Verify, don't trust — including us
What's changed
A self-custody guide is only as good as how current it is. Prices move, devices get discontinued, new models ship. So we re-check the facts on a schedule and write down exactly what changed — no silent edits, no pretending the page was always right.
- Specs
The last two "last verified" dates now have machines behind them — and building those machines found a number of ours that was wrong
This finishes the job started in the entry below, and it did not finish quietly. THE BACKGROUND, IN ONE LINE. Six pages on this site carry a "Last verified" date at the foot. Four of them were already set by machine: something re-checks the facts on a schedule and the date is the oldest of them, so it can never claim more than we have actually looked at. Two were not. The metal-backups page and the dice page had dates typed by a person, and nothing anywhere was watching what those pages say. Both now work like the other four. WHAT WAS ACTUALLY WATCHING THE METAL PAGE BEFORE TODAY: one check that loaded Jameson Lopp’s stress-test page and confirmed it was still online. That is the entire thing. His results are where every grade and price on that page comes from, and we were confirming the address, not the contents. AND THAT IS HOW A NUMBER OF OURS STAYED WRONG FOR A WEEK. We published that of the 75 devices he has tested, 56 came through every test with nothing lost. We went back and counted his overall-grade column properly. 45 devices grade A. Another 11 grade A-minus, each marked down in one of the three tests. We had added those two groups together and then described the total as having lost nothing, which is not what an A-minus means — in at least one case his own write-up explains the deduction as a risk of losing the words on the way back out. The honest figure is 45, and there are now three numbers on that page instead of two, because the 11 in the middle are part of the picture. NONE OF THE ADVICE CHANGES, and we want to be precise about that rather than reassuring. The point of that section is that most of these products are fine and you do not need to agonise — that was true at 56 and it is true at 45, and the ten that did badly are the same ten. What changed is that a number we published was not the number in the source we cited, which is the thing we ask you to trust us about. WE ALSO TOOK OUT A SUPERLATIVE WE COULD NOT SOURCE. We had called one failure "the worst in the whole test set". It graded D; five devices graded F. What his review actually says about it is that the rivets dissolved and every letter fell out, causing catastrophic data loss, so that is what we say now. THE DICE PAGE, which turned out not to be the exception we assumed. Our first thought was that the dice procedures are our own work and have nothing to go stale. They are not: every menu route on that page is read off the maker’s own current documentation, printed word for word, and a menu is a product decision that can be renamed in a single firmware release. Nobody would tell us. So every vendor page behind it is now checked, and there is a watcher for each maker’s procedure — including one whose whole job is to notice if a device we say has no dice option ever gains one, because that is the kind of claim that rots with nothing anywhere disagreeing. THE FIRST RUN FOUND TWO SMALL THINGS ON THAT PAGE. Coinkite has moved its seed documentation and our link pointed at the forwarding page rather than the document — it still landed you in the right place, which is exactly why nobody noticed. And Blockstream writes the first menu item as "Setup Jade" where we had written "Set Up Jade"; on a page whose value is printing the literal words on the screen, ours should match theirs. Everything else on both pages checked out against the makers’ own current documentation, which we read rather than trusted a summary of. ONE THING WORTH PASSING ON. Lopp has now written that having tested 75 devices he does not intend to test many more. So that table is less of a moving target than it was — but the grades and prices in it are still his to revise, and after today we would rather be told than assume.
- Specs
AnchorWatch pricing corrected — and our "last verified" date on that page was claiming more than we had checked
Two things, and the second is the more important one. THE PRICES. AnchorWatch has published a full custody fee ladder and our page was still quoting only its bottom rung. We said "custody from $100/mo", which is true for a vault up to $500,000 and stops being the whole story immediately after: it is $175/month up to $1M, $375 up to $2.5M, $700 up to $5M, and $1,000 above that — capped at $1,000/month for individuals and small businesses no matter how much you hold, which is genuinely reassuring information we were leaving out by quoting only the entry price. We also had the insurance premium wrong at the top end: we said roughly 0.55%–2% a year, and AnchorWatch now publishes premiums starting at $4,000 per $1 million of coverage per year — 0.4% — with their own calculator estimating 0.6% for Flagship and 0.8% for Multi-Institution Custody. Nothing on their site supports a 2% figure any more. The $250,000 minimum insurance policy we already published is unchanged and correct. WE ALSO RE-READ THE OTHER FOUR SERVICES AT THE SAME TIME and they are all still accurate as published: Unchained at $250 per vault per year, Swan Vault at $30/month up to $150k then 0.02%/month capped at $500, Nunchuk's free tier plus Iron Hand and Honey Badger, and The Bitcoin Adviser's stepped 1.00% → 0.75% → 0.50%. THE DATE ON THE PAGE, which is the part worth explaining because it is about whether you can trust the other dates on this site. That page said "Last verified: August 1, 2026". The oldest fact behind it had actually been checked on July 19 — thirteen days earlier. Nothing had gone wrong in the machinery: the date had been moved by hand during an editing pass, and no check anywhere compared what we were claiming against what we had actually verified. On a page that asks you to consider handing a company one of your keys, that is exactly the wrong place for a freshness claim to be decorative. So: every fact behind that page has now genuinely been re-checked against each provider's own pricing page, the date is set by machine from the OLDEST of them rather than typed by a person, and the site now refuses to publish at all if any "last verified" date on it runs ahead of the evidence — or if we have checked something, found it had changed, and not yet fixed the page. TWO OF OUR SIX VERIFIED DATES STILL HAVE NO MACHINE BEHIND THEM (the metal-backup and dice pages). We know which two, the build now names them on every push, and they are next.
- Content
The sending lesson has its knowledge check back
Correcting something we published hours ago in the entry below. When "verify the address on the hardware wallet's own screen" came off the list of twelve rules, the sending lesson's two knowledge-check questions went with it, because on this site the checks are attached to the rules rather than to the lessons. We said so plainly at the time and we were not happy about it. On reflection that was the wrong thing to accept. The topic was demoted from the RULES — it is about spending and this site is about holding — and it was never demoted in importance: address-swapping malware is the most common real-world attack this whole course warns you about, and a lesson where you cannot find out whether you have misunderstood it is a weaker lesson. So /learn/send-bitcoin-safely carries its two questions again. Nothing else changed: it is still not one of the twelve rules, and the habit is taught there exactly as it was. For anyone who cares how it works underneath, this is the only lesson on the site whose check is attached to the lesson instead of to a rule, it is written down as a deliberate exception rather than left to look like an accident, and the site refuses to build if that exception list ever grows onto a lesson that already has a rule of its own.
- Content
The rules have been reworked — still twelve, re-ordered, two of them new, and one of them no longer a rule
This is the follow-on to the entry below about what we now believe, and it is the part that actually changes what you read. The rules are how that philosophy turns into something you can follow, so once the philosophy moved they had to move too. There are still twelve. NOT YOUR KEYS, NOT YOUR COINS IS NOW THE FIRST ONE. It was second. It is the whole idea — everything else on the list assumes you have already done it — and it should never have been anywhere but the top. THERE IS A NEW RULE AT NUMBER TWO, AND IT IS THE FLOOR: protect your Bitcoin with at least two independent things, so no single one of them failing can lose it. Please read the word independent, because it is the one doing the work and it is the one people mishear. This is not an argument against single-signature wallets and it is not a push toward multisig. One seed plus a passphrase that device has never seen is two independent things and clears this bar. Three keys from the same manufacturer do not clear it, however impressive the arrangement looks, because one firmware defect or one bad batch or one company reaches all three at once. Count what has to fail, not how many pieces you own. THERE IS A SECOND NEW RULE AT NUMBER FOUR: the more you are protecting, the more it takes to protect it. A setup is not secure or insecure on its own — it is secure enough, or not, for what it is currently holding. The arrangement you built for money you were learning with does not notice when it starts carrying years of savings. You have to. We still never ask how much you hold, and we never will; what we ask is what losing it would actually do to you. AND THE ORDER OF THE LIST IS THE POINT. The floor sits at two and "choose the simplest setup that covers you" sits at five, and that gap is the ranking written down. Simplicity is still the target. It stops winning the argument at the point where it would leave one thing holding everything. TWO RULES BECAME ONE. "You are more likely to lose access to your Bitcoin than have it stolen" and "choose the simplest setup that covers you" were one idea told twice — the second already argued the first in its own body copy. They are now a single rule, with the self-inflicted-loss material where it belongs: as the reason simplicity matters, rather than as a separate instruction. Nothing was dropped from what it teaches. ONE RULE IS NO LONGER A RULE, and we would rather say so here than let you notice it missing. "When sending Bitcoin, verify the address on the hardware wallet's own screen" is about spending, and this site is about holding and saving. It has come off the list of twelve. IT IS STILL TAUGHT IN FULL on the sending lesson and it is still a step on your checklist and in the device walkthroughs, unchanged, because it is still correct and still the habit that defeats address-swapping malware. What it lost is its place among the twelve, and — being straight about the cost — the sending lesson's two knowledge-check questions went with it, because on this site the checks hang off the rules. That lesson is now the only one to have lost a check rather than never having had one, and we are recording that rather than quietly absorbing it. NOTHING YOU HAVE ALREADY BUILT IS NOW WRONG. No rule reversed. If you followed the old twelve you have followed eleven of the new twelve and the twelfth is still on your checklist. What changed is the order, which is to say what we lead with — and if you built something simple that rests on a single seed and the loss of it would genuinely hurt, the new rule at number two is the one to read.
- Content
We have changed our minds about what comes first — and the About page now says what we believe instead of repeating the rules
This is a change of position rather than a correction, so it is worth reading if you have used anything here to decide how to hold your Bitcoin. WHAT CHANGED. Until today the advice on this site was built simplicity-first: the simplest setup that covers you was the headline, and "do not leave one thing holding everything" arrived afterwards as a qualification on it — literally, in the words "the one thing that rule does not excuse" on the About page and "but for money that would really hurt to lose" on the home page. That ordering is now reversed. NOTHING YOU OWN SHOULD DEPEND ON ONE THING BEING FINE, and where that collides with keeping the setup simple, it wins. AND THE THING PEOPLE MOST OFTEN HEAR WHEN WE SAY THAT IS NOT WHAT WE MEAN. This is not an argument for multisig, and it is not a claim that single-signature wallets are bad. It is about combining things that fail independently. A seed you generated on one device plus a passphrase that device never saw is two independent things. Dice you rolled yourself, feeding a signer that never chose your randomness, is the same idea. Three keys from three different manufacturers is that idea again, at more cost and more complexity. A single-signature wallet with a strong passphrase clears this bar. A three-key setup built entirely from one manufacturer does not, whatever it looks like on paper — because one firmware bug, one bad batch or one company reaches all of it at once. WHY NOW, PLAINLY. The guidance most of this field rests on — including ours until today — was written for a world where attacks were expensive, hand-made and rare. They are now cheap, automated, and increasingly assembled by machines that read code faster and more patiently than any human auditor. In 2026 a defect that had sat in public, readable source for five years made a set of Bitcoin seeds guessable; no audit found it, the reproducible builds did not find it, and we did not find it. Every wallet drained was a lone key with nothing else that had to also be true. You cannot defend against a threat nobody imagined. You can decline to own a component whose failure is total. We do not think the older simplicity-first advice was wrong when it was written. We think it is no longer sufficient on its own, and we would rather move early and be accused of caution than move late. WHAT HAS NOT CHANGED. Complexity you do not control is still one of the largest causes of lost Bitcoin, and we will still tell you when NOT to add something as readily as when to. More keys and more clever schemes have buried more coins than thieves have taken. That is why this is a change of ranking rather than a reversal: the simplest setup that covers you is still the target, it simply no longer wins the argument when it would leave everything resting on one seed. THE ONE PLACE WE STILL RECOMMEND A SINGLE POINT OF FAILURE, AND WHAT WE CHANGED ABOUT IT. For money whose loss genuinely would not change your life, one wallet kept properly is still an honest answer, and we are keeping that — telling someone learning with a small amount that they need more would contradict the other half of what we just said, which is that what is adequate depends on what you stand to lose. What was wrong is that we were not SAYING it. The warning that describes this setup as resting on a single device and a single backup only appeared for readers who told us the stakes were high, which is precisely the group who never see this recommendation. So the one reader we handed a single point of failure was the one reader never told it was one. That is fixed: every such recommendation now carries it in plain words, along with what would change it, and the site refuses to build if one ever goes out without it. THE ABOUT PAGE. It used to introduce the philosophy and then hand you back to the rules. It now states what we believe first — the floor, then how much your situation should change what you need, then where simplicity sits, then what we will not do — and the rules are presented as an expression of that rather than as a substitute for it. The rules themselves are being reworked next, and that will get its own entry.
- Security
We have stopped recommending the Coldcard — and left its rating exactly where it was
This is a recommendation of ours being withdrawn, which is the thing this log exists for, so here is all of it. WE NO LONGER RECOMMEND BUYING A COLDCARD Q OR A COLDCARD MK5. The setup finder does not offer them any more, they are gone from the quick picks on the hardware page, and every place they appear now carries the flag with the reasoning attached. AND WE DID NOT MOVE THEIR RATING, WHICH WILL LOOK LIKE A DODGE UNTIL YOU SEE WHY IT IS THE OPPOSITE. On 1 August we published a review that re-read the Coldcard against our own standard, gate by gate, and said in writing that nothing in it failed and that whatever we concluded would be published rather than quietly applied. That is still true. Every criterion still holds: the firmware cannot ship your keys anywhere, it is open enough to inspect and rebuild, it is Bitcoin-only, it is a minimal signer, your backup is a standard seed you can restore anywhere. If we now went back and marked it down, what we would really be publishing is a rating that bends to whatever happened in the news that week — and a standard that grows a new clause after each incident is not a standard, it is a list of past events. The rating is what our published rubric says about the hardware. The recommendation is what we would tell a friend. Those are different things, they have always been different things, and this is the week they came apart. So the site now says both at once, on the same card. WHY WE WOULD NOT TELL A FRIEND TO BUY ONE RIGHT NOW. The defect is fixed and a Coldcard bought today generates a proper seed; we are not implying otherwise. What we cannot get past is that a build-configuration error sat in the seed generator — the one function a signing device exists to perform — for five years, in source that anyone could read, at a company whose entire pitch is that you do not have to trust it. No audit found it. The reproducible builds did not find it, and could not: they guarantee the binary matches the source, and the source had the bug in it. We did not find it. An attacker did, and the first anyone knew was money leaving. Everything after that is a judgement about a company under conditions nobody outside it can see the end of, and we would rather say plainly that it is a judgement than dress it up as a finding. On a device whose whole job is to still be worth trusting in ten years, that is enough. WHAT IS ACTUALLY DOCUMENTED, because the numbers have moved every day and ours were behind. When we wrote the advisory the reported loss was about 594 BTC from roughly 500 wallets in the opening twenty-five minutes. That turned out to be the first wave rather than the total: further waves followed, and the running tally reported by Galaxy Research now stands near 1,816 BTC, around $116 million, across more than 5,200 addresses. Every tracker publishing a figure calls it preliminary. A class action against Coinkite has been publicly threatened and firms are soliciting claimants; as far as we can tell nothing has been filed. AND HERE IS WHAT WE ARE NOT SAYING. We have found no evidence that any government, regulator or police force is investigating, and we are not going to leave that sentence vague enough for you to read one into it. The investigating that has happened is technical. There are also claims going around that an AI tool found this bug before it was disclosed; we traced them to a single anonymous post made after it was already public, and we are not repeating them. IF YOU OWN ONE, NOTHING ABOUT TONIGHT CHANGES. Your device keeps its rating, we have kept its setup walkthrough, and the dice procedures it can perform are still there. Your exposure was never about the news — it is about your seed: when and where it was first generated, and whether you used your own dice or a passphrase. The advisory is where to check that, and it is the part of all this to act on. If your seed is in scope, migrate deliberately rather than tonight; a botched migration takes more coins than exploits do. If it is not, you own a capable signer and there is no emergency. The moment to weigh any of this is the next time you buy hardware. ONE UNCOMFORTABLE CONSEQUENCE WE ARE NOT GOING TO HIDE. Two of the four ways to put your own randomness into a seed — feeding dice straight into the device, and mixing your throws with its own — can only be done on Coinkite hardware. Nobody else has shipped it. So the strongest on-device forms of the very mitigation that protected people in this incident live on the brand we are now steering buyers away from, and there is no way to make that tidy. We have kept both procedures, because a great many readers own a Coldcard and this is exactly what they should be doing with it. What has changed is which one we point at by default: the printed-table method, where you choose every word yourself and the device generates nothing. It is the most work of the four by a distance and we are not pretending otherwise. It is the default because it is the strongest one that most devices can actually perform. The same goes for a strict air-gap: the only two devices in our cold tier that do it without qualification are these two, and the Jade Plus is the closest thing we can now point you at. WHEN WE WOULD CHANGE OUR MINDS. This is a position about uncertainty, so it should end when the uncertainty does — when the losses are finally counted, when the legal position resolves, and when there is a track record on the other side of it. If those land well the recommendation comes back, and we will say so as plainly as we said this.
