After Coldcard and Liquid, Nico Say Multisig Should Be the Default

Bitcoin has now had two major security scares in about five weeks, and Simply Bitcoin's hosts spent a chunk of Monday's show arguing that the lesson is the same one they keep learning the hard way: a single point of failure is a single point of failure, no matter how good the hardware is.
THE BACKDROP
The Coldcard exploit that began July 30 stole more than $130 million by exploiting a firmware flaw that made some users' seed phrases guessable, a bug traced to a build configuration error from 2021. Barely a month later, a hacker drained nearly 4,000 Bitcoin from Blockstream's Liquid Network before returning most of it. Neither incident touched Bitcoin's protocol itself. Both hit the layer where individual custody choices actually live: the device, the firmware, the bridge.
THE ARGUMENT FOR MULTISIG
One host's position was blunt: if you are holding a meaningful share of your net worth in Bitcoin on a single device, you are trusting one $100 to $300 piece of hardware with your life savings, and that is a single point of failure whether or not the underlying protocol is sound. The pushback from a co-host was just as direct: single-signature seed phrases did not break as a standard, a specific company's faulty entropy did. Both hosts landed in the same place anyway. Multisig, whether through a collaborative custody service, a self-managed setup, or a product that bundles multiple keys into one experience, removes the single point of failure that both Coldcard and Liquid exposed in different ways. Passphrases and dice-rolled entropy on a single-signature wallet were also floated as partial protections, since users who added either step were not exposed by the Coldcard flaw.
SELF-CUSTODY IS NOT DEAD, BUT IT IS NOT SET-AND-FORGET EITHER
The hosts pushed back on the idea, raised elsewhere online, that these exploits prove self-custody has failed and everyone should just hold an ETF instead. Their position: holding a spot Bitcoin ETF or using a collaborative custody service does not make someone less of a Bitcoiner, and there is no one-size-fits-all setup for every holder's technical comfort level. But the show's hosts were equally clear that treating a hardware wallet as a "buy it, bury it, forget it" solution is no longer realistic. Bitcoin is software, and software gets patched, breaks, and occasionally gets exploited by tools smarter than the humans watching for the bugs.
THE AI ANGLE
Both hosts connected the timing of these exploits to the accelerating use of AI models to audit code, for better and worse. As frontier models get faster at finding vulnerabilities than human reviewers, the hosts argued that Bitcoin hardware makers and protocol developers need to be stress-testing their own code with the same tools attackers are already using, rather than waiting to find out the hard way.
THE TAKEAWAY
The hosts did not pretend this was foreseeable in the moment, only obvious in hindsight, and compared the shift in posture to how attitudes about single points of failure change only after something breaks. Their bottom line for anyone holding a significant amount of Bitcoin: passphrases, dice-rolled entropy, or full multisig are no longer optional extras. Splitting custody across more than one setup, rather than trusting any single device or company with everything, is what actually would have protected a holder from both the Coldcard and Liquid incidents.
This story comes from the Simply Bitcoin Live show. Watch the full episode.



