. So if we disappear off the face of the earth, you can still fully recover your assets. By the way, we put out this thing, it's open sources on GitHub. It's called the wallet recovery wizard, which allows you to recover any BICO wallet, self-custy wallet.

The hard thing about that is a simple tool generally, except we don't use any BICO services as part of that recovery. The whole point is that you can recover your wallet without us, right? So imagine we disappear whatever reason. Good, bad, nuclear war, I don't know. You can use that tool. And by the way, our clients audit this stuff. They care a lot. They want to make sure, and these are big clients, our institutional clients are using self-custy. So you know that like, hey, if for whatever reason BICO isn't there, be it regulatory, be it business fails, be it nuclear war. All right, so they test it. Anyway, you can use that to recover completely without BICO. Anyway, you get a lot of flexibility. And then on the custody side, you can also use custody. Of course, for that, we have to go to an AMO KYC process. This is a regulated institution. It's got insurance behind it. It's 100% cold storage. That means all those assets are offline. In that case, BICO does hold all three keys. You can still withdraw 24 hours a day, seven days a week.

We've got staff that manages that. We stick true to the cold storage. We also make it faster by we've got some hot buffers where we can fulfill a withdrawal without having to go all the way to cold storage. When we do that, that's our risk, not your risk, your money's in cold storage. So you can then use a blend. And you can just decide. I'm going to have this wallet for my self-custody. I'm going to connect it over here. I'm going to be doing defy stuff like crazy, whatever. And then I've got my savings on this other side. You can mix them out. And then give us an idea, what are the fees? What are the costs for these things, whether you're doing the self-custody side of it or the custody side of it? For individuals, you can come to BICO and you can do everything I just described at no cost. So give it a try and let us know. We hope that some of our individual users will then use our trading services and our staking services. And we make money there. Or maybe you want to take a loan. We make money there. So in general, what we found is people don't mind if we're taking a small clip as part

of them making money. So when you're doing trading or activity, pay for the service. One thing I will say. I think our industry has failed retail in terms of living up to our promises of lower fees and fewer middlemen. And you can go right now and you can go look at the public financials for the largest US-based retail exchange. And you can say, hey, Claude, what was the retail trade, I'm sorry, what was the take rate on retail trading in the last quarter for that company? And it's going to come up with an answer of about 160 basis points. Institutions don't pay 160 basis points to trade. I shouldn't say they never have, but they just don't. I mean, the fees that we charge institutions is in the tens of basis points at the best. And you can see this by going to BICGO and looking at, doing it, asking the same question, what's BICGO's take rate on trading? And you'll see a big difference.

We offer the same price to other clients. The other thing is we're not in exchange. So when you go to your broker for stocks in the US, there's this regulation called the best execution. Broker dealers are required by law in the United States. When you go to buy some Apple stock, so you get to the best price they can. That is they can't fill your trade with their cousin Vinny and charge you an extra 160 basis points. No, they have to get to the best price. No such rules exist, of course, in crypto. And further, when you go to any single exchange, that's only one price. So again, back to the market, like the best price could be on the NASDAQ, could be on the bads exchange, the American exchange could be on any one of these exchanges. But the broker connects you to all of them and always gets to the best price. When you go to a retail exchange in the US today, that's a single venue. What BICGO does is look, we're not in exchange. We have a smart order router. And what that is is we take your order and we route it in and we get to the best price

wherever we can get it. We go to all the market makers, we go to all the exchanges, we connect all over the planet. By the way, we're regulated not just here in the US, but we're regulated seven different seven different jurisdictions, Qualified Custody and doing a lot of activity. So we'll get to the best price. Well, what do you think the chances that are that that whatever retail exchange you happen to be on is giving you the best price today? Not very good. I mean, it's whatever its market share is. It's got 5% market share. It's probably what's going to be, right? And look, frankly, everybody in the in the industry knows if you're not trading on one of Binance, buy bid or OK, X, you're simply not getting the best price. The US prices are just way higher. So anyway, BICGO connects globally, we get to the best price wherever that comes from. And then yes, we do charge a small fee for that. But the fee is less by a lot than what those other retail exchanges are charging you and you can check it in the public financials that we publish as a public company. And secondarily, we're getting the best price anyway across the planet.

Whereas they don't. And then on the custody side, what are the rough fee ranges again for individuals as free? Yeah, I mean, at the institution custody level. That's a different, that's a different thing. It varies, right? So like when an ETF is holding just Bitcoin, look, we can't stake it. Like they're not trading it, like, et cetera. So we charge them some fees, but that's going to be different than others. In general, look, I believe custody is really part of it. A new move to a reserve banking system that we haven't seen in quite the same capacity ever. And it's thanks to Bitcoin that we now have this. We have a whole banking system around depositories, which is different than what BICGO does as a banking system around reserve. So depending on what activity you're doing, we don't lend out your assets ever. We're not allowed to do that. We don't want to do that. It's your assets or your assets. We can't, we can't hypothesate it without your permission. So sometimes we have to charge fees, but it varies. So anyway, I know I'm being a little bit non-answer over your question, but it's because it's

complicated. On the retail side, it's much easier. I see. OK, yeah. And then I guess coming back to what we were saying about like, where is the industry going? As you said, so your points earlier have been, OK, people are being charged too much in terms of exchange fees. In terms of custody, do you think a lot of people are going to get spooked by a what happened with some of the recent hacks, whether that's the cold guard one or liquid or kind of addresses being doxed? There's been a lot of these things, as I'm sure you're very well aware of. What do you think that means for the industry? Do you think new people will just kind of all go to the ETF or go to custodians instead of self-custody? What do you think? I think over time, yeah, people move their assets to banks and custody in general. I think when you really think about large amounts of your net worth being tied into jail assets, it's a lot of responsibility. It makes people scared and nervous to hold it on themselves.

