Initial reflections on the Coldcard catastrophe, the bitcoin-only approach, and financial freedom:
1) Many people, me included, trusted and recommended Coldcard more than we should have. Especially after it became only source-viewable, and especially given the attitude of the Coldcard creator towards other similar projects. These were obviously red flags in retrospect. This was a huge lapse on my part and I pledge to learn from it
2) Coldcard operated for many years with shocking, betraying negligence that was hidden from the public by a) security theater driven by marketing (i.e. cypherpunks should use this sophisticated tool) and b) an “in circle” reputation and that people like me perpetuated. Another mistake that will stick with me, and guide my future actions
3) We will not be lectured by scammers and ETF promoters and former FTX cheerleaders. There are other Bitcoin-only products like Bitkey, Bitbox, Passport, and Seedsigner. Just because one Bitcoin hardware wallet company failed, doesn't mean the Bitcoin-only approach is bad. Far from it. It just means we need to learn and improve. It DOES NOT MEAN we need to "diversify" into random shitcoins, endorse or tolerate premines, give all our Bitcoin to corporations, or other such nonsense
4) FOSS should be the gold standard in general. And multi-vendor multi-sig or collaborative custody should be a goal for large amounts
5) Exchange hacks have been ~1,000x worse than even this disaster. The answer to challenges in self-custody is *not* to trust someone else with your money. It’s to learn and improve or upgrade your self-custody
6) Fiat currency must be defeated. Entire nations have lost 50% of their money overnight, 75% or even 99% in a matter of months or years. Accounts are regularly frozen and stolen every day. The global monetary system is immensely unjust and predatory and must be resisted. The mission must go on
7) AI makes bugs more exploitable, but it also can be used to secure codebases to an extraordinary degree. This is already happening (see Spiral's Loupe) and really shows the power of open weights. The lesson here is not that frontier AI should be gatekept by the elite, but that it should be open to all, so that we all have more eyes on everything
8) Financial freedom is not easy. And maybe never will be. The price of freedom is eternal vigilance. Self-custody is the pinnacle. Maybe not everyone reaches it, but we should strive to make it an option for anyone
9) I am sorry that HRF handed out Coldcards at two of our events over the past decade, and sorry that I mentioned Coldcards occasionally over the years as a good option. I am NOT sorry that HRF has a laser focus on self-custody and privacy. This approach is *the only option* for people under authoritarian societies. Maybe you want to choose to rely on the good graces of an American financial institution, but this option doesn't exist for billions of people worldwide
10) I am also proud that HRF over the past decade has handed out *many more units* of other devices such as Bitkeys and Seedsigners and Passports, and that we work to teach topics like privacy and multi-sig in our work. I am also proud that we have given out 100+ grants, invested more than $5M, and paid out more than a dozen bounties towards multi-sig, better self-custody, and privacy
11) I can’t say enough about how awesome Casa is and collaborative custody in general. I have heard good things about AnchorWatch and Unchained as well. I highly recommended the collaborative approach for non-profits. Liana is fully open source and superb for managing multi-sig. Casa and Liana have helped HRF sleep easy through the FTX crash, Silicon Valley banking system collapse, Coldcard catastrophe, and other crises
12) It is incredibly inspiring to see the Bitcoin community rally around helping people at a time of need. Many people have barely slept over the past four days as they have helped race to secure funds. It is truly awesome to see this
13) We are in a new age of "back to the basics" in thinking hard about self-custody. Bitcoin doesn't work as freedom money unless people can control it themselves. There is much work to do, but perhaps in 10 years we will look back at this crisis and see that the industry instead of giving up, evolved significantly as a result. Now is the time to make that dream a reality. Thankfully I am seeing a variety of Bitcoin companies and entrepreneurs ranging from Block to Bull iterate rapidly in that direction
🙏
Login to reply
Replies (84)
Astute, and self-aware. Thanks for sharing honestly.
