
Danny Sanders of Trezor says the Coldcard incident is a specific flaw, not a crack in self-custody. He warns against moving Bitcoin to exchanges out of fear.
A flaw in Coldcard hardware wallets' seed generation has drained real Bitcoin from real users, and the fallout is already reshaping how people hold their coins. Some of that Bitcoin has moved back onto exchanges and into custodial products, Danny Sanders, chief commercial officer at Trezor, wrote in an opinion piece published by Bitcoin.com.
Sanders called the response understandable but misguided. The wallets that were drained were built with weak randomness at the moment of creation, a specific flaw in one company's product. It does not affect other manufacturers' devices. "If your wallet was made properly in the first place, nothing about this incident touches you," he wrote. "Your funds sit exactly where they did a week ago, protected by exactly what protected them before."
The instinct to move Bitcoin to a custodian after a hardware wallet failure is human, Sanders said. It gets the lesson backwards. "Someone always holds the keys to your Bitcoin. The only question is who. If it is not you, then it is a company, and you are trusting that company to be honest, competent and still standing tomorrow."
Exchanges have been hacked and custodians have collapsed, he noted. The entire reason Bitcoin exists is so that money can be truly yours, rather than a balance a company shows you and promises is safe.
Sanders also pushed back on the knee-jerk move to multisignature wallets. Multisig is a genuinely good tool for large holdings, he said. Trezor has supported it since 2014. For many people it is more than they need. A simple single-sig setup does the job well: one seed written down properly and stored safely. Multisig has real footguns, from falling below the required threshold to the difficulty of backing it up and restoring it correctly. The easily managed versions carry a yearly fee.
"Do not let fear redesign your setup," he wrote. "Fear is a poor engineer. It pushes people to bolt on complexity they do not understand, and complexity you do not understand is its own kind of risk."
The difference between trusting a custodian and trusting a hardware wallet vendor is fundamental, Sanders said. When you leave coins with a custodian, you hand over the coins themselves. When you use a hardware wallet, you never hand the coins to anyone. What you rely on is narrower: that the tool was built correctly. Because Trezor's firmware and device design are open source, that is something you or an independent expert can actually check.
"One kind of trust is verifiable," he wrote. "The other you simply have to hope is well placed."
Transparency shapes how Trezor builds from the start, Sanders said. The company runs a bug bounty programme that pays independent researchers to find flaws. The code is public every day, not just when the company invites someone in. "The point of Bitcoin was never that you should have to trust a new set of institutions instead of the old ones. It was that you should not have to trust blindly at all. You should be able to verify."
Over the past week, Trezor welcomed many new customers, a good number of them coming from Coldcard, Sanders said. People who care about self-custody and have no intention of giving it up. "After everything we have all watched happen, I still believe the safest hands for your Bitcoin are your own."
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.