Without getting into the hacks, I mean, just for a moment, I mean, even think about how do you protect against fire? I mentioned it earlier, but you got to have your key and then you got your backup key. Right. And the single answer would be, OK, get a metal backup and you got to have metal backups for each of your keys. And this kind of thing. Or you put in a safety deposit box. There's other ways to do it off site. But all of these are hard and most people don't do it. The other thing that happens is a lot of people are getting into crypto today. And when they get in, they're like, OK, here's $10,000. It's meaningful, but it's not like the end of the world. But then that asset can grow. So when they set it up, they set it up with security at home for how they would secure something that's worth $10,000. Now it's worth a million dollars. And when you're thinking about how you secure something that's worth a million dollars, of course, you've got to think at a different level. So you know, wrench attacks obviously become a thing, especially if you're in France. And then lastly, I think what happened with cold card is that we like to think of self-custody as being trustless. But it's actually always naive.

There's always trust somewhere unless you're deriding the whole damn thing as a developer yourself. In which case you have to trust, you didn't make bugs. You have to trust yourself. They're really good to come. And then they're still hardware involved. So good. Well, there's hardware, there's supply chains. There's the algorithms that are used. So with cold card, like obviously the random number generation was done inadequately. People were trusting that this was done by professionals that wouldn't make those types of mistakes. Most people don't even really know how critical the random number generator is, even though a private key is nothing more than a random number. It's critical. And so they were trusting that that was being done. That trust was breached. Now they're thinking, what do I do? By the way, the answer is still, whether it's Biko that you end up using or somebody else, multi-signatures better because instead of having one random number, you've got three random numbers that are protecting your asset. Now, the next thing you have to think about is like, well, where are those random numbers being generated? Because if they're all being generated with the same broken RNG, you're still in trouble.

The Biko model that I described where the keys are generated in different places, it's different implementations for each of the keys. So think about the probability of a failure. Like an insurance guy's thinking about this all the time. Like, what's the probability that one of your keys was done badly or you had malware on it at the time you did? 0.001 percent, whatever. What's the chances that two keys had that? Well, it's 0.01 times 0.01, which is 0.001. So the way you make things really rare is by eliminating single points of failure. You can't completely account for every possible type of risk. You should think about as many as you can, of course, especially when it's self-custy, especially when it's a lot of money. But the next thing you need is you need to be able to do this kind of multiplicative protection by way of reducing risk across those things. What if I were? Yeah. Now, I think for a lot of people, it kind of, you have to balance all of these different

things. As you said, remove these single points of failure. Sure, absolutely. And that's where people in the self-custody world will be looking at, okay, I use maybe two or three or three or five with different hardware wallet types. So that way, we're diversifying that way. So we have full tolerance. But then you layer on those other aspects of like, okay, not just that, but how do I make sure it's redundant? How do I make sure it's, inheritance is handled. But like, when I die, that my wife and kids will get the coins. You know, all of these things, it's kind of like, how do you balance all of these things together, along with the complexity of doing with different device types, right? Because if it's just one device type, that's kind of easy enough. Maybe you can teach your wife to handle that. But once you now start, okay, well, actually, it's this hardware wallet type A, type B, type C, et cetera, the complexity does start to blow out a bit. So let me give a suggestion. So over the years, so many people have come to me and said, like, oh, it should be a two

or three, a three or four, three or five, and there's a lot of great ways to protect things. The reality is, is a trade off of security and usability. So having spent a lot of time, it's not that I'm wed to like two out of three. It's like the one thing and we stick to it. Like we've really tried to figure out, is there a better, better model? The nice thing about two or three is that the usability is really pretty strong. So first off, you've got your account. It's a username, it's a password, it's a two factor authentication. I strongly recommend a Ubikey, something that's got a physical component to it. Perfect. Yeah. Perfect. You know, Biko hasn't used SMS-based two factor authentication since before anybody else banned it, eons go. Okay, but it starts with that. And then, I lost my train of thought here. Yeah, so you were talking about how the two or three as the model and then, you know,

password user password and Ubikey versus others. Right. So Biko has one co-signing key and you tell Biko and you configure it and it's all cryptographically done. Like what policies you want to have in terms of approvers or spending limits or delays and all this kind of stuff. And we can take care of that. So normally when you're interacting with your wallet, you're basically coming in, you're signing, you're presenting a key in a signature, but you only had to deal with one, we deal with the other one. That's how you get the no single point of failure. There's still a third key, which is a backup and hopefully you never have to use it. It sits in a vault somewhere and like, it's fine. When you move to the three of five model and by the way, Casa does a good job of this. So Casa is also kind of a retail thing. Well, now you've got five keys, you've got to figure out how to protect, right? So you might have a co-signing key at Casa and then they, they give you recommendations on where to put the others. Well, first off, your co-signer cannot have a majority because then that's not self-custy. So you have to have three, they can only have that most two. But now where do you put those keys? And they recommend one at home and one at your office and then one is a backup, which

