XRP Ledger co-creator David Schwartz this week proposed splitting Bitcoin cold storage across four people, after a Coldcard firmware flaw reportedly generated predictable seed phrases and let attackers drain 1,367 BTC. His plan separates the devices from the PIN.
Key Takeaways
- David Schwartz proposed a split-control Bitcoin storage plan that divides device custody and PIN knowledge among four different people.
- Two relatives would each hold a hardware wallet loaded with the same 24-word recovery phrase and the same PIN.
- Two unrelated friends would hold only the PIN, without access to the devices or the recovery phrase.
- The Coldcard hack drained more than 4,500 addresses and 1,367 BTC, worth close to $89 million.
- Private key compromise causes 35% of crypto hacks, the largest single cause of security breaches.
Schwartz Splits the Devices From the PIN
Schwartz’s design starts with two extra hardware wallets, each loaded with the same 24-word recovery phrase and locked with the same PIN. The owner keeps the main wallet separately. No participant holds both halves.
The distribution runs four ways:
- Relative one receives a hardware wallet and no PIN.
- Relative two receives an identical hardware wallet, also with no PIN.
- Friend one receives the PIN, with no device and no recovery phrase.
- Friend two receives the same PIN under the same restriction.
Schwartz compared the structure to a “nuclear briefcase” in which no single holder can act alone. He named the SecuX W20 as a suitable device for keeping private keys away from internet-connected systems. After the owner dies, the friends release the PIN to the relatives, who unlock the devices without an exchange, a lawyer, or an online account.
Here’s one way:
— David ‘JoelKatz’ Schwartz (@JoelKatz) August 3, 2026
1) Program two extra cold wallets with your 24 words. Set them to the same PIN.
2) Give one wallet to each of two trusted relatives.
3) Give the PIN to each of two trusted friends. Instruct them to give the PIN to your relatives if you die.
The Coldcard Flaw That Restarted the Debate
The Coldcard hardware wallet breach reportedly began with a firmware defect that produced predictable seed phrases. Attackers then swept more than 4,500 addresses and took 1,367 BTC, valued near $89 million.
That failure mode cuts against the core promise of a hardware wallet. A device that never exposes a private key to the internet still fails if the key was guessable the moment it was created. Some holders responded by returning to paper wallets, which face no remote attack surface and stay exposed to fire, water damage, theft, and simple misplacement.
Key Compromise Drives the Losses
The problem Schwartz is addressing shows up in the theft data. Private key compromise causes 35% of crypto hacks, the largest single cause of security breaches. Personal wallet compromises reached 158,000 incidents and affected at least 80,000 unique victims in 2025.
What the Plan Does Not Fix?
The arrangement addresses custody and inheritance. It leaves the defect that started the discussion untouched. Two devices carrying the same 24-word phrase share the same weakness if flawed firmware generated that phrase, and splitting the PIN across two friends does nothing about a seed an attacker can predict.
Several questions stay open. Which Coldcard firmware version was affected? Over what window were vulnerable seeds generated? How were the 4,500 drained addresses identified, and can a holder check their own device against that set?
Holders who already store Bitcoin on a hardware device can check the firmware version against the vendor’s advisory and confirm how the seed was generated. Regenerating a seed with independently verified entropy helps reduce that specific exposure.
CoinLaw’s Takeaway
The proposal answers a real gap in self-custody estate planning. These setups tend to fail in one of two ways: the owner is the only person who can reach the funds and the heirs recover nothing, or a copy of the recovery phrase sits somewhere one person can find it and act alone. Separating the devices from the PIN closes both paths without handing keys to a custodian.
The design carries a cost the structure cannot remove. Every additional copy of the recovery phrase is another object that can be found, coerced, or lost, and the plan converts one point of failure into four points of trust. That trade reads as reasonable against the loss figures, where key exposure drives a larger share of incidents than physical device seizure. It holds only if the seed sitting behind all three devices was sound when it was created.
