Trezor: Your keys are always held by someone. And that someone should be you.

cryptonews.ruPublished on 2026-08-08Last updated on 2026-08-08

Abstract

Following a recent security incident with a competing hardware wallet, this article defends the concept of self-custody and clarifies its core principles. It argues that while the specific vulnerability was serious, it represents a failure of one product, not of hardware wallets or self-custody in general. The piece cautions against overreactions like abandoning self-custody for exchanges or hastily adopting overly complex multi-signature setups for average users. The author's central argument is that someone always holds your Bitcoin keys—the only question is who. Choosing a custodian (like an exchange) shifts the risk to trusting a third party's honesty and solvency, placing you back in the system Bitcoin was designed to escape. With a hardware wallet, you trust only that the device was built correctly—a claim that can be verified due to open-source code and security audits. The stated mission is to make self-custody as simple and intuitive as possible, moving it from a niche for experts to an obvious choice for everyone. The article concludes by emphasizing that self-custody’s inherent responsibility is the very point of true ownership, and that transparency and verification, not blind trust, are what make it stronger.

If you own a hardware wallet and have been worried these last few days, I understand you completely. The recent Coldcard incident was serious, and real people lost real money – that cannot be ignored under any circumstances. One company made a major mistake in one of the core tasks of a hardware wallet – generating robust randomness for the seed – and it harmed many real people. But at the same time, this is not a blow to the concept of self-custody, and it does not mean that hardware wallets in general can no longer be trusted.

It's worth understanding what really happened, without the noise. The wallets from which funds were stolen were created using weak random number generation at the moment of their creation. This is a specific flaw in a specific company's product, and it has no bearing on how devices from other manufacturers generate their keys. If your wallet was initially created correctly, this incident does not affect you in any way. Your funds are exactly where they were a week ago, protected by exactly the same things.

So the first thing I would say is: don't let fear change your setup. Fear is a bad engineer. It pushes people to implement complexities they don't understand, and not understanding complexities is itself a risk.

There's a lot of talk these days about multi-signature wallets – those that require multiple keys to authorize a transaction. Multi-signature is indeed a good tool, and for those who hold a very large amount of bitcoin, it can make real sense, as it means no single device and no single provider can put everything at risk. Trezor has supported multi-signature since 2014 and is one of the most widely used devices in such setups. But for many people, it's more than they need. Not all bitcoins are meant to be locked away forever, and for the coins you actually use, multi-signature quickly becomes more of a burden than a help. For many people, a simple single-signature setup works perfectly well. One seed phrase, correctly written down and securely stored. Clear and convenient. Multi-signature also has real pitfalls: from falling below the required threshold or misconfiguration, to real complexities with backup and proper recovery, and simplified management versions charge an annual fee. It's simply not for everyone.

And if you're new to all this, please don't let one bad week scare you off before you've even started. Self-custody is a skill, and like any skill, it rewards practice more than panic. Start small.

Someone Always Holds Your Keys

There's another reaction to this incident that I understand but want to carefully refute. In the days since the news broke, some bitcoin has moved back to exchanges and custodial products, as people decided that entrusting the care of their coins to a company seems easier and safer. It's a natural human reaction. But I believe this case teaches the opposite lesson.

Here's what remains constant, no matter how you organize storage. Someone always holds the keys to your bitcoin. The only question is who. If it's not you, then it's a company, and you are relying on that company being honest, competent, and existing tomorrow.

We have witnessed many times what happens when that trust is misplaced. Exchanges have been hacked. Custodians have gone bankrupt. People who believed their coins were safe with someone else learned too late that the coins were never really in their hands. The whole point of bitcoin's existence is for your money to truly be yours, not just a balance a company shows you and promises is safe. Holding your own keys is simply taking that promise into your own hands.

At this point, a careful reader might say: 'But I'm being asked to trust a wallet company, not an exchange, so what's the real difference?' That's a good question, and the answer is important. When you leave your coins with a custodian, you hand over the actual coins to them. You rely on that company remaining solvent, honest, and existing tomorrow, and if it goes bankrupt, your money goes with it. When you use a hardware wallet, you don't give your coins to anyone. You keep them yourself. Your trust is based on a narrower assumption – that the device was built correctly. And because our code is open for anyone to inspect, this is something you or an independent expert can actually verify, not just blindly believe. One type of trust is verifiable. The other, you just have to hope is justified.

This does not mean self-custody carries no responsibility. Of course it does. But that responsibility is the price for truly owning something, and we believe that price is worth paying. Handing your keys over to a custodian does not eliminate risk. It simply moves it to a place where you can't see or control it, and returns you to the very system Bitcoin was created to escape.

Our Job is to Make Ownership Easy

If responsibility is the honest flip side of self-custody, then the task worth solving is to make that responsibility feel light. That's what excites me most, and that's why I'm doing this work.