Want to hear this note? I'll turn it into audio for the thread once 767 sats land here. One zap or many.
Thanx man …. I love your work
Maybe I’m missing something but bitcoin-only and a shout out to Casa does not rhyme
They are exceptional and should be mentioned
One thing I'm sure: we never should recommend wallets that requires normal users save and protect seeds. Even the more organized people will, one day or other, make mistakens and loose their seeds on a long period. We all have bad days, loose memory, houses catch fire, we can be kidnaped and many other situations. The solution for sure is something like @Bitkey. Seedless is safer yes.
Seed things should be just for entusiasts/hackers, never for normal people.
Well said and on point, Alex. 🙏🏻
It takes courage and self awareness to own our own past shortcomings. Even more so to move forward and learn from them 😌
People should only espouse the setups on which their own net worths are stored.
Curiously, what is it that you are calling a “wallet”? A hardware device?
A wallet that if you loose funds, your life will be destroyed. So probably hardware wallets yes. For spending wallets, I don't see a problem show the seed, but I think we should go in the direction of at least have option to restore funds without having to insert seeds, maybe passkey.
#btcfail
Great takes. Terrible for many people, but I’m hopeful that this is a great learning opportunity! It is for me at least
Sounds like we probably have a language barrier my friend. So I won’t go into too much detail here in English.
But please please. Study Bitcoin (at the protocol layer) more with any material you can find. There is so much available now.
You have a few obvious misconceptions. The first one is that all of these hardware devices are the “wallets”. They never were (nor could ever BE) because a bitcoin wallet is simply a piece of entropy. A seed phrase. Possibly with a passphrase on top (more entropy. Good) or multi signature configuration (even more entropy. Better)
These cyberspace “wallets” don’t require ANY device to exist.
The words/entropy are THE “wallet”.
If I smash my hardware device with a hammer that was storing my words, NOTHING has changed in cyberspace. It’s just that without a back-up (in my head or otherwise) I won’t have ACCESS to any satoshis in that (cyber) wallet.
This entire debacle has (mostly) been about WHERE those words that make up your “wallet”/entropy CAME FROM.
A trusted 3rd party or YOU? And did you even know the difference.
Hope that helps. Be safe 🙏🏻🫶
For sure we have language barrier.
Great summary and roadmap going forward. Hard to believe one mistake and the dimension it took could obliterate credibility like this, despite years of work and innovation. I still believe in the coldcard despite this but coinkite will have to ante up, with better developers, and an attempt to make the people who were hacked whole again. The future vs fiat will require all hands even people that were responsible for this. Life has a way of humbling even the least likely characters.. and for everyone else a wake up call to review critical security for the future.
Way to respond! Gotta respect it!
We all have to own this egg on face moment, what a sobering week it's been, even though I don't use a COLDCARD i feel like I also took my eye off the prize and boy did I learn a valuable lesson!
Time to get laser focused again!
Well said.
We will grow from this as our foundations will be stronger.
How about Bitcoin-only Trezor?
This right here:
View quoted note →
View quoted note →"The price of freedom is eternal vigilance" will be burned into my brain.
Trezor has a bitcoin only option too
Recommending Casa is a mistake. Jameson [S]Lopp is a bad actor, investor in Citrea along with Peter Thiel and many scammers and shitcoiners who attack Bitcoin.
Citrea launched a centralized slavery shitcoin, created out of thin air, on top of Bitcoin. They were the reason for OP_RETURN blow up.
Jameson SLopp actively attacks Bitcoin Culture and Bitcoin Values.
Thank you sir for your service. You are an inspiration. 🙏🧡
Very well summarized!
Open source is the only way forward!
