Skip to content
|

Read time

11 mins

What is true cold custody? Why isn’t “offline” the same as “safe”?

For most crypto hodlers, cold custody means keys stored offline; they never touch the internet. Air-gapped. Untouchable. For years, that was a fair enough definition. It just stopped being a sufficient one.

On July 30, 2026, attackers began draining Bitcoin from Bitcoin-only hardware wallet manufacturer. By the time the dust settled, roughly 1,816 BTC (about $116 million, according to TRM Labs) had been pulled from over 5,200 addresses across four separate waves, without a single attacker ever physically touching a device.

Two and a half weeks later, SafePal — another major hardware wallet brand — disclosed a breach exposing the names, shipping addresses, and phone numbers of nearly 40,000 customers. Wallets weren’t drained. But the addresses of thousands of known crypto holders are now sitting on a forum, for sale, which is arguably worse: it’s a shopping list for physical “wrench attacks,” a category CertiK says rose 33% year-over-year in the first half of 2026 alone.

Neither incident involved a hack of Bitcoin itself. Both involved something people trusted completely — cold storage/hardware wallets — right up until they had a very specific reason not to.

These incidents change the question every serious holder should be asking. It’s no longer “is it offline?” It’s “what is exactly standing behind that device?” This article explains everything you need to know about true cold custody and the features of a true, absolute cold custody setup.

Key takeaways

  • A firmware bug from 2021 quietly weakened Coldcard’s key generation. It went undetected for five years and drained roughly $116 million from over 5,200 addresses in 2026 — without a single device being physically touched.
  • Victims did everything self-custody best practice recommends—seed phrases never shared, devices never online, backups in vaults. It made no difference. The failure was upstream, in code they had no way to audit.
  • SafePal’s breach shows the threat isn’t limited to the key itself: an order-tracking bug exposed the names and shipping addresses of nearly 40,000 confirmed hardware wallet owners, fueling phishing and physical “wrench attack” risk.
  • “Offline” describes a device. It says nothing about entropy verification, key ceremonies, audits, insurance, or succession planning. The system-level controls that actually determine whether custody holds up under real-world failure.
  • Institutional custody reduces single points of failure through multi-signature approval, HSM-certified key management, independent audits, and regulatory oversight. The layers of a lone hardware wallet, however well designed, can be replicated.

The definition of true cold custody

Storing keys “offline” describes a device. It says nothing about the system behind it — how the keys were generated, who can move them, what happens if one link in the chain fails, or who’s accountable when it does.

True cold custody isn’t a property of a box. It’s a system, and that system protects your assets against most vulnerabilities that self-custody setups. The features of a true cold custody setup/service include the following.

1. Entropy verification

Entropy is the raw randomness a wallet uses to generate its seed phrase or key. The bigger and more unpredictable the randomness, the larger the number of possible seeds an attacker would have to search through to guess yours. In theory, it should be so vast that guessing is computationally impossible.

Entropy verification means that randomness isn’t just trusted because a wallet provider says so. It’s independently checked and provably strong before any key is ever generated.

In the case of Coldcard, secure elements were never breached. The entropy feeding them was quietly weak for five years.

2. Key ceremonies

A key ceremony is the formal process used to generate and activate a private key. It is carried out by multiple people, in a controlled location, with every step logged and witnessed, rather than one person clicking “generate” alone.

This procedure exists so that no single individual ever controls the entire process unsupervised, and so there’s a documented, auditable record of exactly how and when a key came into existence.

3. Hardware Security Modules (HSMs)

An HSM is a certified, tamper-resistant physical device purpose-built to generate, store, and use cryptographic keys. It is designed in a way that the key material never leaves the device even under physical attack.

Unlike a consumer hardware wallet, HSMs are built and certified to industry security standards, tested against physical tampering, side-channel attacks, and firmware compromise. This is a different tier of hardware assurance than a self-custody device designed to be portable and affordable.

4. Multi-signature technology

Rather than one key controlling a wallet, a multi-sig setup requires several independent keys — say, three of five — to authorise any transaction, with those keys typically held by different people in different locations. Even if one key is stolen, guessed, or compromised, an attacker still can’t move funds without the others.

