We're live.
$130 million just vanished from "self-custody" wallets after the Coldcard firmware flaw. The custody crowd is calling it proof that holding your own keys doesn't work.
It isn't.
We sat down with Bitcoin historian @pete_rizzo_ to put this moment where it belongs: next to Mt. Gox, Celsius, and FTX. None of those disasters made custodians the answer. This one doesn't either.
The real history of self-custody, who collaborative custody is actually for, and what needs to change.
Watch now:
https://youtube.com/live/24Vg1bcb9qE
Bitcoin Well
bitcoinwell@btcw.app
npub19mf4...kfu2
Bitcoin Well is on a mission to enable independence. We do this by making it easy to use bitcoin in self-custody.
Whether you’re looking to buy, sell or use bitcoin, we never hold on to your bitcoin.
Bitcoin Well is automatic self-custody.
Going live at 2:15pm EST!
https://youtube.com/live/24Vg1bcb9qE?feature=share
The loonie just slid to about 71 cents against the US dollar, a two-month low.
That is not weather. Nobody woke up to a storm. A committee sets the price of money in this country, and when the gap between what Ottawa pays and what Washington pays widens, your currency follows that decision down. You didn't vote for it. Neither did your savings.
You see, a dollar that loses value on a schedule isn't a place to store your work. It's a leak. And you can't out-save a leak when the people running the printer set the rate.
There is an exit, and it doesn't answer to any of this. Bitcoin has no committee, no overnight rate, no chair reading the room. Its supply follows a schedule nobody can vote to change. You don't have to beat your own central bank. You can just stop holding what it's quietly diluting.
Not your keys, not your coins. And not your central bank's rate to cut.


$130 million just vanished from "safe" self-custody wallets.
The custody crowd is already taking a victory lap. They shouldn't.
You see, the Coldcard firmware flaw drained $130M from people who did everything right. They took their coins off the exchange. They held their own keys. And it still became one of the worst security failures in Bitcoin's history.
But here's the uncomfortable truth: Mt. Gox lost more. So did Celsius. So did FTX. Not one of those disasters made "hand a company your keys" the answer. Neither does this one.
We will be sitting down with Pete Rizzo, @Btchistory_ and former editor at Bitcoin Magazine and CoinDesk, to put this moment in context. Where self-custody came from. Who collaborative custody is actually for. And why holding your own keys is still Bitcoin's north star.
The hack is real. The lesson isn't "trust a custodian." It's "do it better."
New Bitcoin Well Podcast episode live tomorrow @2pm EST on X, YouTube, Rumble and ZapStream.


Roll Your Own Bitcoin Seed: How to Create a Wallet You Don't Have to Trust
Gary Cardone looked at self-custody, saw a little friction, and said "GTFO, not scalable."
That reflex is the entire reason Bitcoin had to exist.
You see, the dice rolls aren't the point. They're a UX problem, and UX problems get solved. What doesn't get solved on its own is the mindset underneath the comment: the belief that doing the work yourself is beneath you, that "serious money" hands its keys to a suit and calls it control.
It isn't control. The money an institution holds for you is the money that gets frozen, loaned out behind your back, and seized. Ask anyone whose account froze in 2022. Ask the Americans who lived through Executive Order 6102.
The friction is temporary. The subservience is permanent, right up until the day you decide to hold your own keys.
Serious money isn't the money a custodian guards. It's the money nobody can take.
Not your keys, not your coins. Not your entropy, not your keys.


We're starting something tomorrow, and it's for anyone who's ever felt too late or too lost to get into Bitcoin.
It's a beginner series. Every session I bring on a different member of the Bitcoin Well team to help me explain Bitcoin from the ground up, so you learn the basics and get to know the people actually building Bitcoin Well at the same time.
First up: Halston (@halstonvalencia). She runs capital markets and marketing here, she's building Bitcoin Quant, and she doesn't do lukewarm takes on macro.
Tomorrow we cover the fundamentals and walk you through how to set up a wallet and hold your own bitcoin safely.
No jargon. All questions welcome. Come learn or share this with your friends and family that are just getting started!
Tomorrow. 4PM EST.


A company most people have never audited just reported a $1.5 billion profit for one quarter. Its reserves now include roughly 146 tons of gold and nearly 99,000 bitcoin.
That company is Tether, the issuer of the dollar-token in half the crypto trades on earth. Read that again. The people printing the digital dollars are quietly parking their own wealth in gold and Bitcoin.
They know what a paper claim is worth over time. So do you now.
You can hold the token they print, or the assets they're hoarding to back it. One of those you have to trust them for. The other you can hold yourself.


