Bitcoin Retreats Following $3 Billion ETF Inflow Rally
Bitcoin fell to $77,379 after a rally fueled by $3 billion in ETF inflows over nine days.
Coldcard's entropy bug led to bitcoin losses, prompting self-custody advocates to recommend multi-vendor multisignature wallets as a new standard.
Following Coldcard's critical entropy flaw, bitcoin self-custody experts and advocates are now recommending a new baseline: multi-vendor multisignature wallets. This approach aims to reduce reliance on any single hardware wallet manufacturer, among other threats.
The entropy bug in Coldcard, which remained hidden from at least 2021 onward, has delivered a tough lesson for those who hold their own Bitcoin. Regardless of a wallet manufacturer's apparent legitimacy or skill, even a highly recommended and reputable firm can harbor a serious flaw. Consequently, Bitcoin users are rethinking older advice and assumptions, with a number of them proclaiming the 'death of single sig'âthe common self-custody approach that relies on private key generation from a single device.
Holding your own Bitcoin is undeniably an advanced undertaking. Proponents suggest it safeguards user assets against exchange misconduct exemplified by FTX and MtGox, along with numerous other cases. However, recent developments have prompted a reassessment of custody methods, with many bitcoin holders transferring coins to exchanges, at least for a while, while others are updating or completely overhauling their self-custody arrangements. Nick Neuman, Casa's CEO, stated that 233k bitcoins were moved to safety as a response to the Coldcard exploit.
Knowing when self-custody is appropriate, and for whom, requires a grasp of one's own threat model. A threat model involves a diligent examination of the risks an individual faces, aiming to design security measures and frameworks in advance.
A straightforward exercise for threat modeling involves stepping back and writing down every concern you have regarding self-custody. After that, consider all the warnings advocates offer users, and add those to the list. Subsequently, organize or rank the entries according to their likelihood for you personally and their general probability. Lastly, evaluate each item based on the severity of its potential impact: would your existing setup and strategies withstand that threat if it materialized?
In Bitcoin self-custody, the two most frequent causes of fund loss are user mistakes concerning backups or forgotten passwords, along with outright theft. Many wallets that contain presumably lost bitcoinsâthose that have never been spentâoriginate from poor private key backups in the early era, leading to data loss upon computer failure. Other users set passwords that were too complex to crack, only to forget them, thereby encrypting their private keys indefinitely.
Regarding theft, poor-entropy attacks are probably among the most effective assaults on self-custody so far. Coldcard now joins a long roster of wallets that have experienced such flaws, whether deliberate or accidental, including Trust Wallet and a host of lesser-known, possibly harmful mobile wallets. In certain instances, counterfeit wallets such as the iOS Sparrow applications merely pilfered funds by retaining copies of user-created private keys and sweeping the money after deposit. Across all these scenarios, exercising greater caution before entrusting random software with one's life savings is the remedy.
When users possess a well-defined threat model and a solid grasp of the technology, crafting security practices turns more systematic than creative. Although each person has unique factors to consider, certain frameworks have proven to be the most robust against a broad range of risks. One approach that is gaining broad endorsement and adoption among long-term Bitcoin self-custody holders is a meticulously configured multisig arrangement.
The phrase "multi-vendor multisig" is fairly new within the self-custody space. However, the concept of multisig has exploded in popularity in 2026, driven by the Coldcard incident that resulted in the loss of more than $100 million worth of bitcoin, primarily from single-seed wallets. The majority of Coldcard users with a single seed seem to have generated their private keys on the device without an extra passphraseâextra words that introduce custom entropyâor without additional dice rolls, which achieve the same effect differently.
The insufficient entropy originating from the Coldcard firmwareâwhich users had little cause to question, considering the manufacturer's robust reputationâconsequently made it straightforward to infer the corresponding private keys after some tailored effort, which attackers ultimately discovered.
