You know the story by now so I'll keep it short. Broken RNG, five years of weak seeds, $38M+ gone in under half an hour, closing in on $90M since. And if your seed came from the bad firmware, updating does jack shit - you burn everything down, generate fresh, and pray you move funds before the attacker does. Real nice.
And yeah, I don't think the mantra "not your keys, not your coins" is valid anymore. This hack exposed that your keys are only yours if the device that made them actually worked. And how many Coldcard owners verified the hardware RNG was being called? Zero. Everyone trusted Coinkite's firmware the exact same way CEX users trust an exchange. The difference is CEX users admit they're trusting someone.
Self-custody was never trustless. It just moved the trust somewhere you can't see it - into a $150 device from a company whose most fundamental function went unaudited for HALF A DECADE. A device marketed specifically on its hardware key generation, turned out it wasn't using it since 2021. The people using it weren't running audits, they were regular dudes with day jobs trying to do the work of a 200-person security team with a USB stick and some Reddit threads...
Meanwhile big CEXes like Nexo and Kraken have entire floors of people whose only job is keeping funds safe. Security engineers, 24/7 monitoring, multi-sig cold storage, someone to actually call when things go wrong. Exchanges have blown up too, that is a fact. But at least that risk is priced in and everyone knows it exists. The hardware wallet risk was invisible for five years and the people carrying it were told they'd eliminated risk entirely.
So here's the question that should keep every self-custody maxi up. This bug sat in the most respected Bitcoin-only wallet on the market for 5 years before anyone noticed. It took thousands of drained wallets to find it. What are the odds it's the only one? How many other devices are sitting in drawers right now with some unknown flaw that won't surface until the next sweep starts?
At that point "be your own bank" isn't really sovereignty. It's more like doing unpaid QA for a hardware company, but the twist is you're doing it with your own life savings as the test environment.