- Security
Corrections: the Coldcard advisory left the Mk2 out of its own fix list, and a walkthrough claimed to be the only one of its kind
Two things we published were wrong, and both were wrong in the way that is hardest to catch — each page read perfectly well on its own. THE ADVISORY. Our Coldcard seed-generation advisory scopes the highest-risk group to seeds made on an Mk2 or an Mk3, which is right and matches Coinkite. The table below it, the one telling you which firmware version fixes your device, said only Mk3. So an Mk2 owner could read the paragraph that describes exactly their situation, look down for the version that fixes it, and not find their model on the list. Coinkite publishes those two as one row — Mk2/Mk3, version 4.2.0 or later — and now so do we. Nothing about the risk changed and no version number moved; what changed is that the fix list now names everyone the risk list names. We re-read the whole advisory against Coinkite's own page while fixing it, including the update they posted on 1 August, and everything else on ours matches: the affected ranges, both release tracks, the dice and passphrase exceptions. THE WALKTHROUGH. The BitBox02 setup page said its microSD backup default was "the one default on any device in this tier that we would tell you to change." It is not. The Trezor Safe pages tell you to change one too — the backup format, which by default is one only Trezor software can read. The BitBox02 default is still the more serious of the two, because it finishes setup without you having written anything down at all, and the page still says so as plainly as it did. What it no longer does is claim to be alone. We caught this by checking our own pages against each other rather than reading them one at a time, which is the only way a contradiction spread across two pages ever shows up.
- New
You can now see what setting the thing up actually looks like — a walkthrough for every device we rate for cold storage
Almost everything written about hardware wallets stops at which one to buy. The part that decides whether your Bitcoin survives happens twenty minutes later, on a screen the size of a postage stamp, in a room on your own — and until today this site did not show you a single one of those screens. There is now a walkthrough for each device we rate as built for cold storage, under Setting one up in the Hardware & services menu: the four screens that matter, drawn, with what each one is really for and what to do about it. THE PICTURES ARE DRAWINGS, NOT PHOTOGRAPHS OF YOUR DEVICE, AND WE WOULD RATHER SAY SO THAN HAVE YOU FIND OUT. Here is the honest trade. A photograph of a real menu is more reassuring when you are holding the device for the first time — you can match what is in your hand to what is on the page, and that is worth something we are giving up. What a photograph also does is go out of date the moment the maker moves a button, silently, with nothing on our side able to tell that it has happened. We would end up with an artifact that reads as current for years after it stopped being true, and no check we could ever write would catch it. So the screens here are drawn, in this site's own style, at the level of what the moment is for rather than which menu item it lives under. Your device will look different and say the same things. WHICH ALSO DECIDED WHAT THE DRAWINGS DO NOT TRY TO DO. They do not hold a copy of anybody's menus, and they never claim which order the screens come in — makers genuinely disagree about whether the PIN is set before your words or after them, and it does not matter. Every walkthrough links the maker's own setup guide alongside it, because their guide is the authority on what the button is called this month and ours is not. Read both: theirs tells you what it says, ours tells you what to do when it says it — and which of their own defaults to refuse, which their guide is never going to tell you. THE ORDER IS THE CHECKLIST'S ORDER, AND IT IS NOT OURS TO SHUFFLE. Every step names the checklist step it belongs to, and the site refuses to publish a walkthrough whose steps have wandered out of that order. That is not housekeeping. The single most expensive mistake available to anyone in that first hour is moving real money in before the backup has been restored from, because everything looks completely fine either way — so the step that almost no published guide includes, wipe the device and restore it from what you wrote, sits where it sits and cannot be quietly moved down the page. TWO DEVICES HAVE A DEFAULT WE WOULD TELL YOU TO REFUSE, and finding them is most of the argument for doing this per device rather than once. The BitBox02's standard setup never shows you your words at all: the backup goes onto the bundled memory card as a file, and setup finishes without you having written anything down. That is a digital copy of your keys, which is the one thing this course tells you never to make — BitBox publishes a separate no-card path, and that is the one to follow. Take the card as well if you want it, but not instead. And the Trezor Safe line offers a backup type at setup whose default is not the portable one: a twenty-word Trezor backup restores only in software that understands that format, while a plain seed restores anywhere. Unless you specifically want what the twenty-word version buys, take the plain one. WHY THESE DEVICES AND NOT ALL OF THEM. This covers the devices we rate as built for cold storage and stops there, deliberately. A step-by-step walkthrough is an endorsement wearing a diagram's clothes — it makes a device easier to follow onto — and doing that for hardware our own published standard says we would not put a decade of savings on would be arguing with ourselves in a format nobody reads as an argument. The two devices we rate for spending and the one that does not clear our bar are still covered in full on the hardware page, with the reasoning attached. They are simply not walked through.
- Specs
We had the Jade controls wrong, on two devices, and one of them disagreed with itself
Small, and worth owning because of how it was found. Our hardware page described both the Blockstream Jade and the Jade Plus as being driven by a joystick. Neither is. The original Jade has a selection wheel — a jog wheel on later units — and a button; the Jade Plus and the Jade Core have left and right selection buttons instead of a wheel. That comes from Blockstream's own firmware repository, which publishes its build targets one per board revision and says exactly this. Worse, the original Jade's own entry contradicted itself: the summary called it "one button + screen" while the note underneath it called it a joystick, on the same device, on the same page. HOW IT SURFACED. The new setup walkthroughs are built around how you actually drive each device — how you say yes, how you type — so every one of those descriptions had to be read against the maker rather than against ourselves. That is a standing rule here: a claim we sourced from somebody else gets re-read against their material, never against our own page, because ours is the copy that rots. It rotted. Corrected on both devices.
- New
The checklist comes off the screen — a printable sheet for each setup on the ladder
You can now print the self-custody checklist and work down it on paper, with the device in front of you and the browser shut. There are four sheets, and that is the whole design decision, so here is the reasoning. THERE IS NOT ONE SHEET, AND THERE WAS NEVER GOING TO BE. On screen the full list is honest, because the box above it says in so many words that it is everything that could matter to anyone, and the setup finder is one click away. Print it and both of those are gone. What you would be holding is a page telling you to use a different maker for each of your three keys when you have one key, and to back up a passphrase you do not have — with nothing on the paper to tell you which lines are not yours. We have made that mistake before, on the dice method sheet: one page that said "twenty-three words, or eleven for a twelve-word seed" and left every reader doing arithmetic to find their own half while holding key material. We split that sheet per seed length, and this is the same call. So there is a sheet for single-signature, one for single-signature plus a passphrase, one for multisig and one for collaborative custody, and nothing on any of them talks about a setup that is not yours. WHAT IS ON A SHEET. Every step that setup needs, in the order to do them, each with the reason underneath it, a box to tick, the numbered rule it is where it is one, and the address of the lesson behind it — printed as text, because a sheet gets carried away from the browser that could have followed a link. The order is the point and it is not alphabetical or convenient: your backup exists, and has restored a wallet in a real test, before any real money moves. Between nineteen and twenty-four steps depending on the rung, on two or three sides of paper. WHAT A PRINTED SHEET CANNOT KNOW, AND WHICH WAY WE RESOLVED IT. The version on the site trims itself further once it knows which hardware you already own and whether anyone else may one day have to recover your coins. Paper knows neither, so every one of those unknowns is resolved toward keeping the step: the sheet is the longest honest list for that setup, and it says so on its own front. A step you have already done costs you a glance. A step you never saw costs you whatever it was protecting. IF YOU HAVE A PLAN SAVED IN THIS BROWSER, the checklist page puts your sheet first and leaves the other three there, in case you want to see what a different rung would ask of you. If you do not, the page will point you at the finder — it takes a few minutes and the answer is which sheet to print. AND PRINT THE PDF RATHER THAN THE PAGE. A browser print depends on your own margins and on a background-graphics setting most people have never opened, and that last one would drop the tick boxes and leave you a wall of text. NEVER WRITE YOUR SEED WORDS ON THESE SHEETS. They are a list of things to do, not a place to record anything. Every sheet says so at the foot.
- Content
We put a watch on the privacy pages, and the first thing it caught was a date we had got wrong that morning
WHY THESE THREE PAGES NEEDED A WATCH AT ALL. Earlier today we published pages on PayJoin, Silent Payments and CoinJoin, and the reason we published them is that we had been wrong about two of the three for months. Neither sentence was wrong when it was written. Both quietly stopped being true, and nothing on our side noticed, because nothing on our side reads the world — we check that our prices match the shops and that our links still resolve, and neither of those has anything to say about whether a protocol moved. So the same thing was going to happen to the new pages. WHAT WE ADDED. Three standing checks that ask a different kind of question: not "does this link work" but "has the picture changed". One watches which wallets have shipped silent payments. One watches which wallets and payment servers have shipped the new PayJoin. One watches whether anything has reopened the legal question the Samourai case left undecided. They run on their own schedule — the wallet ones every couple of months, because that is roughly how fast wallets ship — and when one of them finds something, a person reads it and decides. Nothing on this site is ever changed by a machine. AND IT PAID FOR ITSELF ON THE FIRST RUN, which we did not expect and are not going to be quiet about. Checking our own silent-payments page against Sparrow's release notes rather than against ourselves, the date was wrong: we said Sparrow shipped sending in February 2026. It shipped sending in October 2025. What arrived in February was the ability to send from a hardware wallet — a real thing, and not the thing we said. The receiving date, May 2026, was right, and it is the one the page's argument actually rests on, because receiving to an airgapped signer is what lets a published address pay into cold storage. Both the page and this morning's entry below have been corrected. THE HONEST VERSION OF WHAT THIS MEANS. We got a date wrong on a page whose entire premise is that dates rot, on the day we published it, and we found it within hours only because we had just built the thing that goes and looks. That is the argument for the check, not against it. The pages now carry their dates cited to the release that carries them, so the next person to look — us or you — has something to compare against rather than a claim to take on trust.
- Content
The optional privacy tools get pages of their own — and we were behind on two of the three
PayJoin, Silent Payments and CoinJoin have been four paragraphs at the end of the node lesson since July. They now have a section of their own, under Privacy tools in the Learn menu: a page each, with what the thing actually does, what it cannot do, what it costs you, and what we would do about it. WHY THEY MOVED, AND IT IS NOT BECAUSE WE THINK THEY MATTER MORE. Two of the three changed materially during 2026, in ways that change the advice rather than decorating it, and neither change fits in a sentence at the end of a lesson about something else. The order they are presented in is the argument: cheapest first, not most interesting first. Ordering them by how much has been written about them would put the heaviest one at the top and quietly recommend it. WHAT WE HAD WRONG ABOUT PAYJOIN. We said the catch was that few sellers support it. That was true and it named the symptom rather than the cause — the reason so few did is that the original design needed the receiving side to run a server and be awake at the moment of payment, which almost nobody was going to do. A replacement design was merged in 2025 that removes both requirements: the two wallets pass the half-built transaction through a directory that cannot read it, so neither side hosts anything and neither has to be online at the same time. The first commercial wallet shipped it in 2026. Our sentence was written for a world that had already changed. WHAT WE MISSED ABOUT SILENT PAYMENTS, AND IT IS THE ONE THAT MATTERS MOST HERE. We said support was a growing but still small handful of wallets. Also true, and it left out the fact that changes who this is for: Sparrow shipped sending in October 2025, and in May 2026 it shipped receiving — including with an airgapped hardware wallet holding the keys. That means an address you publish in public can pay straight into cold storage, with no hot wallet standing in the middle. On a guide whose whole course argues for cold storage, that is not a footnote about wallet support. It is the difference between a tool we would mention and a tool we would point a savings holder at. WHAT WE LEFT HANGING ABOUT COINJOIN. We told you that in 2024 US authorities charged the developers of one of these tools, and that the legal picture had grown uncertain. We never came back to say how it ended: both pleaded guilty in July 2025 to running an unlicensed money-transmitting business and were sentenced that November. The question the case would have settled — whether writing and running a tool that never holds anyone's coins can itself be the offence — was never argued, because the pleas ended the case first. So the picture is not less uncertain than we said. It is uncertain in a more specific way, and a reader deciding about this deserves the specific version. AND OUR ANSWER ON COINJOIN IS STILL NO, FOR MOST PEOPLE. It works. It is also the only thing on this site that demands an ongoing practice rather than a setting, and a practice half-kept is worse than not starting: you will have paid the fees, taken the permanent mark on the coins, and undone the benefit the first time you spend one of them alongside an ordinary coin without thinking. The page says which readers it is genuinely for, says plainly that we are not lawyers, and gives you the record rather than a verdict. THE PRIVACY LESSON HAS ALSO STOPPED LEAVING A HOLE. It has always said never to post a fixed public address — good advice with an obvious gap in it, because some people genuinely need one: a creator taking tips, a business taking payments. It now says so, and points at the answer. NOTHING HERE IS PART OF THE COURSE, and the pages say that at the top and the bottom. The two habits that do most of the privacy work are still free, still in the lesson, and still worth more than everything on these three pages put together: a fresh receiving address every single time, and never being publicly known as a holder. There is also a short list on the hub of what none of these tools fix — chiefly that every one of them protects you going forward and none of them reaches backwards. THREE NEW DIAGRAMS came with them, and were measured rather than looked at, the same way the rest of them were last week.