is a reasonable thing to do. But it turns out to also be hard. So it is a level up in terms of how much complexity do you want to have. So the two out of three model, I think solves the issue of no single point of failure, solves the issue of having a backup and is usable by you. At the end of the day, you've got one key. It looks exactly like you're using a single key wallet, except for that you're not using all of these things. So that's why we like it and it's served pretty well. Certainly compared to any single key model, it's better. And then it solves this problem of having to trust a single RNG because you've got multiple keys that contribute into that. In terms of the other things you mentioned, like your spouse, all BICO accounts are multi-user accounts. So you can invite your spouse onto the account. And then you can even choose roles for you and your spouse. So there's administrators that have control level, concept policy.

And by the way, once you have two administrators, if you want to change the policy, you've got to get approval from both administrators. Then you've got spenders, then you've got viewers. So if you have an accountant, you can bring your accountant right in. They can look right into your accountant, see exactly what's done going on so they can pay your taxes or whatnot without having any private key material. All right. So it's multi-user. And then there's policies. And there's all kinds of policies that we build. Just recently added IP restrictions, location restrictions. I think we've got timing restrictions, velocity limits. So there's a bunch of things. This gets pretty complicated. I think actually maybe the things that the team is working on in terms of the retail usage is to kind of just give a couple of simpler suggestions. I think one of the great things that Steve Jobs did is he takes away choice. He limits the things you can configure. And on one hand, that seems like, ah, you're preventing me from doing what I'm trying to do. But on the other hand, there's some good reason for it because it helps make sure that

the design is clean. And then you're not getting into corners where you can get yourself into trouble. So there's still more work to be done. I think for Bicco and others on that. And that's area we focus on right now. I'm curious. Would you say there's a threshold above which people really should look at having a professional custodian? Like is there a threshold above which even with multi-seq, you think people should not self-custody? Or at least they should start thinking about splitting and having like some in their own self-custody multi-seq and maybe some with a big custodian, this kind of thing. I think it's up to everybody to decide on their own. I'm not sure if everybody actually is equipped to decide on their own, but I'm really about liberty. So I think it is your responsibility to figure out what that number is for you. And by the way, if you've gone through life changes where when you started in the industry, you weren't married and now you are married, you might have a different risk profile either of your own making or by way of your family.

So anyway, I think you got to figure that out on your own. It's, I wish I could say it's easy. By the way, so somebody that lives in the Philippines, their economies are very small compared to US economies generally. So of course they're going to have just a very different number. I had a venture investor years ago. He got into Bitcoin. It was before we were custodian all. We just had self-custody wallets. And the wallet got to be worth, I don't know, a couple hundred thousand dollars. And for this guy, it wasn't a big deal, but he was nervous about it. He's like afraid. He's going to lose the money. And so he just had to get out. We didn't have CUS. He sold his Bitcoin early because he was so nervous about holding on to what he felt was a large amount of money under his own control. Even though his net worth was so much more. So it's really a personal choice. I don't think there's anything wrong with his conclusion. That was his, his choice. Similar to like if you had gold, you know, how would you vault gold?

Or if you had a lot of cash, how much would you put in your closet? How much would you put in your closet before you got bars and you put them on your window? How much would you have in your closet before you decide to hire a security guard or get a get a gun? These are personal questions. Yeah, okay. And so then coming back to the, yeah, I think it's, I get, I can only speak of let's say trends or let's say typical things that people would do like above a certain, let me have one more thing. Yeah. You see, you have a public company. I've gotten to a little bit higher public profile. So for me, the answer is zero. And I, I just, I don't want to have anyone thinking that they can come and, and do anything physically to me to either take my money or the company's money or clients money. Simply won't work. So anyway, I think that also comes into, into account, which is like if you're a celebrity

profile, yeah, what are you going to do? Yeah, absolutely. If you're a public name, especially if you're a public Bitcoiner, then yeah, maybe that tips you more towards like, obviously multi-seag and of course maybe some of that with professional custodians or whatever, different kind of diversifying out your exposure a bit. Of course, there'll be different views on that. But I also want to get back to just for listening to the other one. Did you see the, do you see the Revolut news this week? Yeah, unfortunate. So there was like a KYC leak and basically they leaked the KYC data to someone who was faking to be the government basically. And so that's like, I mean, it's AML KYC laws, FATF sanctions laws, all this stuff. I mean, yeah, it's hard to look at me. First off, you know, I feel sorry for the victims, especially given kind of what's going on right now. A second thing, you know, look, Revolut screwed up here. Now being at a regulated firm, I've seen this stuff come in. It's interesting. But the first time you get an email from some guy at DOJ, you're like, huh?

Like he's just emailing me like, how am I supposed to believe this guy is actually at the DOJ? Yes, you actually have to check all these like the idea that somebody's going to just send you an email. I mean, that's not an authentic, authenticated channel. But the government officials all do it. I'm not talking about just DOJ, like the states all do it, the federal all do it, etc. And then you have to say, no, I have to, I have to verify you out of band in order to be able to answer this, you know, the Sunsupinas right over the email. It's crazy. So, but then the second part of this is not just Revolut. Like we have seen PII leakage over and over in our financial sector and has nothing to do with crypto. It has everything to do with the fact that we've created these honeypots. I don't think there's a solution coming here, unfortunately. I think the government wants to know where your money is. There's a war on cash. They want more of it put into the institution so that they can get a handle on it, kind of if they ever need it.

