A major security flaw in the Coldcard hardware wallet firmware has triggered a fierce debate over the safest way to store Bitcoin. The bug caused the device’s built-in generator to produce predictable seed phrases, enabling hackers to drain 1,367 BTC (worth approximately $89 million) from more than 4,500 addresses. The incident has reignited a fundamental discussion about self-custody, inheritance, and the limits of hardware-based security.
In response to the crisis, Ripple CTO and XRP Ledger co-creator David Schwartz unveiled an unconventional solution he calls the "nuclear briefcase" strategy. Rejecting both pure paper wallets and simplistic hardware setups, Schwartz proposed using two SecuX W20 hardware devices configured with the same 24-word seed and identical PIN codes. One device is given to each of two relatives, while the PIN is entrusted to two trusted friends unconnected to the family. As long as the owner lives, neither group can steal the funds alone; after death, the friends reveal the PIN to the relatives, granting heirs access. The method replaces technical complexity with a human-engineered distribution of roles, mitigating risks of theft, loss, fire, and inheritance disputes.
Meanwhile, early Bitcoin developer Peter Todd defended self-custody’s superiority despite the Coldcard fiasco. He pointed out that even a large-scale hardware failure pales next to the systemic dangers of centralized platforms, citing the QuadrigaCX exchange collapse that cost investors $200 million—more than double the Coldcard losses. Todd argued that securing Bitcoin is simpler than learning to drive, requiring only that users write down 12 words and avoid losing them. He proposed educational courses, similar to driving schools, to eliminate human-error critical mistakes. The vulnerability, he stressed, lies not in Bitcoin’s code but in users’ lack of responsibility and basic digital hygiene.