Self-Custody Was Never the Problem
By Vultisig • • Updated September 1, 2026
Contents
Part 6 of 6. The close. If you're just arriving, the road here matters: the incident, what randomness actually is, what a seed actually is, what the bolt-on defenses fix and can't, and the wallet without a seed. Today: the reactions, the real lesson, and, as promised at the start, our cards on the table.
The takes
Within days of the sweep, serious people reached for big conclusions, loudly, and they deserve to be quoted accurately rather than strawmanned.
ARK's Lorenzo Valente argued that self-custodians have "traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk, backup risk," concluding people are better off holding funds across exchanges or ETFs. In the same piece, Amicus co-founder David Lawrence called the incident a win for "Big Bitcoin" and declared the dream of billions holding their own coins "over. Done." Podcaster Guy Swann called it the worst hit in Bitcoin's history precisely because it struck "the most knowledgeable and 'properly secured'" holders. And developer Udi Wertheimer drew the sharpest practical line: bitcoin security can't be passive anymore, so either monitor the threat landscape constantly yourself or "pay someone else to be worried."
We understand the emotional force behind every one of those sentences. Roughly $116 million evaporated from the wallets of the most careful people in the room, and this series has spent five articles explaining exactly why their carefulness didn't matter. Trust took real damage. Pretending otherwise would insult everyone who lost coins, and cheap "just trust harder" cheerleading is part of how the industry got here.
But now look at Valente's list again with this series' eyes. Software risk, hardware risk, supply-chain risk, phishing risk, backup risk. After five articles, you can name what that list actually is: it's the attack-surface map of one object. The complete secret. Software risk is the birth. Hardware and supply-chain risk are the single device that performs it. Phishing risk exists because a complete secret can be asked for. Backup risk exists because a complete secret must be stored whole. Not one of those risks is inherent to you holding your own money. Every single one is downstream of a design in which a whole key exists in one place.
So the argument, fully unpacked, says: because one architecture of self-custody failed, retreat from self-custody itself. That's a strange leap, and it gets stranger the harder you look.
What the retreat actually buys you
Hand your coins back to a custodian and you haven't eliminated a single point of failure. You've hired a much larger one and agreed to stop watching it. The history here isn't subtle: Mt. Gox was "the safe option" until roughly 850,000 BTC wasn't there. FTX was the adult in the room until the room turned out to be empty. Every generation of this industry relearns that a custodian is a single point of failure with a marketing department, and the phrase "not your keys, not your coins" was purchased with losses that dwarf this incident.
An ETF is the same trade wrapped in a nicer instrument. As price exposure, fine, it has real uses. But be precise about what it is: a claim on a claim, redeemable in dollars, tradeable during market hours, sitting atop a custodian you'll never audit. You cannot withdraw it, move it, or use it as bitcoin. Telling people the lesson of a wallet flaw is to stop holding bitcoin at all is not a security recommendation. It's a surrender dressed as one.
And Wertheimer's binary, monitor constantly or pay someone to worry, quietly assumes the only possible architecture is the one that just failed. A design where no complete key exists doesn't need your constant vigilance, because there's no single object whose silent compromise ends you. The answer to "self-custody demands too much fear" isn't outsourcing the fear. It's removing its object.
The irony nobody mentions
Because here's the detail that gives the whole game away, the one this series built toward. The institutions custodying the coins behind those very ETFs, the professional, regulated, adult-supervision options the retreat crowd points to, do not secure billions with a seed phrase in a drawer. They run MPC and threshold signing: Fireblocks across its institutional network, BitGo with its own threshold stack, and the custody layer around them. Distributed key material, no complete key, no single moment of failure. Part five's architecture, in production, at institutional scale, for years.
Read that from where you sit. The professionals concluded long ago that single-secret custody is unacceptable for them. The technology they chose instead is open, mature, and runs on the phone in your pocket. So the honest version of this incident's lesson was never "individuals can't be trusted with their own keys." It's that individuals have been holding keys with an architecture the professionals already retired, and almost nobody offered them the upgrade.
Self-custody was never the problem. The single secret was. Retail was told to give up. It should have been told to catch up.
Our cards on the table
Time to say plainly who has been writing this series. We're Vultisig, and we build the wallet from part five.
A Vultisig vault is created in an MPC ceremony across devices you already own: your phone and laptop, or three devices, or more. The complete key never exists, not at birth, not at signing, not ever. A threshold of your devices approves every transaction. There are no 12 words anywhere in your life: nothing to write down, nothing to display, nothing to phish. It's open source, fully self-custodial, works across every major chain, and our own treasury lives on exactly what we ship to you. We said at the start that this series would be biased, and here's the shape of the bias: we spent years betting everything on the argument these six articles just made, that the seed phrase is the single point of failure the industry has been armoring instead of removing. This incident is why that bet exists.
What we won't do is claim perfection. Nobody in security gets that word anymore, and Coldcard's five silent years should humble every team shipping code that guards other people's money, ours included. What we can offer is the architecture this series argued for, and the receipts to check us on it: the code is public, and the skeptical read is the one we respect most. Hold us to the standard this series set, on GitHub, anywhere you find us. We are not perfect. We listen, and we ship.
More users, more secure
This series had one goal, and it wasn't fear. Fear is what sells hardware after incidents, and everyone reading this has seen enough of it. The goal was understanding: why this happened, what the object in your backup actually is, and the fact that an architecture without that object exists, works, and is already trusted with more money than any of us will ever touch.
What you do with that understanding is genuinely yours, and every secure path counts. If this convinced you to build a proper multisig with diverse devices, do it well; you have our respect and you'll sleep fine. If it convinced you to check a firmware version and migrate a weak seed this weekend, that alone made the series worth writing. Sovereignty comes in more than one architecture, and more secure users is the win, full stop.
But if you finished part five with that itch, the curiosity about what a wallet feels like when the solemn write-these-words-down moment simply never arrives: vultisig.com. Two of your own devices and a few minutes, and you'll stand in that strange, quiet moment yourself, waiting for words that never come. Bring your skepticism, it's open source. Bring your questions. And that friend of yours still holding a seed on hardware from 2021? You know exactly why they should come along.
Trust in self-custody took a real hit. The answer was never less sovereignty. It was better architecture.
Thank you for reading all six. Now go check on your coins, and on your friends'.
Related Articles
The Wallet Without a Seed
A key that works without ever existing. How threshold signatures remove the complete secret, and why institutions adopted them years ago.
The Bolt-On Defenses
Passphrases, Shamir, multisig, air gaps, steel. What each one actually fixes, what it quietly can't, and the pattern hiding underneath.
One Moment of Randomness
A build flag turned Coldcard's randomness into 40 guessable bits. How $116M was swept, and why every wallet's security is decided in one moment.