The subsequent surge of interest in multisig is justified. Multisig Bitcoin wallets shield users from hardware manufacturer defects by enabling the creation of a Bitcoin address that demands signatures from multiple private keys and thereby multiple devices, via what is called a Bitcoin script. Bitcoin scripts are essentially contracts that determine how funds in a wallet can be spent. Every Bitcoin wallet incorporates some kind of script, with the simplest and most prevalent being that any party capable of signing a valid transaction can spend all or any of the funds. Multisig scripts, however, require a certain number of valid signatures from distinct keypairs to authorize a withdrawal. These scripts are enforced by Bitcoin's consensus rules. The theory behind multi-vendor multisig holds that users should ensure each keypair used to create a Bitcoin multisig originates from a different wallet maker.
A potentially common example today could involve a Trezor Safe 7 device for one key, a Ledger Nano producing a second key, and a third key from a multisig wallet provider, serving as a recovery key. Such a script would demand any two valid signatures from the three available in the arrangement.
Employing two distinct hardware wallet makers reduces the user's reliance on any one vendor, shielding them from an entropy defect similar to Coldcard's.
Additional multisig configurations can incorporate more keys, with a 3-of-5 threshold also widespread and a standard feature of a multisig-focused wallet such as Casa. At this point, the everyday terminology for Bitcoin spending software becomes less precise, requiring clarification. Wallets like Casa serve as software interfaces that allow users to combine partially signed transactions from various private key pairs. In this context, it becomes more accurate to label hardware wallets like Trezor or Ledger as "key signers," because no single keypair in the set possesses enough key material to spend all the bitcoin held in the multisig script address.
Thus, Casa is a multisig wallet that enables users to employ a threshold of hardware signers to protect and transfer bitcoin. Essentially, it assists users in engaging with Bitcoin script and crafting transactions that comply with consensus rules. Additional examples of similar multisig wallet providers are Nunchuck, Sparrow desktop wallet, and Unchained Capital.
With providers like Casa and Unchained, the company provides users with a recovery key that it controls, a feature some find beneficial. Conversely, Nunchuck and Sparrow are built for complete user independence in that area, although Nunchuck also has a paid plan associated with recovery keys.
Another advantage of a multisig wallet is its potential resilience against so-called wrench attacks. Nations such as France, where Bitcoin and crypto ownership becomes public information through tax filings, have emerged as hotspots for cryptocurrency theft linked to kidnapping. Whether using self-custody or not, individuals targeted by this type of crime are susceptible to theft, especially when funds can be moved in their entirety quicklyâwhether from a custodial exchange accessible via phone or some self-custody arrangement. Sophisticated forms of multisig, including multi-jurisdictional or time-locked multisig, require users to travel, ideally through an airport, to retrieve other key signers necessary to assemble a valid Bitcoin transaction. Alternatively, the recovery key in the multisig might have a condition stipulating that it will not sign for two weeks after the user submits the request along with the corresponding transaction data. The outcome is the elimination of the last central point of failure in Bitcoin custody: the user's own readiness to send the bitcoin, especially when under coercion. Although best practices regarding wrench attacks primarily aim to avoid being in that scenario altogether, making it difficult to spend one's coins actually provides protection against a variety of attacks, including phishing and other social engineering tactics that apply pressure to trick users into sending funds hastily.
Multisig is also starting to facilitate new types of Bitcoin insurance, exemplified by AnchorWatch, a multisig wallet and insurance firm that provides bitcoin theft coverage priced in BTC. Currently, the company's services are mainly available to United States residents via the Lloyd's of London underwriter.
A significant drawback of multisig is that the user must not only possess access to the required threshold of key material for signingâwhether two hardware wallets as in the earlier example, or one hardware wallet plus a recovery key from the wallet providerâbut also must retain a copy of the multisig script or template. This is necessary to reconstruct the smart contract and thereby the valid conditions for spending. Most multisig wallets save this data for their clients, but they also furnish a copy to users, enabling recovery without relying on the multisig wallet in case it ever becomes unavailable.
Share to
Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.
Bitcoin fell to $77,379 after a rally fueled by $3 billion in ETF inflows over nine days.
An exploit drained over $653,000 from Avici's card collateral vaults on Solana, crashing the AVICI token by 40%.
Justin Sun is suing ex-girlfriend Jing Tian for $4.5M and says AI advised him not to pay her $50M demand.
Metaplanet CEO Simon Gerovich says at Bitcoin Asia that the region's moment for bitcoin is here, with a market bottom and deep savings ready to move.