OfCosts

The Invisible Ledger: CZ, Coldcard, and What We Don't Count When We Count Bitcoin Losses

CryptoCobie
Companies
There is a particular silence that descends on a hardware wallet community when a vulnerability is announced. It is not the loud panic of an exchange hack, with its Twitter mobs and insurance claims; it is something quieter, a held breath among people who had built their identity on the conviction that cold storage had ended the era of fear. In late 2025, that silence broke around Coldcard, the austere Canadian device that had become a badge of ideological purity among self-custody maximalists. A novel attack had been demonstrated. Mitigations were issued, but the damage to a certain kind of faith had already been done. And then came the detail that would quietly shape the next month of industry debate: the incident was not included in any major loss statistics. Days later, Changpeng Zhao stepped into the silence with numbers. The former Binance chief executive, still arguably the most recognizable figure in the industry, cited data assembled by the prominent on-chain analyst Willy Woo to make an argument that would have seemed heretical just a few years earlier: self-custody has lost more Bitcoin than centralized exchanges ever have. Roughly 1.57 million BTC lost through self-custody failures, the report claimed, against 1.51 million BTC lost through exchange user losses. The margin was thin. The implication was not. Centralized exchanges, the very institutions that the cypherpunks taught us to distrust, appear — by this accounting — to be safer than our own hands. I have spent the better part of a decade building a crypto education platform in Nairobi, teaching people who are often the last to be consulted about the industry's direction how to actually read the mechanics beneath the marketing. I have audited token standards, watched communities fracture over secondary-sale royalties, and helped Kenyan artists structure DAO-governed systems that promised them dignity, only to watch speculation devour intent before the paint dried. I have learned, slowly and sometimes painfully, that numbers in crypto are never neutral. Every statistic is a story told from somewhere, by someone, for a reason. Tracing the moral code behind every token has become less a slogan and more a survival practice. The custody debate now erupting across social media is not really about Coldcard, and it is not really about CZ. It is about something deeper — the stories we tell ourselves about whose hands are safe enough to hold what we value. And, as with most narratives in this industry, the statistics are doing far more work than they can honestly bear. Let us lay out the battlefield, because the terrain matters. Two custody paradigms stand in opposition, each with its own sociology and its own sacred texts. On one side stands the centralized exchange, a fortress of multisignature vaults, cold-wallet segmentation, insurance funds, and a standing army of security engineers. Binance has spent years constructing and refining this edifice, and its security apparatus is genuinely world-class; the company has a financial incentive to keep it that way, and its track record on covering confirmed hacks is real. On the other side stands the hardware wallet, the self-custody ideal: private keys that never leave the device, seed phrases etched into steel plates, and with them the foundational principle that has defined this industry's moral imagination — not your keys, not your coins. Coldcard occupies the ascetic end of that spectrum, an intentionally stripped-down device for people who trust code more than they trust corporations. Willy Woo's dataset, cited approvingly by CZ, was constructed to argue that the fortress has historically protected user funds better than the toolkit. But the numbers demand closer reading. 1.57 million versus 1.51 million is not a landslide; it is a statistical hair's breadth. A mere 600,000 Bitcoin separate two catastrophic, civilization-level failure modes in the short history of this asset — less than the amount lost in a single exchange collapse such as Mt. Gox or FTX. To call this dataset evidence of institutional superiority requires a confidence that the data does not support. One could just as easily read the numbers as proof of a chilling symmetry: regardless of where you place your trust, the industry has found a way to lose roughly one and a half million Bitcoin on every side of the fence. And the dataset carries a qualification that should haunt every conclusion drawn from it: it excludes the Coldcard incident. This is not a footnote. It is a confession. The single most relevant security event at the moment of the analysis was, by the analyst's own admission, omitted from the spreadsheet. This omission matters not only because it flatters the conclusion, but because it reveals a deeper structural problem: Bitcoin's loss history is not a ledger, but a collection of partially overlapping diaries, each with missing pages. The Bias of Visibility CZ's response to the criticism was telling. Self-custody losses, he noted, are not reported and are much harder to count. He is correct. But that correction cuts in both directions. If self-custody losses are genuinely harder to track, then the 1.57 million figure is not a total — it is a floor. It is an inventory of the failures that were visible enough to be noticed, not the failures that actually occurred. This is where I need to lean on what the years have taught me. In 2017, I served as a senior auditor on the ZEIP-20 standardization working group, reviewing roughly 150 token proposal drafts over six months in Nairobi. We identified 42 critical edge cases in token transfer logic that subtly favored centralized validators at the expense of ordinary users. I submitted fifteen pull requests to the Ethereum Improvement Proposal repository, arguing that technical neutrality often masks systemic bias. I was young enough, then, to believe that a well-documented edge case would be enough to change a consensus. I learned instead that the most dangerous bias in any system is the bias of visibility: the things you can measure become the only things you can see, and the things you cannot measure quietly become the things you refuse to believe. Exchange losses are visible because there is an entity to blame — a press release, an insurance claim, a forensic report, a class-action lawsuit. Self-custody losses are invisible because they are scattered across millions of private tragedies: a seed phrase written on a piece of paper that a mother threw away