Security Is the Price of Admission for On-Chain Finance
By Christopher Russell, Chief Technology Officer, tZERO

Beginning on July 30, attackers exploited a flaw in certain Coldcard hardware wallets to sweep approximately 1,816 bitcoin – then worth about $116 million – from more than 5,200 addresses across four waves of theft. The Bitcoin ledger processed every transaction correctly: it verified signatures, updated balances and recorded transfers exactly as designed. Its job is to record what a valid key authorizes, not to know whether that key should still be trusted.
Coldcard manufacturer Coinkite has warned that seeds generated on Mk3 devices – and on certain firmware versions for its Mk4, Mk5 and Q models – may be at risk. A separate technical analysis from Block points to flaws in the devices’ generation of randomness, or entropy, that may have produced keys an attacker could reconstruct. The precise exposure varies by model and firmware, and the analysis remains preliminary. But the central lesson is clear: a device can be offline and its keys protected by powerful cryptography, yet a weakness when those keys are created can undermine the entire security model.
Blockchain makes tokenized assets, faster settlement, programmable ownership and continuously operating financial infrastructure possible. Underlying all of those capabilities is something more fundamental: security. Cryptography can establish digital ownership and transaction integrity without a single central database, but that trust depends on every component involved in creating, storing and using the keys that control an asset.
A Wallet Is a Security System
A blockchain wallet does not hold an asset the way a physical wallet holds cash. The asset remains recorded on the ledger; the wallet manages the private key that authorizes activity. Anyone who gains unauthorized access to that key may be able to move the asset. If the key is lost and no recovery mechanism exists, the asset may become inaccessible.
Key security begins at generation. A private key must be created using sufficient, unpredictable entropy. An air-gapped, tamper-resistant device protects nothing if the key it holds was never truly random, because an attacker may reconstruct the key without touching the wallet.
Secure architecture must therefore address the full key lifecycle – generation, encryption, storage, access, backup, recovery, rotation and retirement – as well as who can initiate and approve transactions, what limits apply and how abnormal activity is detected.
Cold, warm and hot describe how connected a wallet is, but the more useful distinction is between passive storage and active governance: a wallet that simply holds a key versus a system requiring proof of intent through multiple parties, defined roles and explicit approvals before assets can move.
Why Custody Choice Matters for Institutions
Self-custody is an important feature of blockchain-based finance. For individuals and institutions equipped to manage their own keys, technology and controls, it can provide autonomy and flexibility. Custody through a regulated financial intermediary serves a different, complementary need.
Institutions often manage assets for clients or operate under frameworks requiring independent oversight, documented controls, segregation of duties, supervised access and established books and records. For them, custody is not simply who holds the key; it is how assets are safeguarded, authorized, recorded and recovered.
Whatever model an institution chooses, it should ask: How was the key created? Who can authorize a transaction? Can one compromised device or employee move assets? How are software and firmware changes reviewed? What records establish ownership and authority? What happens if a key is lost or stolen? An appropriately registered broker-dealer can combine on-chain custody and settlement of digital asset securities with supervision, recordkeeping, access controls, operational resilience and regulatory accountability. Some institutions will use self-custody, an intermediary-based model or both, depending on the asset, mandate and transaction.
Recoverability Changes the Risk Equation
Tokenized securities can support a capability many bearer-style crypto assets cannot: recoverability. A security has an issuer, a legal owner and regulated recordkeeping obligations. When the token and its infrastructure are designed appropriately, issuers, transfer agents and broker-dealers may be able to restrict transfers, freeze, invalidate or burn a compromised position, and reissue the security to a verified replacement wallet, subject to the asset’s governing documents and applicable law.
That authority must not become a vulnerability. Recovery should require verified identity, documented authorization, reconciliation with official ownership records and appropriate governance over smart contract functionality. No single individual or compromised administrative key should be able to cancel or reissue a position unilaterally.
This is not a new seizure power. Securities markets have long provided processes for replacing lost or stolen instruments through affidavits, transfer agents and indemnity bonds. Properly designed tokenized securities preserve that investor protection. A compromised key can become a governed operational incident rather than an irreversible loss of the underlying security.
The Attack Surface Extends Beyond the Wallet
Strong cryptography does not automatically make an entire system secure. Attackers target key-generation processes, firmware, applications, browser extensions, endpoints, backups, employees and third-party services. They may steal credentials through phishing or malicious software, compromise a device or deceive an authorized user into approving a transaction.
Wallet security is therefore inseparable from cybersecurity. Institutions need strong identity and access management, phishing-resistant multifactor authentication, endpoint detection, network segmentation, continuous monitoring and rehearsed incident response. They must also evaluate the full technology and vendor path from key generation and transaction initiation through signing, validation, recording and recovery.
Programmability Expands the Security Mandate
Smart contracts encode the rules governing an asset’s issuance, ownership, transfer and lifecycle. For tokenized securities, those rules may cover investor eligibility, transfer restrictions, holding periods, supply limits, corporate actions and recovery. This can automate processes that are manual and reconciliation-intensive today, but it also raises the stakes for secure development.
Security must be built into the development lifecycle through threat modeling, code review, automated testing, independent audits and governed deployment and upgrades. Teams must consider both technical vulnerabilities and business logic failures: a contract can operate exactly as written and still produce an unintended result because a rule, permission or dependency was designed incorrectly. Product, engineering, security, legal, compliance and operations must work together from the beginning.
Institutional Adoption Requires Defense in Depth
No control is infallible. Defense in depth combines secure key generation, distributed signing authority, transaction policies, real-time monitoring, network controls, smart contract audits, regulated recordkeeping and defined incident response so one failure does not lead directly to lost assets or disrupted operations. Accountability must also be explicit: institutions need named owners for security decisions, exception approvals and control testing, and must understand dependencies on wallet providers, cloud platforms, blockchain networks and other partners.
The standard for institutional infrastructure is not whether a key can ever be compromised; certainty is impossible. It is what happens the day after. Cryptography establishes ownership and authority. Wallet infrastructure turns those principles into operational control.
Cybersecurity protects the surrounding people and systems. Regulated custody and recoverability add accountability and resilience when controls fail, keeping a single failure from becoming permanent.
Security is not a constraint on blockchain’s growth. It is what allows blockchain-based financial markets to scale.
About the author:
Christopher Russell, EVP, Chief Technology and Security Officer, tZERO Group, Inc. sits at the forefront of digital asset security. He holds a Master’s in Cybersecurity and is pursuing his PhD specializing in blockchain security. He holds a wealth of technical experience spanning cloud security, EDR, SIEM, AppSec and NGFWs. Chris is particularly known for his extensive research into adapting existing security tools for blockchain processes. He is an advisor for several VC firms specializing in Cybersecurity start-ups. He’s also a combat veteran and Arabic linguist from his distinguished service as a US Army HUMINT collector.