Obyte

Coldcard, Trezor, SafePal hacks... Is Crypto Self-Custody Dead Now?

Coldcard, Trezor, SafePal hacks... Is Crypto Self-Custody Dead Now?

August 2026 was a rollercoaster for the crypto space. Kind of a bad one. Just before the start of that month, some unknown attackers managed to take advantage of a bug in the Coldcard hardware wallets to steal up to 2,055 BTC (~$130 million) directly from users. This is being considered the largest hardware wallet exploit to date. And it was followed by more attacks on Trezor and SafePal, two other major hardware wallet providers. Self-custody is thus called into question for many.

We’ve been told, repeatedly, that our private keys must remain offline, out of reach for hackers and scammers. Therefore, numerous crypto users have chosen to invest in more security and purchase specialized hardware devices to safeguard their coins. Now, among those who chose a Coldcard as this specialized device, several have lost their funds without even doing anything about it, because the attack was completely remote and out of their control.

It feels unfair. But wait, because there are still things to unpack before losing faith in self-custody.

So, What Happened to Coldcard and Company?

The first thing we must understand is that no, crypto networks aren’t just insecure now. The recent attacks weren’t against strong distributed ledgers, but against specific companies and their products. Let’s start with the Coldcard case: the problem came from the way certain devices generated wallet seeds or private keys. 

In an average crypto wallet, just “guessing” seeds by applying brute force (many repetitive attempts) is impossible. A 12-word phrase alone has about 340 undecillion possibilities. This implies, as Knowing Bitcoin explains, that “if every computer on Earth tried a billion seed phrases per second, it would take trillions of times the current age of the universe to try them all." Unfortunately, it wasn’t like that for some Coldcard devices. 

bfd9c9c86b57a01bfd18ffd5c773cd65c9f686ea114560507e2675c9f2529b67.jpg

A software change introduced in 2021 caused certain devices to use a software-based pseudo-random number generator instead of the hardware-based random number generator intended for creating secure seeds. In other words, the wallet's security relied on insufficient randomness. Attackers were able to guess the private keys when they should never have been able to.

Even after applying a firmware fix, those seeds are just not suitable to use anymore. Anyone who has generated seeds on a Coldcard between 2021 and 2026 is advised to withdraw all their funds to a more secure wallet. 

What about Trezor and SafePal?

At the very least, no funds were compromised in these two attacks. However, they can be considered equally serious, because personal data and physical addresses were, indeed, leaked. On August 12, Trezor informed that ShipMonk, one of their shipping providers, suffered a severe data breach that exposed the full names, phone numbers, email addresses, and physical addresses of almost 12,000 of its customers.

d3e7385127c57f2a416541e367ff583f251bd82cffc5913efba1a9256520d9df.jpg

In the same fashion, barely some days later, SafePal announced the discovery of a bug that could let someone access or track customer order information without having the proper permission. Which some hackers did. Confidential data like names, phone numbers, emails, and physical addresses from almost 40,000 customers was stolen. 

It seems "better" than having funds or private keys taken away, but it isn't. With all this information, hackers can easily find customers, carry out targeted attacks, phishing, and even plan "wrench attacks" or physical break-ins at their homes. Indeed, according to Certik, violent physical attacks against crypto users have increased by 33% in 2026, compared to the previous year.

Should we rush to crypto exchanges, then?

According to CMC, "Coldcard Hack Sends Bitcoiners Scrambling for CEXes." So, are they safer for us, after all? Is that a real solution in the long-term for crypto users? The answer isn't that simple. Centralized exchanges, even with tons of investment in security, can and have been hacked. 

In 2025, Coinbase, one of the largest exchanges worldwide, suffered the same type of leak as Trezor and SafePal. In previous years, other firms like Liquid, KeepChange, Celsius, and OpenSea faced major data breaches, too. Beyond that, numerous crypto exchanges have been robbed or bankrupted over the years —or they were just scams from the beginning. Mt. Gox, QuadrigaCX, Cryptopia, and FTX are only some of them. Thousands of users globally suffered massive losses from these cases. That’s why this motto is so common in crypto: Not your keys? Not your coins.

686dd08863f7f76cf1a3a27fb005335442664ec0a39607c23ff77c3cc478343f.jpg

However, now that self-custody appears to be threatened, what is the alternative? Where do we run to? You may think that, well, the flaws were limited to certain brands, so we just change brands and that’s it…! And that’s still not the answer.  The answer is that nothing and no one is exempt from failure. Self-custody requires more responsibility, while external custody presents a different set of risks. That’s the thing, though. 

Neither arrangement removes risk. They put different risks on different sides of the table, and you need to choose which of these risks is “less risky” for your own circumstances. Which benefits do you prefer (i.e., full ownership vs. convenience) and what are you willing to risk for them? Even fiat currencies and banks have their own risks and disadvantages, and their pitfalls are the whole reason why cryptocurrencies exist. Sad, but true.

New Lesson: Don't Put All Your Eggs in One Basket

Decentralize, like crypto networks themselves! If one device, one manufacturer, one backup, one company, or one process can determine whether your entire stash survives, that's a single point of failure you need to fix ASAP, no matter how secure you believe it is. There are several solutions for this. 

A simple starting point is backup redundancy, with copies stored in separate locations so one fire, flood, or defective device doesn't wipe out everything. In Obyte, you can create several textcoins with different amounts in them, and store them offline. However, you’ll have to take care of noting down your textcoins (seeds), copying them to different secure locations, and taking care of them to the best of your ability. The only way for self-custody is high responsibility. 

137a28165f832afaa0bd1e6320eacdd22d6898ce4c52682e21c4cd84312c637f.png

For stronger protection, multisignature wallets can require two or more separate keys before coins can be moved. A 2-of-3 setup, for example, uses three keys but requires any two to approve a transaction. That means losing one key doesn’t automatically lock you out, while compromising one key doesn’t give an attacker enough control. You can also spread keys across different devices or manufacturers, reducing dependence on one technology. 

In Obyte, you can create a multisignature (multidevice) account in just a few steps to increase your security and, if you wish, include other people as co-signers, not just your own devices.

d2d5aee60cd1f2e483ba5a0c223224694a31b4ff0feffe8b38e2ca348bac4829.jpg

There’s also value in testing recovery. A backup that has never been checked is a plan on paper. A successful recovery test provides evidence that the plan works. And complexity deserves its own warning label. Every extra passphrase, device, location, and backup adds another thing to remember and maintain. 

So, Is Crypto Self-Custody Dead?

No. If anything, the bumps along the road make the idea more mature. Self-custody avoids potential financial censorship and can give people full control, but control comes with homework, from understanding how keys are created to knowing where backups live and what happens when a device fails. To be prepared for a device to fail, even. 

Self-custody means taking ownership of the entire security model, not just buying a device with the words “hardware wallet” on the box. Do your own research (DYOR) on every brand, every software, and every process. This is worth repeating: the only way for self-custody is high responsibility!

 

How do you rate this article?

2


Obyte DAG
Obyte DAG

Obyte is a distributed DAG-based cryptocurrency network dedicated to pioneering the next frontier of decentralization and individual autonomy. Founded in 2016, Obyte has emerged as a trailblazer in the realm of distributed ledger technologies, driven by a steadfast commitment to innovation and ideological principles that assert individual freedoms.


Obyte
Obyte

Obyte is a distributed DAG-based cryptocurrency network dedicated to pioneering the next frontier of decentralization and individual autonomy. We share content about digital freedom, crypto networks, and decentralization. The future is decentralized!

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?