In 1993, before most people had ever touched the web, a mathematician named Eric Hughes wrote a line that predicted your whole future: "Privacy is necessary for an open society in the electronic age."
He wasn't talking about hiding. He was talking about choice. The right to reveal yourself to the world on your own terms, and to reveal nothing when you choose nothing.
His answer wasn't a law or a protest. It was code. Hughes and a small group of cryptographers understood you couldn't ask governments or corporations for privacy, because they profit from taking it. You had to build it yourself, in math, and give it away. "Cypherpunks write code," he wrote. Someone had to write the software that defends privacy, so they were going to write it.
Fifteen years later, one of those someones published a whitepaper for peer-to-peer electronic cash.
Money you can hold and move without asking, without announcing, without a permission slip from anyone. Hughes saw the shape of it in 1993. Most of the world is only catching up now.
The tools of your freedom were never going to be handed to you. Someone had to write the code. Someone did.


Normal people double-check the stove is off.
I've verified the same receive address four times and I'm going back for a fifth.
Self-custody comes with a little paranoia. I'll take it.
Canada is the only G7 country that holds no gold.
Not a reduced reserve. Zero. The Bank of Canada sold its last bars in 2016, the end of a sell-off that ran for decades under governments of every party. The official reasoning was that gold had become an illiquid relic in a world of floating currencies.
So the country traded the hardest money on earth for other people's paper promises, and called it prudent.
You don't have to make the same trade. You can hold an asset no central bank can print, dilute, or quietly sell out from under you. Canada gave up its hard money. Nothing stops you from picking up better.


Nine years ago today, Bitcoin's users won the most important fight in the network's history. Almost nobody outside the space noticed.
By the summer of 2017, a handful of the largest miners and companies had been sitting on an upgrade the rest of the network wanted. Their leverage was simple. They made the blocks, so they set the pace. For over a year, nothing moved.
Then the users did something that wasn't supposed to be possible. They ran software that said: after August 1, we reject any block that ignores the upgrade. No vote. No permission. No company in charge. Just people running their own nodes, refusing to accept anyone else's rules.
The pressure worked. Within weeks the upgrade the users wanted was locked in.
That's the part most people still miss about Bitcoin. The miners don't run it. The exchanges don't run it. The developers don't run it. The people who verify their own transactions do. Every node is a quiet vote you cast just by refusing to accept an invalid block.
August 1 got a name that year. Independence Day. Not because a price went up, but because a network proved it answered to no one except the people actually using it.
Run a node. Verify your own money. That was always the whole point.


"This is why you should just leave it on an exchange."
Every time self-custody has a bad day, the custodial crowd shows up to tell you the fix is handing your coins to a company. They said it this week about the Coldcard flaw. They're missing the forest for the trees.
Here's the question that ends it. What if you had moved your Coldcard stack onto FTX the week before it collapsed?
You'd have "solved" a firmware bug by handing everything to Sam Bankman-Fried. A risk you can inspect and patch, traded for one you never see coming until the withdrawals freeze for good.
Funny thing. The company at the center of this week's story is the same one that told you, during the FTX collapse, to get your bitcoin off exchanges. They were right then. They're still right.
The answer to a self-custody problem was never to give up self-custody. It's to make yours better. Verify your entropy. Roll your own dice. Spread the keys across vendors with multisig. Remove the risk you can find, and keep control of the rest.
Sovereignty isn't believing nothing breaks. It's being the one who can fix it when it does.


1/A hardware wallet spent years quietly generating guessable Bitcoin keys.
Last week someone drained $38 million from them in about 25 minutes.
The culprit wasn't a hacker. It was bad entropy.
Here's what entropy actually is, why it's so important in self-custody, and how to make a wallet from scratch with nothing but dice. 🧵


All this talk about entropy has got me thinking...
I think I've been preparing for this moment my whole life.
- Zach 🧙


The Coldcard Hack: A Timeline of the $38M Entropy Failure, and How to Keep It From Happening to You
My funds are safe but I'm in the danger zone with a mk3 ColdCard wallet.
If you haven't heard, if you have a mark 3 ColdCard with version 4.0.1 or newer you are potentially at risk.
As a stop gap measure you can move your funds to a new version of your same wallet with a passphrase, which will generate a new wallet based on your initial seed phrase plus whatever new pass phrase you input.
Remember that will only be as secure as your new passphrase so make it a good one.
Also don't panic and make sure to test your new wallet (send test funds, test sending those funds from the new wallet and test restoring that wallet) before you send all of your funds!
Will be talking about other wallet alternatives and multisig set ups here in the future. Stay tuned!
EMERGENCY POD: FED RAISES RATES (we assume) 
X (formerly Twitter)
Bitcoin Well
EMERGENCY POD: FED RAISES RATES (we assume)
Everyone is watching whether Warsh raises rates a quarter point tomorrow. But that's the wrong number to be paying attention to.
The only number that matters is $40 Trillion.
And that number says, ultimately, this train only goes in one direction.


The Last Analog Man: What John C. Dvorak Understood About Value That the Algorithm Never Will