BAS Webinar: Self-Custody Under Pressure
August was a rough month for Bitcoin security.
A seed generation flaw in Coldcard firmware, an actively exploited vulnerability in BTCPay Server, a logistics vendor breach exposing Trezor customer addresses, and a support database compromise at Pocket Bitcoin. Four very different failure modes, all within a few weeks.
We take an hour to work through what actually happened, what it means for how we hold and spend bitcoin, and what each of us should change in practice.
Thomas Lohbeck opens with a simple technical breakdown of randomness, entropy and classification of the Coldcard incident: what the entropy flaw was, who is affected, and what the recommended remediation path looks like.
From there the session is an open exchange. Bring your questions and your own setup. Topics we expect to cover:
Hardware wallet trust: firmware verification, dice rolls, passphrases, multisig as a hedge against single vendor failure
Self-hosted infrastructure: patch discipline for BTCPay Server and node operators
Data leaks as physical risk: what an exposed shipping address means, and how to buy and receive hardware with less exposure
Phishing after a breach: how attackers use real support history to sound legitimate
Practical takeaways: what would you actually do differently tomorrow
Speaker input: Thomas Lohbeck
Format: Short input, then open discussion. Come with questions.
Platform: Jitsi (link shared after registration)
Language: English
Educational only. No financial advice. This is a community discussion, not a vendor assessment.