
Episode #38
Coldcard Aftermath: What's Next for Bitcoin Security | Jade, Passport, Trezor, SeedSigner
Mentor Sessions Ep. 089: Bitcoin hardware wallet makers Zach Herbert, Tomas Susanka and Drew Fischer discuss the Coldcard hack, multi-sig, entropy and self-custody security. The Coldcard hack was the single biggest blow to Bitcoin self-custody yet — so four rival hardware wallet makers sat down together to figure out what it means for everyone holding their own keys. This is the conversation the industry needed. Zach Herbert (Foundation Passport), Tomas Susanka (Trezor), Drew Fischer (Blockstream Jade) and Seed from the SeedSigner team break down the fallout: what the vulnerability actually exposed, why open source alone wasn't the safety net people assumed, and the entropy/dice-roll debate that split the panel. You'll learn why multi-vendor multi-sig is emerging as the strongest defense, how entropy is really generated on these devices, and the honest trade-offs between usability and security. You'll also hear the fresh news on the Trezor fulfillment-partner data leak (disclosed August 10, 2026) and what to do if you're worried about shipping and privacy. This is a rare, candid roundtable where competitors disagree openly — and that dialog is exactly what makes it worth your time. ⏱️ Timestamps: 0:00 - Intro 0:56 - Four wallet makers respond to Coldcard hack 1:58 - Ben's question on self-custody downstream effects 3:02 - Zach on short-term setback and great hardening 6:19 - Tomas on AI helping attackers and defenders 8:44 - Drew on custodians, ETFs and verify don't trust 10:30 - SeedSigner on entropy sources and multi-sig 13:11 - Usability versus security trade-off debate 17:20 - Should self-custody be made harder not easier 18:56 - Dice rolls versus RNG entropy disagreement 22:16 - Zach on how many people actually self-custody 26:14 - Priorities when choosing a hardware wallet 29:01 - Security as a journey not a destination 33:03 - Sponsor: Abundant Mines 36:00 - Why multi-vendor multi-sig should be the goal 41:25 - Source available versus fully open source explained 47:34 - Open source as required but not sufficient 51:11 - How to know if a wallet is actually safe 56:57 - Trezor fulfillment data leak disclosed August 10 1:03:49 - Private device purchases and local meetups 1:06:01 - Where to find each project online Links & Resources: → SeedSigner: https://seedsigner.com → Foundation Passport: https://foundation.xyz/ → Trezor: https://trezor.io → Blockstream Jade: https://blockstream.com/jade Subscribe for weekly Bitcoin Podcasts Follow on X: https://x.com/BTCSessions Follow on X: https://x.com/theBTCmentor ⚡Sovereign Sessions — AI, Privacy, and Bitcoin education: http://youtube.com/@SovereignSessions?sub_confirmation=1 BOOK Private Sessions with Nathan, Ben and the BTC Mentor Team: Master self-custody, hardware, multisig, Lightning, privacy, and more. Visit btcmentor.io ⚡ POWERED by Abundant Mines: Fully managed Bitcoin mining. Learn more at https://qrco.de/bgYKPB #Bitcoin #BTC #BTCSessions #BitcoinSelfCustody #ColdCard #ColdcardHack #BitcoinHack #HardwareWallet #MultiSig #SeedSigner #Trezor #Passport #BlockstreamJade #BitcoinSecurity #NotYourKeys #ZachHerbert #TomasSusanka