5. Independent audits

An independent audit means a qualified third party — not the custodian itself — regularly reviews the security architecture, code, and operational controls behind a custody system, and publishes or reports its findings.

Regulated true cold custodians don’t just say their systems are secure. They submit them to third-party review on a recurring basis, with the findings feeding back into the process, not filed away.

6. Insurance and regulatory oversight

Regulatory oversight means an outside authority sets rules for how a custodian must run its operations, and checks that it actually follows them. Institutional custody sits inside a supervisory framework. It isn’t the custodian’s own marketing claim about how safe it is.

In the case of a Swiss-regulated crypto bank offering cold custody, FINMA, Switzerland’s financial regulator, sets binding standards for asset segregation, operational resilience, and client protection, backed, in many cases, by insurance against specific risks such as custodial fraud or cyber theft; though the scope and limits of this coverage vary by provider.

7. Succession and continuity planning

This is the documented plan for what happens to assets if the person or process managing them is unreachable, incapacitated, or gone — who can act, under what authority, and how access is restored without relying on one person’s memory or presence.

Self-custody puts the entire responsibility on one person’s shoulders. A regulated custodian runs disaster recovery and continuity protocols designed to reduce single points of failure, including in the case of the asset owner’s untimely demise.

Why this is landing differently right now

The technical case for institutional custody has existed for years. What’s changed is that it’s no longer theoretical. We’re hearing this directly, from people who never thought they’d say it: people who spent years managing their own keys as a point of principle, now reaching out and saying, in effect, I’m done.

What they’re asking for isn’t a better hardware wallet. It’s one point of contact who can take that weight off their hands and answer it.

What should I do if I want to move from self-custody to institutional, true cold custody?

In practice, you would need to understand a custodian’s key ceremony, audit, and insurance framework; deciding what governance controls you want on your own account (approval workflows, whitelisted addresses); and working through a supervised migration of funds from your existing wallet rather than moving everything at once.

The way forward with your cold custody

The question worth sitting with isn’t which hardware wallet to buy next, or which firmware version you’re running. It’s who — or what system — is actually accountable when something goes wrong that you never saw coming.

Self-custody puts you at the center of that answer, permanently, by design. True cold custody, done properly, distributes the risk involved with audited processes, regulated oversight, and people whose job is to keep getting it right, every single day, not just once.

FAQs

Q. Is cold storage still safe?

Cold storage as a concept — keeping keys offline — is still sound. What the Coldcard incident showed is that “offline” only protects against one category of risk (remote access). It may not have the measures/protocols to protect against a flawed key generation process, which is a systems-level failure, not a connectivity one.

Q. Do I need to move my funds if I own a self-custody wallet?

That depends entirely on your specific device, firmware version, and how your seed was originally generated. In general terms, if you’re unsure which firmware your seed was generated on, the safest move is to treat it as at risk: generate a new seed on current, patched firmware and migrate your funds to it, rather than assume a firmware update alone resolved anything.

Q. Does moving to institutional custody mean giving up control of my assets?

No. It means transferring operational responsibility for key management to a regulated custodian, under governance controls you can define — such as approval workflows and whitelisted addresses. It’s a different model of control, built around oversight and accountability rather than sole personal responsibility.

Q. Why does regulatory oversight matter for cold custody?

A regulator like FINMA sets binding, externally enforced standards for how client assets must be segregated, protected, and reported on. This provides materially stronger assurance than a manufacturer’s own security claims; though regulatory oversight reduces risk, it does not eliminate it entirely.

Q. Are hardware wallets a bad choice now?

Not inherently. They remain a reasonable tool for individual investors comfortable with sole responsibility for key management and recovery. However, there are limits of what a single device and a single person can guarantee, particularly as digital asset holdings grow and the stakes of a single mistake rise.


Disclaimer, Research and Educational Content

This document has been prepared by AMINA Bank AG (“AMINA”). AMINA is a Swiss licensed bank and securities dealer with its head office and legal domicile in Switzerland. It is authorised and regulated by the Swiss Financial Market Supervisory Authority (“FINMA”).