- Content
One of our diagrams was drawing the wrong thing — and now all seven are measured, not eyeballed
THE PASSPHRASE DIAGRAM WAS BROKEN IN TWO WAYS AT ONCE, and the first was not cosmetic. It is the picture on the ladder page for the second rung: one set of seed words opens a small decoy wallet on their own, and the same words plus your passphrase open the hidden real one. The branch labelled "+ passphrase" left the seed words, curved downwards, and then simply stopped in mid-air. A second, separate arrow began further along the same line and pointed into the real wallet, with a gap between the two. Read as a diagram — which is the only way a diagram is read — the passphrase sat outside the chain it is the whole subject of, and nothing on the page connected your words to the wallet they open. It is one fork now, two branches, each leaving the words and each arriving with its own arrowhead: the plain branch into the decoy, the passphrase branch into the real one. A picture that teaches a mechanism has to be right about that mechanism the way a sentence does. AND THE REAL WALLET COULD NOT HOLD ITS OWN LABEL. "hidden · your savings" ran four pixels past the box on both sides, so the words describing that wallet were printed across its border. It fits now, with room either side. WE THEN MEASURED ALL SEVEN INSTEAD OF LOOKING AT THEM. This site has a standing rule that a printed or drawn artifact is checked by measuring the render rather than by looking at it, because the eye has been wrong on this project's artwork in both directions before — and these diagrams had never had that treatment. Every label is now checked against the box it sits in, and every connecting line against whatever it is supposed to join, in a real browser at real font sizes. That check finds both of the faults above on the old drawing, which is the only reason to trust it on the others. THREE MORE CAME OUT OF IT, all small and all real: the words box on the keys lesson had its "write these down — they ARE your Bitcoin" line pressed flat against the bottom border; the Shamir share boxes held their labels with almost no room either side; and the hot-and-cold spectrum bar ran out past the circles at both ends, so it read as cut off rather than drawn between them. Nothing any of these diagrams teaches has changed. [ADDED LATER THE SAME DAY: and two of them were saying the same thing twice. The Shamir diagram had "Any 3 of 5 rebuild the seed — two or fewer reveal nothing" printed inside the picture, directly above a caption reading "Any three of the five shares rebuild the seed. Any two reveal nothing at all" — one sentence, twice, stacked. The signing diagram did the same thing with the second half of its own caption. Two renderings of one idea on one screen is the failure this site keeps finding in its own pages, and there was no reason to keep it in the artwork either. The caption is the one that stays; the drawings are shorter for it.]
- Content
The two longest lessons get a map, and the metal numbers stop being approximations
Four small things, and the first is the one you will notice. THE LADDER AND THE KEYS LESSON NOW HAVE AN "ON THIS PAGE" RAIL on wide screens — the same one the other lessons have had. The ladder is far and away the longest thing on this site, and it is long on purpose: all four setups sit on one page so you can read what rung 2 costs you against what rung 3 buys you without holding one of them in your head across a scroll. That is the whole reason the four separate rung pages were merged into it. What was missing was never brevity, it was a way to see where you are — four rung sections, all of them individually linkable, and nothing on screen telling you they existed. Now there is. WE ALSO STOPPED KEEPING FOUR COPIES OF THAT RAIL. It was written separately into each page that had one, and the copies had already drifted apart in small ways — one used a different colour for its numbers. There is one of it now. THE HOT AND COLD LESSON PUTS YOUR IDEA BEFORE OUR ANSWER. The section on how much belongs at each temperature gave our recommendation and then, underneath it, walked through the arrangements people reach for instead — one cold wallet for everything, a phone wallet for savings because it is non-custodial, an old laptop kept offline. Those are the ideas a reader arrives with, and meeting them after the verdict reads as us marking our own homework. They come first now. THE METAL BACKUP FIGURES ARE COMPUTED, NOT WRITTEN OUT. The backup lesson said "three quarters" of tested plates came through clean and "about one in eight" did badly. Both were fair roundings of Jameson Lopp's published results, and both were typed by hand next to a comment asking whoever edited next to re-sync them. That guard has already failed once on this exact pair — an earlier version of the page said roughly half fail, against a table where three quarters passed, wrong by four times on a safety-critical page and wrong in the direction that makes people more anxious than the evidence warrants. The lesson now reads the numbers straight off the same data the metal-backups page uses: 56 of 75 came through everything, 10 did badly. When the next round of testing lands, both pages move together or neither does. AND "COIN CONTROL" IS IN THE GLOSSARY. Two lessons used the term and explained it in passing; the glossary, which is where you go when a word goes past you, did not have it.
- New
The setup finder had two engines inside it. Now it has one
Nothing about your result changes today, and this is here anyway, because for a while the site carried two separate pieces of code that could each explain the same recommendation to you — in wordings that had drifted apart. THE HISTORY, PLAINLY. On 31 July the finder was rebuilt as a scored risk assessment. The new engine decided WHAT to recommend from the start, but the card you actually read was still built by the old one, which had to be handed a set of answers nobody gave in order to produce it. That is where the defect we owned on 1 August came from: a card telling a reader "because your worry is being targeted or coerced" a few lines under their own profile reading that risk as low. The card builder was rewritten then, and since 3 August every word on your result has come from one place. WHAT WAS STILL WRONG UNTIL TODAY. The old engine stayed in the codebase, unused by the site but still carrying its own copies of the same explanations — the passphrase decoy, the multisig trade, the step-up advice — and those copies had drifted from the live ones. Nothing rendered them any more, so nobody would have caught them going further out of date. Two versions of the same explanation is the failure this site keeps finding in its own pages, and there is no reason to hold it in the code either. It is deleted. WHAT WE KEPT ON PURPOSE. If you saved a plan before 31 July, it holds an answer to a question the finder no longer asks — the one that had you rank your worries. The translation that turns that old answer into today's scores is untouched, and the test that proves it still works got stronger rather than weaker: it now checks all 3,240 old answer shapes produce a complete result, which is the check that actually protects anyone with a plan sitting in their browser from last month. The five questions themselves moved to a file of their own, so a page that only wants to tell you what the finder is no longer has to load the whole scoring engine to say it.
- New
The knowledge check comes off pilot — every rule now has one
Since 30 July two lessons ended with a couple of questions on what you had just read. That was a pilot, and it is over: all twelve rules now carry a check, so every lesson that teaches one ends with two questions and a short explanation when you miss one. NOTHING ABOUT THE PROMISE CHANGES. Nothing is scored, saved, or sent anywhere — not to your plan, not to this browser's storage, not to us. There is no request to make and nothing to leak; close the tab and it is gone, and reloading the page is how you clear it. A wrong answer is learning, not a deliberate action, and filing it would put the "nothing is sent, stored or logged" promise elsewhere on this site back in question. WHAT THE QUESTIONS ARE FOR. Not an exam — a check that the lesson landed. Every distractor is a plausible half-truth people actually hold, because being told why the reasonable-sounding answer fails is the part worth reading: a phone wallet where you hold the keys is genuinely non-custodial and still is not cold storage; splitting your seed words across two houses feels like halving the risk and doubles the ways to lose the lot; reading your written words back against the device tests your handwriting rather than your wallet. The explanation only appears when you get one wrong. Answer correctly and it stays folded away — you already have the point, and printing it anyway trains people to stop reading them. THE EXPLANATIONS SEND YOU NOWHERE. They teach in place, in full, with no links out and no mention of material further along the course. That is the same rule the rest of the course runs on: on this site, links point backwards. A CHECK BELONGS TO A RULE, NOT TO A PAGE. Each one is filed against the rule it tests rather than the lesson's address, so if a rule ever moves to a different lesson its check moves with it instead of being stranded on the old page. AND SHIPPING THEM EXPOSED A COUNTING BUG WE COULD NOT HAVE SEEN BEFORE. One lesson — privacy — teaches two rules, so it now carries two sets. It numbered each set from one and printed "1 2 1 2" beneath a heading saying four questions, as though you had met two checks rather than one. Fixed, and it could only ever have shown up on the day the second set existed.
- Content
A full site audit — and the contradictions two weeks of restructuring left behind
The course was rebuilt heavily over the last two weeks — lessons merged, split, renamed, re-levelled, and a whole level removed. We then audited the entire site along six lines (consistency, teaching order, redundancy, fidelity to our own stated principles, readability, and structure) and fixed what the churn had broken. The ones worth owning by name: THE LADDER CONTRADICTED THE TESTING LESSON. Rung 2 told passphrase users to prove their setup by restoring "on other software — a second wallet", while the testing lesson says restoring a live seed into a wallet app on a phone or laptop is the one thing this guide asks you never to do. It now says what it always meant: a second hardware device, ideally another maker's. THE LAST LESSON STILL THOUGHT IT WAS OPTIONAL. Running your own node became the course finale on 1 August — it is the umbrella rule in its fullest form — but its prose still called itself "completely optional", "a bonus, not a requirement", five times over, leftovers from the removed level it used to live in. The honest split is now stated once and kept: the machine is optional, the habit of verifying is not. TWO OLD ADDRESSES SENT YOU TO THE WRONG PAGE. /how-to/hot-vs-cold pointed at the keys lesson although the hot-and-cold material has its own page again, and the old ladder Shamir address dropped you on a bare demo instead of the lesson that now teaches it. Both retargeted. TWO NUMBERS DISAGREED WITH THEMSELVES. One lesson said 11–25% of all Bitcoin is lost while our methodology page — the sourced one — says 11–23%; and the 2020 Ledger breach was "roughly 270,000 customers" on one page and "around a million" on another. Both figures are real and they measure different things: about a million email addresses leaked, with names, home addresses and phone numbers for roughly 270,000 of them. Every page now says which it means. A PROMISE THAT BROKE ONE CLICK LATER. Lesson 1 said "every lesson after this one is a single rule, in full" — and the very next lesson carries no rule. The true promise runs the other way and is now the one made: every rule has a lesson that teaches it in full. AND THE PHISHING LESSON OVERCLAIMED. It called phishing the most common way people LOSE Bitcoin, which contradicts our own rule 1 — you are the main risk. It is the most common way Bitcoin is STOLEN, and now says so. A pile of smaller repairs shipped alongside: material the merges left taught twice (coin control, the memorised-passphrase trap, the device-is-not-your-wallet idea) is now taught once and pointed to elsewhere; the Learn menu stopped reserving a fifth column for a removed level and the footer stopped cramming six columns into five; three hand-written lessons gained the knowledge-check slot the template pages already had; the syllabus page's loudest button now starts the course instead of skipping past it; "about an hour end to end" became the honest "a couple of hours"; the demos hub lists its demonstrations in the order the course meets each idea; and every "last verified" stamp that predated its own page's newest material was bumped, which is what those stamps are for.
- Content
"Watch a seed get born" moved to the lesson about how a seed is made
Where it should have been. That demo builds a seed in front of you — 128 random bits, hashed, a checksum bolted on, cut into twelve chunks, turned into words, and finally into your first receive address. The lesson called "How a seed is made" opens with exactly those steps written out in prose. The demo was on the previous lesson instead, which talks about what a key IS, so a reader could finish the three steps and find a different demo underneath them. It now sits directly below the list it animates. WHAT MOVED WHERE. The seed lesson now has two: the seed being built, under the steps that describe it, and the checksum demo further down, under the paragraph about a wrong word passing silently. The keys lesson keeps the one that suits it best — the demonstration of why a key cannot be guessed, under the sentence that says hold the key, hold the coins — and still points at the seed demo where it used to sit. Nothing was removed from the site: every demo still has its own page, and none of them changed.
- Content
A correction to this morning's correction — and the reroll button moved
Two small things on the checksum demo, one of which is us correcting ourselves twice in a day. WE IMPLIED MORE WAS NEW THAN ACTUALLY WAS. This morning's entry said the demo "now says" both that roughly one wrong phrase in sixteen still passes, and that the demo stacks the deck in its own favour. The second was genuinely new. The first was not: a line near the bottom of that page had said all along that the checksum catches about fifteen of every sixteen single-word slips, that it is not a guarantee, and that you should verify a backup by test-restoring it. All true, and all already there. What was actually wrong was narrower than we made it sound — the demo's opening promised more than that line delivered, and the line itself sat in faint small type at the foot of the page while the promise was in the first paragraph. A caveat nobody reads is a weak caveat, not an absent one, and we should have said so precisely. The earlier entry now carries that note rather than being quietly rewritten. AND WE THEN SAID IT TWICE. Our fix added a second, louder caveat without noticing the first, so for part of today the page made the same point in two places. There is one now, and it is the prominent one. THE "NEW SEED" BUTTON MOVED UP. It was at the very bottom, below both explanatory boxes, so rolling a fresh phrase meant scrolling past the whole explanation to find it — and our own change had pushed it further away. It now sits directly under the words it replaces, where you would reach for it.
- New
The checksum demo now runs inside the lesson that explains it
A fourth demo joins the three that went inline earlier today. The seed lesson is the only page on this site that explains the checksum — the few extra bits tucked into your last word that let a wallet notice when one word is wrong — and it now lets you watch that happen without leaving the lesson: generate a throwaway phrase, tap a word to miscopy it, watch the wallet refuse it. WHY HERE AND NOT ON "TESTING A BACKUP", which is where the word "typo" would have suggested. That lesson never mentions the checksum at all; it is about rehearsing a restore. A demo belongs where its mechanism is taught, not where its subject sounds like it fits. AND IT BRINGS THE CAVEAT WITH IT. The correction we published earlier today — that roughly one wrong phrase in sixteen still passes the check silently, opening a different empty wallet — is part of the demo now, not something the page around it happens to say. So a lesson can never end up showing you the reassuring half on its own. /demos/typo is unchanged and still its own page; the lesson and the demo page render the same thing rather than two copies of it.
- Content
Four demos were telling you a more comforting story than the lessons — corrected
We checked every interactive demo against the lesson that teaches the same thing, and four of them were quietly reassuring in a way the lessons are not. Each is now fixed, and we are naming all four rather than tidying them up quietly, because in every case the comforting version gives you LESS reason to do the one thing this guide cares most about: testing your backup. (1) THE TYPO DEMO said a wallet "refuses the whole phrase" if you copy a word wrong. Most of the time it does. But roughly one wrong twelve-word phrase in sixteen still adds up — the check passes, no error appears, and a real, perfectly ordinary, empty wallet opens instead of yours, with nothing to tell you it is the wrong one. The demo also stacks the deck: it always swaps in a word that breaks the maths, so the catch happens every time. It now says both of those things, on the page, under the demo. [NOTE, added later the same day: the one-in-sixteen half was already on that page, in a small line at the foot of it; what was new was the stacking, and moving the caveat somewhere it would actually be read. See the later entry.] (2) "WHY A KEY CAN'T BE GUESSED" said every real-world loss comes from the human side, "never from someone cracking the math". The maths has never been broken and that page is the reason why — but a key is only as unguessable as the randomness behind it, and when a device has produced seeds from far less randomness than it should, those keys have sat in a space small enough to search and coins have been taken. There is a live advisory about exactly that on this site. The keyspace was never the weak part; where the number came from was. (3) THE SEED DEMO said the same words always rebuild the same wallet. True of the words alone — but add a passphrase and the same words rebuild a DIFFERENT wallet, silently. If you ever add one, it is part of your backup too. (4) THE PASSPHRASE DEMO offers "pizza", "correct horse" and "moon 2024" to try. Those are short so you can read them at a glance — and they are precisely the shapes we tell you elsewhere never to use: a real word, real words in order, a word and a date. They are now labelled as the deliberately weak examples they are. NONE OF THESE WAS ON A LESSON PAGE; all four were on the demos themselves, which is where we looked last.
