B-ank · Briefing 06
The Two Layers of Custody Risk
Self-custody is the correct objective for a serious Bitcoin holder — it removes the intermediary that can be compelled, frozen, or breached. But self-custody carries its own risks, and a disciplined holder addresses both layers deliberately rather than assuming a reputable device eliminates them. Two events in 2026 illustrated each layer precisely.

By Chris Vaneman · Principal, B-ank
Bitcoin research full-time since 2020
Published
September 3, 2026
Last Reviewed
September 29, 2026
Summary
Custody risk exists at two layers: the cryptographic (whether the key was generated soundly) and the operational (whether the holder can be socially engineered into surrendering it). A hardware wallet addresses secure storage — not the integrity of key generation, and not the human factor. Both require independent verification.
01
Layer one — cryptographic integrity
A Bitcoin private key is derived from a randomly generated seed. The security of the entire holding depends on that randomness being both genuine and private. If the generation process is flawed, the resulting key may be guessable regardless of how securely it is subsequently stored — the vault is sound, but the key placed inside it was compromised at creation.
The disciplined mitigations are established practice: contribute independent entropy at seed generation (e.g., verifiable dice rolls) so the holder does not rely solely on the vendor’s randomness; and apply a strong, unique passphrase as an additional layer the vendor’s process cannot undermine. Firmware updates address future generation only — an already-compromised seed must be replaced and funds migrated.
CASE — COLDCARD FIRMWARE FLAW, JULY 2026
A firmware version from 2021 generated seeds using a weak, predictable source of randomness rather than the device’s hardware generator. Beginning July 30, 2026, attackers exploited this to drain approximately 1,800 BTC (over $116M) from more than 5,200 wallets. The device’s secure element was never breached; the seeds it protected were weak from creation. Holders who had added their own entropy or a strong passphrase were unaffected.
02
Layer two — operational and personal security
The second layer involves no cryptographic weakness. Here the keys remain sound, but the holder becomes the target: an attacker who knows an individual holds significant Bitcoin — and possesses their contact and location details — can construct highly credible fraud, or in extreme cases pose a physical-security concern. The exposure is the holder’s identity, not their key.
The mitigations are procedural discipline: treat all unsolicited contact as suspect (no legitimate provider requests seed words or urgent firmware installs); verify independently through official channels rather than any link or number provided in a message; and never enter seed words into any interface other than the device itself. For higher-net-worth holders, minimizing the public linkage between one’s identity and one’s holdings is itself a security measure.
CASE — TREZOR / SHIPMONK DATA BREACH, AUGUST 2026
A breach at Trezor’s third-party shipping provider exposed names, email addresses, phone numbers, and shipping addresses for nearly 14,000 customers. Trezor’s own systems, devices, and seeds were not compromised. The risk is targeted fraud: a criminal with a confirmed hardware-wallet owner’s real details can produce a convincing fake support message, security alert, or delivery notice — and, with a home address, a potential physical concern.
03
The correct conclusion — not a retreat to custodians
These events may appear to argue for returning to a custodial intermediary. They do not. A custodian does not eliminate these risks — it accepts them on the holder’s behalf while adding its own (compulsion, insolvency, and breach, addressed in the companion briefing on custodial risk). The sound conclusion is that self-custody remains correct and is materially safer when both layers are addressed with discipline. Competence, not delegation, is the mitigation.
The B-ank View
We regard both layers as the client’s to control, and our role as ensuring they do so knowingly. Verify the integrity of key generation; verify the authenticity of every request. This is the substance of a bridge to self-custody — not merely acquiring a device, but understanding what it does and does not protect. We hold our own practice to the same standard, including disciplined data minimization for anyone we serve.
– Chris Vaneman, B-ank

