Towards New Self-Custody Best Practices

Posted by seed-cat

Aug 4, 2026/20:23 UTC

The recent vulnerabilities in Bitcoin wallet security, particularly the Coldcard incident which led to significant financial losses, underline the urgent need for updated self-custody best practices among users. The technical community must address these issues by drafting protocols that are both secure and user-friendly. This begins with a move towards multi-vendor 2-of-2 multisig setups, where utilizing hardware from different manufacturers can prevent a systemic failure should one vendor's device be compromised. The Coldcard cases have shown that relying on a single vendor for multiple signatories negates the benefits of multisig as it leaves the door open for simultaneous exploitation.

Another important aspect is the generation and verification of entropy by the user. It has been observed that user-generated entropy often falls short compared to what is generated by dedicated security chips. However, the ability of users to verify the randomness of their wallet setup is crucial, which is not possible when they do not generate their own entropy. One effective method proposed is for users to select the majority of their seed words themselves from a complete set of BIP39 words, ensuring randomness through physical mixing methods or creative alternatives like shuffled card decks. Users should avoid passphrases as they generally add unnecessary complexity without significantly increasing security.

Backup strategies are also critical, with robust materials such as steel or titanium plates recommended for punching or stamping seed words. Such backups need to be tested by wiping and restoring the wallet to confirm their accuracy before being stored in separate, secure locations. This ensures funds remain safe even if one storage site is compromised.

In terms of transaction practices, after setting up their wallet, users should conduct small test transactions to ensure everything functions correctly. This includes verifying addresses and transaction details on the device itself, which helps guard against potential vulnerabilities in the transport mediums used, whether USB, QR codes, or MicroSD. Devices should ideally be dedicated solely to cryptocurrency transactions to avoid risks associated with general-purpose devices.

Implementing these recommendations can help users maintain control over their digital assets while minimizing risks associated with device or vendor-specific vulnerabilities. For further assistance and detailed steps, services like Casa and Unchained can provide additional support, though it’s important to note the independence from any product or company affiliations in these suggestions.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback