The Bybit hack in February 2025 drained about $1.5 billion from a multisig wallet. The attackers didn’t break any code.
They manipulated the sign-off process itself – tricking multiple approvers into approving fraudulent transactions. That’s what made it unsettling.
If a major exchange with dedicated security teams can be taken down this way, what hope does an individual holder have?
The answer is more straightforward than it seems. The real vulnerability had little to do with cryptography. It was about how people and systems interact.
For everyday users, that’s actually reassuring. It means most threats are preventable, not inevitable.
Why Self‑Custody Still Matters
Since Mt. Gox collapsed in 2014, the principle has stayed constant. Between 2.3 million and 4 million Bitcoin, roughly 11-19% of the total supply, are estimated to be permanently lost. Forgotten passwords, lost seed phrases, destroyed hardware – these account for the bulk of it.
Exchanges have their own track record. FTX, Celsius, BlockFi; each failure left customers as unsecured creditors. Bybit demonstrated that even cold storage isn’t safe when the approval workflow gets corrupted.
Self-custody removes the counterparty. No exchange freeze, no bankruptcy proceedings. But it replaces institutional risk with personal responsibility.
No fraud department, no password reset, no chargeback. For anyone holding more than a trivial amount, the trade-off is worth examining. Non-custodial on-ramps have emerged as a practical alternative to the traditional exchange-first approach.
Services like ChangeNOW allow users to buy bitcoin with debit card and receive it directly at their own address, eliminating the step where funds sit on an exchange wallet at all.
What Actually Drains Wallets in 2026
Earlier this year, a fake Trezor wallet appeared on Apple’s App Store. It mimicked the company’s branding so convincingly that some users mistook it for the official app and installed it.
By the time Apple took it down, there were already reports linking the app to stolen cryptocurrency and substantial financial losses.
The same attackers are now running search ads that point to counterfeit wallet sites. If you search for a wallet provider, the first result might be a scam page. AI-generated emails have also made things harder — they replicate branding almost perfectly.
The flow is simple: you follow what looks like a legitimate link, arrive at a familiar-looking site, enter your details—and access is gone before anything feels off.
Approval drains work differently. A malicious dApp requests a signature on what appears routine. The signature grants unlimited spending authority. One approval, and the attacker clears your wallet.
Then there’s the storage problem. People put seed phrases in Notes, take screenshots, save them in cloud-synced password managers.
Malware such as RedLine and Vidar scans devices for data like this. If a seed phrase is stored in any digital form on a device with internet access, it should be treated as exposed. Move funds immediately.
Physical theft gets less attention, but it’s real. People have been threatened at gunpoint to unlock their wallets. Others have lost hardware devices in break-ins. This side of the threat landscape doesn’t involve code at all.
Some hardware wallet makers are responding to these challenges by expanding what their devices can do.
The D’CENT × ChangeNOW case shows how a cold storage provider integrated exchange functionality directly into the wallet environment, letting users trade without moving funds to a hot wallet. This approach reduces the attack surface considerably.
Hot, Cold, and the Space Between
Wallet choice comes down to a single trade-off: accessibility versus exposure.
Hot wallets – mobile apps, browser extensions, exchange accounts – keep private keys on connected devices. They’re fast. Transactions happen in seconds. The cost is constant exposure to malware, phishing, and device theft.
A malicious browser extension might appear legitimate while quietly extracting keys. Keep a small balance here. An amount you’d accept losing.
Cold wallets operate offline. Hardware devices like Ledger and Trezor sign transactions only when physically connected and confirmed on the device screen.
For long-term holdings, this remains the standard. Buy directly from the manufacturer. The keys never touch the network, eliminating remote attack vectors.
Some solutions blur the line. D’CENT wallet integrated with ChangeNOW to enable in-wallet swaps while keeping private keys offline.
Users trade Bitcoin for other assets without moving funds to a hot wallet or exchange. The attack surface shrinks considerably.
Compartmentalising Your Holdings
One wallet rarely fits all needs. The sensible approach involves splitting across multiple wallets with different risk profiles.
A hot wallet for daily spending and small transactions. Fund it monthly. A hardware wallet for the bulk of savings – 80-90% of your stack. Accessed rarely. A burner wallet for airdrops, NFT mints, experimental contracts. Minimal funds only.
The logic is straightforward. If your hot wallet gets drained, your savings are untouched. If your burner is compromised, the loss is contained. For larger holdings, consider splitting cold storage across two devices or using multi-signature.