- Devices
The Jade Core finally has its picture
It was the one device in the comparison shipping without an illustration — carried since 31 July on the strength of its specs while the drawing waited. All twelve now have one, drawn in the same line-art style as the rest and inverting cleanly in dark mode. Cosmetic, and mentioned only because the missing picture is on this log already: it caused a real bug in early August, when the code that works out which of your wallets is which walked the list in order, reached the device with no image, and gave up — silently switching off the personalised parts of your plan and checklist for every device after it. That was fixed at the time by making the picture optional rather than assumed. It stays optional, because a device should be able to ship the moment we have judged it, not the moment we have drawn it.
- New
Three of the demos now run inside the lesson that talks about them
You no longer have to leave a lesson to try the thing it just explained. THE KEYS LESSON says a Bitcoin key cannot be guessed, and now shows you: generate a random key and watch a counter run against 2²⁵⁶ while every atom in the Earth fails to make a dent. A section later it says your seed words ARE that key, and the seed demo builds one in front of you, seven steps from raw randomness to your first address. THE BEYOND-THE-LADDER LESSON explains Shamir backups — cut a secret into five pieces where any three rebuild it and any two reveal nothing — and now lets you drop a share and watch the value mask itself. That last one is the claim people most often disbelieve, and reading it is not the same as doing it. THE DEMOS DID NOT MOVE. Every one still has its own page, still in the Tools & demos menu, still linkable and shareable on its own. These are not copies — the lesson and the demo page render the same component, so they cannot drift into two versions of one demonstration, which is a mistake this guide has made before with a printed table. WHAT IT COSTS YOU: the keys lesson is about a tenth longer before you touch anything, and the safety warning that belongs with a demo travels with it, so a lesson can never end up showing you a seed generator without the "never your real seed" note attached. The heavy cryptography still only loads when you press the button. THE OTHER EIGHT DEMOS STAY WHERE THEY ARE for now — several are simply too tall to sit inside a lesson without burying it, and one lesson is already seventeen screens long. We measured all of them rather than guessing.
- Content
The lessons stop trying to send you somewhere
Five lessons ended by handing you a button — find your setup, go compare devices, buy a plate, start the procedure. They are gone, and no lesson in the course links to a take-action page any more. WHY, PLAINLY: this is a seventeen-lesson course, those buttons sat at lessons three, six, eight, nine and ten, and every one of them offered you a decision at the point you had the least context for making it. Taking one meant leaving the course at exactly the moment the material starts paying off. That is our fault for putting it there, not yours for clicking it. WHAT YOU GET INSTEAD. Each of those lessons now ends with a short note saying what you have just learned, that you are in the course and the course teaches rather than sets things up for you, and where the doing lives — named by its menu: "it is in the Hardware & services menu, under Metal backups." Two seconds of navigation, and you go when you decide to go rather than when we ask. That location is read from the menu itself, so if a menu entry is ever renamed the sentence renames with it, and the build refuses if a lesson ever points at a menu entry that does not exist. WHAT WE KEPT. Links back to earlier lessons, the glossary, and the interactive demos — those are limited, self-contained, and they hand you back where you were. And the Coldcard security advisory stays linked from the seed lesson: that is a warning, not a thing to go and do, and losing a safety path for the sake of a tidy rule serves nobody. NOTHING WAS DELETED. Every page those buttons pointed at is still there, still in the menu, and still one click away whenever you want it.
- New
"Has your situation changed?" now asks people who have been away a while
Your plan page carries a tool that re-places you on the ladder — it asks a few honest questions and tells you whether to climb, which for most people is no. It only ever appeared for a plan that had ARRIVED from somewhere else: imported from a file, or restored from your own Nostr. That gate exists for a good reason. Asking "has your situation changed?" ninety seconds after you finished the finder implies something might have, and nothing has. BUT IT MEANT THE ONE READER MOST LIKELY TO SAY YES NEVER SAW IT. If you built your plan in this browser and came back a year later, the question never got put to you — even though a year is exactly when holdings have grown, families have changed, and the thing that worried you then is not what worries you now. It now appears after six months as well, with a line saying why it is asking. WHAT SIX MONTHS IS MEASURED FROM, because it is not what you would guess. Not the last time you touched the plan — ticking one checklist box would have made a two-year-old plan look brand new. It is measured from when you last SETTLED ON A SETUP, which is the decision the tool exists to revisit. If you look at it again and stand by your answer, that counts as deciding it, and the clock starts over. Plans made before today have no record of that moment, so they fall back to the last time they were saved — which can only make the question arrive later than it should, never earlier.
- New
The two things that matter most are now the two you can change — and one of their labels was meaningless
On the risk-picture screen you can nudge any of the four risk bars if our arithmetic does not match how you honestly see your own life. Two rows sat there read-only: how much would be riding on this, and how you feel about a company ever holding a key. THOSE TWO CARRY MORE WEIGHT THAN ANYTHING ELSE ON THE SCREEN, which made them the worst two to leave fixed. You can change both now, without starting over — and because they came from questions rather than from the assessment, you change them by re-answering, with the original options right there. AND CHANGING THE STAKES ANSWER MOVES EVERYTHING, ON PURPOSE. It is not just a row: it sets what "typical" means for every other bar above it. So the screen rebuilds when you change it, and you can watch the rest of your picture move with it. Letting you nudge that one bar while leaving the rest measured against your old answer would have given you two versions of the same fact on one screen, one of them quietly out of date. WHILE BUILDING IT WE FOUND A LABEL THAT COULD NEVER HAVE BEEN RIGHT, and it had been on your result since we built that screen. Those two rows carried a level — low, typical, elevated, high — like the four risk bars do. But their score IS their baseline, by construction, so the word could only ever read "typical", for every reader, forever. It looked like a judgement about you and contained no information at all. They now show your own answer back to you instead — "life-changing", "no third party" — which is both true and worth reading. The four real risk bars are unchanged.
- New
Your result now names what worries you — and lets you say we got it wrong
The assessment works out which risk you are most exposed to, and until now it never said so out loud. It does now, at the top of your result, with where it came from written on its face: "from your answers, the one you are most exposed to is..." — and four buttons to change it if that is not how it feels to you. WHY THIS IS NOT JUST THE OLD QUESTION BACK. The finder used to open by asking what worried you most, in one tap, before you had been shown anything — and that single answer largely decided your setup. We replaced it with the assessment for good reason: an answer given cold is a guess, and evidence you tick off about your own life is not. But an assessment can only see what it thought to ask, and you know things it did not. So the derived answer is offered as a first draft rather than a verdict, exactly like every other claim on this site. WHAT CHANGING IT ACTUALLY DOES. It moves the model, not the wording. Pick a different one and we raise it above the typical holder's picture, leave everything you told us where it was, and rebuild the whole result — the bars, the reasons, the trade-offs, both cards. Nothing you ticked is discarded; your word is added to the evidence rather than replacing it. And if the setup we recommend is weak on the thing you just named, the result says so in its own paragraph instead of quietly recommending it anyway. IF NOTHING IN YOUR ANSWERS STANDS OUT, WE SAY THAT TOO, rather than dressing up a rounding difference as a finding — and we tell you which one catches most people, which is where the guide starts if you have nothing else to go on. You can always put it back to what your answers said; the button to do that appears as soon as you have changed anything.
- New
The interactive demos moved to a simpler address
They live at /demos now instead of /deep-dive. NOTHING ABOUT THEM CHANGED — same eleven demonstrations, same real cryptography running on throwaway keys in your own browser, same links from the lessons. Only the address in your bar is different, and every old link still works: a bookmark, a shared link, or an entry further down this log will take you straight to the same page. WHY BOTHER. "Deep dive" was the retired address of a retired idea: the demos used to sit inside course level 201, "Under the hood", which we removed at the start of the month — running a node became the last lesson of the long-haul level, and the demos stopped pretending to be a chapter you had to complete. [Corrected 2026-08-04: this entry originally called the removed level "Deep dive"; that was its URL, not its name.] The menu has said "Interactive demos" ever since, so the only place the retired name survived was the address bar and a handful of "deeper dive" links inside the lessons. Two names for one thing is how a guide starts contradicting itself, and this one was ours rather than yours. The lesson links now say "See it work" and point at a demo, which is what they do.
- New
The word-table page was still handing you all eight sheets at once
A reader reported this and they were right. There are two doors onto the dice procedure, and until now they gave you different answers about what to print. THE TOOL PAGE offered three separate documents — a 24-word seed, a 12-word seed, or just the table — which is what you actually want, because you are doing one of those things and not all of them. THE WORD-TABLE PAGE still offered the old pair: a Print button that sent every sheet the page holds to your printer (both lengths' instructions, both worksheets, and the four table pages) and a single combined PDF that was the same everything-at-once bundle. So the same reader met two different answers depending on which link they had followed, and one of them wasted paper on instructions for a seed length they were not making. BOTH PAGES NOW OFFER THE SAME THREE DOCUMENTS, from one list, so they cannot drift apart again — and the page count beside each one is now read from the file itself rather than typed, because those counts move when the print layout changes and a typed number would quietly go wrong. The old combined PDF still works if you have it bookmarked or printed; nothing on the site points at it any more. Nothing about the table or the method changed, and a print-out you already made is still correct.
- Content
Every lesson now shows its working — and one of them was contradicting itself
A sweep of the whole course against a standard we set for ourselves earlier today: a teaching page owes you how the thing works, then what is actually possible with it — including the options we advise against — and only then what we recommend. Handing you a rule with the mechanism left out asks for exactly the trust this site tells you not to extend to anyone else. WHAT CHANGED, PAGE BY PAGE. The ladder had four rungs and only one of them explained itself, so the other three now do: what a single key actually is (your coins are not in the device, and every backup rule you have ever been given falls out of that one fact), how several keys become one wallet (the rule tying them together lives outside all of them, which is why a multisig has one thing to keep safe AND one thing to keep findable), and what a collaborative third key can and cannot do. The seed lesson was telling you how to choose where your randomness comes from without ever telling you how a seed is built, so it now opens on the three steps — and on why exactly 8 of the 2,048 words can be the last word of a 24-word seed, which is not a rule anyone chose. Testing a backup, backing one up, phishing, and the Recovery Kit each gained the part that was missing: the things people do instead, and where each one quietly fails. AND A CORRECTION WE OWE YOU PLAINLY. Our glossary said a passphrase was "an extra secret word you add on top of your seed phrase," and four other pages said something similar — that you "choose" one. Both halves are wrong. It is not a word (any string of any length works, which is why there is no such thing as a wrong-passphrase error), and it should be rolled off the dice table rather than thought up, which is what we started telling people yesterday on one page while five others still said otherwise. Fixed everywhere, and our claim-checking script gained a passphrase-construction sweep so the next change to this subject cannot land on one page and miss the rest.
- Content
The premise this whole guide rests on, said out loud on the front page
We have been running on a conviction we never actually wrote down, and the recent hardware-wallet failure is what made it worth stating. HERE IT IS: SECURITY IS SOMETHING YOU LEARN AND PRACTISE, AND THERE IS NOTHING YOU CAN BUY THAT DOES IT FOR YOU. No device, no service and no clever arrangement is safe on its own. What actually keeps Bitcoin is a person who understands their own setup and has rehearsed it at least once. That is why this site is a course before it is a set of tools, why every recommendation shows its working instead of just landing on you, and why testing a backup is a whole lesson here rather than a line at the end of one. AND IT IS WHY OUR ADVICE LEANS THE WAY IT DOES, which we would rather you understood than simply accepted. Attacks only ever get cheaper and better, and they are now being automated faster than the guidance warning people about them. A shortcut that is merely risky today is the one found at scale tomorrow. Anything standing on convenience, obscurity or plain good luck is on a clock. So the question we ask of a recommendation is not "is this safe right now" — it is "is this still standing in ten years, operated by a real person having a bad week." THE TWO RULES YOU ALREADY SEE US APPLY ARE THAT CONVICTION AS ARITHMETIC. Choose the simplest setup that covers you, then lean one step past it; and above the smallest stakes, never leave anything whose single failure takes everything. Neither of those is caution for its own sake and neither is us being dramatic. They are what falls out of believing that the failures which reach you are the ones nobody modelled, and that the only general defence against a threat you did not imagine is not having a component whose failure is total. It is on the front page as the first thing we say about ourselves, and on the about page in full.
- Content
The course levels and lesson titles now describe the material instead of talking at you
A naming pass across the whole syllabus, and the reason is the same one behind renaming level 102 earlier today. LEVEL 102 IS "WALLET CONFIGURATION" and LEVEL 103 IS "PRIVATE KEY CREATION". 102 teaches what the arrangements are — hot and cold, the four rungs of the ladder, how to pick a device — so it is named for the subject rather than for you. 103 is where the keys themselves come into existence: made, backed up, proven, and used for the first time. "The build" was vague about which build it meant. AND THE LESSON TITLES STOPPED GIVING YOU ORDERS. Nine of the seventeen either said "your" or were phrased as instructions — "Back up your seed phrase", "Test your backup", "Send Bitcoin safely", "Build the Recovery Kit". A title should say what the lesson is about, not tell you what to do before you have read it; that is what the checklist is for. They are now "Backing up a seed phrase", "Testing a backup", "Sending Bitcoin safely", "Building a Recovery Kit", "Generating a seed", "Choosing a hardware wallet", "Running your own node", and "Hot and cold — where savings belong". Two keep their wording on purpose: "Not your keys, not your coins" is the saying itself, and running your own node is what the practice is actually called. NO PAGE MOVED AND NO LINK BROKE — every address is exactly what it was, so a bookmark or a link someone sent you still lands where it did. WHAT WE FOUND WHILE DOING IT, since we would rather say: this site kept lesson titles in two separate files and they had already drifted apart — the syllabus said "Back up your seed phrase" while the lesson page called itself "Back up your seed", and the syllabus said "Run your own node" against the page's "Run a node". They are one set now. And twelve of our rules name, in plain text, the lesson that explains them — deliberately as text rather than a link, because the rules page sends nobody forward through the course. That means nothing could ever catch those names going stale, and a rename of this size would have left all twelve quietly pointing at titles that no longer existed. The site now refuses to build if a rule names a lesson title the curriculum disagrees with, the same way it already refused if a rule named the wrong level.
