Treasure Fleets & Cold Wallets: What the Age of Piracy Teaches Bitcoin About Its Self-Custody Crisis
The exploit that shook cold storage
In late July 2026, Bitcoin self-custody suffered its most unnerving failure to date. Attackers drained bitcoin from thousands of Coldcard useres as a result of insecure seed phrases generated by affected Coldcard firmware, with losses climbing toward $89 million within days of the first coordinated sweep. Blockchain analysts at Galaxy Research documented one wave in which roughly 1,082 BTC was taken from nearly 1,200 wallets in just 41 minutes.
What makes this incident different from prior hardware wallet compromises is that the attackers never needed physical access to a device, never phished a seed phrase, never made a wrench attack and never installed malicious firmware. According to a security advisory reports, a coding error introduced in Coldcard firmware version 4.0.0 in March 2021 caused affected devices to bypass their hardware random number generator and fall back on predictable, software-based randomness during seed creation.
A firmware integration error introduced into the Mk2/Mk3 release line in March 2021 caused seed generation to rely on a deterministic software pseudorandom-number generator rather than the intended STM32 hardware random-number generator. The result was a bounded, reproducible pool of possible private keys—meaning an attacker with the disclosure and sufficient computing power could reconstruct keys entirely offline. Coinkite says it was unaware of the defect until the attack and disclosure brought it to light
The devices did exactly what they promised in one sense: no attacker ever extracted a key from a Coldcard over a cable or a network. But the second, deeper promise—that the key was unguessable to begin with—had been silently broken at the moment of wallet creation, five years before anyone noticed.
The episode has reignited a familiar debate: if even a respected, security-focused, air-gapped device can fail this way, is self-custody viable for ordinary holders? Or will Bitcoin drift inevitably toward custodians, ETFs, and exchanges?
History has run a version of this experiment before. For roughly two and a half centuries, the most valuable bearer asset on Earth—New World gold and silver—had to move through waters infested with pirates, privateers, and hostile navies. How the gold era solved, and failed to solve, its security problem is directly instructive.
Lesson one: The convoy, not the stronger ship
Spain's answer to maritime predation was not to build individually impregnable vessels. It was systemic. Beginning in the mid-16th century, the Spanish Crown organized the Flota de Indias—a formal convoy system, operating from roughly 1566 to 1790, in which merchant ships crossed the Atlantic in large escorted groups rather than alone. The Casa de Contratación in Seville had decreed as early as 1526 that vessels sail in protected groups to deter piracy, and by the 1560s—following the sacking of Havana by French privateers—this had hardened into a scheduled two-fleet system designed on the recommendations of admiral Pedro Menéndez de Avilés. Two convoys of dozens of ships sailed each year, one to Veracruz and one to Cartagena and Portobelo, assembling their treasure at Havana before the escorted crossing home.
The system worked remarkably well. Historians note that the convoys were so effective that most enemies gave up attacking the fleets at sea and targeted treasure ports instead; the greatest actual risk to the fleets became storms and reefs, not pirates. In more than two centuries of operation, an entire fleet was captured only once—by Dutch privateer Piet Heyn off Cuba in 1628.
The mapping to Bitcoin is similar, and it is the most practical takeaway from the Coldcard incident. The convoy's logic—never let one hull, or one point of failure, carry the whole cargo—and that is the logic that defends the use of multisignature Bitcoin custody. Security researchers reviewing the exploit noted that holders using multisig arrangements across devices from different manufacturers remained protected: even an attacker who fully reconstructed a compromised Coldcard seed could not authorize a transaction without the other required keys. The same analysis found no evidence that other major hardware wallet makers shared the flaw, underscoring that vendor diversity itself functions as a defense—a bug in one manufacturer's firmware does not propagate to competitors running different code. Provided that the multisig plan is roperly implemented using independently generated keys—across different devices or codebases.
The 16th-century insight was that security is a systems property, not a product property. A single galleon, however well-armed, was a single point of failure. So is a single hardware wallet, however well-engineered.
Lesson two: Danger creates insurance—and Bitcoin's Lloyd's does not yet exist
The second institutional response to maritime risk was financial rather than military. In London around 1686–1689, Edward Lloyd opened a coffee house near the Thames that became the gathering point for ship captains, merchants, and men with capital willing to underwrite voyages. Lloyd's real innovation was information: he collected and published reliable shipping intelligence—arrivals, departures, losses—which made marine risk quantifiable and therefore priceable. The underwriters who gathered there spread large risks across many participants through syndication, so that no single loss ruined any single backer, and the venue evolved into Lloyd's of London, the foundation of the modern insurance industry.