Bybit showed multisig isn’t impervious when the signing interface is attacked. For individual holders, though, it still offers significant protection over single-key storage.
Seed Phrases: The Rules That Don’t Bend
Your seed phrase is the master key. Lose it, and your Bitcoin is gone. Expose it, and it’s gone too. There’s no middle ground.
Write it on paper or stamp it into metal. Paper burns, gets wet, fades. Metal survives fire and flood. Never photograph it. Never type it.
Never store it digitally – not in Notes, not in Google Drive, not in a password manager’s synced vault. Malware hunts specifically for these files.
Keep two copies in separate secure locations. One at home, another in a bank deposit box or with a trusted contact.
If you suspect any exposure, even briefly, move funds to a fresh wallet immediately. Waiting is not an option.
For significant holdings, add a passphrase – the “25th word”. This creates a hidden wallet accessible only with both the seed phrase and the passphrase.
Even if someone finds your 24 words, they can’t reach the hidden wallet. Store the passphrase separately from the seed phrase.
Getting Bitcoin Into Your Own Wallet
Once your storage is set up, the next step is moving Bitcoin in. If you bought on an exchange, withdraw to your cold wallet. If you’re buying fresh, use services that send directly to your address.
The transfer process:
- Get your receiving address from your wallet. Copy the string or scan the QR code.
- Initiate the withdrawal on the exchange. Paste the address.
- Double-check the first and last characters. Some malware replaces the clipboard with an attacker’s address.
- Verify the amount and network fee.
- Authorise on your hardware wallet. Read the device screen. Never blind-sign.
Start with a small test amount. Send $5 worth, wait for confirmations. Then move larger sums. This catches any address or network errors.
Three Possible Futures
Base case. Most users adopt layered storage: exchange for buying, hot wallet for spending, hardware wallet for savings. Seed phrases on metal plates. A few hours of setup covers the majority.
Optimistic case. Biometric authentication and social recovery mechanisms are slowly making self-custody less intimidating. Hardware wallets are becoming cheaper. If these trends continue, more Bitcoin moves off exchanges. Systemic risk decreases.
Stress case. Deepfakes and cloned voices are already making phishing attempts more difficult to recognise. There have also been documented cases where researchers carried out physical attacks on specific hardware devices.
Regulatory uncertainty adds another layer. MiCA’s full enforcement started in July 2026 across the EU. Self-custody wallets remain outside the CASP perimeter, but the Commission’s assessment of self-hosted addresses could tighten verification requirements.
Some users may decide the hassle isn’t worth it and move back to exchanges. That would recreate the very risk Bitcoin was designed to bypass.
The Responsibility That Comes With Freedom
Safe Bitcoin storage comes down to understanding the risks and setting up protection that fits your situation. Smaller amounts can stay within easy reach, while larger holdings are better kept offline. A seed phrase should never be stored in digital form.
The fundamentals haven’t shifted in a decade. Control your keys, control your coins. The threats have grown more sophisticated, but the countermeasures haven’t changed much. Diligence. Redundancy. Scepticism toward anything requesting your private information.
There’s no customer service to call when something goes wrong. That’s what freedom looks like in this space. It costs something.
FAQ
- What’s the safest way to store Bitcoin in 2026? For most users, a hardware wallet remains the practical option. The recovery seed is best kept offline at all times.
- Is keeping Bitcoin on an exchange safe? It’s fine for funds you’re actively trading. Long-term holdings are usually moved to a wallet controlled by the owner.
- What’s the difference between a hot wallet and a cold wallet? Hot wallets are connected to the internet and used for everyday transactions. Cold wallets are kept offline and used for storage.
- What should I do if I lose my seed phrase? Move your funds to a new wallet while you still have access. If both access and the recovery phrase are lost, recovery is unlikely.
- Can I store my seed phrase in a password manager? No. Password managers sync online and get compromised. Keep it offline only.
- Should I use a passphrase? Yes for significant holdings. Even if someone finds your 24 words, they can’t access the hidden wallet without it.
- How do I avoid phishing? Type wallet URLs manually or use bookmarks. Never click links in emails or DMs. No legitimate service asks for your seed phrase.
- How much should I keep in a hot wallet? Only what you need for the near future. An amount you’re comfortable losing.
- My hardware wallet broke. What happens? Your Bitcoin is on the blockchain, not the device. Use your seed phrase to recover on a new device.
- Are multi-signature wallets worth the trouble? For very large holdings, yes. They spread risk across multiple keys but add complexity.
Disclaimer
This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency involves risk, and users should conduct independent research before making any decisions.

