Every custody model in use today exists because the one before it failed. This is that record: 17 major failures from Mt. Gox to the 2026 entropy defect, what caused each one, and what it should have changed about how people hold bitcoin.
It includes the self-custody side. A registry that records only exchange collapses is an argument for custodians rather than an honest history, and the most recent entry is a hardware wallet.
That common root cause: in nearly every entry below, one party could act alone. One company held the keys, one interface decided what got signed, one firmware generated every seed, or one set of terms decided who owned the assets.
Almost nobody held their own keys. Exchanges were the only usable interface, and the losses were simply the cost of that convenience. The lesson people drew, not your keys not your coins, was correct and incomplete.
Self-custody hardware went mainstream and a new failure surface arrived with it. The threats stopped being only about who held the keys and started being about who knew you held them.
Yield products and regulated wrappers failed in sequence. These were not anonymous offshore exchanges but audited, licensed, household-name institutions, and the losses turned on legal title and segregation rather than on cryptography.
Attackers stopped breaking cryptography and started breaking the operators, the interfaces, and the build pipelines. Then a firmware defect showed that self-custody had a concentration problem of its own.
Read chronologically, the failures look unrelated. An exchange collapse in 2014, a lender in 2022, a firmware defect in 2026. Read structurally, they are the same event repeating with different actors.
The first era taught the wrong lesson too well. Mt. Gox and Bitfinex produced “not your keys, not your coins,” which was correct. It was also incomplete, because it said nothing about what happens when the keys you hold are all generated by the same company, kept in the same place, or understood by only one person.
The middle era proved that regulation is not architecture. Celsius, FTX, and Prime Trust were licensed, audited, and in some cases household names. What failed was legal title and segregation, not cryptography. A clean audit and a custody licence tell you almost nothing about whether one party can move your bitcoin alone.
The current era moved the attack off the cryptography entirely. Bybit, BigONE, WazirX, and DMM were not broken mathematically. Attackers compromised the people, the interfaces, and the build pipelines around the keys. Then the Coldcard defect demonstrated that self-custody carries a concentration risk of exactly the same shape: a multisig wallet built from several units of one device has one firmware and one entropy path.
How many separate parties or systems must fail before the bitcoin is at risk. Devices are not domains. Keys that share a manufacturer, a firmware build, or an entropy path all fail together.
The question that survives all fifteen years is not which product to buy. It is how many independent parties or systems have to fail before your bitcoin is gone, and who is responsible for keeping them independent once you stop paying attention.
We turned that into a published test with four questions you can apply to your own setup, including a setup we have never scored: the Custody Independence Standard. The longer walkthrough of what it means in practice, including why more dice rolls and more hardware wallets do not answer the question, is in Is your custody setup actually safe?
Proof of Custody, Bitcoin Custody Failure Timeline, proofofcustody.io/timelineAcross the failures recorded here, reported losses run from hundreds of thousands of bitcoin at Mt. Gox to billions of dollars at FTX and Bybit. Figures are as reported by courts, regulators, and named on-chain researchers; Proof of Custody has not independently reproduced the on-chain analysis.
The record does not support a simple answer. Custodial failures dominate by total value, but the 2026 Coldcard entropy defect and documented self-custody losses show that holding your own keys concentrates risk differently rather than removing it. What separates durable setups from fragile ones is how many independent parties or systems must fail, not who holds the keys.
One party being able to act alone. In nearly every recorded failure, a single company controlled the keys, a single interface decided what got signed, a single firmware generated every seed, or a single set of terms determined who legally owned the assets.
Because a record that lists only exchange collapses is an argument for custodians rather than a history. Vendor data breaches that drive years of targeted phishing, and firmware defects that reach every key in a multisig at once, are custody failures with the same structure as an exchange losing customer funds.
Almost nobody held their own keys. Exchanges were the only usable interface, and the losses were simply the cost of that convenience. The lesson people drew, not your keys not your coins, was correct and incomplete.
Self-custody hardware went mainstream and a new failure surface arrived with it. The threats stopped being only about who held the keys and started being about who knew you held them.
Yield products and regulated wrappers failed in sequence. These were not anonymous offshore exchanges but audited, licensed, household-name institutions, and the losses turned on legal title and segregation rather than on cryptography.
Attackers stopped breaking cryptography and started breaking the operators, the interfaces, and the build pipelines. Then a firmware defect showed that self-custody had a concentration problem of its own.