--:--:-- UTCF&G--QUIET-
A stamped steel seed-backup plate beside a pair of dice and a sealed envelope on a workbench.

THE CIPHER SCHOOL · MODULE 08 OF 08FIELD CRAFT

Custody

Field craft for holding your own.

Phillipe Christodoulou did what careful people do: he checked the reviews. The Trezor app on Apple's App Store had nearly five stars, so in March 2021 he typed his seed phrase into it — and watched 17.1 bitcoin, his family's savings, vanish in seconds. Trezor has never made an iOS app that accepts seeds. The counterfeit had passed Apple's review as an innocuous "cryptography" tool, then flipped after approval; five victims lost about $1.6 million from a thousand downloads in under a fortnight. Every protective instinct he had — big platform, official-looking brand, social proof — pointed the wrong way. Custody is the discipline of knowing exactly which verifications count, because the ones that feel like security usually are not.

§ § §

Start with what a hardware wallet actually is: a machine for keeping private keys off internet-connected computers, signing each transaction on its own screen so malware on your laptop can neither read the keys nor swap the destination unseen. Against remote attackers, that is a genuine wall — the deep end of cold storage. But the wall has an edge, and Module 3's standing exhibit marks it: the Coldcard failure of 2026 — an air-gapped, security-first device whose flaw sat latent in the field for five years — cost users more than 1,300 BTC without the attackers ever touching a device, because the weakness lay in the randomness the seeds were born from. A hardware wallet does not protect you from its vendor's mistakes, from a bad RNG, from phishing that persuades you to type the seed elsewhere, or from your own backup errors.

The doctrine that survives that incident is verification over reputation. Reputation is what the App Store sold Christodoulou; verification is what would have saved him. Concretely: check firmware signatures on every update, so you install what the vendor published and not what someone substituted. Prefer vendors with reproducible builds, so independent parties can confirm the shipped binary matches the public source. And supply your own randomness — dice entropy is the one entropy source whose honesty you can witness with your own eyes, and Coldcard owners who had mixed fifty-plus private dice rolls into their seeds were untouched in 2026. A device cannot fake the mapping from your rolls to your words if you verify the result against a second, offline implementation. None of this is paranoia; it is the substitution of arithmetic for trust.

The seed phrase is the wallet, so its storage is the custody. Doctrine, in order: metal over paper — house fires burn at around 600°C, which chars paper long before good steel fails, and in Jameson Lopp's long-running stress tests stamped and centre-punched steel plates survive torches, crushing and acid (avoid aluminium; it melts). Never photographed, never typed into anything online, never in cloud notes, email or a password manager: every major theft wave has harvested digitised seeds. The optional passphrase is a power tool, not a default. It means a burglar holding your metal plate still has nothing — but it is a second single point of failure with no checksum: a typo silently opens a different, empty wallet, and a passphrase that dies with you takes the coins along. You are trading theft risk for loss risk; back it up separately, or leave it alone.

Multisig is the strongest tool, so cost it honestly. A 2-of-3 across three vendors' devices in three places has no single point of failure: one key lost, stolen, or born of a broken RNG — the Coldcard scenario exactly — and the coins do not move; you rotate the bad key at leisure. Every confirmed victim of the 2026 sweep was single-signature. Now the bill. Every spend needs two devices co-ordinated, usually by passing a PSBT between them; the wallet descriptors and each xpub must themselves be backed up in several places, since without them you cannot even see the wallet; and inheritance gets genuinely harder. Most real-world multisig losses are self-inflicted — lost descriptors, forgotten quorum locations — not attacks. Complexity you cannot confidently rehearse is itself a risk, which is why single-sig with a passphrase remains the honest recommendation for most holders.

Coins that die with you were only half-owned. Inheritance planning is documentation your heirs can execute without being able to spend today: a sealed letter, held by a lawyer or in a safe, that names what exists and where the instructions are — never the secrets themselves — rehearsed once with the person who will need it. And plan for the attack no cryptography stops. Jameson Lopp's public list documents 260-plus physical attacks on bitcoiners since 2014, accelerating sharply through 2025: that January, Ledger co-founder David Balland and his wife were kidnapped from their home, a finger severed, before French police freed them. His security was excellent; his visibility was the vulnerability. The defences are unglamorous — tell no one the size of your holdings, and prefer setups, like multisig and timelocks, where instant coerced transfer is impossible by construction.

Finally, the field guide, because the scams are standing infrastructure. Fake support accounts answer your public wallet complaint and steer you to a seed-entry page — no legitimate party ever needs your words: not support, not the vendor, not "validation". Fake apps pass store review and flip, as Christodoulou learned. Drainer sites trick you into signing a malicious transaction — the defence is reading what you sign on the hardware screen, every time. Address poisoning plants lookalike addresses in your history, hoping you copy one. SIM swaps turn a phone number into a master key — Michael Terpin lost $24 million to one in 2018; phone numbers are not authentication. And Ledger's 2020 breach leaked no keys at all, just 272,000 customers' names and home addresses — a targeting map that fuelled years of phishing. Even telling a vendor where you live is part of your threat model now.

INTERACTIVE · THREAT MODELLING

Custody is a threat model, not a product.

QUESTION 1 OF 4

If you lost it all tomorrow, how would it feel?

This is education, not advice. No amounts, products or providers are being recommended to you personally — verify everything independently before moving real money.

» The right custody setup is the one whose failure modes you have actually rehearsed.

The root problem with conventional currency is all the trust that's required to make it work.

Satoshi Nakamoto, P2P Foundation forum · 2009

Updating the firmware does not change or repair an existing seed.

Coinkite, Coldcard security advisory · 2026

Your keys, your bitcoin. Not your keys, not your bitcoin.

Andreas M. Antonopoulos, Popularised across his public talks

READING LADDER

Climb at your own pace.

SIGN IN TO CHECK OFF READS
Beginner
Inventing Bitcoin
Yan Pritzker · 2019
The whole system in an afternoon — the context every custody decision sits inside.
Intermediate
10x Security Bitcoin Guide
Michael Flaxman · 2020
An opinionated, step-by-step multisig security walkthrough — where doctrine becomes procedure.
Deep
Cryptoasset Inheritance Planning
Pamela Morgan · 2018
The inheritance half of custody that nothing else covers — letters, executors, rehearsals.

FIELD TEST · SIGN-IN REQUIRED

Take the quiz. Track the curriculum.

The module text is open to everyone: no account required to read. The 3-question field test and the curriculum-wide graduation stamp need a free account so we can record your progress.

SIGN IN TO TAKE THE QUIZ

FREE · NEW ACCOUNT TAKES 30 SECONDS