Holding your own Bitcoin, explained simply.
This is general information, not financial or legal advice. The Coldcard theft is an active, developing situation; figures below are current as of early August 2026.
Key Takeaways
- Self-custody means you hold the keys to your Bitcoin, not a company. No exchange, no middleman. That is the whole promise of Bitcoin, and the whole responsibility.
- The Coldcard hack is not a Bitcoin problem, and it is still ongoing. A firmware flaw created weak, guessable keys. Across multiple waves since late July 2026, attackers have drained more than 1,596 BTC, over $100 million, from thousands of wallets, and researchers say the theft is still active. [1] [2]
- Protecting yourself takes a few real habits. Add your own randomness, create a strong passphrase, and use multisig. This isn’t easy, but with large amounts of funds it becomes extremely important.
What Is Self-Custody? (Explain It Like I’m Five)
Think of your Bitcoin as cash locked in a vault. Your seed phrase is the combination to that vault. Whoever knows the seed, controls everything inside the vault.
Seed Phrases are typically generated via a user’s wallet service and takes the form of 12 to 24 words. And as long as your seed phrase is “truly random”, then protecting those words is protecting your money.
Self-custody means you keep that combination yourself, instead of leaving it with a bank or an exchange. The upside is that nobody can freeze your vault or lose your money for you. The downside is the same sentence: nobody else is guarding it, so you have to. There is a saying in Bitcoin: not your keys, not your coins. Self-custody is how you make them truly your coins.
The Coldcard Lesson
So what went wrong with Coldcard? The vault was fine. The problem was how the combination got made. A flaw in the wallet’s firmware meant some devices created combinations that were far more predictable than they should have been, weak enough that an attacker could simply guess them. The first wave swept roughly 594 BTC, about $38 million, from hundreds of wallets in minutes. [1]
It did not stop there. Across multiple waves since late July 2026, losses have grown past 1,596 BTC, more than $100 million, from thousands of addresses, and some estimates run higher as new waves are investigated. Security researchers describe the exploit as still active, which is exactly why it is worth understanding now. For the full story, see our companion article, Coldcard Wallet Hack: What Bitcoin Holders and Miners Need to Know. [1] [2]
The lesson is not “hardware wallets are bad.” They are still the right tool, and self-custody is a cornerstone of bitcoin technology. However, if you are protecting a seed phrase that wasn’t created with enough “entropy”, then your just waiting for disaster.
A Quick Word on “Entropy”
Since the “hack”, one word keeps coming up everywhere: entropy. Everybody has been saying it, so here is what it actually means. Entropy is just randomness, how hard something is to guess. When your wallet builds your combination, it effectively flips a huge number of imaginary coins to make it unpredictable. [3]
A normal 12-word seed has about 128 bits of entropy. That is 2 to the 128th power of possible combinations, a number so enormous that guessing it is effectively impossible, even for every computer on Earth working together. The Coldcard flaw quietly dropped that randomness to roughly 72 bits. Still a big number, but small enough that a determined attacker can grind through the options and rebuild your combination. In plain terms: entropy is the difference between a lock with endless combinations and one a thief can pick. More randomness, more safety. [3] [4]
Self-Custody Is a Cornerstone, But Not for Everyone
Holding your own keys is one of the foundations of Bitcoin, the thing that makes it different from money a bank controls. It is not going away, and for good reason. But being your own bank is a real responsibility, and it is not the right fit for everyone on day one. If you have recently bought Bitcoin, or you have friends or family who have, the most important step is not buying a device. It is taking the time to educate yourself thoroughly on how custody works before you transfer any funds. Nothing about the process is so urgent that it is worth losing your coins over.
What This Means for Miners
Mining is only half the job. Whether you mine Bitcoin, buy it, or receive hosted payouts, it all ends up in a wallet, and that is where value is kept or lost. At BlockOps, clients are paid their mined Bitcoin directly and hold their own coins, so you control your custody instead of trusting ours. That is the right default, and it means the simple habits above are worth getting right before the balance gets big.
Sources
[1] Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million, CoinDesk
[2] Hackers steal over $130M by exploiting bug in offline hardware wallets, TechCrunch
[3] What Is Entropy in Crypto? Ledger Academy
[4] From entropy to addresses: anatomy of a bitcoin wallet, Unchained