Secure bitcoin custody: Balancing control, convenience and responsibility There is no single right solution for bitcoin custody. What matters is who controls the keys, which risks come with the chosen model and whether it can still be used securely years from now. Custody is a trade-off, not an ideological battleThe recently disclosed Coldcard security incident, which we covered last week, has brought a fundamental question back into focus: How secure is bitcoin self-custody? On certain devices and firmware versions, seed phrases were generated with significantly less randomness than intended. As a result, the private keys derived from them could be predicted under certain conditions. The vulnerability did not affect Bitcoin itself. It concerned the generation of the keys used to access it.The incident is not evidence against hardware wallets or self-custody. Instead, it highlights a specific risk: Even a device used without a permanent internet connection depends on secure key generation, reliable software and robust processes. The key question is therefore not simply: "Which wallet is the most secure?" The following questions are just as important:What could go wrong with my custody model?Will I still be able to use the chosen setup correctly several years from now?What happens if I lose the ability required to manage it?A sound custody solution combines technical security with a realistic assessment of your own abilities and personal circumstances.A wallet does not store bitcoinBitcoin is not a file stored on a smartphone or hardware wallet. Put simply, the Bitcoin blockchain records how bitcoin may be transferred and under which conditions. A wallet manages the keys required to sign transactions.Anyone who controls the necessary private keys therefore has the technical ability to sign a valid transaction and transfer the bitcoin to another address on the Bitcoin blockchain. If access to these keys is lost, the bitcoin concerned can generally no longer be moved. In a multisignature setup, several keys are required. Four key termsWalletA wallet is not a container for bitcoin. It is a system for managing keys, addresses and transactions. Depending on the setup, it may take the form of an app, a dedicated device or a combination of several components.Private keyA private key is a secret cryptographic key used to sign transactions. With a simple wallet that requires only one signature, anyone who controls this key can generally access and transfer the associated bitcoin.Seed phrase or recovery phraseA human-readable backup, often consisting of 12 or 24 words. From the seed phrase, a wallet can deterministically derive numerous private keys and Bitcoin addresses. A seed phrase and a private key are therefore not the same: The seed phrase is the starting point from which the individual private keys are generated. Anyone who knows it can generally restore the entire wallet and access the bitcoin managed within it.Public key and Bitcoin addressA public key can be derived from a private key. A Bitcoin address is in turn derived from this public key or its data and is used to receive bitcoin. A public key and an address are therefore not technically the same. Both can generally be shared, and neither provides control over the bitcoin on its own. Three basic custody modelsSelf-custodyWith self-custody, users control the necessary keys themselves. The options range from a software wallet on a smartphone to a hardware wallet. They include simple single-signature solutions as well as multisignature models that require several keys.AdvantagesRisksdirect control over the bitcoinno central counterparty required to approve transactionsa high degree of independence and resilience against access restrictionsfreedom to design individual backup and security processesloss or destruction of the seed phrase backuptheft or disclosure of the seed phrasephishing and the unintentional approval of manipulated transactionserrors during setup, backup or recoverytechnical vulnerabilities in devices or softwareinadequate planning for illness, incapacity or deathoverly complex solutions that cannot be operated correctly when they are needed mostImportant: A hardware wallet alone does not constitute a complete security framework. Its primary role is to protect private keys during their generation, storage and use. Secure seed phrase storage, transaction verification, wallet recovery and estate planning remain the user's responsibility.Collaborative custodyWith collaborative custody, control is distributed across several keys and often across several people or locations. A multisignature solution is generally used. In a two-of-three setup, for example, two of three keys are sufficient to sign a transaction. One possible arrangement involves one key held by the user, a second key stored in a separate location and a third key held by a specialised provider. However, which party can execute a transaction depends on how the keys are distributed.AdvantagesRisksno single key provides sole control over the assetsprotection against the loss or theft of an individual device or backupprofessional support with setup and recoveryless reliance on a single party than with full third-party custodygreater technical and organisational complexityadditional costsreliance on software, documentation and effective processespotential privacy risks involving participating service providersCollaborative custody is not automatically the same as self-custody. The decisive question is whether users can move or fully recover their bitcoin without the provider's consent or continued existence. Anyone who controls only one of two required keys remains dependent on another party.Third-party custodyWith third-party custody, a provider manages the necessary keys. This provider may be a crypto exchange, a bank, a regulated custodian or an app provider. Clients access their bitcoin through an account and the processes defined by the provider. The legal structure varies. Depending on the provider, contract and jurisdiction, the custodied assets may be allocated directly to the client, or the client may only have a contractual claim against the provider. This should be examined in advance.AdvantagesRiskssimple operation and familiar access proceduresno need to manage a seed phrasesupport if a password is lost or access is blockedregulated structures and professional security processes, depending on the providerpotential integration into existing banking, trading or estate-planning solutionsinsolvency and counterparty riskcyberattacks, internal errors or fraudtemporary account freezes or restrictions on withdrawalsreliance on the provider's terms and processesno direct control over the private keys Which model might be suitable for whom?A general recommendation would not be appropriate. The