Casa CEO Nick Newman: Multi-Vendor Multisig Is the Fix for the Coldcard Wallet Disaster

Casa CEO Nick Newman joined Simply Bitcoin this week to walk through why multi-vendor multisig has gone from a niche recommendation to the baseline standard for anyone holding meaningful Bitcoin. He arrived with a personal story attached: the Casa team, including Newman himself, spent hours on a live call helping a Simply Bitcoin viewer migrate funds off a compromised Coldcard setup.
WHY THIS WEEK IS DIFFERENT
The urgency traces back to the Coldcard hack. Hackers figured out that there was a flaw in how Coldcard wallets generated users' seed phrases, which were predictable, according to security researchers at Block. By Monday, an on-chain analysis by Galaxy Research found three confirmed attack waves and other smaller incidents had drained 1,596 bitcoin from roughly 7,300 addresses, with a suspected fourth wave pushing the total toward 2,055 bitcoin, or roughly $130 million.
Newman said the affected users generally had one thing in common: a single point of failure. They trusted one hardware device, with no passphrase and no second vendor standing between an attacker and their coins. Casa's standard setup, a two of three multisig, splits that trust across a phone key, a hardware key, and a key held by Casa itself, so a single compromised device is never enough to move funds.
HOW THE VAULT TIERS WORK
Casa's product spans a simple mobile pay wallet for spending money, a two of three vault for most savings, and a three of five vault for larger holdings, where any three of five total keys can sign a transaction. Newman said users who came to Casa mid-crisis with a vulnerable Coldcard were able to connect that same device, generate the additional keys, and move funds into a protected multisig vault in under ten minutes.
He was careful to note that the Coldcard vulnerability itself does not indict self-custody broadly. Anyone holding Bitcoin ultimately trusts the security engineering of whoever built the device or platform they use, whether that is a hardware wallet maker or a centralized exchange. Multisig simply spreads that trust across more than one party, so a mistake by any single vendor does not sink the whole vault.
THE RECOVERY KEY, DURESS PHRASES AND INHERITANCE
Casa holds one key in every vault, but it is never enough on its own to move funds. If a user loses access to their other keys, Casa can help restore access after identity verification, a waiting period for standard accounts, or a video call and a pre-set duress phrase for higher tiers. Newman explained that if a client uses the duress phrase during that call, Casa's team acts normally on the surface but silently declines to sign and activates an emergency contact protocol instead.
The company's inheritance feature works on a similar principle. A designated family member links a free Casa account as beneficiary, and if the original owner passes away, requesting access starts a six month waiting period during which Casa repeatedly alerts the account holder in case the request was made in error or under duress.
CASA CANNOT BECOME THE SINGLE POINT OF FAILURE
Newman also addressed what happens if Casa itself is compromised or goes out of business. Casa's key is stored offline and never sufficient by itself to move funds, so a server breach exposes wallet metadata at most, not coins. If Casa disappeared entirely, users could export their setup into open source software like Sparrow or Electrum and continue using the keys they already control. Users can also sign up without linking a real identity, paying in Bitcoin rather than a card tied to their name.
Casa's standard tier costs $250 a year with a 30 day trial, rising toward $2,100 a year for the premium tier with dedicated advisor calls. Newman's recommendation is straightforward: once someone is holding an amount they would be genuinely upset to lose, multisig stops being optional.
This story comes from the Simply Bitcoin Live show. Watch the full episode.