And I think it's unfortunate. So the government creates this. The government does nothing to protect individuals. And you know, you can yell at the regulators. It's not quite their fault. There's kind of layers of this. It starts with legislation goes into this regulator and then ultimately into this enforcing regulator. And the enforcing regulator is just like doing his job. So you can complain to him all you want, but you got to go to your lawmakers if you want to get rid of this. My own personal belief is that the PII collection has never worked for stopping crime. And there's I think there's very little evidence that it does work very well. I think it's mostly about making sure you pay your taxes actually. And they say it's about financial crime, but it's really about paying your taxes. So it's unfortunate. They are putting us at risk. Inc and a change. That's one thing that you lose when you go into custody. Yeah, that's it. I mean, this is one of, I've spoken about this on the podcast and I've hosted people who like there's an academic Ron Paul, not Ron Paul, Paul P.O.L.

And he's spoken about how the actual number of crimes stopped by these KYC AML. It's like a tiny, tiny fraction. And of course, the massive compliance burden. And of course, you and I in Bitcoin land, we see all these data leaks and hacks and people getting attacked and crypto kidnappings and all this. It's horrific. But it seems to me like, of course, if I could wave a wand and abolish KYC AML sanctions laws, you know, sure, I wish. But is it happening anytime soon? Probably not. Most of the people probably believe in it. And so that's probably the challenge, right? That people who are more, you know, Bitcoin is tend to be more libertarian, cypherpunk aligned. So they, they might agree with that idea of abolishing those policies, but the masses will not. And they drive most of the policies, right, around the world. I don't know. I think actually most Americans don't, don't really have a view. I think it, it's like a lot of debates. You'll have like some people that are staunchly opposed, some are staunchly for, most here in, in the middle.

The staunchly for is the status, right? The status want to make sure the state has power. Money is power. Anytime you see a conflict like this, it's usually related to money. In fact, I might even go so far as it's always related to money. So maybe that's me speaking my opinion here. But I mean, let's say, let's say, as you said, a lot of people are ambivalent or they don't really know or care. They just kind of think, oh, my bank officer is always asking me all these questions about what I want to do with my money. And I just kind of answer them because, you know, how are some of them going to get my money? That's probably how a lot of people are thinking about it. Unless they ideologically libertarian or syphapong. Well, those are the silly ones, right? Like, you know, what's your source of income? How many transactions are you going to do this month? I mean, these are silly, right? Like, they don't help anybody. They don't really hurt anybody either. The main thing that hurts is like, once you've collected all this information, now you become a honey pot. And then like, it's super easy to accidentally lose it. Like, what happened with Revolut? But also what's happened a zillion times over, even remember, not trans-earning, equifax,

equifax a few years ago, right? That was a big deal. All Americans money, I'm sorry, information all over the dark web. They're still around, happily operating, still accredited, credit bureau, still collecting the information. What's the difference? A recent case with a French government or a French tax agent, I think leaked a bunch of info. So I don't know. I'm in France, there were two. It happened twice. The first one was, yeah, somebody that works at the French IRS was paid to cough over the Bitcoin list. And they didn't really realize, apparently, exactly whether, she's in jail, I believe, for that. So she sold out the IRS information. And then they had a second one where they were just hacked. As soon as you start collecting this, you are a honeypot, and it's actually super hard. And by the way, the interesting thing, I mean, Bicco, we consider this a lot. We started out, how do you secure the Bitcoin? It's number one, don't lose the money, right? Okay, that's number one, we all agree.

And so we built all these layers at this technical level and then the custody level and the cold storage and the policies, etc. Okay, what about the PII? How do you protect that? Now I think the reason it leaks so much is A, you end up with compliance legal operative personnel that just aren't very technical. B, we tend to prioritize it less than the money. I mean, I guess if you have to prioritize one or the other, the money should be prioritized higher. C, we use a lot of fintechs to manage this. So basically, the government has come in and slapped all these requirements on you. You need this, you need that, you need this, you need that. And you're like, okay, so you hire somebody, right? And it's persona or sub-sub or serdeena. And those guys now need to have access to it. Now you're like, wait, you're going to give the PII to a third party and there's all kinds of legal stuff that comes in that. So the government regulation is so expensive, that's kind of forced this. So now you've got a third party, you're dependent on them to also operate perfectly.

But then lastly, like, look, we do have to do more as an industry. Like, how do you store it? Who has access to it? Like when you call customer support, can I impersonate Stefan Lavera, right? And what are we doing to prevent that? You have to all the same controls that you have on your money, you have to put on the PII. Yes, it's technically less important. But when it turns out it's important, it's really important. So yeah, you got to do it. And it's expensive. And I don't know where, like, because the thing is, whenever you travel, right, if you're flying internationally or you check into the hotel, you need your passport, right? You need, like, so there's so many places where people are collecting this information and it's being recorded. And this database that they store, like, when you check into the hotel and they, some countries, they will scan your passport. What's the security on that, right? So then, like, they'll have all this stuff and your info will just be out there. And I don't know, I don't really know what the solution of this is going to be because imagine longer term, like, basically everyone's going to get doxed some way somehow.

