Scar Tissue
In this post, Johan shares a video collaboration with TBL Friend Pascal Hügli, while also sharing his latest thoughts on bitcoin
A five-year-old firmware bug rattled a core pillar of bitcoin, and price barely blinked
To be honest, I’m not sure where or how to start this week’s letter. So much has happened in the last couple of days, but at the same time, so little has happened.
It has been a devastating time for people who did the work to understand bitcoin and to figure out how to self-custody their bitcoin, and still lost the wealth they stored on addresses created with a Coldcard. Nik already wrote a very strong letter, and he also recorded multiple videos with our own team member Demian and another one with Galaxy Digital’s Alex Thorn (and one more coming up with Jack Mallers…stay tuned!).
I won’t be spending too much time on what happened, because a lot has been said already. Also, people like Rob Hamilton from AnchorWatch keep working tirelessly to explain and inform people, help people migrate, and find any other vulnerabilities and stop them before they get exploited.
What I will do is point out what hasn’t been said or what I think is important to reiterate.
We recorded a video with Pascal Hügli from Less Noise More Signal to explore if we can create a collaboration similar to the one with the Checkonchain team. This wasn’t a typical recording because of the Coldcard situation, but the idea is that it will be about markets: possibly in combination with other analysts to gather a kind of mastermind around bitcoin and markets, plus some regular monthly updates between the two of us. We hope TBL Pros enjoy hearing my thoughts in video form. Please share feedback/thoughts on today’s video, so we know if this is something that you’d like to see more of:
This is neither the time nor the place to write a twenty-page report on bitcoin self-custody, but since the moment I started to make sense of how bitcoin custody works, I’ve felt the community was using suboptimal words to describe how things work. Semantics matter. I do understand why this has grown as it did: you want to create analogies so people intuitively understand the concept better.
‘A hardware wallet to store your bitcoin’ makes it easier to grasp and explain what these companies are trying to accomplish.
But the fact of the matter is: it’s not a wallet, nor does it store your bitcoin.
Bitcoin the asset lives on a shared ledger, the timechain. Coins move from address to address, and the transactions that move them get batched in blocks, validated, timestamped, and added to a practically immutable chain. That’s it.
The address type and its pre-programmed conditions (scripts) determine how the bitcoin can be spent. Does it require one signature or multiple signatures? What threshold of signatures needs to be met?
One needs the right private key to create a valid signature to spend the bitcoin. ‘Hardware wallets’ like a Coldcard or a Blockstream Jade are just devices that make certain parts of the process easier.
Those devices have their own function, and most have multiple:
Generate private keys
Sign transactions
Store private keys
Verify transactions
Software like Sparrow can help create the right type of addresses according to the user’s needs and wants. Because the standard became hierarchical deterministic, multiple addresses can be created out of one extended public key, also known as an xpub. Addresses that share the same root and are derived from one source create the idea of a ‘wallet’ or ‘account’ with multiple addresses.
Wallet software, like Sparrow, helps you (among other things) with:
Setting up the right type of address (script) you want to use, which determines how the bitcoin can be spent once you’ve sent sats to it (single signature or multi signature, native segwit or taproot);
Showing the addresses that can be derived from your extended public key, which we experience as the ‘wallet;’
Updating those addresses with new information from the bitcoin timechain: showing the activity on those addresses and their total balance;
Creating a new transaction: choosing which UTXOs to spend, what amount, and what address to send to, and helping gather the right signatures for the transaction; and,
Broadcasting the (valid) transaction to the network (nodes and their mempools).
It’s important to understand that companies like Trezor, Foundation, Ledger, or Blockstream are trying to provide both the hardware piece and the software piece. The device and the suite. Together they offer the possibility to self-custody your bitcoin.
Why do I say all of this? Because I think if people who hold bitcoin in some way, shape, or form understand this process better, they’ll understand better where the shoe pinches in the current situation.
Semantics are important so that people better understand that it’s not Coldcard or Trezor that provides ‘the wallet;’ the bitcoin protocol does. It needs to become obvious that those hardware devices are signing devices, storage devices and/or key-generating devices.
Then people become aware of the fact that they let one single device, with firmware created by a single company, create the private key that has access to their wealth.
If people understand this concept better, the logical step towards wanting to create your own private key, add entropy (with actual dice rolls) or build a quorum with multiple keys, created by different kinds of devices with different kinds of firmware, will come almost naturally.
Precisely because the bitcoin network stores the bitcoin, and because private keys are generated according to a shared standard, with a matching public key from which addresses are derived, it’s all interoperable. You can recreate the bitcoin wallet from Trezor Suite in Sparrow. You can generate a private key with a SeedSigner, import it into a Foundation Passport, and sign a transaction built in BlueWallet.
If you send bitcoin to an exchange, it’s not like sending gold to another physical vault. The bitcoin just moves to another address, of which people working for the exchange hold the key(s).
It’s not magic. I know it can sometimes feel like magic. But if it feels like magic, that’s a problem. If it feels like magic, you don’t understand the process.
It should feel majestic. There’s a big difference.
The bitcoin protocol didn’t break. Bitcoin self-custody didn’t fail. Faulty firmware from Coldcard created weak private keys.
I know it offers little to no solace, but what happened isn’t the fault of the users of Coldcard. They did what was expected of them. That’s why it feels so painful and unfair.
As a community, we need to step up. ‘Don’t trust, verify’ doesn’t mean anything if we don’t execute on it. We shouldn’t let big talk stop us from reviewing companies, hardware, and software.
We shouldn’t let people get bullied into self-custody. We need to reject manipulative behavior. It’s ironic that the loudest voices cheering for Strategy’s downfall in June were the biggest Coldcard promoters. It went from ‘Stack real bitcoin, not the fake shit’ to ‘Only the paranoid survive’ real quick.
Self-custody shouldn’t be scary either. We need to create the tools and the content, and offer help so people are able to do so in a comfortable way.
The relative amount of bitcoin somebody stores in self-custody should reflect the amount of knowledge, experience, and willingness to learn they have. Again, it should feel majestic, not like magic.
Having said that, if for whatever reason you want to self-custody your bitcoin today but don’t have the knowledge and experience yet, you could choose to hire somebody who can close that gap for you.
That’s what companies like Unchained, Casa, AnchorWatch and The Bitcoin Way (among others) are doing.
“There is no bitcoin without self-custody. This is non-negotiable.” - Rob Hamilton






