Bitkey's Lead Engineer Defends Dropping The Seed Phrase, Months After The Coldcard Hack

Bitkey, the self-custody wallet built by Block, made a deliberate choice that still unsettles plenty of Bitcoiners: it never shows the user a seed phrase. Clay Garrett, Bitkey's lead engineer, joined the show to explain the design and why he thinks the Coldcard hack changed how people hear that pitch.
THE PROBLEM BITKEY WAS BUILT TO SOLVE
Garrett said the wallet started from a simple observation: plenty of people want to self-custody Bitcoin but don't feel equipped to manage the operational security a traditional setup demands. Mismanaged seed phrases and phishing attacks account for a large share of historical Bitcoin losses, and Garrett said Block saw a gap between the people capable of running a flawless multisig setup and everyone else who still wants real self-custody.
Instead of exporting a 24-word phrase for the user to protect, Bitkey generates three separate keys during setup: one on the user's phone, one on the hardware device, and one held by Block's server. Each key is generated independently, using the native secure random-number generator in its own environment, a hardware-backed generator on the device itself, Apple's or Google's native APIs on the phone, and an Amazon Nitro Enclave on the server side.
WHAT HAPPENS IF BLOCK DISAPPEARS
Garrett walked through the wallet's answer to the obvious objection: what happens to a user's Bitcoin if Block goes out of business. Every user gets an "emergency exit kit," a PDF stored locally and in the cloud at onboarding that contains an encrypted version of the user's app key. Recovering funds without Block requires that PDF plus the user's unlocked hardware device to decrypt it, after which the funds can move without the company's involvement at all.
Garrett said the team deliberately avoided building anything proprietary into that recovery path beyond convenience. The same protocol could run from a command-line tool or an NFC card; the app is simply the easiest version to ship today.
THE SINGLE-VENDOR QUESTION
Asked how he responds to critics who argue Bitkey isn't "real" multisig because all three keys originate from one company, Garrett pushed back on the framing directly: it is real multisig, just not multi-vendor. He argued a single, vertically integrated system lets Block run roughly 250 automated integration tests continuously across the whole setup, a level of ongoing testing he said a four-vendor, roll-your-own stack can't replicate. He added that Bitkey wasn't designed to be single-vendor by philosophy, and that the team is exploring ways to let users bring in third-party hardware down the line.
A PRIVACY FEATURE BUILT TO LIMIT WHAT BLOCK CAN SEE
Garrett said Block does not want visibility into users' balances or transaction history, and built something called chain code delegation, now formalized as BIP-89, to avoid it. In a standard multisig setup, a co-signing service typically holds the chain codes needed to derive every address in a wallet and calculate its full balance and history. Chain code delegation lets the co-signer complete its half of a signature without ever learning the chain code itself, so Bitkey only sees a transaction it is actively co-signing. A full-stack recovery sweep is the exception: that process does require Block to see the entire balance being moved.
WHAT THE COLDCARD HACK ACTUALLY TAUGHT HIM
Garrett was one of the engineers who helped trace the July 2026 Coldcard theft, a firmware flaw that silently weakened seed randomness on certain devices and let attackers drain roughly 1,800 BTC across multiple waves. His team's investigation linked part of the attacker's on-chain activity to a paid blockchain data provider account, a lead that has since been shared with law enforcement.
Garrett said the exploit shouldn't be read as proof that single-signature wallets are finished. The actual failure, he said, was a specific, badly implemented entropy source on one device line, not a flaw in single-sig as a concept. What he does think is non-negotiable is eliminating single points of failure wherever possible, which is why he personally runs multisig and why Bitkey's own design lets a user recover funds even after losing both their phone and their hardware device.
This story comes from the Simply Bitcoin Live show. Watch the full episode.