- Content
We told collaborative-custody readers that one brand could only cost them one key
A correction, and it was wrong in the direction that made the risk sound smaller than it is. Your checklist has always carried a step telling you to use hardware from different makers, and its wording was written for do-it-yourself multisig: "three identical devices share one point of failure — different makers means a problem with one brand can only ever cost you one key." That is true when all three keys are yours. It is not true for collaborative custody, and collaborative readers were being shown it anyway. IN A COLLABORATIVE SETUP YOU HOLD TWO OF THE THREE KEYS, AND TWO IS ENOUGH TO SPEND. So if both of your devices come from the same maker, one flaw in that one brand does not cost you a key — it reaches a spending quorum by itself, and the service's key never comes into it. The step is now two steps, one for each setup, and each states its own arithmetic. Our plan page had this right the whole time, which is the uncomfortable part: two pages of ours, one subject, and each of them internally consistent. AND THE ADVICE IS NOW A CHECK. "Use a different maker for each key" appeared on four surfaces of this site and was enforced on none, so you could fill in every slot of your plan from one brand and be told "✓ Every slot is filled" — a completeness tick sitting over a setup that defends against nothing it was built for. Your plan now works out whether one maker is holding enough of your keys to spend, and says so by name, even when every individual device clears our bar. A multisig built from three of the same device is not the setup you think you bought.
- Content
We tested a seventh risk for the setup finder, and decided not to add it
This one is a decision to publish rather than a change to use, and we think the reasoning is worth more than the outcome. WE ALMOST ADDED "THE DEVICE YOU BOUGHT IS QUIETLY BROKEN." It is not hypothetical — a hardware wallet we rate shipped a seed generator that produced predictable seeds, people lost coins, and it is why this site carries a standing advisory. It is a real way to lose Bitcoin and it plainly belongs somewhere. So before writing a word of the copy, we ran it through the engine as though it were live, across every combination of answers the finder can produce, to see what it would actually change. IT GOT QUIETER AS THE STAKES GOT HIGHER, WHICH IS BACKWARDS. Turned all the way up it moved the recommendation for roughly half of readers holding Bitcoin they are learning with, one in five with meaningful money at risk, fewer than two in a hundred at serious stakes, and not one single reader where losing it would change their life. It was loudest for exactly the people we have decided on purpose not to push into buying three hardware wallets, and silent for everyone else — because our floor for money that would hurt to lose had already moved them. A SECOND PROBLEM MADE IT WORSE. Every risk on our methodology page starts from a published base rate, so a seventh one would have quietly re-weighted the answer for readers who never opened that section at all. The only version that left them alone was one with a base rate of zero, and a concern with no base rate is not a concern — it is a thumb on the scale wearing a label. SO WE DID SOMETHING ELSE INSTEAD, and it is the part that will actually help you. The defence against a broken device is not a different rung of the ladder; it is not having a component whose failure is total, which is already the floor we hold you to. What it really argues for is a property of how you BUILD your setup — keys from more than one maker, and randomness that did not come only from the device — and both of those are now checked on your plan and spelled out on your checklist rather than being scored on a bar. We are publishing this because a finding that says "do not build it" is worth as much as one that says build it, and because a method you cannot watch us change our minds inside is not a method.
- Content
How to actually build a passphrase — which we had never told you
A real gap, and one we made worse ourselves. This guide has told readers to "choose your passphrase carefully" and warned that "a weak or guessable one is almost as bad as none" since the day rung 2 was written, and it has never once said how to meet that standard. Then last month we made a passphrase our FLOOR for money whose loss would hurt — we now send people there on purpose — which turned a missing paragraph into a floor we had built ourselves and not finished. THE ONE THING THAT MATTERS: GENERATE IT, DO NOT INVENT IT. A passphrase you thought of is worth a small fraction of the strength it feels like, because the part that makes it memorable — real words in a sensible order, a name, a date, a substitution you thought was clever — is the first thing a cracking rig models. And there is nothing to slow that rig down: BIP-39 stretches your passphrase with only 2,048 rounds of hashing, a number frozen into the standard and thin by any modern measure, so someone holding your seed backup can test guesses offline as fast as their hardware allows. Nothing rate-limits them, nothing locks out, and there is no "wrong passphrase" error to trip — type it wrong and a different wallet opens, empty and perfectly valid. SO WE TELL YOU TO ROLL IT, off the same printed word table and with the same dice you used for the seed. Six words is the floor and eight if it is protecting savings, which is thirty throws and six coin flips for one and forty and eight for the other — ten minutes with dice you already have on the table. The word counts, the bits and the throws are all calculated from the same file the seed procedure uses, so the lesson, the checklist step and the procedure page cannot drift apart. AND THE TRAPS, because most of them are invisible. Plain ASCII only: wallets genuinely disagree about accented letters and emoji, so a passphrase built from them can open your wallet on one make of device and not another. No space before the first word or after the last — invisible on paper, and part of the secret. Capitals count. Check the maximum length every device you might restore on will accept, because makers differ and a passphrase too long for one of them is one you cannot recover there. And prove the whole thing on a second wallet before you fund it: the point of a passphrase is that your words plus your passphrase rebuild your wallet anywhere, and that is a claim about other people's software, so test it on other people's software. The full guidance is on rung 2 of the ladder; the rolling procedure sits with the seed procedure. AND WE CHANGED HOW WE WRITE THIS KIND OF PAGE, because the first draft of it was wrong in a way worth naming. It was a list of rules with the mechanism left out — you could follow every one of them and still not be able to explain a single one, which is the opposite of what this guide is for. So rung 2 now starts by telling you how a passphrase actually works: it is not stored anywhere, it is an ingredient, and your words plus your passphrase go into one standard calculation with a wallet coming out the other end. Almost everything else follows from that. It is why there is no "wrong passphrase" message — nothing holds a copy of the right one to compare against, so every passphrase is valid and they simply open different wallets. It is why it cannot be reset or rate-limited. It is why any string at all works, and why a typo is also a perfectly good passphrase. It is why one seed can open any number of separate wallets, which is exactly what makes the decoy possible. And it is why the wallet fingerprint your device shows you is worth writing down: it is the only feedback the design permits, and a fingerprint that matches is the one way to know you typed the thing correctly. FROM HERE ON, EVERY TEACHING PAGE HERE OWES YOU THREE THINGS IN ORDER: how it works, what is actually possible with it — including the options we are going to advise against — and only then what we recommend and why. A guide that publishes conclusions and skips the reasoning is asking you for exactly the trust it spends the rest of its time telling you not to extend to anyone. Existing pages have not all been read against this yet; they will be.
- Content
The dice-to-word table is organised differently — and the page and the PDF finally match
If you have printed our BIP-39 word table, the copy in your folder is still perfectly correct and you do not need to reprint it. The words, the order and the throws that find them are fixed by the standard and have not changed. What changed is how they are grouped on the page. THE OLD LAYOUT REPEATED ITSELF 2,048 TIMES. It blocked the table on your first three throws and then printed the whole five-throw key on every single line — so three of those five characters just restated the heading directly above them, on every row of the table. The new layout nests instead: a box for your first two throws, the four three-throw groups as cards inside it, and each line printing only the last two throws and the coin flip, because the headings above it already say the rest. Finding a word is now three short steps in the order the dice actually come out, rather than one long key to match. Four boxes per page and four pages, so the page number tells you your first throw. Same page count, same type size — this buys you organisation, not density. AND IT FIXES SOMETHING WE SHOULD NOT HAVE SHIPPED. The new layout has been inside the downloadable PDFs for two days while the page on the site still showed the old one, because it arrived as an experiment on a separate address. So the table you read on screen and the table you printed from the same page were two different layouts of one artifact — exactly the kind of disagreement this guide keeps catching in other people's work. There is one table now. The experiment's address redirects to it. WHAT WE FOUND WHILE MEASURING IT, since we would rather say: the merged page came out at nine printed sheets instead of eight, and the ninth held nothing but our own "last verified" line. A styling rule meant to hide that line on print-outs had never worked at all — it had simply never cost anything, because the old table's last sheet had room to absorb it. The new one fills its fourth page exactly, so a dead rule that had been harmless for months bought a whole extra sheet of paper the moment the layout tightened.
- Content
Level 102 is “Wallet setups” — because “Your setup” meant two different things
A naming fix on the front door. The course's second level was called "Your setup", and so is the menu group holding the setup finder, your plan and your checklist — which meant the same two words named the general idea and your own particular instance of it, and both of them appeared on the home page, one in the level list and one on the card sitting beside it. The level is the generic one: it teaches what the arrangements ARE — hot and cold, the four rungs of the ladder, how to choose a hardware wallet — and asks you to decide nothing. So the level is what renamed. "Your setup" now means only the pages that build yours. While we were in there we also stopped typing level names into page copy by hand: five sentences across two lessons named a level and its title in plain text, and would have gone on naming the old one indefinitely. They read it from the syllabus now, like every other count on this site.
- Content
All three “roll your own seed” procedures were partly describing each other
A correction on a safety-critical page, and the kind we would rather own loudly. The page offers three methods for putting your own randomness into a seed and turns into whichever one you pick — but all three were being handed the SAME nine steps, and those steps described only one of them. OPTION 1 WAS THE WORST OF IT. It is the fully sovereign method: you choose every word yourself from our printed dice-to-word table, and your randomness never touches a machine. That is what the panel said at the top. Four lines down, the steps told you to find the dice screen on your hardware wallet, enter each throw into it, and read the finished words off its screen — which is option 2, and the one thing option 1 exists to avoid. It also broke a promise made on the dice-to-word table itself, which tells you that you do not roll the last word and that the procedure on the site explains how, for each device. It did not. Option 1 now has its own steps: print the table and read its method sheet first; you are choosing 23 words for a 24-word seed or 11 for a 12-word one; fill in one worksheet row at a time — the three throws that find your block, the two that find the line, the coin flip, then the word; count and spell-check before the device is even switched on. THE DEVICE HAS EXACTLY ONE JOB IN THIS PROCEDURE: the final word. It carries the checksum — 8 bits of it for a 24-word seed, 4 for a 12-word one — which is arithmetic over every word before it, so there is no table entry for it and no way to reach it with a die. You use the device's import or restore flow rather than "create a new wallet", which reads oddly the first time and is correct, and it produces a valid final word: 8 possible ones for a 24-word seed, 128 for a 12-word one, because a few bits of your own randomness still live in that word alongside the checksum. Some devices calculate one and some offer the valid options and let you pick. WE ALSO HAD THE PAPER RULE BACKWARDS, and this is the part most worth reading. An earlier version of this fix told option-1 readers not to write their throws down at all — while our own printed worksheet gives them a box for every throw, because you cannot look a word up without them. The truth is the one the worksheet already states: writing the throws down is the procedure working correctly, and it means the sheet in front of you IS your seed from the first mark you make on it. So it is treated exactly like the words themselves — never photographed, never typed up — and it is destroyed only once your words are on their permanent backup and you have restored from that backup successfully. Destroying it any earlier leaves the only copy of your seed on a device you have not finished testing. The top-of-page warning has been corrected the same way: your throws belong on paper or straight into the hardware wallet, never onto a screen. AND OPTION 3 WAS BORROWING OPTION 2'S RULES. Option 3 adds your throws to randomness the device generated itself. Its own panel says there is no minimum and more is simply better — and then the steps told you to write a roll target at the top of a tally sheet and to make sure you passed it. There is no target in option 3 and there is no tally: you stop whenever you like, and because your throws are mixed with the device's own, your throws alone reconstruct nothing. Option 2 is the one where the throws ARE the seed, so it keeps its target, its tally, and the instruction to destroy that tally. Three procedures, three sets of steps, and the page can no longer show one under another. [CORRECTED, same day: option 1's step about how many words you choose still ended by telling you to write your target at the top of the sheet so you would not have to remember it — one more sentence inherited from option 2, where there IS a roll target to hit. There is nothing to remember here. The worksheet is numbered, a rule across it marks where a 12-word seed stops, the last row says you do not roll it, and the line under the table spells out both lengths. It now says that instead.]
- Security
Our stance has moved: no single point of failure for money that would hurt to lose
This changes what we recommend, so it gets said plainly. A single point of failure is one hardware wallet, one seed, no passphrase — everything you hold depending on one thing staying fine. Until now our advice was "choose the simplest setup that covers you", full stop, and for a reader with real money at stake the finder could and did land on exactly that arrangement. THE COLDCARD SEED FLAW IS WHY THIS MOVED. Every wallet drained in the 30 July sweep was single-signature with no passphrase. The holders who came through untouched were the ones with a strong passphrase, their own dice throws, or a key from a second maker in a multisig — not because they had predicted a firmware bug, but because they had a second thing that also had to be true. Nobody saw that flaw coming, which is the entire argument: the failures that get you are the ones you did not model, and the only general defence against an unknown failure is not having a single component whose failure is total. SO THE RULE NOW HAS A FLOOR UNDER IT. Simplest-that-covers-you still decides between the rungs above that floor, and we will still talk you out of complexity you do not need — that has not changed and it is still the advice most readers need to hear. What changed is that for money whose loss would genuinely hurt, the recommendation never comes back as a lone key. WE DID NOT MAKE THIS A PROMISE, WE MADE IT A TEST. The wording is easy; keeping it true on every path is not. So the finder is checked across every combination of answers it can receive — every current setup, every stakes level, every recovery, comfort and privacy answer, crossed with the whole range of each risk bar — and the build fails if any one of them comes back with a lone hardware wallet above the smallest stakes. On the engine this replaces, that same check fails 7,425 times, 1,305 of them for readers who said losing their Bitcoin would be devastating. AND IF YOUR STAKES ARE GENUINELY SMALL, NOTHING HAS CHANGED FOR YOU. Bitcoin you are learning with, an amount whose loss would not change your life — one hardware wallet kept properly is still an honest answer, the finder will still say so, and we are not going to talk you into buying three. The stance is about consequence, and we still never ask how much you hold.
- New
Your plan page points at the next thing — and we were miscounting your checklist
Four changes to your plan, and the last one is a correction. AN UNFILLED SLOT NOW LOOKS UNFILLED. This is the page whose whole job is showing you what is still missing, and a wallet you had not chosen yet was the quietest row on it — a faint dashed outline sitting under rows carrying a device name, a green verdict and a tag. It is outlined in red now, and so is an unchosen collaborative service key. Nothing about the plan changed; the hole is just visible from across the room. THE NEXT CLICK IS THE OBVIOUS ONE. Your next step — choose the wallet you are short, or start the checklist once your plan is complete — used to be a small text link carrying no more weight than "import a plan", two blocks above the only filled button on the page, which was "download my plan". Keeping a copy is a good idea; it is not the next thing to do. So the next step is now a button and downloading is not, and there is exactly one of each. THE RISK PICTURE IS NO LONGER REPEATED HERE. The four bars showing your worries against a typical holder's belong to the setup finder, where you walk them, review them, and change them — and where changing them changes what we recommend. Copied onto your plan they were read-only, so you could see the picture and do nothing about it, in the middle of the one card that exists to tell you what to do. It is one click away and it is adjustable there. "HAS YOUR SITUATION CHANGED?" ONLY ASKS PEOPLE IT MAKES SENSE TO ASK. The re-place-yourself tool at the bottom of the page was being put to readers who had finished the setup finder ninety seconds earlier. Nothing has changed in five minutes, and asking implies something might have. It now appears for someone whose plan arrived from somewhere else — imported from a file, or restored from their own Nostr — because that plan came from another day or another device, which is when the question is worth asking. AND THE CORRECTION: WE TOLD SOME OF YOU THE WRONG NUMBER OF STEPS. Your plan said "your checklist is ready — 23 steps" and then the checklist showed 22. The missing one was "get a hardware wallet": the checklist knows to drop that step when you already own a device that clears our bar, and your plan was still counting it. Neither page was wrong on its own — they were answering the same question with two pieces of code, which is the failure this guide keeps finding in its own work. They now share one, so the number you are promised is the list you get.
