Bitcoin Well's Adam O'Brien on the Coldcard Hack: Self-Custody Isn't Dead, It Evolved

Three weeks after the Coldcard hack, the conversation around self-custody has shifted from shock to strategy. Bitcoin Well founder and CEO Adam O'Brien joined the show to make the case that self-custody didn't fail. Single sig did.
WHAT ACTUALLY HAPPENED
Beginning July 30, an attacker exploited a five-year-old firmware flaw in Coinkite's Coldcard hardware wallet to systematically drain Bitcoin from affected devices. Galaxy Research's running tally puts the losses near 1,816 BTC, worth close to $116 million, drained from more than 5,200 addresses across multiple waves. The flaw traced back to a March 2021 firmware release with a build configuration error that caused seed generation to fall back on a weak software random number generator instead of the device's hardware-based entropy source, collapsing effective key strength from a designed 128 bits down to as little as 40 bits on older devices, low enough to brute force without ever touching the physical wallet.
O'BRIEN'S ARGUMENT: IDENTIFY THE SINGLE POINT OF FAILURE
O'Brien said the lesson isn't to abandon self-custody, it's to stop trusting any one point in the chain. He said he personally avoided exposure because he generated his own wallet using dice-rolled entropy years before the exploit, and that the habit of eliminating single points of failure, whether it's a seed-generation method, a mailing address, or a single hardware device, is what separates a stack that survives from one that doesn't. "There is no such thing as removing all single points of failure," he said. "All you can do is identify them and then put yourself in a position to feel comfortable with the ones that you have."
He drew a direct line to how custodians work: any exchange or proof-of-reserves setup is ultimately still self-custodying coins somewhere, on someone else's infrastructure, with its own single points of failure investors rarely see.
WHY MULTISIG IS THE NEXT STEP
The show's hosts framed multisig, splitting custody across multiple independent keys so no single seed or device controls the coins, as the practical answer for anyone holding a meaningful amount of Bitcoin. Collaborative custody providers like Casa and Unchained were named as options for people who don't want to manage a fully sovereign multisig setup themselves. On the show, hosts also cited a figure that roughly 22,000 BTC moved from self-custody wallets back to custodians in the exploit's immediate aftermath, a number Simply Bitcoin has not been able to independently verify.
THE TAKEAWAY
O'Brien's closing point was blunt: the goal isn't a perfectly unhackable stack, because that doesn't exist. It's making your setup harder to steal than the next person's, whether that means multisig, a collaborative custody provider, or simply removing your name and address from anything tied to your holdings. Single sig on one device was never the finish line. It was the starting point.
This story comes from the Simply Bitcoin Live show. Watch the full episode.