Actually, to be clear I mean Free/Libre Open Source Software
Guys it's simple
All you need to do is buy 3 hardware devices, each from a different manufacturer, for a multi sig setup
Purchase a LLM subscription to audit and verify the codebase for each of the three wallets
Roll dice 300 times to generate the seeds for each device
Stamp the seed words into metal plates and geographically distribute them to avoid risk of loss, theft, or fire
And ensure when you send bitcoin to the multi sig setup you check all numbers and letters are correct and in the right order to avoid losing funds when sending to the wallet
It's super simple, the future of finance and mass adoption is almost here
😳
Casa, the etheritirium house 🤡
I may be wrong yet I'm getting the between the lines feeling that the multi signers may not matter much if the RNG is eventually found lax on some wallets (still could happen, no?) and there are a lot of folks that didn't consider rolling dice or creating a passphrase when creating their wallet. I'd like to know how many self holders actually performed dice rolls and/or created passphrases up to this point, thinking all along that a set of "random" 24 words was enough. I would think that many multi-signers may have just wanted to pass off some of the risk of sole self custody. I get that. This seems like this is the new way being pushed out to the community from influencers. Not really sure how that maintains sovereignty either if you are giving them some of your keys and you can't act without the other parties signing off. Seems like that creates another risk level. There obviously is no perfect solution
Back to the basics 👏
There were known cognitive biases at play here, all throughout the Bitcoin space. Everyone in their inner heart (yes Shogun reference) wants to paint themselves as the intelligent know-it-all, but it's necessary—and actually perfectly okay—to recognize that you, me, the other normies in these comments and across Nostr, are all inclined to be retarded.
1. Red flags have to be 'flagged' 🚩when they happen in advance, not remembered after the fact like "Ah I felt there was something off about that."
2. We can't afford a cool kids table that's above criticism. Fiat sponsorships can distort incentives.
3. We need to troll each other more and give each other a little more shit—not because we're assholes, but because we're probing for weakness and we care.
4. Influencers need qualifications. I don't necessarily mean academic, but mother fucker, if you're talking authoritatively about seed generation I want to know what you know about cryptography, right?
5. It's useless for someone to beat themselves up (too much) because "I recommended a Coldcard 😔." It did good things (integrating physical entropy into its seed generation is legitimately good) that can be used again in the future. Nobody knew about the PRNG bug.
6. This 👆is what needs to be focused on more. The PRNG bug is not some hyper obscure bug only Skynet could have found, and people have been complaining online about Coldcard sweeps for years without garnering attention because it was assumed they were just stupid. It only got attention because someone Pearl Harbored everyone with a Coldcard at once.
7. Sure as sally, all of these problems are still affecting the network. We have to take stock and think about what we're doing, right now, that we don't recognize that we're doing, that can lead to yet another avoidable disaster. It sure as shit is not arguing on Twitter about muh quantum.
Success in crypto and stocks starts with the right guidance, and Craig delivers exactly that. His disciplined approach, deep market knowledge, and commitment to teaching helped me turn $15K into $130K in just one week. More than profits, Craig builds confidence, consistency, and the mindset needed to thrive in any market.Telegram ⬇️
WhatsApp ⬇️ 

Telegram
Craig World
Trader || Coach || Recovery Professional ✔️ || Learn how to trade📈

WhatsApp.com
Share on WhatsApp
WhatsApp Messenger: More than 2 billion people
in over 180 countries use WhatsApp to stay in touch with friends and
family, any...
1,2,9: Respect for your humbleness, @gladstein. Onwards. 🫡
4. Calling FOSS the 'gold standard' is fitting, though we ditched the gold standard for the sats standard. 😂
6,8,9,12,13: 💯
10: Why not hand out all different Bitcoin-only vendor products like the ones you mentioned above? Specifically: BitBox.
The biggest red flags were the VC money and "not for profit" opensats, hrf etc. throwing money at coldcard to prevent people from using better alternatives.
It's a lot like primal.
Create an inferior and overpriced product, manipulate the market to prevent competition and convince everyone that your lower quality version is the standard
Too soon. No one that saved for years working a blue collar job and was drained of their life savings following “the experts” gives a shit about your faggot opinion and reflection.