with the junk mail; a hardware device dropped into a lake on a misguided safari adventure; an inheritance buried in a safety deposit box whose key was never found; an elderly collector tricked into signing a malicious transaction by a voice that sounded kind. None of these events appear in a dashboard. None of them are counted in Willy Woo's spreadsheet. And yet they are the true, quiet erosion of wealth that self-custody inflicts on its most faithful followers. I have seen this from the ground, and not only in spreadsheets. In 2020, through my educational nonprofit, I partnered with Kenyan university lecturers to translate DeFi mechanics into Swahili and English. We published white papers and held workshops, and I personally mentored twenty young developers from underserved communities. I watched one of those mentees, a brilliant young woman from a small town in the Rift Valley, lose nearly a year's savings because she stored her recovery phrase in her phone's notes app — a convenience that a well-crafted piece of phishing malware turned into a catastrophe. She did not report it to anyone. There was no one to report it to. The theft left no trace in any industry statistic, but it left a scar in a human life. Preserving the human story in digital ledgers has become my quiet obsession, precisely because the ledgers keep failing to see the people they are meant to serve. This is the fundamental statistical asymmetry at the heart of the CZ argument. The exchange side of the dataset is a census; the self-custody side is a sample of convenience. Comparing them as if they were equivalent measurements is not analysis; it is advocacy dressed in a lab coat. If we cannot count what we cannot see, then the honest conclusion is that the true number of self-custody losses is unknowable — and an unknowable number cannot be used to declare victory for either side. The Coldcard Question But let us not romanticize away the real issue. The Coldcard incident is a genuine turning point, and it deserves a clear-eyed technical analysis. A single hardware wallet vulnerability does not invalidate the self-custody paradigm — but it shatters the aura of absolute certainty that the paradigm depends on. The security model of self-custody has always rested on a threat-model assumption: that the user can be the custodian, provided the user is disciplined, technical, and careful. Coldcard was the device chosen by precisely that profile of user. The most security-conscious cohort in the entire community held its breath in December, because if the ascetic's choice can fall, what remains of the mass-market alternative? Those of us who have spent years recommending hardware wallets to nervous newcomers suddenly had to add a caveat, and a caveat destroys a creed. The critical variable is causation, and I want to stress this because it is the difference between a footnote and a fracture. If the Coldcard attack turns out to rely on supply-chain interference or physical possession of the device, the incident will be treated as an outlier, a narrow edge case in the long adversarial history of the industry. If it turns out to be exploitable remotely, or worse, through a compromised firmware update, then the event will have cracked the foundation of trust for the entire hardware wallet sector. We do not yet know which story we are in. That uncertainty — not the attack itself — is the most under-reported risk in this entire debate. Listening to the silence between the blocks has become, for me, a discipline: when the data does not yet know the answer, the only honest posture is open-eyed waiting, not certainty. I have been through this pattern before. In 2021, I helped launch the Savanna Voices NFT collection with ten Kenyan digital artists, structuring a DAO-governed royalty system that directed seventy percent of secondary sales back into the artists' hands. The project raised a hundred and fifty thousand dollars in forty-eight hours, and then, predictably, the speculation arrived. Collector engagement collapsed within months, and the artists were left with a reputation and a floor price, but not the sustainable creative economy we had designed for. A single incident was never just an incident; it was a referendum on the story we had told ourselves. The Coldcard debate is a referendum on a similar story: the story of the sovereign individual who needs no one, no institution, no backup — and who is therefore never prepared for the moment the story fails. The Promise That Only Covers What It Can See CZ's second argument — that exchanges have historically covered user losses — deserves an audit of its own. It is true that Binance absorbed the losses from its 2019 security breach. It is true that a well-capitalized exchange can, and sometimes does, make customers whole. But the promise of coverage only extends to the losses that happen inside the fortress. It does not cover the loss of the fortress itself. Mt. Gox did not cover its users; it entered bankruptcy, and its creditors waited a decade for partial recovery. FTX did not cover its users; it imploded in a liquidity crisis and left its customers fighting for pennies on the dollar. “You will be reimbursed” is a beautiful sentence when the speaker is solvent, and a cruel one when the speaker is the one who failed. The exchange coverage argument is, in the end, a promise from an institution to itself — and history suggests that the institutions most confident in their own safety are precisely the ones most likely to fail spectacularly. There is also the moral hazard of consolidation, which is the part of this debate that keeps me up at night. If users genuinely believe that centralized exchanges are safer, the rational response is to consolidate assets in those exchanges. But this is exactly the behavior that creates systemic fragility. The 1.51 million Bitcoin lost to exchange failures did not vanish because of a single villain; it vanished through a succession of highly concentrated custodians, each of whom failed in ways unique and devastating. Every argument that pushing more assets into fewer hands reduces risk fails to account for the very risk it creates: the risk of the single point of failure sitting smugly at the center of the web. Community over capital, always — but that slogan rings hollow when a community voluntarily hands its capital to one fortress and then cheers the fortress for being tall. And then there is the regulatory weaponization, which is the quietest and most dangerous dimension of all. The claim that “self-custody is more dangerous” is a gift to every regulator who