Your Seed Isn't Enough Anymore
#Bitcoin #SelfCustody #Nostr #OPSEC
The recent Coldcard mess (100M+ drained from "cold" wallets) scared a lot of self-custody bitcoiners. Good. Fear is useful when it makes you check your setup.
Let's talk about three ways people try to add security to their seed, and why one of them beats the other two for almost everyone reading this.
1. "I'll just roll dice for my seed" — bad idea
Sounds bulletproof on paper: no computer, no RNG bug, pure physical randomness. But the weak link isn't the dice. It's you.
Real dice aren't perfectly fair. Cheap dice have tiny manufacturing biases. Even casino-grade dice drift slightly over thousands of rolls.
Humans roll badly. People unconsciously develop a "style," same grip, same throw height, same surface, which nudges results in subtle, non-random ways.
Humans get lazy. 24 words needs 99+ dice rolls depending on method. By roll 70 people start rushing, miscounting, or re-rolling results they don't like without realizing that itself destroys randomness.
Verification is hard. Unlike a hardware RNG that's been tested and audited, nobody's independently checking whether your dice session was statistically sound.
Manual entropy generation asks a human to behave like a random number generator. Humans are pattern-making machines, the opposite of what you need here.
2. Multisig — great for companies, brutal for a person
Multisig (like 2-of-3) is genuinely one of the strongest setups that exists. But look at what it actually demands:
Multiple hardware devices, ideally from different manufacturers, so one vendor's firmware bug (like Coldcard's) doesn't wipe out your whole setup.
Multiple independent seed backups, stored in multiple secure, geographically separate locations.
Coordination software to build and sign transactions across devices, another layer that can break, go unmaintained, or confuse you at the worst moment.
Inheritance nightmare. Try explaining a 2-of-3 multisig recovery process to your spouse or kids after you're gone. Institutions have lawyers and key custodians for this. You have a notebook, maybe.
Cost and friction. Three hardware wallets, three secure storage locations, ongoing firmware maintenance on all of them, this is a treasury-management problem, not a personal-savings problem.
Multisig makes total sense for a company, a fund, or a group of co-signers with defined roles. For one person protecting their own stack, it's often more attack surface and more ways to mess up recovery than it's worth.
3. The passphrase — the real answer
This is the one almost nobody uses, and it's the one that would have actually mattered in the Coldcard situation.
Here's the idea: your 24-word seed, generated with good entropy from your device's real hardware RNG, not dice, is already strong. A passphrase is an extra word or phrase you choose, added on top of it. Sometimes called the "25th word."
Why it's so powerful:
It changes everything. A different passphrase means a completely different wallet, different addresses, different coins. Your 24 words alone open an empty decoy wallet.
No new hardware, no new backups to juggle. It's free, instant, and lives only in your head, or split between memory and a separate secure note.
It neutralizes exactly the kind of disaster we just saw. Even if your seed's underlying entropy were somehow weakened or your 24 words leaked, exposed, or guessed, your funds are still safe, because without the passphrase, that seed just isn't your wallet.
Plausible deniability. Under duress, you can hand over a decoy seed that opens an empty or low-balance wallet, while your real funds sit behind the passphrase.
The catch: if you forget your passphrase, or nobody else knows it, the funds are gone forever, there's no recovery. Treat it with the same seriousness as the seed itself. Write it down, store it separately, test it.
Bottom line:
Dice: false sense of security, human error ruins the entropy.
Multisig: excellent, but built for organizations, not individuals.
Passphrase: cheap, simple, and the single best upgrade a solo self-custodian can make today.
In a year where "cold storage" turned out to have a very hot bug, the passphrase is the quiet hero. Add one. Test it. Sleep better.