Turning my $18,000 investment into $64,000 felt incredible. Mr. Craig's guidance helped me stay focused and make better decisions throughout the process. His knowledge and teaching style are truly impressive. I highly recommend learning from him if you want to grow as a trader...
All thanks to @Cragstradinghub
Reach out to him to begin your investment journey on
Telegram ⬇️
t.me/Cragstradinghub
And WhatsApp ⬇️


WhatsApp.com
Share on WhatsApp
WhatsApp Messenger: More than 2 billion people
in over 180 countries use WhatsApp to stay in touch with friends and
family, any...
hi -- we were trying to zap you -- but it looks like you haven’t set up a NIP-05 or ⚡ lightning address yet — grab one free at
.. then pls reply here and we will try zapping you...

Rizful: Lightning Services
Free Lightning vaults, and instant, disposable Lightning Nodes.
The difference between guessing and trading with confidence is having the right mentor. Craig a known mentor on primal provided the knowledge, structure, and strategies that helped grow my $20,000 portfolio to $233,000 in only two weeks. Every step emphasized discipline over emotion and smart risk management over hype. The experience completely changed my approach to both crypto and stock trading, delivering remarkable results and lasting confidence.Telegram ⬇️
WhatsApp ⬇️ 

Telegram
Craig World
Trader || Coach || Recovery Professional ✔️ || Learn how to trade📈

WhatsApp.com
Share on WhatsApp
WhatsApp Messenger: More than 2 billion people
in over 180 countries use WhatsApp to stay in touch with friends and
family, any...
We all have our vices 🤭

Thank you
10 we will explore but want to keep it heavy on education and letting people choose
It's sort of nice to not be influencer right now, because a lot of influencer influenced people into coldcard and so they are now getting quite a bit of heat.
Also as folks already mentioned - Trezor! The folks behind it have done multiple BIPs they spun off into Stratum V2, etc. Low on marketing in the US though.
All fine. Thank you for even reading this and responding. You are truly a man of the people, for the people.
(h/t @jack mallers for punching the last sentence into my brain. 😜)
You don't defeat fiat by deleting your own wealth. Many Bitcoin maximalists reject the idea of diversification. This is the real issue.
View quoted note →
I invested $30,000 and grew it to $95,000 with Mr. Craig's guidance. What impressed me most wasn't just the outcome but the knowledge I gained along the way. His teaching is straightforward and focused on long-term improvement. I highly recommend checking out his page if you want to become a better trader.
@Cragstradinghub
Telegram ⬇️
t.me/Cragstradinghub
WhatsApp ⬇️


WhatsApp.com
Share on WhatsApp
WhatsApp Messenger: More than 2 billion people
in over 180 countries use WhatsApp to stay in touch with friends and
family, any...
Don’t die.
Don’t quit.
Keep learning.
This is the dawn of a new era and every piece of software out there will be attacked in similar ways. The ones who survive will write the history books.
#bitcoin is #sovereign #money
why don't people just keep their bitcoin and other crypto on ordinary flash drives?
why would you ever rely on some stupid thing no one's ever heard of to store your bitcoin? And why would you limit yourself to just bitcoin? Monaro exists, there's a few other lesser known cryptos that are also worth a lot
Well said.
And that then will make them more knowledgeable and credible?
Sorry: NO.
I think you're conflating two kinds of concentration risk: asset concentration (what most investors think of), and security/threat model concentration.
What just went down with Coldcard is like having your life savings with a single bank. Then it turns out that bank was far less secure than they claimed to be, they get breached, assets are gone and your savings are gone with it.
No victim of a loss like that would say "well clearly I should have saved some of my money in Zimbabwe dollars, some in Turkish lyra, some in Argentinian pesos, etc".
The wake-up call is simply "I should not have trusted it all to a single bank."
