Coldcard Hack Exposes Flaws in Self-Custody and Third-Party Custodians
The recent Coldcard hack has left thousands of Bitcoin holders scrambling to secure their assets. The incident, which has resulted in over $130 million worth of losses, has reignited debates about who should hold the keys to one's cryptocurrency.
Michael Tanguma, co-founder and CEO of Onramp, argues that relying solely on self-custody or third-party custodians is no longer a viable option. He points out that even the most secure hardware wallets can be compromised if their firmware is not regularly updated. In the case of Coldcard, the device's weakness was discovered after five years.
Tanguma advocates for multi-institution custody, where independent regulated companies hold one key each, and a quorum must sign off on transactions. This approach eliminates the risk of single-point failures and provides an additional layer of security. Onramp has already implemented this model with clients such as BitGo, Coincover, and Tetra Trust.
Others in the industry disagree with Tanguma's assessment, including Jameson Lopp from Casa, who suggests that multi-vendor multisig is a more effective solution to mitigate vendor risks. However, Tanguma believes that his approach has several advantages, including lower costs and greater ease of use.