has ever wanted to make non-custodial technology harder to access. If the dominant narrative shifts toward institutional custody as the only responsible choice, we will see legislative consequences: stricter hardware wallet licensing, limitations on seed phrase generation, tax penalties for self-custodied assets, and an ever-expanding definition of “custodial service” that swallows the very concept of personal ownership. In my work on the African AI-Blockchain Ethics Charter, which I co-authored in 2026 and which was adopted by two East African regulatory bodies, we spent eight months consulting with farmers, technologists, and policymakers on a single foundational principle: accountability requires transparency. The charter insisted that any algorithm making consequential decisions about human lives must be auditable by the people whose lives it affects. The same principle applies to this debate. If a centralized exchange wants to claim it is safer than self-custody, it carries a fiduciary obligation to prove that claim through real-time, verified proof of reserves — not through a blog post, not through a celebrity tweet, and not through a dataset that conveniently omitted the incident that started the conversation. Ethics is not a feature; it is the foundation, and transparency is the only load-bearing wall. The Conflict Behind the Counsel I cannot conclude this analysis without naming the elephant in the room, quietly but firmly. CZ is not a disinterested observer. He is the founder and dominant shareholder of the largest centralized exchange in the world, and he stepped down as chief executive only after pleading guilty in 2023 to failing to maintain an effective anti-money-laundering program. His personal and corporate history does not invalidate his argument, but it is an essential lens through which the argument must be read. When a person with a massive fiduciary stake in one answer tells you that the answer is clear, the only responsible response is to check the math twice and the conflicts three times. The industry awarded him the title of liberty hero once; it should not so easily award him the title of custody truth-teller without demanding the underlying evidence. Willy Woo, for his part, is a respected on-chain analyst, and I mean him no disrespect. But the independence of the analyst does not indemnify the dataset against its own methodological blind spots. A statistic that excludes the most relevant incident while drawing a conclusion favorable to the speaker's business model is not a neutral measurement; it is a narrative device. That narrative is already shaping user behavior — funds are being moved, hardware wallet sales are being canceled, exchange deposits are rising — all on the strength of a comparison that every honest statistician should refuse to certify. This is how narratives become default assumptions in our industry: not through rigorous proof, but through repetition by trusted voices. The Contrarian Test: A Dangerous Grain of Truth And yet — and this is the part of the analysis that makes me uncomfortable — there is a dangerous grain of truth in what CZ said. Pure self-custody is not for everyone. It never has been, and it never will be. For a panicked newcomer who does not understand seed phrases, has no backup discipline, and has never heard of a supply-chain attack, a well-regulated exchange with insurance and a professional security team might genuinely be the safer option. The cypherpunk romance of the sovereign individual has a body count, and we do not like to count it because it does not fit the story. The professor in Kenya whose seed phrase went through the laundry, the grandmother who threw away the recovery card, the startup founder who lost an entire treasury to a phishing drainer — these are the invisible casualties of self-custody maximalism, and their losses deserve as much compassion as the victims of any exchange collapse. I lived through the 2022 bear market in a way that taught me the limits of absolutism. My educational platform faced a sixty percent drop in donations, and I was forced to downsize to a core team of four and rewrite forty percent of our curriculum to focus on risk management and ethical governance. That period of financial strain tested everything I believed about resilience. I learned that authenticity is maintained not by refusing to bend, but by knowing when and where to bend without breaking. The same lesson applies to custody. The real safety of this industry lies not in any single institution or device, but in diversity: diversified custody, layered backups, honest risk education, and institutional accountability. The enemy has never been “the exchange” or “the hardware wallet.” The enemy is the single point of failure — a fixed belief, a single device, a single dataset, a single leader — wearing the mask of certainty. So perhaps the honest conclusion is not that self-custody beats the exchange, nor that the exchange beats self-custody. It is that the question itself has been malformed by the people who benefit most from a binary answer. The industry does not need a winner in this debate; it needs a richer vocabulary for describing risk. It needs to acknowledge that custody is a spectrum, that every point on the spectrum carries its own failure modes, and that the responsibility of leadership is to help users find the point on the spectrum that matches their own technical competence, their own threat model, and their own tolerance for the silence of unrecorded losses. In the months ahead, the Coldcard incident will be resolved, one way or another, and the news cycle will move on to the next outrage. But the deeper question will remain, waiting quietly beneath the market's noise. We need a public and audited registry of self-custody loss events, so that the invisible becomes legible. We need hardware wallet vendors to treat incident disclosure as a core responsibility, not a liability. We need exchanges to earn their safety claims through real-time proof of reserves and genuinely independent insurance. And above all, we need a culture that treats custody as a spectrum of decisions, not as a religious allegiance. The 1.57 million figure is not a verdict. It is a question, and the question will not be answered by any single dataset or any single founder. It will be answered only by how honestly we are willing to count the losses we cannot see — and by whose hands we choose, knowingly, to hold the keys to our own stories. Building libraries where others build empires means accepting that the truth is never stored in a single vault.

