A faulty wallet, a hacker, or one person acting in bad faith — alone, none of them can touch a system built the way we design.
The defining constraint of the firm, not a footnote — written into every engagement letter as non-waivable.
The firm never generates, views, or stores a seed phrase or private key.
Clients generate all key material themselves, on their own devices. The firm instructs; the client executes.
The firm is never a named keyholder, signatory, or authorised person on any client vault or wallet.
The firm never possesses a signing device, never co-signs, never broadcasts a transaction.
The firm never takes possession of client bitcoin — for any period, for any reason, including testing.
The firm does not advise on whether to acquire, dispose of, or hold bitcoin. That is investment advice — separately regulated.
Two lines of engagement — one recurring product underneath both.
For finance directors and boards holding bitcoin on the balance sheet, who need to answer: who can move it, under what authority, evidenced how.
A 2-of-3 multisig scheme for high-net-worth individuals, with the client's own solicitor holding the third key as client property — under their existing regulatory framework, not ours.
Documents, checklists, witnessed procedures, and a dated certificate — repeated annually.
A current-state risk assessment: how much bitcoin, where it sits today, who could move it, what the board minutes say. This document alone is usually the point where the risk becomes visible.
A multisig design mapped to existing board authorisation limits, a signer matrix, a hardware list the client purchases themselves, and geographic placement.
A written script executed entirely by the client's own people, on their own devices. The firm observes and records — never touches a device — then issues a signed observation report.
Board custody policy, recovery runbook, and incident procedure delivered as a bound pack. Engagement closed.
A test signature from every key, observed and verified, the certificate reissued, the retainer invoiced. Repeated every year.
Self-custody removes one risk. It does not remove the risk that no one checked the setup.
On 30–31 July 2026, roughly 594 bitcoin — worth around $38 million — was swept from about 500 wallets in a single 25-minute window. The cause was not a stolen device or a phished password. It traced to a firmware fault, quietly present since March 2021, in a widely trusted hardware wallet: a broken check meant the device's true random-number generator was silently disabled during key generation, so it fell back to a predictable software substitute seeded from the device's own serial number and clock. Anyone who generated a seed on the affected firmware had, without knowing it, a guessable key.
Every wallet drained held a single signature. There was no second key required to move the funds, no second person who had to approve the transaction, and no independent process that had ever reviewed whether the setup was sound. The device did exactly what it was designed to do — the flaw was invisible to the person holding it, and would have stayed invisible indefinitely if it had never been exploited.
~$38m moved in 25 minutes, across roughly 500 wallets, once the flaw was found.
The fault was live for over five years before anyone outside the manufacturer noticed.
Every affected wallet was single-signature — one key, one point of failure, nothing to check it.
No hardware manufacturer, however well regarded, is a substitute for an independent review of the setup.
This is not an isolated case. Hardware wallets fail in ways their owners cannot see for themselves — firmware bugs, weak randomness, supply-chain tampering, and manufacturers who have previously exposed customer data to phishing and physical targeting. A single device, trusted on reputation alone, is a single point of failure. A multisig structure with a documented signer matrix, a witnessed key ceremony, and an annual verified drill does not make any individual component infallible — it makes sure that one flawed component, in one device, from one manufacturer, is never enough on its own to lose everything.
A structural difference, not a marketing one.
Tell us how bitcoin is currently held, who can move it, and what keeps the finance function awake at night. We'll tell you plainly whether an engagement makes sense.
info@vasilevsecurity.com