August 14, 2026 Roundup: Trading Keys for Claims
Brian Cubellis | Chief Strategy Officer
Free. Every week. One story that matters, read all the way down.
In the wake of a long-trusted hardware wallet's entropy bug, which two weeks ago led to roughly $130 million in bitcoin stolen straight out of cold storage, the industry is going through a security reckoning.
This week, another device manufacturer, the one many holders turned to after abandoning their Coldcards, leaked the personal information of roughly 14,000 buyers in a supply chain breach. Names, emails, home addresses. The true burden of self-custody is being recognized in real time.
The knee-jerk reaction has been to buy, or move assets into, ETF vehicles: a paper claim in place of key management, one single point of failure exchanged for another. In this week's roundup we walk through why that trade is illogical, and why another path to secure bitcoin ownership exists, one without the operational burden and without the centralized honeypot risk.
Trading Keys for Claims
A $130 million hardware wallet failure, 14,000 leaked home addresses, and the wrong lesson spreading fast.
We have covered the Coldcard failure itself and won't re-litigate the mechanics here. The figure that matters is the running total: roughly 2,000 bitcoin, some $130 million, stolen from thousands of addresses over a handful of days. As industry participants ponder where we go from here, the ongoing reaction to the incident may be more instructive than the exploit itself.
Start with this week's latest news, which belongs in the same conversation. Trezor disclosed that its shipping partner ShipMonk suffered a breach affecting nearly 14,000 hardware wallet buyers: 11,742 whose full names, phone numbers, email addresses, and home addresses were exposed, plus a second group of 1,947 whose names, cities, and emails were leaked.
No devices were compromised, no firmware failed. The customers were simply identified and located. This is the same category of data that saw Ledger breach victims mailed counterfeit devices, and Trezor is already warning those affected to expect phishing impersonating banks, exchanges, and Trezor itself.

These two failures are complementary halves of one problem. Coldcard showed that the digital layer can break silently beneath a careful holder, in firmware he has no realistic way to audit, for years. ShipMonk showed that the physical layer can break through a logistics vendor he never chose to trust, handing strangers a list of who holds bitcoin and where they live.
One attack came through the mathematics of key generation. The other arrives at the front door. Taken together they describe the actual burden of self-custody at material scale: sole responsibility for attack surfaces you cannot see, across domains even the most technically capable individuals struggle to defend in perpetuity. The holders feeling that weight right now are not being irrational, and the instinct to reassess their custody setup is fair. What deserves scrutiny is the destination.
The flows make the dominant answer unambiguous. In the five sessions after the exploit, US spot bitcoin ETFs took in $853 million in net inflows, their strongest week since April, with BlackRock's IBIT alone absorbing $693 million of it. Bloomberg's Eric Balchunas noted that IBIT, FBTC, and a handful of others saw inflows every single trading day from the hack onward, and that it is "hard not to see causation in the correlation".

source: Eric Balchunas on X
BlackRock, for its part, read the moment perfectly, cutting the minimum for in-kind conversions of bitcoin into IBIT from $25 million to $1 million on August 10, days into the fallout, with more reductions promised. A rattled holder can now deliver actual bitcoin, receive shares, and defer the tax bill in the process.
What that holder ends up owning is worth examining clearly. An IBIT share is a claim on a trust whose bitcoin sits with one custodian, Coinbase Custody, the same institution behind nearly every US spot ETF. The shareholder holds no key, controls no coins, cannot verify or take delivery at the asset level, and has no recourse to the underlying bitcoin if the custodian layer fails.
To be fair, Coinbase runs a serious operation: multisignature authorization, cold storage, distributed key material. The architecture looks robust on paper. But every signer, policy, and system sits inside one organization under one operational umbrella.
Bybit's cold wallet was multisig, the standard institutional-grade setup. In February 2025 the Lazarus Group compromised their front-end infrastructure and altered what Bybit's signers saw on their screens. Each of them approved what looked like a routine internal transfer, and about $1.5 billion in assets went to North Korea in the largest theft the industry has recorded. Every signer worked for the same company, used the same vendor interface, and trusted the same display. Multisig inside a single organization still presents single entity risk. The holder fleeing Coldcard for IBIT is not exiting counterparty risk. He is concentrating it in the largest single bitcoin custodian in the world.
Importantly, continued concentration of bitcoin in Coinbase's coffers changes the economics of attack itself. A single institution holding the bitcoin behind nearly every US spot ETF is the most valuable target the industry has ever assembled, and the return on a successful breach grows with every dollar of inflow while the cost of attempting one is declining with the acceleration of AI. Every shaken holder who converts to IBIT this month is, without intending to, raising the bounty on the vault he just bought into.
We have watched a bearer asset walk this exact path before. Gold's monetary role did not fail at the assay office. It failed at the vault: possession intermediated, ownership pooled into claims, and once the metal was centralized the rest followed, from Executive Order 6102 to the closing of the gold window in 1971. Centralization is what made gold confiscable and then severable from the claims issued against it. An asset engineered from first principles to remove trusted third parties is now being re-intermediated, and the larger the pile grows, the more certain the pressure on it becomes.
We have had a front-row seat to the alternative. The past two weeks have been the most active onboarding period in Onramp's history. Existing clients are adding to their vaults. Prospects who had been circling for months, sometimes years, are finally moving, and the refrain is remarkably consistent: the incident was the last straw, the moment the arithmetic of self-custody stopped making sense.
"What am I doing managing these devices in perpetuity, keeping them on my person, around my family, just to secure my own wealth?"
These are not people fleeing bitcoin, and they are not people who misunderstand custody. They are hardened bitcoin holders who held their own keys through multiple cycles and have now concluded that the burden has outgrown the individual. They just refuse to trade sovereignty for a share certificate to escape it.
That refusal points at the flaw in how the past two weeks have been framed. The choice on offer, self-custody or the wrapper, is a choice between two concentrations of trust, one borne by an individual and one by an institution, each with documented failure modes.
Bitcoin already provides the alternative. A 2-of-3 multisignature quorum spread across independent, regulated institutions means no single key holder can move funds and no single breach or failure reaches the coins. The institutions constrain one another through incentive rather than goodwill. The client authorizes transactions without ever generating, storing, or handling key material, which dissolves the operational burden of self-custody and the physical exposure, while ownership remains segregated, verifiable, and attributable to the client at the level of the asset itself rather than pooled behind a share certificate.

This is the architecture Onramp has spent four years building, not in response to this month's headlines but in anticipation of them.
Coldcard demonstrated that hardware relocates trust into firmware no user can verify. ShipMonk demonstrated that the physical layer cannot be waved away once holdings become material. BlackRock's threshold cut demonstrated that the centralized alternative will always be waiting, patient and well-funded, for self-custody to frighten people into the honeypot.
These single points of failure are not edge cases, they are certainties on a long enough timeline. The only question a custody architecture has to answer is whether any one failure can knock you out of the game.
CLOSING NOTE
Onramp provides bitcoin financial services built on multi-institution custody. To learn more about our products for individuals and institutions, schedule a consultation to chat with us about your situation and needs.
Until next week,
Brian Cubellis