
Eleanor Gaywood, Ecosystem Director at RootstockCollective, explores how trusting decentralised technology does not mean overlooking the responsibilities that come with self-custody.
The recent COLDCARD incident, where a flaw in entropy generation left hundreds of Bitcoin wallets vulnerable, quickly reignited a familiar debate. For some, it’s evidence of the risks involved in holding your own keys, for others it’s an implementation error in a security model that remains fundamentally sound.
The real lesson many have forgotten is that Bitcoin has changed where we place trust, but it never meant operating without trust altogether. Even the most technically capable rely on a collection of assumptions about the software, hardware and cryptography protecting their assets.
Bitcoin didn’t eliminate trust, it redistributed it
One of Bitcoin’s greatest achievements was removing the reliance on a central bank to issue money responsibly, or a commercial bank to honour a balance. Consensus is instead established through mathematics, cryptography and distributed networks. Over time, however, ‘don’t trust, verify’ morphed into the belief that Bitcoin users no longer need to trust anyone or anything. In reality, trust has dispersed into a collection of smaller, more transparent assumptions.
The hardware wallet, for example, is bought because the customer has good reason to believe that the entropy generation and firmware have been implemented properly and scrutinised by people with the expertise to do so. Rarely will the customer inspect or test those things themselves because that purchasing decision still relies on trust, even if it looks different to how one might trust a bank.
Similar to a bank faltering and customers rushing to protect their assets and questioning their trust in said institution, the COLDCARD incident illustrates perfectly how an invisible assumption suddenly becomes visible. Entropy generation, key derivation, compiler reproducibility, cryptographic libraries and code review rarely become topics of public discussion precisely because they usually work. It’s only when there’s an issue does it become the topic everyone is talking about.
Decentralisation doesn’t remove responsibility
This is where discussions around Bitcoin security often become unnecessarily binary. The temptation is to conclude that because one implementation failed, an entire custody model must be flawed while others rush to defend the model by dismissing the incident as an isolated bug.
Neither response captures the broader lesson that implementation risk exists everywhere, and every approach creates its own dependencies. A hardware wallet gives the holder direct control over their private keys but is still reliant on the security of the device. Multisignature custody can spread control across several keys but the security of the arrangement still depends on how those keys are generated and managed. Multi-party computation distributes the process used to authorise a transaction across multiple parties, useful for organisations that want to remove a single point of failure, but introduces reliance on software and system design.
The mechanisms differ, but human judgement never disappears from the equation. Bitcoin holders have to decide which responsibilities they want to carry themselves and which they are comfortable placing elsewhere, a decision that should be based on the risks they can understand and manage themselves.
The infrastructure we depend on
The same principle extends well beyond custody. The ecosystem is supported by an extraordinary network of wallet developers, cryptographers, auditors, researchers and maintainers whose work is rarely visible outside technical circles. Their contributions aren’t measured in daily transactions or market capitalisation, yet they shape the resilience of the entire network. And while the same rules apply to visibility when something works, it also makes it difficult to fund.
As Bitcoin continues to mature as a global financial system, investment in public infrastructure cannot remain an afterthought. Security cannot be taken for granted as a feature of the protocol for it’s an ongoing process of engineering, review and maintenance carried out by people whose names most users will never know.
A different way of thinking about trust
Perhaps the lasting lesson from the COLDCARD incident isn’t that self-custody failed, nor that it is inherently flawed. It’s that decentralisation changes where trust lives.
For some, that trust is placed in a hardware wallet and for others it’s distributed across multisignature wallets or custodians. Even opting to trust yourself ultimately means trusting the software, hardware and cryptography you’ve chosen to rely on. Of course, a holder doesn’t need to personally audit every line of code, but they should have a reasonable view of how resilient the infrastructure is and what assumptions they’ve made to use it.
Fundamentally, Bitcoin gives users far more choice over where responsibility sits but requires a need to understand the systems they depend on. And as Bitcoin utility increases, investors will need to examine beyond the asset to the infrastructure on which they rely to hold and use it.
Eleanor Gaywood is Ecosystem Director at RootstockCollective. Previously, Gaywood served as Head of Marketing-Brand Communications and GTM at Coincover. She has also held roles at Yapily, Currensea, Satago, Equiniti, Currencies Direct, Open Energi, and Informa Exhibitions.
Stay updated on crypto and AI by following our socials