Insurance is what made continued participation in dangerous trade rational. A merchant could lose a ship and stay in business. Self-custodied Bitcoin has no mature equivalent: when a seed is compromised, the loss is typically total, uninsured, and irreversible. The Coldcard sweeps illustrate the point brutally—the stolen coins consolidated into attacker-controlled addresses with no recourse for victims—and no terms of service that offer a path for recovering lost assets.
This is arguably the largest missing institution in Bitcoin self-custody, and history suggests its absence has predictable consequences. To date, self-custodied Bitcoin has no broadly available, standardized insurance market comparable to mature marine underwriting. Where individuals cannot easily insure a risk, they outsource it to entities that can. Large holders gravitate toward regulated custodians precisely because custodial insurance exists. Until something like a functioning underwriting market for self-custody emerges—which would itself require Lloyd's-style reliable loss data and standardized security practices to price risk—the economic gravity will keep pulling toward custody.
Lesson three: How gold's self-custody actually died—and the twist verification reveals
Here the historical record delivers a correction to the story Bitcoiners usually tell, and it is worth stating carefully because it changes the moral.
The common narrative is that physical danger—pirates, essentially—drove gold holders into the arms of custodians. The verified history is more pointed. Modern custodial banking in England emerged in the 1640s when London's goldsmiths began accepting deposits of coin and bullion for safekeeping, issuing receipts that gradually circulated as a transferable form of paper money—the forerunners of modern banknotes. But the precipitating event was not piracy. It was the state: Charles I's seizure of bullion that merchants had stored for safekeeping at the Tower of London in 1640, followed by the upheaval of the English Civil War, created acute anxiety about where valuables could safely be kept and sent depositors to the goldsmiths.
From there, the trajectory was swift and one-directional. Goldsmiths issued receipts payable "to bearer" rather than to named depositors; the receipts began circulating in place of coin; goldsmiths discovered they could issue receipts to borrowers as well as depositors, creating money and fractional-reserve banking in the process. Within decades, the physical metal sat still while paper claims moved—and the holder's relationship to the asset had been transformed from possession into a promise. The instability of undercapitalized goldsmith-bankers contributed to the founding of the Bank of England in 1694, and eventually the redemption promise itself was extinguished.
Three points in this arc deserve emphasis for Bitcoin. First, gold's bearer-asset era did not end because self-custody was technically impossible; it ended because custody was convenient, and convenience compounded. Every step—receipts, bearer notes, ledger transfers—was individually reasonable and collectively irreversible. Bitcoin's equivalents (exchange balances, ETFs, paper claims on coin) offer the same individually reasonable convenience. Second, custodial concentration created a new attack surface that pirates never had: the custodian itself, whether failing through overextension like the bankrupt goldsmiths of 1672, or through the sovereign's pen, as in 1640—and as in the U.S. gold order of 1933. The pirates could take a ship; only custody made it possible to take everything at once. Third, and most striking: the very event that birthed custodial banking was a custody failure. People fled one custodian (the Tower) to another (the goldsmiths). Fear does not necessarily produce good custody decisions; it produces movement, and movement tends to flow toward whoever projects trustworthiness at that moment.
That is the real risk of episodes like the Coldcard exploit. The danger is not that $89 million was stolen—Bitcoin's market barely reacted, with the price holding around the mid to low $60,000 range through the disclosures. The danger is the narrative: each self-custody failure makes the custodial vault look like the adult choice, exactly as the goldsmith's strongroom did in 1640.
The other side of the ledger: the vault's own body count
Honesty requires weighing both pans of the scale, because the historical record of Bitcoin's custodians is far bloodier than that of its hardware wallets—and the goldsmith analogy predicted exactly this.
The single largest loss event in Bitcoin's history was not a self-custody failure. It was Mt. Gox, the Tokyo exchange that at its peak handled more than 70 percent of all global Bitcoin transactions. When it filed for bankruptcy in February 2014, it disclosed the loss of approximately 850,000 BTC—roughly 750,000 belonging to customers and 100,000 belonging to the company—from a breach that had been running undetected for years. That figure represented nearly 7 percent of all bitcoin in existence at the time, and creditors waited a full decade before partial repayments in bitcoin finally began in 2024. Measured in coins, the Coldcard exploit—for all its severity—so far, is roughly one five-hundredth the size of Mt. Gox.