- New
The setup finder now reads your answer about the hardware you own
The finder has always asked which hardware wallets you already have — and then recommended devices as though it had never asked. That is fixed. When your result appears, it now names what you own and says how each piece lands against the setup it just recommended: which of it works here, which of it we would not build this setup on and why, which models we simply have not rated (which is not the same as failing — most models never have been, and inventing a verdict would be worse than saying so), and then the sentence you actually came for: how many keys short you are. "You are two short. This setup needs three keys of your own, and you hold one that clears our bar." The device suggestions underneath now leave out anything you already own, because telling you to buy the wallet in your drawer is the whole reason this was worth fixing. And where a setup needs three keys, if what you own is concentrated in one maker, it says so — one brand covering two of three keys means a single vendor flaw reaches enough of them to spend your coins. NOTHING ON THIS PAGE IS EDITABLE, deliberately. There is no "I own this" button here, no picker, nothing to add or remove. This page decides which setup fits you; choosing and changing hardware belongs on your plan, and that separation is the reason the result can name your devices in the first place. If you chose "I would rather not say," the whole block stays silent — that was an answer we asked for and it gets respected.
- Content
Bitkey is collaborative custody — for spending, not for a savings vault
We listed six collaborative-custody services side by side and treated them as answers to one question. They are not. Five of them are the fourth rung of our ladder: you assemble a vault, you hold two keys of three, and a Bitcoin-only service holds the third as a backstop for a stack you are locking away for years. Bitkey is genuinely collaborative custody too — a real 2-of-3 with a real third party — but it is a sealed, single-vendor product built around money you are spending. Listed flat among the others it read as a candidate for "who should hold the third key of my savings", which is not a question it is applying to answer. So the comparison page now has two parts: the five savings services, compared as before, and Bitkey in a section of its own that says what it is and what it is not. It is not a demotion and it is not a warning — it is the cheapest, simplest, no-KYC way into a 2-of-3, recovery is built in, and for a non-technical holder it is an unusually good on-ramp. It is answering a different question, and the page now says which. The setup finder no longer offers it when it recommends collaborative custody, because that recommendation is about long-term savings. It keeps its row on the wallet comparison and its rating there is unchanged: built for spending. THE PART THAT MATTERS FOR EVERYTHING ELSE: this is the same judgement made twice about one product — is it for savings or for spending — and that is exactly the shape of bug this guide keeps finding, two pages answering one question differently. The site now refuses to build if the custody list and the hardware rating ever disagree about it.
- Content
The first risk section now admits it does not change the answer
The setup finder opens its risk assessment with company failure — your exchange going under, freezing your account, or losing your coins. Seven questions, a bar that visibly climbs as you answer them, and no effect whatsoever on which setup we recommend. We checked: move that bar from bottom to top and all four setups gain exactly the same amount, so the order never changes and neither does the result. That is not a bug in the scoring — it is the honest answer. Every setup on our ladder takes company failure to zero, because that is what holding your own keys means. Even the collaborative option, where a Bitcoin-only service holds one key of three: if the service fails you still hold two keys and your coins still move. What you would lose is the safety net, not the money. So the section now says so, in the section, rather than letting you infer from a moving bar that your answers are steering something. It reads: every setup here takes this one to zero — these questions shape your picture, not the recommendation. And it asks four questions instead of seven. The three we dropped — who audits your platform, whether you have ever seen a withdrawal delayed, whether the venue is regulated where you live — are all refinements about WHICH venue, and they only matter once you have said there is one, which the first question already establishes. The closest call was the delayed-withdrawal question: it is the best early warning there is, since withdrawal friction preceded the Celsius collapse by about a month. But it tells you to get out now, and the checklist already tells you that. WHAT WE DID NOT DO is give collaborative custody a lower score here to make the section feel more influential. It was tempting and it would have worked. It would also have been untrue, and the cost of bringing a company into your setup is already charged where it belongs — in how much you say you mind a third party being involved at all.
- Content
A Tools & demos menu — and the course ends on running your own node
The menu had a hole in it. Everything interactive on this site was scattered: the demos sat inside the course as though they were a lesson, the dice procedure was reachable only from one lesson and one checklist step, and the printable dice table only from the procedure. There is now a TOOLS & DEMOS group holding all three — the eleven interactive demos, the roll-your-own-seed procedure, and the dice-to-word table with its printable PDF. The test for what belongs there: you do something on your own device, and nothing is saved, scored, or added to your plan. That is what separates it from Your setup, where every tool writes to your plan, and from Hardware & services, where every page sends you out to buy something. LEVEL 201, "UNDER THE HOOD", IS GONE. It held two things and they were different kinds of thing: a real lesson about running your own node, and the demos hub — which has no reading position, no rule attached, and nothing to complete. Running your own node is now the last lesson of 104, The long haul, which is where it belonged: checking the rules yourself is the final habit in a level about ongoing habits, and it is the guide’s umbrella rule in its fullest form. As a bonus tier at the end of an optional level it read like something nobody was expected to reach. The course is now four levels and seventeen lessons, and every one of them is meant for you. Counting the demo hub as a lesson also had a quiet cost: because it was "lesson 18", every link from a lesson into a demo counted as a link to material further along the course, and the checker that enforces our no-forward-links rule had to make a named exception for it. It never was one. HOW WE WEIGH RISK MOVED TO ABOUT. It sat next to our hardware standard because both are published "how we decide" pages — but the standard is a rubric applied to products you might buy, and this one explains how the site itself reasons. That is About material. Two small repairs found on the way: the rules page named the wrong level for the node lesson in plain text, and the privacy lesson pointed at "level 201" for the optional privacy tools. Both now name the right place, and the site refuses to build if a rule’s stated level ever disagrees with the curriculum again.
- Content
Our philosophy on the front page — and the seed options stop having a “default”
Four changes, and one of them is a correction. THE HOME PAGE now states what we actually think, up front, instead of quoting a single rule and calling it the foundation. Six lines: we hold no keys and sell no device; choose the simplest setup that covers you; every choice trades one risk for another, and we will tell you which one you are picking; we never ask what you hold and nothing leaves your browser; we publish our conclusions including the ones that do not flatter us; and verify, don’t trust. Every guide has a point of view whether it admits to one or not, and you should be able to read ours before you read anything else. THE FOUR SEED-GENERATION OPTIONS no longer carry an “our default” badge on one of them. The stance has not changed — where your device allows it, adding your own dice throws is still what we would do, and it still cannot make the result worse. What changed is the shape of the advice. Which option is right for you depends on the device in front of you and how far you want to go, and a rosette on one tile made the other three read as runners-up before you even knew which your own hardware could perform. All four now get the same frame, and the page says plainly that there is no single right answer here. In time the finder will ask what you want out of this and the recommendation will be yours rather than ours. WE LEFT A DEVICE OFF A LIST. The page explaining what each device allows named eleven of the twelve hardware wallets we rate, and simply did not mention Bitkey — not as a yes, not as a no. Bitkey has no seed phrase to build at all: it is a multisig by design and its recovery kit holds an encrypted key rather than words, so the whole question sits outside it. Our data said exactly that; the page published neither. It does now, and the site refuses to build if a device we rate ever falls off all three lists again. ROLL YOUR OWN SEED is now in the top menu, under Hardware & services, between how we weigh risk and metal backups — the order you meet them in: the words get made, then they get stored. It was reachable only from the lesson and your checklist before, which is a lot of clicks for something this important.
- Security
The Coldcard keeps its cold-storage rating — the review we promised, in full
When the seed-entropy advisory went up we promised in writing to re-read the Coldcard against our published standard rather than assume the old rating held, and to publish whatever we concluded rather than quietly apply it. Here it is: it keeps its place in the cold-storage tier, and none of our five criteria fails. Keys still cannot leave over the internet — the flaw made seeds guessable from the outside, it never shipped one anywhere. The firmware is still source-available and independently reproducible. Bitcoin-only, minimal and portable recovery are untouched. But the verdict is more comfortable than the reasoning, and we are not going to pretend otherwise. The defect sat in public, readable, reproducible source for five years, and researchers linked the exact lines the day it surfaced. Reproducible builds worked perfectly: they guaranteed the shipped binary faithfully matched the source, and the source had the bug in it. “It is open, so someone would have caught it” is what everybody assumed, us included. Nobody had. What verifiability actually buys you is finding out afterwards, fast and precisely — genuinely worth having, and not the same thing as prevention. We considered adding a sixth criterion about where a device gets its randomness and who outside the company can check it, and decided against it. Open, reproducible code is the highest bar available today; there is no stronger standard to hold a maker to, and the Coldcard already clears it. A rule written now would be a rule written against the thing that just went wrong, and the next failure will be something nobody has thought of yet — a standard that grows a clause after every incident stops being a standard and becomes a list of past events. What we changed instead is what we tell you to do about it: the people whose coins survived were the ones who had not left the randomness entirely to the device, so there is now a full dice procedure on the site. That would have helped here, and it helps against failures we have not imagined.
- New
Generating your seed is now a lesson — and you can put your own randomness into it
The course taught you how to choose a device, back a seed up, test the backup and spend safely. It never told you how the seed gets made. That is now lesson 1 of level 103, The build, in its proper chronological place: make the seed, back it up, prove the backup, then move coins. WHAT IT TEACHES is that your seed is one very large random number, that normally the device picks it and you have no way to check that it picked well, and that you have four options ranging from choosing every word yourself to letting the device do it. Each option says which of the devices we rate can actually perform it — and that is the part most people will not expect. Only Coinkite lets you roll dice on the device itself, so two of the four options belong to one maker. On a Jade or a BitBox02, choosing every word from a printed table is the only way your own randomness gets in. And on the Trezor Safe line, Passport Prime, Ledger and Bitkey there is no way in at all: the device generates your seed and that is that. That is not a reason to replace any of them — Trezor argue in writing that you should never choose your own backup, and the losses back them up — but it is worth knowing before you buy, so /wallets now has a filter for it. OUR DEFAULT, stated plainly: where your device allows it, add your own dice throws on top of the randomness it generates. It costs a few minutes, it needs no lookup table, and Coinkite states in its own documentation that it cannot produce a worse result than letting the device decide alone. THE PROCEDURES live on their own page, one option at a time, with the exact current menu path for every device — including the Coldcard Mk3, whose menus differ from every newer Coldcard. THE PAGE WILL NEVER ASK WHAT YOU ROLLED. There is no input on it and there is not going to be one: the sequence of numbers you roll IS your seed in another alphabet. AND THERE IS A PRINTABLE PACK — a method sheet, a worksheet with a numbered row per word so your place is on the paper instead of in your head, and the full 2,048-word dice table, as a page or a four-page PDF. We generated the table from the standard word list and then checked every one of its 2,048 entries against the table BitBox publishes: all of them match. Two tables built separately agreeing on every row is the reason to trust either.
- Specs
Fixed: your plan and checklist were broken if you own a Trezor, Jade Plus, Bitkey or Ledger
A bug we shipped on 31 July, found while building something else. The code that judges your owned hardware against our standard identified each device by its picture filename. When the Blockstream Jade Core was added it shipped before its illustration was drawn, so it has no picture — and the lookup walked through every device in turn, hitting the one with no picture and failing there. The result: for anyone whose device is listed after the Jade Core, the personalised parts of your plan and your checklist silently stopped working. That is the Jade Plus, all three Trezor Safe models, Bitkey and Ledger. The Jade Core itself was fine, which is exactly why this went unnoticed for a day — the device with no picture is not the one that breaks. It now identifies devices by their own permanent id rather than by a filename, which is what the rest of the plan feature has always used. Nothing you saved was lost or changed; the pages simply stopped tailoring themselves. If you own one of those and your checklist looked generic, it should be personalised again now.
- Security
We got four things wrong in yesterday’s Coldcard advisory — here they are
We published the Coldcard advisory fast, and re-reading it against Coinkite’s own advisory and Block’s technical analysis turned up four defects. One of them could have told an affected reader they were safe, so we are naming all four rather than quietly tidying the page. (1) THE VERSION-NUMBER TRAP, the serious one: Coldcard ships two separate release tracks, standard and Edge, and Edge version numbers are HIGHER. We listed only the standard fixed versions, so someone running Edge 6.5 could compare it to our "5.6.0 or later" and reasonably conclude they were patched. They were not — the Edge fixes are 6.6.0X for Mk4/Mk5 and 6.6.0QX for the Q, and both are now on the page. (2) WE GAVE THE WRONG FIRMWARE RANGE for the worst-affected devices: we wrote "4.0.1 through 5.0.3" for the Mk3, which contradicted our own page, since we also said 4.2.0 fixes it. The real range is anything below 4.2.0 — 4.0.1 through 4.1.9 by Coinkite’s reckoning, 4.0.0 through 4.1.9 by Block’s. We also failed to mention the Mk2, which Block confirms is affected on the same firmware. (3) A SEED CARRIES ITS WEAKNESS WITH IT. If you generated a seed on an affected Coldcard and later restored it onto some other wallet — another maker’s device, a phone, software — that seed is still weak. Our page never said so, so a reader who had already migrated could read every risk band and correctly conclude that none of them described them. (4) WE FILED PASSPHRASE USERS UNDER "NOT AFFECTED." A strong passphrase genuinely blocks this attack, and it is why those wallets were not drained — but the weak seed is still underneath it, and Coinkite’s own guidance is to migrate anyway. It is now its own band that says so. Also sharpened: the dice exception requires rolls that were independent, private and never recorded digitally, and we now give Block’s harsher figure alongside Coinkite’s for the newer devices. Our own take and the rating review are unchanged — that work is still owed and will be published here.