What do we do about it? Is there anything we can do about it? I kind of assume that I am already just all over the dark web. You probably are too. You know, I mean, just look at the number of breaches from major institutions that have lost, you know, 50% of all American stuff. It just happened over again. So I assume that's all out there. The more concerning one is when you start tying it to somebody's actual holdings. So in France, the reason was so dangerous is because the IRS had specifically said, hey, if you're a Bitcoiner, you have to tell us where your Bitcoin is and how much you have. So now that's a different level of information. And yes, people then say I'm going to go physically attack those people. So the fact that they went after self-custody as something that you have to report is the problem. Yeah, but I mean, realistically, what is going to be actually done about it? These are just that we just have to like hope that enough people use multiseg or that

enough people have Bitcoin that it's assumed that everyone has some or I don't know, like what is the, where is it going to go? Or is everyone just going to use custodian because people don't go and rob Jeff Bezos for his Amazon stock because they know you can't steal that. Well, you can't get away with stealing it. I think that's the issue. But look, I think there's a higher level issue, which is really kind of a war on cash and a war on personal property rights. This will resonate with Bitcoiners as part of why they're here. But I do think politically we have to start making sure that cash is protected. I know a lot of Bitcoiners don't like cash, so it's not my point. My point is you should be able to use cash. You should be able to pay in cash and you should be able to keep yourself anonymized and self-sovereign with cash. Did you know in France, it's illegal. To spend more than a thousand euros in cash to buy something. Most people don't know that. Yeah, I know. And most of the EU is getting pretty bad in terms of war on cash. So it's the same thing. And then all the CPDC stuff is happening all around the world.

So yeah, I think the same thing is going to happen in the US as people opt out of the system. So I did meet with Secretary Bezos at Treasury a couple weeks ago. And I asked him about his views on the war on cash and he hadn't really thought about it. So in America, we do have stronger property rights, which makes it so it doesn't seem like it's as big of an issue. But just think about what's going on with the real meaning of why there's a fight over clarity right now. Is really about, are you going to keep your money in the system? Are you going to be outside the system? And it is about self-sovereignty. This is why self-custody is so important. But more importantly, we need to make sure cash is preserved. If they start eroding cash, that's eventually going to erode on gold. That's going to erode on Bitcoin as well. And I think we have to watch out for that. So vote for people that have a strong belief in you can have your own property and that you can pay in cash. Well, yeah, for sure.

I mean, that's definitely part of it. I think the political activism part of it is becoming more and more of a thing. Like Bitcoin is becoming bigger and bigger. And therefore, Bitcoin is could start being politically active in terms of donations and things like that. I guess some people will have a bit of a, that gives a bad taste in the mouth because maybe they don't want to be involved in the state or politics at all. But yeah, I kind of do a line more on that side of, hey, it's, what's the saying? It's like politics. You may not be interested in politics, but politics is interested in you. And for that reason, yeah, I think we're going to have to try to improve that situation. And that's kind of in many places around the world. I want to get back to kind of the custody side of things and security questions on like Bitcoin and HSM and things like this. How do, because this is something that I know, actually, I think we spoke about it, you

know, six or seven years ago, is this something that you're looking at from a multi jurisdiction perspective as well that you might start, you know, you'll start, you'll have keys in different jurisdictions as a, as a protection. Yes, you know, you might recall that a couple years ago, we moved, uh, rap Bitcoin, which, you know, we were the custodian for into a multi jurisdictional, uh, storage. And that was, you know, primarily because we're really afraid of what was happening here in the US at the time as a different regulatory scene. Right now, I guess those fears here in the US are a little bit subsided, um, but I do think it's an important thing to get to. So we have it in some areas, not as perfect as I'd like it mainly because there's been other areas of focus, um, more recently, um, but that will come back up, um, in the future. And then yes, one nice thing about multi sig is that it's, it's very doable to get kind of this multi jurisdictional protection. So, um, then even if any particular region, uh, you know, has a straight up banning, um,

you can protect against it. I guess even as I think about the go forward, I think that's a less likely, um, worry right now as some of the other risks that we have. I think fortunately, you know, we're getting legislation all across the world about how you to treat digital assets and that comes in. I think the, the chances of just a confiscation or a ban gets pretty low. Um, but you know, this thing can change. I mean, it's only 24 months ago. We were talking very differently. Uh, there we are right now. Or even think about the debt situation of the US, right? What is it? 40 trillion in debt or whatever that, whatever the number is, imagine in another, a mere 40 trillion, right? And then imagine in another 10 years time or 15 years time, like if Bitcoin is, you know, over a million dollars at that point, and the, the national debt is, you know, much more than 40 trillion. Because the confiscation question become more serious at that point. Look, I'm sure your viewers are all well aware of executive order, 6102, right? And it absolutely could happen.