Mt. Gox was not an outlier; it was a pattern. In August 2016, hackers exploited a flaw in Bitfinex's multi-signature wallet implementation and stole 119,756 BTC, a loss the exchange socialized across all customer accounts by issuing debt tokens representing each user's share of the shortfall. In 2019, Canada's QuadrigaCX collapsed after the reported death of founder Gerald Cotten, initially framed as a key-person custody failure—Cotten was said to be the only person able to access the exchange's cold wallets, stranding roughly $190 million in customer assets. The Ontario Securities Commission later concluded the collapse was in fact the product of Cotten's fraud: he had created false accounts and traded customer assets against his own users with essentially no internal oversight. And in 2022, FTX—one of the most prominent exchanges in the world—imploded in a fraud exceeding $8 billion, with customer deposits misused inside the business itself.
Notice what these failures have in common with the goldsmith story and what they don't share with the Coldcard story. The Coldcard exploit was a technical failure: a randomness bug, disclosed publicly, bounded in scope, reproducible by independent researchers, and had they known of the failure, could have been mitigated, had users known of it. The great custodial losses were failures of trust and opacity: breaches running for years undetected, sole-keyholder fictions concealing fraud, customer funds quietly rehypothecated—precisely the failure modes of the 17th-century goldsmiths who lent out more than they held, and of the 1672 Stop of the Exchequer that bankrupted them. A hardware wallet bug can be audited, patched, and routed around. A custodian's balance sheet, as Mt. Gox and FTX customers learned, can lie until the day it can't.
The comparison also exposes an asymmetry in remedies. Coldcard victims could have protected themselves (had they been made aware of the downgrade in the seed phrase creation mechanics) in advance with multisig or independent entropy, and unaffected users could verify their safety immediately. Mt. Gox and FTX customers had no equivalent defense available at any price—no configuration of personal diligence protects a depositor from a custodian's hidden insolvency. The pirates, again, could only take a ship at a time; only the vault made it possible to take everything at once. Any honest accounting of Bitcoin's security history must conclude that vastly more bitcoin has been lost inside the vaults than outside them.
None of this downplays the devastation of the losses or makes the Coldcard exploit trivial, and none of it means custody is never appropriate. It means the question posed at the start of this article—does this exploit doom self-custody?—has the comparison backwards. The relevant question is not whether self-custody is risky, but risky compared to what?
Lesson four: Assay what you hold
Gold had one property that made distributed self-custody durable for millennia before and after the goldsmiths: anyone could verify it. Touchstones, acids, and scales let a holder confirm what they possessed without trusting any issuer.
The Coldcard failure is disturbing precisely because it broke the digital analogue of assaying. Users trusted that the device's randomness was real, and for five years, for a subset of devices, it wasn't. Yet the incident also demonstrated the remedy: Coinkite has indicated that users who supplied their own independent entropy—physical dice rolls mixed into seed generation—may not be affected by the vulnerability at all. Dice are the similar to an acid test of key generation: verification the holder performs personally rather than trust extended to a manufacturer. The Bitcoin maxim "don't trust, verify" has always been applied to transactions and consensus; the Coldcard episode extends it, non-negotiably, to the birth of the key itself. This of course give little comfort to the thousands of users who had no idea they needed to resort to tossing dice because the strength of the embedded entropy resilience was weakened without their knowledge.
What history predicts, and what remains open
The age of piracy ended when states decided suppression was worth the cost of navies—a solution unavailable against an anonymous adversary grinding key spaces offline. There will be no Execution Dock for whoever swept those wallets. The defensive burden on Bitcoin holders is permanent.
But the treasure-fleet era's deeper verdict is not fatalistic. Security crises did not destroy gold as an asset; they reorganized who held it and how. The organized, systemic responses—convoys, syndicated insurance, verifiable assay—worked. The drift toward custody happened where those systemic responses were absent or where trust was extended without verification.
Bitcoin's open question is therefore institutional, not technical. Multisig is the convoy, and it already works. Independent entropy is the assay, and it already works. What does not yet exist is the Lloyd's—the information and insurance layer that makes self-custody survivable for people who make mistakes. If Bitcoin builds it, the bearer asset survives in bearer form. If it doesn't, the market will choose the vault—despite the vault's record being, coin for coin, hundreds of times worse. That would repeat Lombard Street's mistake with the ending already known: from receipt to banknote to broken promise, the second half of that story is already written, and Mt. Gox, QuadrigaCX, and FTX suggest Bitcoin's custodians have been writing their own chapters of it all along.
Disclaimer: I'm not advocating for self-custody or centralized custody—both have burned people, as this article makes clear. This is education, not advice. Do your own research, know your own risk tolerance, and never store bitcoin in a way you don't fully understand.

