A bug in Coldcard's hardware wallet has resulted in an $88 million loss for users, reigniting the perennial debate over self-custody versus centralized exchanges. But early Bitcoin developer Peter Todd argues the incident doesn't undermine the case for holding your own keys.
The $88 million bug
Coldcard, a popular hardware wallet known for its security focus, suffered a bug that led to a massive loss. The exact nature of the vulnerability hasn't been disclosed, but the $88 million figure makes it one of the costliest hardware wallet incidents on record. Users who relied on Coldcard for cold storage found their funds drained, shaking confidence in a product built to be impenetrable.
Todd's defense of self-custody
Peter Todd, an early Bitcoin developer, didn't mince words. He argues that self-custody remains superior despite the Coldcard bug. In his view, the risks of holding your own keys — even with a flawed device — are still lower than the risks of handing control to a third party. It's a stark position, especially when users just lost $88 million. But Todd insists the math favors the individual.
The QuadrigaCX comparison
To make his point, Todd points to QuadrigaCX, a centralized exchange that collapsed after losing user funds. The exchange's failure wiped out hundreds of millions of dollars, and many customers never recovered their money. For Todd, that's the real cautionary tale. Centralized services concentrate risk in a single point of failure — a CEO, a server, a bad actor. Self-custody, even with bugs, spreads that risk across many devices and users.
The Coldcard bug is a serious blow, no question. But Todd's argument forces a hard look at the alternatives. Exchanges have a long track record of losing money, freezing withdrawals, or simply vanishing. QuadrigaCX is just one example. The question isn't whether self-custody is perfect — it's whether it's better than the alternative.
For now, the Coldcard incident serves as a reminder that no system is perfect. But as Todd sees it, the alternative — trusting a third party — has proven even more dangerous.