And then that would be an order at the custody level and the self-custee level potentially, right? So, um, you may not have any legal protection of it, at least with self-custee, uh, you have choices like you can move. But, uh, yeah, let's, let's hope it doesn't come to that. But look, I do think money is power. Power is money. Uh, they go hand in hand and the state, uh, needs more money, um, to maintain power. So, uh, it, it is something that, the big winners that have a little bit of paranoia should worry about. Yeah. Uh, and then I guess diving into some of the more technical sides of things. I know, obviously you were an innovator in multi-seag right? Like, so for listeners who aren't familiar, I guess I'll give a very kind of brief like, there used to be bare multi-seag right from day one, but that was not very practical. And then what you did in was at 2012 or 2013, uh, you, you came out with this idea of P2SH multi-seag, pay to script hash multi-seag and, uh, talk to us a little bit about kind

of the evolution of multi-seag over time, um, and how you kind of see it nowadays. Uh, sure. Uh, what the, the bottom layer, like you mentioned, we've had multi-signature, uh, UTXO outputs, uh, from the beginning of this is where, uh, you know, at the end of the day, Bitcoin is a bunch of, you know, uh, transactions with unspense and in order to unlock and unspent, you have to provide some sort of proof. And so the idea that you could have multiple keys that need to be provided to make that prove happen, that's always been there. That's at the transaction level. The challenge with it is like, well, you got to set it up on every transaction. With, uh, P2SH, they said, okay, let's wrap that inside of the address. So you get a special address, which has kind of that, uh, script in it and then it applies to the whole wallet. So every UTXO in that wallet, uh, uses the multi-sick path. And now humans can kind of manage a whole wallet. Um, I think the second level of, of changes actually, there's more on the multi-sig, that I'll get to in a second, but, um, you know, just like best practices on wallets has taken

a while and not all wallets do this. Um, but, you know, never reuse addresses you're familiar with. Always use change and new change addresses so that you're constantly, uh, you know, moving. Lately, we have this thing, Quantum, people are worried about. Um, people sometimes say, Mike, the, I'm gonna make a statement that we have a quantum resistant wallet at BICGO, which we do. But people like, Mike, you can't be quantum resistant unless you change the, the, um, the signature from ECDSA to the, I know, there's more to it. But my point is this, quantum resistance today, if you put your BICO in, at BICGO, A will tell you how much is exposed to quantum, meaning how much is exposed to a public key or set of public keys that have already been put onto the chain. Um, and, uh, we also let you move and operate your wallet in a way that anytime you expose a public key, we move everything that would have gone with it. So, um, I think around 30%, I might have this wrong of UTXOs right now, uh, are using public keys that have already been exposed.

So this could be fixed. All wallet providers should be moving to the same unspent algorithm or something like it, like what BICGO did. And what this would do is we would make it so that everybody's quantum resistant right now. So if a quantum computer showed up tomorrow, your BICOins would not be vulnerable. So there's still more to be done. We gotta get the memple fix. The short range thing, there's long range attacks. And what you're talking about there is it would make you safe against the long range attacks just to not have address or use. But the short range attack, which is kind of if, if the, the quantum hacker can see your transaction in the memple and he does it, you know, that kind of thing. But by then we'll probably have mitigations on that too. Correct. This other is a report that just came out. I think it's last week about a quantum computer at 20,000 qubits or something like that. And they estimated it would take something like 73 days to hack a, a private key from a public key. So by the way, that means if you had two keys that need to be hacked, like in a two out of three multi-sig, you'd have to do two 73 day

sequences. So again, the multi-sig will be more resistant than single-sig always, although that's not enough by itself, really should be doing more. But by moving to a wallet that's quantum resistant now, you know, that whenever that quantum computer shows up, your coins aren't going to be lost. Now Satoshi's coins and all that other stuff that's vulnerable, you know, that's a different issue that has to be solved. But yeah, every wallet should be doing this. So anyway, back to innovations on multi-sig. Like Bicco does more than just Bitcoin. We do Ethereum and we do more coins than anybody else. More of the top 100, more of the top 250 than any other provider from Firefox to Anchorage to Coinbase, etc. And a lot of times the technology we're using there is MPC instead of multi-sig. The reason, you know, a number of blockchains, including Ethereum, don't support multi-sig on chain. Now multi-sig is strictly better than MPC in all cases. And the reason for that is that you get multiple independent keys. They'd be signed completely asynchronously,

completely independently. And you don't have to come online to sign with MPC. It's a protocol and it goes around and around. And it's really hard to do in cold storage. But moreover, it's not independent implementations. Every MPC protocol is like that vendors MPC protocol and you can't have independent implementations like the thing we're just talking about you need in order to mitigate the cold card, bad random number generator. So I'm not trying to say MPC is bad. MPC is good, right? We do two out of three MPC and it's used all over the place, but multi-sig is better. And then the next problem you run into is like, well, how do we make multi-sig or an MPC kind of work in a multi-vendor mode or in a compatible way across multiple blockchains? And here you start to run into trouble. So BICCO does support some models that we use in conjunction with like on ramp as a client that does anchor watch is another one. Well, they'll use a BICCO key along with another

key that they provide plus another provider. So that gets you kind of multi-vendor stuff. There's some advantages to that. It at least has completely different operators, which takes away that that single point of failure at the operator level. Disadvantages like you can't get it insured very easily. You can't really do qualified custody very easily because it's different vendors. The SOC audits and other things can vary. The meantime between failure actually gets worse when you bring multiple parties together rather than better, which is not decided. So you're saying there's actually a higher failure rate there in terms of like, is that like process failure, security failure? What kind of failure are you referring to there? Anytime you have a risk that's got some chance of a failure, like a hard disk, has a failure on average once or very two years. When you throw in lots of hard disks, a hundred hard disks, or what's the chance that any one of them is going to fail next week?