- Security
Security advisory: Coldcard seed-generation flaw — and it lands on a device we recommend
A build-configuration error introduced into Coldcard firmware in March 2021 made seed generation fall back to a non-cryptographic random number generator. Seeds created on affected firmware carry far less randomness than they should — on a Mk3 running 4.0.1 through 5.0.3, little enough to be guessed offline — [CORRECTED, same day: that firmware range is wrong. The affected Mk3 range is anything below 4.2.0, and this entry also missed the Edge release track. Both are owned in full in the entry above; this line is left as published rather than quietly rewritten.] — and on 30 July 2026 an attacker did exactly that, sweeping hundreds of wallets in under an hour. Every one of them was single-signature with no passphrase. We rate the Coldcard Q and Coldcard Mk5 in our cold-storage tier and the setup finder recommends the Q by name, so this lands squarely on our own advice and we are not going to be quiet about it. There is now a full advisory on the site, linked from a banner on every page: which devices and firmware are in scope, the thing almost everyone gets wrong (updating your firmware does NOT repair a seed that already exists — exposure was fixed at the moment the seed was generated), what actually protected people, and what to do, in order, without rushing. What protected people is the part worth keeping: a strong unique passphrase, 50+ of your own dice rolls, or a multisig holding a key from another maker. Each of them meant this flaw could not reach the coins on its own. We are re-reading the Coldcard against our published standard rather than assuming the old rating still holds, and whatever we conclude will be published here rather than quietly edited in.
- New
The finder now runs a real risk assessment
The old "rank your worries" question asked you to guess at your own threat model in one tap. It’s gone. In its place: the standard picture of how Bitcoin is actually lost — most of it self-inflicted or scammed away, almost none of it robbers — and then a walk through all four risks with concrete "true of me?" statements, each carrying its receipt ("25% of documented physical attacks happened during in-person trades"). Your bars move as you answer; the words — low, typical, elevated, high — are the whole scale, because a decimal point would be false precision. The result now shows its work: your picture next to the typical holder’s, the reasons in plain language, and — when we deliberately did NOT add something — why not, computed from your own answers. A passphrase, for example, no longer gets recommended to someone whose biggest risk is locking themselves out: it defends one concern by inflaming the other, and the result says so. Skip any section and keep the standard estimate; nudge any bar by hand and the recommendation follows. When two setups genuinely tie, the result says "either of these fits" and names the trade instead of faking a winner. Saved plans from the old finder still work — we estimate your picture from your earlier answers and say so, and walking the assessment replaces the estimate.
- New
Your checklist now says which steps matter extra — for you specifically
When your saved plan carries a risk assessment, the checklist tags the steps that answer your elevated or high concerns with a small "matters extra for you" marker and one sentence of why. High on locking yourself out promotes the backup, recovery-test, and re-test steps; scams promote the verify-on-device and official-app habits; targeted theft promotes the low-profile steps; company failure marks the final move itself — the whole point, don’t stall there. Emphasis only: the order of the steps is safety-critical and never changes, and without an assessment the list is exactly as it was.
- Content
The finder shows its homework: how we weigh risk
The risk assessment starts everyone from a research-based default, and that default is now a published page — How we weigh risk, next to the hardware standard in the menu. The four concerns with their evidence bands, the primary sources behind each number (the FBI’s annual fraud reports, Chainalysis crime data, the lost-coin estimate family including River’s deliberately conservative low, the physical-attack registry and the academic study of those attacks, and the original exchange-failure research), the questions we deliberately don’t ask — your age, "are you careful," "is your neighborhood safe" — with the evidence for skipping each one, and the places the data is honestly uncertain: the bands are wide on purpose, and the scale is words instead of scores because the underlying research can’t support a decimal point. The headline statistics sit on the same scheduled freshness watch as the device prices, so the verified date on that page means what it says.
- Devices
Blockstream Jade Core joins the comparison — the twelfth device
Blockstream launched the Jade Core in April as its beginner-focused hardware wallet, and it now has a row in the comparison: $99, USB-C or Bluetooth, guided setup through the Blockstream app, a device-authenticity check at first power-on, and the same fully open-source blind-oracle security model as the rest of the Jade line. It clears our security floor and lands in the cold-storage tier, which now holds nine devices. The honest caveats are on the card: no camera, so no air-gapped QR signing (that’s what the Jade Plus adds), Bluetooth is present, there’s no dedicated secure-element chip (Blockstream’s deliberate blind-oracle design, shared by every Jade), and the hardware is new enough that its track record is measured in months. Its line-art portrait is still being drawn — the row ships first, the picture follows. While we were in the Blockstream aisle: the $79 original Jade remains on sale at their store and keeps its row; nothing was replaced.
- Price
Jade Plus back down to $149; Trezor’s sale doesn’t change our list prices
A full re-check of every device against its vendor’s own store today. One real change: the Blockstream Jade Plus base model is back to $149 — it launched at $149, rose to $169 in July, and has come down again; the table now says $149. Trezor is running a limited-time sale on the whole Safe line (Safe 3 $47, Safe 5 $103, Safe 7 $224 at time of writing) — the guide keeps showing the regular prices of $59, $129, and $249, because sale prices churn and a guide that quietly tracked them would overstate the cost the week after the sale ends. If you’re buying this week, enjoy the discount. Everything else — the Coldcards, BitBox02, Passport Prime, the $79 Jade, Bitkey — verified unchanged. Also on our radar: Blockstream formally launched the Jade Core ($99) in April as its beginner-focused device; we’re evaluating whether it earns a row in the comparison.
- Security
Correction: the checklist had you move everything onto your new wallet before its backup was tested. The big move now comes last.
The old order was setup, then backup, then prove the backup works — and the last step of setup said to move a test amount off the exchange "then move the rest." Follow that literally and your whole stack lands on a device whose seed phrase has not been written down or restore-tested, right before a later step tells you to wipe that device to prove recovery. That is the one ordering mistake on this site that could actually lose someone their Bitcoin, and the guide’s own lessons have always taught the opposite: back up, prove recovery, then fund. The step is now split the way the lessons say. A small test amount still arrives early — you verify the receive address on the device’s own screen and see a real payment land. Moving the rest is now the final step of proving your backup, worded the way it should have been all along: now that the backup is proven. If you had already ticked the old step, your tick carries over to the moved one.
- Security
Correction: the setup finder said two device makers were enough for multisig. Three keys need three makers.
The lessons, the ladder, and the hardware comparison all say the same thing about a do-it-yourself 2-of-3: use three different manufacturers, one per key, so a bug in any one maker’s device can touch at most one key. The setup finder — the tool most likely to be followed word for word — said two vendors. Two makers across three keys means one vendor’s flaw can reach two keys, and two keys is exactly what it takes to spend a 2-of-3. The finder now says three different makers and explains the one-brand-one-key reasoning, matching every other page. While we were in there we also fixed the multisig rung’s cost line: the cheapest trio of cold-storage devices in the current catalog comes to $275, not $300.
- Content
Correction: the ladder lesson had quietly lost content a July rework was supposed to keep. Restored.
When the ladder walkthroughs were merged into one lesson on July 30, four pieces of each rung’s write-up stopped being shown without anyone deciding they should: the "what it gains you" list (the page’s own intro promises the gain-for-cost trade, and only the cost was rendering), the note that multisig keys should come from three different manufacturers, the warning that sovereign recovery — can you rebuild your wallet without the service? — is the make-or-break test for collaborative custody, and the whole discussion of bigger 3-of-5 setups that the page still pointed readers at. All four render again. We also retired the "Tier 1 ($1K–$50K)" dollar-bracket labels that sat on each rung: this guide’s whole position is that your setup should follow your threat model, not a dollar amount, and the labels collided with the completely different meaning of "tier" on the hardware standard page.
- Content
The path from exchange to cold storage had missing steps. They’re in now.
Reading every page in order as a first-timer turned up three places where the site said what to do but not how the moment actually goes. First: nothing ever told you to install the maker’s wallet app — every USB hardware wallet needs its companion app to receive and send, and the checklist now has that step, with the warning to download only from the maker’s own site because fake wallet apps are a top way people get robbed. Second: the checklist’s seed step now walks first power-on concretely — start at the maker’s printed setup address, set a PIN, and the device shows your words on its own screen, to be copied by hand and never typed into a computer. Third: Send Bitcoin safely gained "Put it together: your first withdrawal" — generate a fresh receive address, confirm it on the device’s screen, make sure the exchange’s network menu says Bitcoin, send a small test, and what "arrived" actually means (the glossary now explains confirmations). Test your backup also now says plainly what to do if the restore fails — stop, and go back to the written copy you checked against the device before wiping, which is the whole reason that check comes first.
- Content
Collaborative custody: choosing the service now comes before choosing hardware, everywhere
The finder has always said it in bold — choose your service first, because each service supports different devices — and then the checklist and both plan pages walked you to the hardware shop first anyway. Someone following the steps in order could buy a device their eventual service doesn’t support. On a collaborative plan, every surface now puts the service decision first and the device second: the checklist step order, and the "what’s missing" prompts on your plan and your checklist.
- Content
Your plan stopped over-promising and started confirming
A batch of honesty fixes to the finder and plan pages. Saving now tells the truth: if your browser blocks storage (private windows do this), you get "couldn’t save" instead of a green check over nothing. Importing a plan file or restoring from Nostr now asks before replacing the plan already in this browser, showing the dates of both. "Start fresh" on the finder becomes "Clear my plan and start again" when you actually have a plan, and asks first — it was silently erasing checklist progress and notes. The result screen gained "Change my answers," so revisiting one question no longer means starting over. The device cards under your recommendation now say what tapping really does — puts that device first in your plan — instead of promising steps that adapt. Progress counts on your plan now use the same list your checklist shows, so the numbers always agree. A holder already in one kind of multisig whose answers lean toward the other kind now gets an honest "same rung, different holder for the third key" instead of being told they are ahead of what they need. And the step-up card now reasons from your actual top-ranked worry instead of whichever one happened to be listed second.
- Content
A sweep for plain speech, defined terms, and Bitcoin-only examples
Fallout from a full read-through of every lesson in learner order. Exchange examples are Bitcoin-only everywhere now (River, Swan, Strike) — a multi-coin exchange had crept into two lists, and this guide doesn’t send anyone there. The one sneer on the site ("crypto casino") became an argument: fewer products competing for your attention, and withdrawal treated as a first-class feature. The two big statistics on How people actually lose Bitcoin now name their source family. Lightning, satoshi, on-chain, and coordinator software are all explained the first time you meet them, and the glossary gained Confirmation and Coordinator software. Hot and cold now says the phone-wallet sentence the careful way: fine for spending money — but savings belong cold, however small. The densest paragraph in the early lessons (the physical-theft defenses) is broken up and its riddle spelled out. A pointer in Beyond the ladder sent you to "the next lesson" for advice that actually lives two lessons later; it names the right lesson now. And a link to bitcoiner.guide on the resources page had quietly gone dead — fixed.
- Content
Every page now carries a real "last verified" date — and missing one breaks our build
The dating promise is the visible half of how this site earns trust, and an audit found it slipping: several lessons carried stamps older than their own published corrections, the twelve demo pages had no date at all, and a page missing its date silently showed the launch date. Fixed on all three fronts. Stamps are bumped as part of any substantive edit — every page touched today says July 31. The demo pages now carry the date of their last substantive check. And a lesson without a date now fails our build instead of guessing. Behind the scenes, the scheduled checker that re-reads vendor stores got two upgrades: when a full pass comes back clean it now advances the "prices & specs last verified" date you see on the hardware pages (it previously only recorded the check privately, so the public date understated), and it now watches the collaborative-custody services’ fees and minimums too — those were marked volatile in our own data and nothing was re-checking them.
- New
Phone-friendly tables, a foldable checklist, and "On this page" shortcuts
The comparison tables were technically scrollable on a phone and looked finished at the cut — nothing said more columns existed, and scrolled down, the hardware table showed bare ✓ and ✗ marks with no header to say what they meant (a red ✗ next to a device reads as "fails" when it only means "no air-gap"). Tables now keep their header row and the device or rung name in view while you scroll, the cut-off edge fades to show there’s more, and a small hint says to swipe. The checklist’s phases now fold closed — collapsed, the page is a quarter of its length, and your "Next up" step always stays visible. Long lessons and the twelve rules gained an "On this page" shortcut list on wide screens. Small print got a touch bigger and small links got bigger tap areas throughout. The mobile menu also closes flush with the bottom of the screen and properly freezes the page behind it — fixing that turned up and fixed a subtler bug where the header lost its stickiness.
- Content
Choosing a metal backup is now its own page, in Hardware & services
The guidance on which metal plate to buy was buried partway down the lesson about backing up your seed, where you could only find it by scrolling. It is now a page of its own — Metal backups, in the Hardware & services menu, next to hardware wallets and collaborative custody. That is where it belongs: it is a buying decision with links out to five vendors, which is exactly what the other pages in that group are, and unlike any lesson on the guide — no lesson else sends you out to buy something. It was also a third of that lesson’s length, which made a mid-sized lesson the second longest page on the site. The lesson keeps the teaching: why metal at all, how to copy the words without a mistake, what makes a plate fail, and the advice to practise on a throwaway seed first. The new page answers the separate question of which one to get. Every page that tells you to move your seed onto metal can now point somewhere, including the checklist step whose whole job is that moment. While we were there: five checklist steps had a link labelled “Read the lesson” that did not point at a lesson at all — two went to collaborative custody, one to the wallet comparison, one to an interactive demo. Each now says what it actually opens.
- Content
Correction: we said half of metal backups fail their stress tests. Most of them pass.
The lesson on backing up your seed told you that “roughly half of the products marketed as fireproof or indestructible fail at least one test”, citing Jameson Lopp’s stress testing. We went back to his published results and that is wrong, and wrong in the direction that makes people anxious: of the 75 devices he has burned, dissolved in acid and put under a 20-ton press, 45 came through everything with nothing lost and another 11 were marked down in one test only, while just 10 did badly. Roughly one in eight, not one in two. (This entry originally said 56 came through with nothing lost. That added the top two grades together and mislabelled the total; corrected 6 August 2026 — the recount, and how it was caught, are in the newest entry above.) The lesson now says so, and the metal section leads with it, because the useful advice turns out to be the opposite of what we published — this is not a minefield you must tiptoe through, it is a market where most things work and a short list of specific designs fail. We also name the failures individually now, with the reason each one broke, so the list teaches you what to look for instead of just blacklisting five brands. One of them is Blockstream’s own metal backup, whose rivets dissolved and dropped every letter out — worth knowing precisely because we rate Blockstream’s Jade highly as a hardware wallet. A company can build an excellent signing device and a poor backup plate. And three of our five picks carried the wrong price band, including a “best value” badge on a plate that costs more than half the list; the badge has moved to the one that is actually cheapest, and every band now matches the price published in the source we cite. Finally, the guidance is reachable: every page that told you to “move it to metal” had no way to get to the page that says which metal, including the checklist step whose whole job is that moment. It links there now.
- Content
After you choose a setup, the next step is your plan again — not the checklist
There are three steps here and the site had flattened the middle one. You choose a setup, then you build that plan out — which hardware fills it, whether anything you already own clears our bar, and for a collaborative setup who holds the service key — and only then do you work the checklist. Yesterday’s change moved the hardware decisions off your plan entirely and onto the checklist, which was one page too far: the checklist is for doing the thing, and it can only name your devices if the plan already knows them. So the wallet slots, the recommendations and the verdict on hardware you already own are back on your plan, where you are choosing. Choosing a setup stays a clean single decision with no device talk in it. And the big button on the result page no longer sends you past your plan to a checklist that has nothing to trim yet — after you save, it points at your plan; before you save, it isn’t there at all, because the thing to do first is save. The plan card also stopped congratulating you on a full set of slots when one of them holds a device we would move you off: it now says which one, and why, while leaving the choice to you.
