BTC$104,872.40+2.41% XAU$3,318.12+0.42% SPY$5,917.88-0.18% M2INFINITE+∞%
BLOCK 945,231
Guide · Bitcoin custody

How to keep your Bitcoin safe.

Not your keys, not your coins. Six words every holder knows, and a custody decision most holders never actually made. This guide lays out the models, the tradeoffs, and the failures that sit outside all of them.

Talk custody with us → 30 MINUTES · NO PITCH · NO OBLIGATION
§ 01

Why this, why now?

Since the beginning, Bitcoin investors have lived by those six words, relying on cold wallets and seed phrases secured under lock and key.

That assumption was tested this summer. In July 2026, Coinkite disclosed that certain COLDCARD firmware versions generated seeds from predictable software randomness instead of the hardware's true entropy. A flaw at the point of key generation, not at the point of use, meant some seeds were guessable well before anyone noticed. No phishing, no physical access, no user error. The failure sat upstream of every security practice a holder might have followed.

The scope matters: seeds generated on affected firmware were at risk unless they came from independent dice entropy or sat behind a strong, unique passphrase. And the emergency firmware fixes future generation only. It cannot repair a seed that was already exposed, so those coins had to move.

This isn't a verdict on hardware wallets or on self-custody as a category, but it is a reminder that the model itself has a shape and the shape has a weak point most people never examine.

Custody is a decision. Most holders inherited theirs from whatever they set up first.
§ 02

The frame.

"Not your keys, not your coins" is still true. The question is what it means to act on it in 2026.

Every custody model answers two questions: who can move the coins, and what has to fail before they're gone.

INDIVIDUALS WEIGHT

What has to fail?

Death, a lost key, a forgotten passphrase. The risks that end a position quietly.

COMPANIES WEIGHT

Who can move them?

Signing authority, internal controls, and what an auditor will accept.

No model removes risk. Each one relocates it. It's up to the individual, or the controlling entity, to decide which risks they're equipped to carry.

§ 03

The six models.

Six models exist on a spectrum, ordered here from least to most control.

Least controlMost control
01

Exchange or broker.Think Coinbase · Kraken · Gemini

The custodian holds the keys, you hold an account balance. This is the easiest and most liquid option. The tradeoff: the platform controls the keys, and your protection depends on its custody arrangements, legal segregation, solvency, and your withdrawal rights.

FITS · Small positions, active traders, and companies in the middle of an acquisition or a fundraise, where holding period is short and liquidity matters more than control.
02

Single-signature self-custody.One device · one seed

One device, one seed, full control. This is the model the COLDCARD incident hit hardest, and it reveals the model's core property in one sentence: when the only seed is compromised, lost, or generated badly, every failure is total. There is no second key to fall back on.

FITS · Individuals with modest holdings and real operational discipline. It's difficult to defend for any entity that answers to a board.
03

Multi-signature self-custody.A quorum · every key yours

A quorum, such as 2-of-3, with every key held by you. This removes the single point of failure and adds real operational weight: more devices, more procedures, more people who need training.

The caveat: three keys generated from one vendor on one firmware version aren't three independent keys.

FITS · Large individual holders and companies with staff to run it properly.
04

Collaborative multi-sig.Think Unchained · Casa

In the typical structure, a 2-of-3 quorum where you hold two keys and a partner holds one. You can spend without the partner. The partner can never spend without you. Exact key arrangements vary by product, so confirm them, and apply the test that matters before choosing any vendor: can you still spend if they disappear tomorrow?

This is the middle path most holders don't know exists.

FITS · Both individuals and companies.
05

Institutional custody.Think Fidelity Digital Assets · BitGo · Anchorage

A qualified custodian holds distributed key material, backed by an audit trail and insurance. Read the insurance closely: coverage is policy-specific, capped in aggregate, and typically excludes protocol failures and client instruction errors. Counterparty risk returns here, but now with disclosure and a phone number attached to it.

FITS · Entities operating at scale. Below a certain threshold the economics rarely work, which makes it a non-option for most individual holders.
06

Hybrid.Working balance + long-term vault

A working balance sits with a custodian for liquidity, while the long-term position sits in self-custody or collaborative multi-sig. Think a Coinbase Prime account for the operating balance paired with an Unchained vault for the treasury.

This requires a written rule for how funds move between the two tiers, decided in advance rather than in the moment.

FITS · Most operating companies, and individuals who both hold long-term and transact regularly.
§ 04

The quantum threat.

Quantum computing is a real, developing threat to Bitcoin's cryptography, and it deserves a mention rather than dismissal.

But let's keep it real: as of this writing, the computing power required to break current signature schemes doesn't exist yet. The estimates are moving, though. Research published in 2026 cut the projected hardware requirement by roughly 20x, to under half a million physical qubits, and vendor blueprints now put dates on paper: one September 2026 estimate claims a future fault-tolerant machine of roughly 20,000 trapped-ion qubits could break a single key in under a month. These are resource estimates, not demonstrated attacks, but the horizon is shortening without collapsing.

On the protocol side, quantum-resistant proposals are in active development (BIP-360 and BIP-361 among them), though none has been activated and the migration path for already-exposed coins remains contested.

To be clear, this is absolutely something crypto asset holders need to be aware of and on top of, but it's not something to lose sleep over today.

§ 05

Don't sleep on.

A few failures sit outside any custody model and apply no matter which one you choose.

01

Passphrases

A real layer of protection, and a real self-destruct button if forgotten or mistyped under pressure.

02

Inheritance

What your estate, or your company, can actually execute without you in the room.

03

Testing the recovery

An untested backup is a hypothesis, not a plan.

04

Vendor diversity

Redundancy only helps when the parts fail independently: independent seed generation, vendors, firmware, storage locations, and recovery docs. A 2-of-3 whose seeds all came from the same flawed device is one key wearing three hats.

§ 06

Where we stand.

Carroll Park Capital holds a view on how to reason about custody. We don't hold a view on which specific product to buy.

Our Strategy, Section 6 sets out how we apply this thinking to our own treasury, and our case study series documents the work behind it.

This piece is educational. Nothing in it is investment or financial advice, and anyone making a custody decision at scale should involve legal and accounting counsel early. Do your homework, understand the system and secure your assets.

Schedule

A 30-minute conversation about custody.

Pick a 30-minute slot below, or email and we'll come back inside one business day. No pitch. No obligation. Just clarity.

OR EMAIL info@carrollparkcapital.com