Buy the ETFs then.
For me, still the most important part:
FIAT CURRENCY, MUST BE DEFEATED!
And thats what Bitcoin was made for.
It's sort of nice to not be influencer right now, because a lot of influencer influenced people into coldcard and so they are now getting quite a bit of heat.
Also as folks already mentioned - Trezor! The folks behind it have done multiple BIPs they spun off into Stratum V2, etc. Low on marketing in the US though.
Fear will never set one free.
That's what intel VCs like him do. He's just here to regain trust for the intel community.
Gladstein is an intel asset.
You miss all the red flags again and again and again and wonder how we got here?
Bitcoin maxis...
Damn! Why pitch Casa in this otherwise great write-up? Casa default setup is 2-of-3 with the **closed source** client and their server being two parties. Or has that changed?
Whenever I read about cold wallet recommendations, Blockstream Jade is rarely mentioned. Any thoughts about this one regarding the latest events?
The idea of an "in circle" can be very dangerous. Conservations must be about problems and how to solve them, not about people.
HRF is a Soros entity.
don‘t verify, trust
Other prominent bitcoin advocates should, at the very least, apologize for promoting Coinkite products.
Neither is also an option
ETFs defeat the whole purpose of Bitcoin
And having to jump through 500 hoops each with their own pitfalls for self custody is equally dumb
What is an HRF?
A human rights org that has deeply integrated bitcoin into its work and function
Never accepted (or been offered) any money from Soros. Try again
Thank you. Why pitch it? Because we use it at the institutional level. Not in that arrangement. They have been great. I also mention Liana which we also use, which is open and a better fit for individuals for the reasons you mention
So you think a government is paying me to try and convert global dissidents away from fiat currency to a currency that they cannot control? Good story!
OSF
Don't forget to call out the scammers.
Is the patch firmware even trustworthy to generate a new seed?
Alex, if I challenged you to take a step back and reconsider this response, would you be able to see a resemblance in this and the way we let red flags about NVK slide?
Respectfully.
Food for thought.
If we intend to heal this wound, we should be vigilant and really call ourselves and each other out on potential bullshit.
also Peter Thiel Foundation
Human Rights Foundation - Wikipedia
Thiel Foundation - Wikipedia
Exactly that. I doubt they pay you directly, that would be dumb. But through the foundation or other means like every other intel asset. Absolutely?
They don't control Bitcoin? It's 2026, not 2014 anymore where I would have given you the benefit of the doubt.
Tell me how they don't control Core devs and controlled opposition BIP110 devs and markets and derivatives and custodians and merchant solutions and KYC regulation that renders Bitcoin a fully neutered non-fungible shitcoin.
There are a handful of projects that are not captured yet - some wallets (Zeus) some payment services (BTCPayServer) some exchanges (Bisq), some merchants (Oshi).
You mention freedom and privacywithout recognising even once. That's just like Proton, a known honeypot. So either you integrate Monero into your freedom and privacy pitch deck or I will call you out every single time.
at this point im not trusting ANY hardware wallet to generate my seed.
Say something about the #Gaza genocide @gladstein
I guess you don’t follow me, I have posted repeatedly and frequently over the years on that topic. I even got into a huge debate here on nostr with Peter Todd on the topic, he just wants to nuke them all.
Great. I guess about 10 people saw that (I wasn't one of them).
Would you be prepared to speak on stage outside UK Parliament at a forthcoming protest?
only slaves protest to their slave masters
peter todd's cheerleading for ukraine was vile. i mean, just saying but someone who supports MIC wars, building bitcoin? most obvious red flag of who is dishing out the money to pwn bitcoin.
I have an entire chapter about the repression of the Palestinians in my book and mention it whenever I can on stage at big conferences and in podcasts. It is something that very much upsets me and I speak my mind about it. Not that I need to justify anything to you, it’s just how I feel.
The apologies have been so shallow
💯 made me question everything