Market Prices

BTC Bitcoin
$77,120 -1.99%
ETH Ethereum
$2,408.93 -2.46%
SOL Solana
$99.59 -3.63%
BNB BNB Chain
$679.6 -1.66%
XRP XRP Ledger
$1.34 -2.64%
DOGE Dogecoin
$0.0814 -2.00%
ADA Cardano
$0.1952 -1.91%
AVAX Avalanche
$7.19 -0.50%
DOT Polkadot
$0.8610 +2.92%
LINK Chainlink
$11.18 -1.33%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,120
1
Ethereum ETH
$2,408.93
1
Solana SOL
$99.59
1
BNB Chain BNB
$679.6
1
XRP Ledger XRP
$1.34
1
Dogecoin DOGE
$0.0814
1
Cardano ADA
$0.1952
1
Avalanche AVAX
$7.19
1
Polkadot DOT
$0.8610
1
Chainlink LINK
$11.18

🐋 Whale Tracker

🔴
0x5728...3156
30m ago
Out
3,568,811 USDT
🔵
0xaa93...bf0f
1d ago
Stake
49,650 BNB
🔴
0xb785...7e0f
30m ago
Out
4,794.55 BTC

💡 Smart Money

0x4d25...57c9
Early Investor
-$2.3M
67%
0x2af3...8ca6
Arbitrage Bot
+$4.0M
83%
0xd5cc...626c
Early Investor
-$3.9M
83%

Tools

All →