This document is published solely for educational purposes; it is not an advertisement nor a solicitation or an offer to buy or sell any financial investment or to participate in any particular investment strategy. This document is for publication only on AMINA website, blog, and AMINA social media accounts as permitted by applicable law. It is not directed to, or intended for distribution to or use by, any person or entity who is a citizen or resident of or located in any locality, state, country or other jurisdiction where such distribution, publication, availability or use would be contrary to law or regulation or would subject AMINA to any registration or licensing requirement within such jurisdiction.

Research will initiate, update and cease coverage solely at the discretion of AMINA. This document is based on various sources, incl. AMINA ones. In preparing this document, AMINA may have made limited use of artificial intelligence enabled tools to assist with research, summarisation, and drafting, with all content subject to human review and validation.

No representation or warranty, either express or implied, is provided in relation to the accuracy, completeness or reliability of the information contained in this document, except with respect to information concerning AMINA. The information is not intended to be a complete statement or summary of the subjects alluded to in the document, whereas general information, financial investments, markets or developments. AMINA does not undertake to update or keep current information. Any statements contained in this document attributed to a third party represent AMINA’s interpretation of the data, information and/or opinions provided by that third party either publicly or through a subscription service, and such use and interpretation have not been reviewed by the third party.

Any formulas, equations, or prices stated in this document are for informational or explanatory purposes only and do not represent valuations for individual investments. There is no representation that any transaction can or could have been affected at those formulas, equations, or prices, and any formula(s), equation(s), or price(s) do not necessarily reflect AMINA’s internal books and records or theoretical model based valuations and may be based on certain assumptions. Different assumptions by AMINA or any other source may yield substantially different results.

Nothing in this document constitutes a representation that any investment strategy or investment is suitable or appropriate to an investor’s individual circumstances or otherwise constitutes a personal recommendation. Investments involve risks, and investors should exercise prudence and their own judgment in making their investment decisions. Financial investments described in the document may not be eligible for sale in all jurisdictions or to certain categories of investors. Certain services and products are subject to legal restrictions and cannot be offered on an unrestricted basis to certain investors. Recipients are therefore asked to consult the restrictions relating to investments, products or services for further information. Furthermore, recipients may consult their legal/tax advisors should they require any clarifications.

At any time, investment decisions (including, among others, deposit, buy, sell or hold investments) made by AMINA and its employees may differ from or be contrary to the opinions expressed in AMINA research publications.

This document may not be reproduced, or copies circulated without prior authority of AMINA. Unless otherwise agreed in writing, AMINA expressly prohibits the distribution and transfer of this document to third parties for any reason. AMINA accepts no liability whatsoever for any claims or lawsuits from any third parties arising from the use or distribution of this document.

©2026 AMINA, Kolinplatz 15, 6300 Zug

Share this article

Authors

Shania Santwan

Content Marketing Manager, AMINA India


Explore more

  • Read time

    11 mins

    Self-Custody Fatigue is real: Why Bitcoin holders are reconsidering DIY security

    Self-custody fatigue is driving crypto holders to reconsider DIY security. Discover why even principled holders are moving to regulated custody in 2026.

    Learn more
  • Read time

    11 mins

    What is true cold custody? Why isn’t “offline” the same as “safe”?

    Cold storage isn't enough. Learn what true cold custody requires from key ceremonies to HSMs and more.

    Learn more
  • Read time

    10 mins

    What to Look for in an Institutional Crypto Custody Provider: Best Practices for Institutions

    Learn the institutional crypto custody best practices that help institutions evaluate custody providers, protect assets and meet compliance requirements.

    Learn more

Subscribe to AMINA Research

Subscribe to AMINA Research for our latest perspective.

Notice for UK visitors

AMINA Bank AG (AMINA) is a Swiss bank, authorised and regulated by the Swiss Financial Market Supervisory Authority (FINMA). AMINA’s products and services are only licenced in Switzerland. They are not registered or approved outside of Switzerland. Your IP address indicates that you are attempting to access AMINA’s website from the UK. If you want to explore AMINA’s products and services that are available in the UK, you can do so by accessing AMINA’s UK specific website.

Please click “Continue” to do this. If you don’t want to continue to the UK version of AMINA’s website, please click on “Back”.