Key Highlights
- Metaplanet CEO Simon Gerovich commented publicly on the recent Coldcard wallet exploit.
- He said the incident exposed the operational complexity of self-custody rather than flaws in Bitcoin itself.
- Gerovich contrasted individual self-custody with institutional custody used for corporate Bitcoin treasuries.
The debate surrounding Bitcoin custody continues to intensify after the Coldcard hardware wallet exploit, with Metaplanet CEO Simon Gerovich becoming the latest industry figure to weigh in on one of the ecosystem’s most divisive topics.
In a post on X, Gerovich expressed sympathy for users affected by the exploit while arguing that the incident demonstrates how difficult it can be to securely hold Bitcoin can be even for experienced users. According to Gerovich, the attack should not be viewed as a failure of Bitcoin itself.
Why Gerovich blames device failure, not bitcoin
Gerovich argued that the exploit reflects the operational challenges surrounding custody rather than weaknesses in the Bitcoin network.
“Nothing about this exploit was a failure of Bitcoin. The protocol was not compromised; a device was.”
He said self-custody places significant responsibility on individual users, requiring them to manage hardware reliability, key backups, inheritance planning, recovery procedures, and protection against unforeseen vulnerabilities.
Gerovich added that even users who carefully follow security best practices can still become victims of flaws they could not reasonably detect.
Why Metaplanet chooses institutional custody
Gerovich also explained why Metaplanet has chosen a different approach for its corporate Bitcoin treasury.
He said the company’s holdings are secured through regulated institutional custodians using segregated cold storage, multi-party authorization controls, and independent oversight.
Gerovich said those safeguards are better suited for managing a publicly listed company’s treasury than relying on a single hardware device.
Coldcard exploit continues to spark industry debate
Gerovich’s comments add to a wider discussion that has unfolded since the Coldcard exploit became public.
Earlier, Binance co-founder Changpeng Zhao (CZ) urged users to remain vigilant after researchers reported that the exploit had resulted in more than $70 million in stolen Bitcoin, while noting that the attacker-controlled wallets remained under observation.
The incident has also reignited debate over Bitcoin custody philosophy.
Bitcoin analyst Willy Woo argued that users should continue prioritizing self-custody despite the exploit, saying holding private keys remains fundamental to Bitcoin’s sovereign ownership model even as institutional products such as spot ETFs continue gaining adoption.
At the same time, hardware wallet manufacturer Ledger published a technical explanation describing how its certified true random number generator (TRNG) differs from the flawed randomness process identified in the compromised Coldcard wallets, emphasizing that the vulnerability was specific to Coldcard’s implementation rather than hardware wallets in general.
Bitcoin security debate moves beyond the protocol
The exploit has exposed differing views across the Bitcoin community about how digital assets should be secured.
Some continue to argue that self-custody remains the core principle of Bitcoin ownership despite the operational risks involved. Others believe institutions, companies, and large treasury holders may benefit from regulated custodial arrangements that distribute security responsibilities across multiple layers of oversight.
While opinions differ, the incident has reinforced one common conclusion: Bitcoin itself was not breached, but securely managing access to it remains one of the industry’s most difficult challenges.
Also Read: Michael Saylor Clarifies Bitcoin Stance After Strategy’s 1,638 BTC Sale