For a long time, the industry tacitly accepted that self-custody was a complex and somewhat scary option, and convenience would always be the prerogative of exchanges. I've come to the opposite conclusion of what that assumption implies. Convenience has influenced where people keep their bitcoin more than complexity has. Most people don't leave their coins on an exchange because they weighed the risk of that exchange going bankrupt and decided it was worth it. They leave them there because it took thirty seconds and felt familiar. If we want more people to own their keys, the answer isn't to lecture them on why they should. It's to make owning keys feel as natural and simple as using the apps they already use every day.

That's the standard we are aiming for across the industry. It's not about self-custody accessible only to a select few technically savvy users, but about self-custody that feels obvious and simple for any person. Security was never about how 'hardcore' or complex a setup looks, with dice rolls, air gaps, and the like. All those things can create a feeling of security that doesn't always match reality. What matters is getting the everyday version of self-custody right, because that's what most people will use. A reliable single-signature wallet is a great starting point, and anyone can build from there.

Don't Trust Us. Verify Us.

There's another thread running through this whole conversation, and after an incident like this, it becomes more important, not less. If you are going to store your keys yourself, you have a right to know that the tool you are trusting is actually doing what it promises. And the honest way to earn that trust is not to ask for it, but to give people the means to verify.

That's why our firmware and our device architecture are open source. Anyone can see exactly how a Trezor works, including exactly how it generates the randomness that protects your funds. Openness itself is not a magic shield, and I would be wary of anyone who claims otherwise. Open source helps only if people actually study it and if others build on top of it, which brings even more eyes to the code. So we do everything we can to make that happen.

We run a bug bounty program where independent researchers are paid to find and report flaws, turning the phrase 'someone could check it' into real motivation for them. And because the code is open, the door for thorough scrutiny is open every day, not just when a company decides to invite someone.

Transparency isn't something we add as an afterthought. It defines how we build the product from the ground up. The point of Bitcoin was never that you need to trust a new set of institutions instead of the old ones. It was that you don't need to trust blindly at all. You should be able to verify. A wallet company that asks you to trust it while hiding how it works has completely missed that point.

Responsibility is the Point

So no, this difficult week does not mean hardware wallets don't work, and it doesn't mean self-custody was a mistake. It means what it has always meant. Owning your own money requires a certain posture from you. That is not a weakness of the idea itself. It's just the point of ownership. And a hard week like this doesn't just cause pain. It forces the entire industry to do more rigorous audits and ask tougher questions, with code facing more scrutiny than ever before – from researchers, new tools, and the broader community. It may not feel like it today, but self-custody is quietly getting stronger – faster than almost any other part of this space.

Someone will hold the keys to your bitcoin. Tellingly, this past week we've welcomed many new users to Trezor, a significant portion of whom moved from Coldcard – these are people for whom self-custody matters and who have no intention of giving it up. We'll take care of them just as we've taken care of everyone for the last twelve years, keeping them safe. After all we've seen, I still believe the most reliable hands for your bitcoin are your own. Your money, finally fully yours.

_________________________________________________________________________

Bitcoin.com assumes no liability and will not be liable, directly or indirectly, for any loss, damage, claim, cost or expense of any kind, whether actual, alleged or consequential, arising out of or in connection with the use of or reliance on any content, goods or services mentioned in this article. Any reliance on such information is taken solely at the reader's own risk.

Related Questions

QWhat is the main argument of the article regarding the recent hardware wallet incident?

AThe article argues that the recent Coldcard incident was a specific failure of a single company's product, not a failure of the self-custody concept or hardware wallets in general. It emphasizes that devices from other manufacturers are unaffected, and funds in properly created wallets remain safe.

QWhy does the article caution against a fear-driven switch to multi-signature wallets?

AThe article cautions that fear can lead to implementing unnecessary complexity. While multi-sig is useful for large holdings, it can be cumbersome for everyday use, introduces new risks like improper setup or backup difficulties, and isn't needed by everyone. A simple, well-managed single-signature setup is sufficient for many users.

QAccording to the article, what is the fundamental difference between trusting a custodian and using a hardware wallet?

AWhen using a custodian, you surrender your actual coins and trust the company's solvency and honesty. With a hardware wallet, you retain your coins, and the trust is limited to the device being built correctly—a claim that can be verified through open-source code and independent audits, rather than being based purely on hope.

QWhat does the article state is the key to encouraging more people to practice self-custody?

AThe article states that convenience, not just security, is the key. To encourage self-custody, it must be made to feel as simple, natural, and obvious as using everyday apps, moving beyond a niche, technically complex option. Making the everyday version of self-custody reliable and easy is crucial.

QHow does the article justify the principle of 'Don't trust us. Verify us.' in relation to Trezor?

AThe article justifies this by explaining that Trezor's firmware and device architecture are open-source, allowing anyone to inspect how it works, including its random number generation. This transparency, combined with a bug bounty program, enables real-world verification and builds trust based on evidence, not blind faith. This aligns with Bitcoin's core principle of removing the need for blind trust in institutions.

Related Reads

Trading

Spot
活动图片