I have always been a staunch advocate for self-custody. The very ethos of decentralized finance rests on the principle of individual sovereignty over assets. But the $38 million Coldcard exploit, which saw a significant breach of funds just last week, exposes a persistent and dangerous blind spot in our ecosystem. This is not just another hack; it is a fundamental indictment of our collective failure to implement robust security standards and provide adequate user education for self-custody solutions. We must re-evaluate our approach, right now.
The industry cannot simply parrot "not your keys, not your coin" without acknowledging the technical complexity that phrase places on the average user. We tout the security of hardware wallets, but the Coldcard incident proves these devices are not impenetrable fortresses. They are tools, and like any tool, their effectiveness is limited by the operational security of their user and the unforeseen vulnerabilities in their design or implementation. With Bitcoin trading at $62,933 and Ethereum at $1,867, and the Crypto Fear & Greed Index sitting at 27 (Fear), the market demands more than platitudes; it demands real security.
Many in our space are quick to dismiss such events as user error or isolated incidents. This is pure BS. While user vigilance is critical, the industry has a responsibility to build systems that are resilient, intuitive and secure even in the face of human fallibility. We have seen significant progress in other areas: Bitcoin spot ETFs were approved in Jan. 2024, followed by Ethereum spot ETFs in May 2024, bringing institutional capital and regulatory comfort. The GENIUS Act, signed into law in 2025, provides a clear federal framework for stablecoin issuers, fostering stability and trust. Even the CLARITY Act is moving through Congress to define digital asset market structure. Yet, when it comes to the very foundation of individual ownership, we are still operating in a digital wild west.
This is not to say that self-custody is inherently flawed; it is to say that our implementation and educational efforts around it are. We have projects like Hyperliquid, with its native HYPE token launched via airdrop in Nov. 2024, demonstrating cutting-edge Layer 1 technology for on-chain perpetual futures. We have EigenLayer, Jupiter, Ethena and Ondo, all with widely traded tokens like EIGEN, JUP, ENA and ONDO, innovating at a rapid pace. These advancements in financial infrastructure are meaningless if the act of holding one's own assets remains fraught with this level of peril.
President Trump's administration, with Federal Reserve Chair Kevin Warsh and SEC Chairman Paul Atkins at the helm, is clearly leaning into innovation, but they also prioritize consumer protection. The Coldcard exploit provides ammunition to those who argue that crypto is too risky for the mainstream. Treasury Secretary Scott Bessent understands the need for a robust digital economy, but exploits like this undermine confidence. We cannot expect widespread adoption if even "secure" self-custody solutions result in $38 million losses.
The solution is not to abandon self-custody. It is to re-engineer it. That means investing in vastly improved user interfaces that minimize error, creating standardized, open-source security audit frameworks for hardware and software wallets, and launching comprehensive, industry-wide education initiatives that go beyond basic key management. The current state of self-custody is not fit for purpose for the billions of users we hope to onboard. This exploit is a harsh reminder that our innovation must extend to security and user experience, or the promise of true financial sovereignty will remain just that—a promise.
David Gokhshtein Founder, Gokhshtein Media
