Written by: Muneeb
Compile: Blockchain in Plain Language
The Coldcard incident offers three key lessons. First, about how to store your Bitcoin; second, about the impending threat of quantum computing; and third, about how to make the BTC ecosystem healthier in the future. Below, we elaborate on each.
(1) How to store Bitcoin
The Coldcard incident is especially regrettable because those affected were individuals who invested their life savings and took every precaution. They avoided high-risk investments, diligently learned about self-custody, and genuinely believed Bitcoin was the best store of value.
I won’t repeat the details of this attack (others have already covered them). Looking ahead, the best strategy is to diversify your allocations.
Consider allocating 20%–30% to an ETF (such as IBIT). I prefer ETFs over direct placement on exchanges because they offer two advantages: first, the underlying custodians are more diversified; second, regulated ETFs provide additional legal protections.
Allocate another 40%–50% to a three-key solution like @CasaHODL: one key held by a security company, one on a mobile device, and one in a hardware wallet (such as Trezor).
An additional 20%–30% can be allocated to solutions that emphasize self-sovereignty, using hardware wallets from different brands and entropy from diverse sources to generate keys (suitable for advanced users).
Don't put all your eggs in one basket.
(2) Regarding the threat of quantum computing
If quantum computers ever truly break encryption, the result would likely look very similar to your BTC suddenly being drained from your cold wallet. The community already has firsthand memory of this pain and knows just how devastating it feels.
Quantum threats are real, and we likely have only a few years left to take meaningful action. Rather than downplaying advances in quantum computing, it’s wiser to proceed with caution—especially given that LLMs are accelerating scientific breakthroughs.
(3) Improve the health of the Bitcoin ecosystem
Over the past few years, certain parts of the Bitcoin community have become overly insular. Many talented security researchers and security firms operate outside the "just Bitcoin" bubble. Most people in the industry haven’t even heard of Coldcard, and I suspect top-tier security research firms have likely never audited their code.
Some of the best security talent often choose to stay away entirely to avoid the potential arguments and dramatic conflicts that can arise when offering feedback to certain "Bitcoin maximalist" developers. It’s time to move beyond these self-imposed limits and internal friction.
The Bitcoin community should be more inclusive and welcoming to engineers who don’t focus solely on Bitcoin. (I know I’ll likely get flak for saying this, but I’m already used to it.)
Engineers working on other cryptographic protocols are not inherently "evil." In fact, some of the most talented engineers—particularly in security—are found outside the Bitcoin ecosystem (e.g., Trail of Bits, Asymmetric Research).
Bitcoin-focused companies should collaborate more closely with these security firms and researchers to build friendly relationships and audit processes.
When Bitcoin is hurt, our entire industry suffers. Don’t limit ourselves for ideological reasons—let’s work together toward a safer future.