Pretty hot. So it kind of doesn't matter. When you're talking about failures, you're talking about like any of those companies losing a private key, getting hacked, going out of business, obviously it's different failure rates for each of those different types of risks. But when you go to multi-vendor, you do end up with that. On the other hand, you don't have any single party that can like, you know, you're more secure, but there can be more failure rate in certain contexts is what you're getting at there. But in this way, multi-institutions. Yeah. Yeah, so look at this with BlackRock. They run the largest Bitcoin ETF. They use one custodian, that's Coinbase. And everybody's like, ah, you know, that's a lot of money. Just at one custodian, you should split it up. From a you know, catastrophic loss perspective, maybe, right? Like they could take it, put it at two, and now instead of having 50 billion at one entity, they'd have 25 at two entities. But every entity goes dies eventually. And if

you figure that the the meantime between failure of a custodian X, you've actually increased the chance that you will have a 25 billion dollar failure. Although you've decreased the chance that you'll have a 50 billion dollar failure. So it's, you know, everything's risk, I guess, at some level. Obviously, you take a lot of precautions to avoid these things. Yeah, kind of scary when we talk about all these things. But I mean, ultimately, there's risk in everything and you have to just you have to manage it somehow and you sometimes you spread that out across different providers. Sometimes that's better technology. And I guess I kind of back to the I guess the Bitcoin multi-seag. I guess there's there's been some evolutions and things along the way also, right? And actually, I believe you at Bitcoin did music too, right? You guys have music too. So that's like so there's been kind of further evolutions there also. And maybe in the future people will look at things like Frost,

which is like another thing or like mini-script stuff. Or I guess these are all different ideas that can add different things. Can you give us any insight on to if you're looking at any of those or do any of those interesting to you or not really? Yes and no. Look, I think they're always interesting, but it's hard when they operate on one chain and not others for Bicco because we're trying to provide that same protection across all chains. And so per chain specific things gets a little tricky. But the other problem I think is one of human nature. And again, kind of back to like I've heard over the years, people like, oh, you should use three out of four or you should five out of seven. Like all these are good ideas. And yet like at the end of the day, you've got to take the concept operationalize it and make it ready for everybody to use without any errors. So every key that you add is more complexity. That means you have to have opsec on every single one of them. That means you have to have recovery routines and every single one of them. That means you have to different people

in charge of every single one of them. There's a lot that goes into building that. And the same thing is true of like we've got mini script and other things which would push policy all the way down onto the chain. Well, A, it seems like every user seems to have kind of a different idea of what policy that they want. So there's not like there's a universal like one single truth for what to do there. The great, I love these things because they give you like a ton of control and you can pick. On the other hand, if you lock up your coins for three years and then afterwards you kind of realize, oh, wait, I locked up my coins for three years and they're on chain locked. That can be a problem. So I've definitely seen a lot looking a lot of a lot of proposals around time locks. I feel like we can do those pretty well at the application layer, which is how we do it at Bitcode today. But you could push them down. I'm excited about the never ending stream of innovation that comes from having all of this technology in front of us. So I think more will come so far. At least

right now, we think we're mitigating the risk. We've got the on chain. We've got the two out of three. We do policy above that. We do application levels. We can choose with that. We split them across different locations like our three keys that we use in custody. They're all separate by a thousand miles apart from each other. That allows us to get insurance where we're where the insurance policy covers geographic natural disasters. I think we might be the only company that has that. And look, I think it's on one hand kind of a small thing, but I also think it demonstrates the power and the care that's gone into the deliberate choices that we've made. So anyway, yeah, there will be more evolutions in terms of how do you on chain secure? And I think I think those are good. The harder parts going to be getting the op-sec right and then getting models that kind of fit with what everybody wants. I think you started to get pretty tailored and personal. Yeah, which is interesting though, because I would say from what I'm reading there, it's just which and rightly so it's a bit of a

conservative approach. You don't necessarily want to take on like every latest newest thing. But I would say if anything, you guys are relatively early on getting musy to support like that was probably a relatively early thing compared to some of these other things, right? True, but the crypt that was really just kind of the cryptography and the cryptography has been well established there. So you know, Shnorris as well, you know, I mean, you know, that's not that's not a new thing. MPC, we were actually slow. And the reason we were slow is because we wanted the two out of three models. So the early variants of MPC were two out of two, then they count with three out of three. Those protected against theft, but they don't protect protecting its loss. And by the way, our competitors that are using MPC, they're pretty much all using two out of two and three out of three today. They've never upgraded to two out of three. The two out of three MPC took longer to evolve. It's more computationally expensive. It's harder to scale, but we felt like, look, you just have to have that across everything that we do. Otherwise,

the losses will happen. And in fact, they do, right? There's documented cases of where people used a three out of three MPC and they had that theft protection, but then they screwed up the last one piece of it and they didn't have a backup. And so then the loss of coins. Yeah, as you said, it's a balancing game of making sure you have redundancy and security. And not just only once, if you make it too secure, but that you forget or don't prioritize the redundancy component enough that you can recover from the failure. Well, site correction, you can totally have both theft protection and loss protection. That's doable. That's not a balance you have to make. That you can get. The balance, I think, is around usability or ease of use for accessing your coins versus security. And to some degree, this is easy to deal with. You just risk mitigate, right? So I've got my hot wallet. It's got less protections on it. I can spend whatever. It's on my mobile phone. It can still be multi-sig. It still operates just like a single