following overview indicates which models may be considered depending on the circumstances.SituationPotentially suitable modelSmall amounts and initial experienceEstablished provider or easy-to-use mobile walletTechnically confident users with a long-term investment horizon Hardware wallet with a clearly documented single-signature setupLarger bitcoin holdings Multisignature, collaborative custody or professional third-party custodyCompanies, funds or family wealth Institutional custodian, clearly defined responsibilities or distributed key controlNo willingness to manage backups or test recovery procedures Professional third-party custodyStrong preference for independence Self-custody with a documented and tested recovery processThe value of the assets is not the only deciding factor. Technical knowledge, personal discipline, family circumstances, physical security and the ability to operate the setup correctly several years from now are equally important. A simple and well-understood solution can be more secure than a technically sophisticated system that few people can operate reliably. Risks that are often overlookedLoss and theftLosing a hardware wallet does not automatically mean losing the bitcoin, provided that a functioning seed phrase backup exists. However, the device and seed phrase should not be stored in the same location. Depending on the setup, anyone who finds both may gain access. Multiple backups increase resilience, but they also create additional potential points of attack.User errorMany losses result not from a technical attack but from incorrect entries or inadequate checks. Receiving addresses should be verified on a trusted device. Before making a large transfer, it is advisable to conduct a small test transaction. A controlled recovery test is equally important. A backup that has never been tested may provide only a false sense of security.Technology and supply chain risksHow was the seed phrase generated? Can the source of the wallet software or firmware be verified? Are security notices and updates reviewed regularly? Does recovery depend entirely on a single manufacturer? The Coldcard incident falls into this category. It shows that even an offline device is only as reliable as its underlying key generation, software and implementation. Publicly available source code can facilitate independent reviews, but does not in itself guarantee that the software is free from errors.Physical securityBackups must be protected against fire, water and other forms of damage. At the same time, the custody setup should not leave unnecessary indications that someone owns bitcoin. The more visible the setup and the more people who know about it, the greater the risks of burglary, theft or extortion.Estate planning and incapacityA technically secure wallet can become inaccessible if nobody other than its owner knows that it exists. Family members do not necessarily need direct access to the seed phrase. However, they should know that the bitcoin exists, where reliable instructions can be found and which steps must be taken in an emergency. An estate-planning solution must achieve two objectives: Unauthorised individuals must not gain access during the owner's lifetime, while authorised persons must be able to act in the event of illness, incapacity or death. Professional and legal advice may be appropriate for complex or substantial holdings.A simple security checklistUnderstand who controls the necessary keys and which approvals are required for a transaction.For third-party custody, review the provider, legal framework, treatment of custodied assets, withdrawal procedures and emergency processes.With self-custody, store the seed phrase and device separately.Do not photograph the seed phrase or store it in an ordinary cloud service or unencrypted file.Never share a seed phrase with support staff or enter it on a website.Test the recovery process in a controlled manner, initially with a small amount.Keep firmware and wallet software up to date, but install updates only from verified sources.Document the setup clearly and plan for loss, illness, incapacity and death.Avoid unnecessary complexity. A solution is only secure if it can be operated correctly over the long term. Conclusion: Security starts with the right model of responsibilityNo bitcoin custody solution is free from risk. Third-party custody offers convenience and support, but creates reliance on the provider. Self-custody provides direct control, but also transfers full responsibility to the user. Collaborative models can reduce single points of failure, but require clear processes and reliable documentation.The Coldcard incident does not change this fundamental trade-off. It serves as a reminder that security does not end with the purchase of a hardware wallet. What matters is the system as a whole: how keys are generated and distributed, how backups are stored, how transactions are verified, how the wallet can be recovered and what arrangements are in place for an emergency.The best custody solution is therefore not necessarily the most technically sophisticated. It is the one whose functionality and risks are understood and which can be operated reliably over the long term. Author: Pascal HügliPascal Hügli, Crypto Investment Manager at Maerki Baumann and founder of Insight DeFi, produces high-quality content on bitcoin and crypto and contributes to Maerki Baumann's development in the area of blockchain and cryptocurrencies. As a lecturer in digital finance and crypto assets at the HWZ University of Applied Sciences in Business Administration Zurich, he has in-depth expertise in this field, which he is now also applying to the establishment of our new brand "ARCHIP by Maerki Baumann". Important legal informationThis publication is intended for information and marketing purposes only, and does not constitute investment advice or a specific individual investment recommendation. It is not a sales prospectus and does not constitute a request, an offer, or a recommendation to buy or sell investment instruments or investment services, or to engage in any other transaction. Maerki Baumann & Co. AG does not provide legal or tax advice. Investors are therefore advised to obtain independent legal or tax advice concerning the suitability of such investments, since their tax treatment depends on the personal circumstances of the investor in question and is subject to change at any time. ¬Maerki Baumann & Co. AG holds a Swiss banking licence issued by the Financial Market Supervisory Authority (FINMA). This publication is expressly not intended for persons domiciled in Germany or so-called U.S. persons.Editorial deadline: 10 August 2026Maerki Baumann & Co. Ltd.Dreikönigstrasse 6, CH-8002 ZurichT +41 44 286 25 25, info@maerki-baumann.chmaerki-baumann.ch | archip.ch