single-sig, but a single breach on your phone won't steal your money. And then you can have your cold storage and your more advanced stuff for your large amounts of money. So risk-based mitigation, I think, is how you deal with this. You have two different policies for two different sets of activity. Yeah. And then on the insurance side of the house, can you talk to us a little bit about that? Like, do you think it will be more and more commonplace that your entire balance is insured, this kind of thing like over time? Or no, it's difficult to do that. It's going to depend on the use case a little bit. So I mentioned coin cover. We work with them on third keys. They sell insurance for retail on multi-sig wallets. So for personal stuff, they can provide insurance like today. And that'll cover some amount of size. For the global Bitcoin digital assets are out there. The total underwriting coverage in the world is probably $57 billion

in size. And yet Bitcoin is- Like $26 trillion or whatever. Yeah. So that means that Bitcoin and Coinbase and Fireblocks and Crack-In and all these other companies added together only have about six billion in cover. That's just not going to change. I mean, the reality is you've never had a hundred percent cover of assets for insurance ever. So, all right. Then you might say, well, is insurance useless? No, insurance is still very important. It's important for a few different reasons. A, we can absolutely architect solutions where you reduce risk by making losses uncorrelated. Meaning that you split things up into to multiple pieces. I'll come back to that in a second. And the second part is, when you get somebody to stand behind your product with a $250 million check, it's a big deal. They look at a lot. They look at the governance. They look at like the technology. They look at the operations. They look at everything. So even though just having that inspection,

like having an audit is not a guarantee, it does mean that you had something that put $250 million behind that they think it's unlikely that you're going to have an issue. Back to the first issue. A lot of wallets out there, though, you'd reuse the same keys. They'll derive them from a common route. You know, bigger than some of that within a wallet, but actually we use separate keys across our client's segregated funds. And so what that means is that you breach one client, like there's zero chance, zero correlation to another. And then inside of our own storage, we split as well. So even though we got upwards of $100 billion of assets in the bank, it's not like it's sitting in one big pile. And in fact, if you were to show up and have a billion dollars to put a BICO, we would split that into somewhere in the neighborhood of 10 to 15 wallets. And a couple of good things come from that. A, it means that if you lost any single wallet, it's like $100 million

instead of $100 million. And this happened, remember, buy BIT was hacked. I think two years ago now, right? That was the diagnosis-safe thing. I think it was like a North Korean Lazarus group or something. And they had like, I think the CEO signed something. And then like the ledger guys are coming out saying, well, that was because you didn't do clear signing and blind signing. That was what that was the one, right? That's correct. So the ledger device was blind signing. So there is like, so that thing failed. And then the hack was into the user interface, which affected, I guess, all of the approvers on it. But then third, you know, without using a BICO wallet, without like, you know, I could say them a billion dollars, don't put $1.5 billion in a single wallet. Split it. Just don't. You don't need to spend $1.5 billion in a single transaction. It just doesn't happen. But they did, right? So had they split that the way BICO has been doing since 2018, the loss would have been $150 million instead of $1.5. One tenth. Because they love me. So like, these are things you can do. And then, you know,

separating the keys across clients is one. And then also when we do take a client, we split them across 10 wallets. You know, typically they'll have like some small amount of activity that keeps happening. That all just happens at wallet A wallet BCDE F and G. Those keys are parked and not touched. So the chances of having a single event that breaches all those wallets as low, I can't say it zero, right? Like, there's things that we do that, you know, we got the same people, we got the same vaults, we got the same tech. But we minimize that stuff, which is why we're able to get really big insurance packages, etc. It's also why you can feel comfortable at a company like BICO, even though we don't have, and it's not possible to get $100 billion of insurance coverage. Yeah. One other question I had, now you mentioned earlier in passing multi-institution custody, right? So on ramp and anchor watcher are in this camp. And I believe you are one of the participants there. How should people think about that in terms of using, let's say, BICO as a single custodian versus

a multi-institution custody set up? Well, so those are really more like kind of elaborate self-custody solutions, I think, you know, they're not qualified custodians. So BICO tends to hit kind of the institutional side of it. They use some of our tech, it's a feed-in to theirs. If it's something that appeals to you, you should use it. And you get a little bit of advantage there. I don't know, I feel like we get most of the cover from what BICO does. But different people want different things. So this is how you get choice. Yeah. Look, I think that's probably the, you know, that's probably the one big takeaway, right? Like there's no one size fits all, there's no one answer that's best. Some people are going to do self-custody, some people are going to do their own multi-seag, some people are going to go, you know, whether that's using a BICO wallet or some other wallet, they're going to use whatever. Well, I'd be remiss if I didn't say there's one that's best, we just use BICO and it'll be fine. But I fully recognize it. Like everybody's got kind of different preferences that they want. So there's things that'll make you sleep better at night with

your Bitcoin. You should use them. You know, be smart, be educated and make the best choices for you. All right, well, I think we'll leave it there. And let's make sure it's not six or seven years until our next interview. Thanks for joining me, Mike. Thanks, Stefan.

More episodes

More from Stephan Livera Podcast

View all episodes →