- Content
Choosing a setup and choosing hardware are now two separate steps
Your plan page was asking you to pick hardware and judging the hardware you already own, at a point where neither decision was in front of you. Those have moved. Your plan now describes the setup you chose and what it takes — one hardware wallet, or three from different makers, or two of your own plus a service key — and for a collaborative setup it asks who holds that service key, because which service you run with is part of which setup you are running. Everything about which device fills it now happens on your checklist, where you are actually doing it: which model to get, and whether something you already own clears our bar or is worth replacing. The result is that you are never told to consider upgrading a device at a moment when you are only trying to decide what kind of setup you want.
- Content
Fixed: a saved step-up was named after the action, not the setup — and your plan said the same thing three times
If you saved the second choice, your plan came back reading "Plan: Add a passphrase" — an instruction where a plan should carry a setup name, and it ran straight into the wallet count, which made the line hard to parse at all. Two causes, both fixed. The step-up card was headed with its action ("Add a passphrase") while the first choice was headed with a setup ("Single-signature cold storage"), so the two were not comparable side by side; the step-up now leads with the setup it produces — single-sig plus a passphrase — with the action underneath it. And the plan itself now saves the setup name rather than the heading. Separately, a plan with an unchosen wallet was giving the same instruction three times: once on the empty slot, once in a line underneath the slots, and once again under "your next step", each with its own link to the same page — and the line underneath the slots still called hardware wallets keys. The slots now show the state, and "your next step" gives the instruction, once. On a multisig plan the different-makers advice was likewise printed twice, word for word; it is said once now, where the instruction is.
- Content
The lowest setup we recommend is now cold storage, not a phone wallet
If you told the setup finder that losing this Bitcoin wouldn’t change your life, it used to recommend keeping a small amount in a non-custodial phone wallet and graduating to a hardware wallet later. That has changed. The lowest setup this guide recommends is now single-signature cold storage for everybody, and low stakes change the budget rather than the setup. Two reasons. A phone wallet really is self-custody, so the objection was never custody — it is temperature: the rule this whole guide rests on is that savings do not live on an internet-connected device, and it was odd to publish a standard for eleven cold devices and then point the least experienced reader somewhere else. And "graduate later" puts the single riskiest thing a holder ever does, moving a wallet, in front of the person least equipped for it. Cold storage starts at the price of the Trezor Safe 3, which is less than the spread on a lot of first Bitcoin purchases, and the cheap devices in our cold-storage tier do the same job as the ones costing four times as much. None of this changes what the guide says about phone wallets for money you are actually spending — a hot wallet for walking-around money is still exactly right, and the lesson on hot and cold says so.
- Content
The checklist now tells you when it isn’t yours yet
If you have chosen a setup but not yet picked the hardware for it, the checklist page used to look exactly like a finished, personalised one. It now says plainly that your plan is not finished, names what is missing — a hardware wallet, two more of them, a collaborative custodian — and points you back at the step that closes it. The page is not blocked and never will be: the first steps on it are how to get the hardware a finished plan would name, and reading ahead is reasonable. What it no longer does is dress the full list of everything up as a list built for you. Once the plan is complete it trims to just your steps and says so, exactly as before.
- Content
Your plan now says what to do next, instead of announcing a checklist that isn’t ready
A saved plan with no hardware wallet chosen was still telling you "your checklist is ready — 16 steps", which was backwards: the first thing that checklist would have said is to go and choose the device you had not chosen. The next step is now whatever is actually next. No wallet picked yet and it says choose your hardware wallet, and explains that your checklist gets built around that exact device once you have. Multisig with one of three chosen says choose two more, and mentions that different makers is the point. A collaborative plan with its own wallets set says the last piece is who holds the service key. The page also stopped talking about keys where it meant hardware wallets — "needs 1 key" and "1 more key to add" now say what they mean, and the slots read Wallet 1, Wallet 2 rather than Key 1, Key 2. The only place that still says key is the collaborative service key, which genuinely is one and is not a device you buy. "Rework devices" no longer appears when there are no devices to rework, and the link out to a rung walkthrough has left the top of your plan, where it was a detour at the moment you most wanted a next step.
- Content
Fixed: saving one recommendation marked both of them as your plan
When the setup finder gave you a first and a second choice, saving either one put a green "this is your saved plan" tick on both. Only one was actually saved — the page was deciding which band to mark by comparing the rung each recommendation lands on, and two different recommendations can honestly land on the same rung. Starting simple on a phone and graduating to cold storage, and going straight to cold storage, are both single-signature setups; they differ in where you begin, not in where you end up. The page now matches on which recommendation you actually saved. In the same pass, the wording after you save puts your plan first and the checklist second, which is the order they happen in — and before you save, the page no longer offers you a checklist, because until there is a plan the checklist is just the full list of everything, which is not yours in any meaningful sense.
- New
Clearing your plan no longer forgets everything else — and a footer you can read
There was one button, and it deleted the lot: the setup you chose, your checklist progress, every answer you had given, and the list of hardware you own. Those are not the same thing. What you own is a fact about you — you can mark devices on the comparison page without ever opening the setup finder — and your answers are what your setup was derived from. So there are now two actions and they do what they say. "Clear my plan" clears the setup you chose and the checklist progress under it, and keeps your answers and your hardware, so you can pick a different setup without starting over. "Forget everything" removes all of it, and says so rather than hiding behind a gentler label. Starting the finder fresh now also clears a stale setup, because re-answering the questions while the old answer sits saved made no sense. Separately, the footer has been rebuilt. It had been listing all seventeen lessons in one narrow column beside three columns of three links, which crushed the lesson titles into two-word lines and made the thing a thousand pixels taller than it needed to be. It now lists the five levels instead — every lesson is one click away in the menu on every page, so the footer was carrying a second copy of something you already had — and the glossary and further reading get a column of their own instead of hiding under Learn.
- New
The guide now checks whether the hardware you own actually meets the standard — and how to pick a metal backup
Tell the setup finder you own a Ledger and, until now, it recommended two other devices without ever mentioning yours, and your checklist said "get a real hardware wallet" underneath the name of the one you have. That is fixed everywhere. The result page now names what you own and says plainly whether it clears our bar, why, and that you are not obliged to replace it. Your plan shows a verdict beside every device — clears our bar, built for spending, doesn’t clear our bar, or simply not rated by us, because most models never have been and pretending otherwise would be inventing a judgement. And the checklist stops telling you to buy hardware you already have: own something that clears the bar and the step disappears, own something we would move away from and it becomes "consider upgrading", with the reason. If that device is the one you deliberately chose, it drops to the end as a note rather than blocking a build you already decided on. Two other things came out of the same pass. The checklist was being generated in two places, which is why the one on the checklist page looked generic next to the one on your results; there is now one, on the page called checklist. And "back up the seed on metal" has become "write it on paper, check it, then move it to metal", because nobody has a steel plate on the day they set up a wallet and the lesson never said they should. Which exposed a real gap: this guide rates eleven hardware wallets against a published standard and then said "move it to metal" without a word on which metal. There is now a section on choosing one — what actually matters (punched or stamped rather than engraved, one solid plate rather than loose tiles, stainless being genuinely enough, no proprietary format) and five that survive independent stress testing, with prices as bands rather than figures because we do not track them the way we track wallet prices. We did not run those tests ourselves and we say so: they are fire, acid and a twenty-ton press, Jameson Lopp has run them on seventy-five devices, and the criteria are ours while every verdict is his.
- Content
Rewritten: what a “wallet” actually is, and the one-way chain behind it
The lesson on Bitcoin keys used to define a wallet as “a configuration of keys” — and it did so before it had explained what public and private keys are. Both halves of that were wrong. A configuration of keys answers what it takes to move your coins; it never answers which coins are yours. So the page now runs in the order the ideas actually depend on each other. First the chain: your private key produces a public key, which produces an address, and each step runs one way only — nobody can work backwards from an address to a public key, or from a public key to a private key. That is why handing out an address costs you nothing, and it is arithmetic rather than a promise anyone is making. Then the wallet, defined as the answer to two questions: which coins are mine, and what does it take to move them. The first is the extended public key — the xpub — which lets software find every address you will ever receive at and add up your balance without being able to spend anything. The second is whether one key signs, or a key plus a passphrase, or several keys where a few must agree. Both together are the wallet, and written out as one line that is a wallet descriptor. And a caution that follows from it, which was nowhere on the site before. Nothing below your private key can spend your coins — but that is not the same as harmless, because everything below it is public and permanent, and whatever can be linked together eventually is. Handing out an address is normal and costs you nothing in coins. Handing out an xpub is different: it still cannot spend, but it reveals every address in that wallet, past and future, so anyone holding it can see your whole balance and history. Finally, the explanation of why a hardware wallet is called a signing device rather than storage moved down beside the section on signing, where it belongs.
- New
The front page rebuilt — what we promise first, then what is actually here
The front page now leads with what this site promises — no device to sell, no keys held, Bitcoin only, and nothing logged — then shows what is actually here: the course laid out by level, the setup finder and the checklist it builds, the hardware comparison, and a first look at the interactive demos.
- New
New: a short knowledge check at the end of two lessons
Two lessons now end with a couple of questions on what you just read, and a short explanation when you get one wrong. A pilot for now. Nothing is scored, saved or sent anywhere — close the tab and it is gone.
- Content
The quiz is now "Find your setup" — and two safety sections got more specific
The setup quiz is now called Find your setup, because it never tested what you know — it asks about your situation. Old links still work. Two lessons also got sharper: spreading your keys across several places cannot protect you from a confrontation if you hold a single set of recovery words, so the privacy lesson now names the setups that can; and the inheritance lesson says plainly that keys are access, not legal title — nothing here is a will or a trust.
- Devices
Correction: two Trezors were listed as clearing the bar with no caveat, and they have two
Correction: we described the Trezor Safe 3 and Safe 5 as clearing our bar with no caveat at all. They do clear it and their rating has not changed — but both ship multi-coin by default, so the Bitcoin-only firmware is a build you choose, and their Shamir backup only restores in wallets that understand that format. The comparison page had been showing both facts all along. That leaves the BitBox02 as the only cold-storage device with no caveat against it.
- Content
The configuration ladder is now one lesson instead of five pages
The configuration ladder is now a single lesson with a comparison table of all four rungs at the top, instead of five separate pages. Every old address still works. Two things moved into lessons of their own: how much of your money belongs hot versus cold, and the two options that are not rungs — BIP-85 and Shamir backup.
- Content
Fixed: some “how →” links on the quiz and checklist pointed at the wrong lesson
Fixed: sixteen “how →” links on the setup finder and checklist opened a real page, but not the one that answered the step you clicked. All of them now point where they say they do.
- Security
Correction: a passphrase kept only in your head is not a defence
We got one wrong and we are fixing it in the open. On “how people actually lose Bitcoin,” the defence against a physical attack said to keep your real coins behind a passphrase that lives “nowhere but in your head.” That contradicted the rest of this guide — a passphrase kept only in memory is the single most documented way people lose passphrase-protected Bitcoin — and it contradicted the same page four items earlier. The decoy idea is sound and stays. What changed is where the passphrase lives: backed up as carefully as the seed, and stored somewhere the seed is not.
- Content
The course now opens with twelve rules — and every lesson teaches one of them
The course now opens with twelve rules — one plain numbered list, no links, two minutes to read. Follow them and you have done the important part. Every lesson after it teaches one of those rules in full and says which. Several lessons were merged in the same pass, and every old address redirects.
- New
Learn is now a course — five numbered levels, and every lesson points to the next
The guides became a course: five numbered levels in reading order, with every lesson pointing to the next — so you can read the whole thing front to back without going back to the menu.
- New
The guide is reorganised — learn first, then act, and your checklist is now built for you
The site is organised around one idea: learn first, then act. The menu separates the course from the tools, and your checklist is now generated from your own plan rather than being one long list for everyone.
- Security
New: our published selection standard — every wallet now rated in three tiers
Every hardware wallet is now rated in three tiers against a published standard: built for cold storage, built for spending, or does not clear our bar. Two of the criteria are hard security requirements; the rest decide whether a device suits money you are locking away for years. The reasoning for every device is written out.
- Content
Sharper risk defenses + a quick way back to your plan
On “how people lose Bitcoin,” the physical-attack defence gained the decoy-wallet idea: your recovery words alone open only a small believable stash, while the real coins sit behind a passphrase. (The “keep it in your head” part of this was wrong, and was corrected on 30 July 2026 — see that entry.) The exchange-failure defence now points at Bitcoin-only services rather than multi-coin exchanges.
- New
Your recommended wallets follow you to the comparison page
Wallets the setup finder recommends for you are now marked on the comparison page, so you can spot them while you browse.
- New
The tools now talk to each other — and a clearer menu
The tools now talk to each other: the setup finder remembers the wallets you own and the answers you have already given, and welcomes you back rather than starting from scratch.
- New
New: compare collaborative custody services — honestly
New: an honest comparison of six collaborative-custody services, where you hold two of three keys and a Bitcoin service holds the third. Compared on KYC, whether you could recover without them, insurance, fees and minimums.
- New
Rework the devices in your plan · encrypt your plan file · a slimmer page
Your plan is now fully reworkable — move devices between key slots, set one aside as a spare, or retire it. You can also download the whole plan as a password-encrypted file.
- New
Your plan now knows which wallets you own — and maps the road to your setup
Your plan now knows which hardware wallets you already own, and maps the road from where you are to the setup you are aiming for: which key slots your devices fill, and what is still to get.
- New
Nostr sign-in now survives your return — fixed the failed save on a second visit
Fixed: signing back in to Nostr on a return visit could fail to save. Your session now resumes properly.
- Security
Nostr save now hides which app it came from
When you save your plan to Nostr it is stored under a scrambled tag derived from your own key, rather than a plain “bitcoinkeys.guide” label — so nobody can scan the relays to build a list of this guide’s users. The contents were already encrypted; this closes the last piece of metadata that advertised the app. Your key still signs the event, so someone who already has your public key could confirm it.
- New
The quiz now starts from where you are — your plan as a journey
The setup finder now starts from where you are today and frames the result as a journey — a roadmap from your current setup, never a verdict on it.
- New
BIP-85 demo: type any index and watch its wallet appear
The BIP-85 demo now lets you type any index and watch that child wallet appear.
- New
Save to Nostr sits right beside “download my plan” — and remembers you
Save to Nostr now sits beside “download my plan” as one of the save options, and remembers you between visits.
- New
The quiz now leans toward self-sovereignty — no funnel to services
The setup finder now leans toward holding your own keys. Where multisig fits, it offers two equal paths — do it yourself, or use a service — with the honest trade-offs of each, and the do-it-yourself option leads.
- Price
Trezor Safe 3 dropped $79 → $59
Trezor Safe 3 dropped from $79 to $59 — a permanent cut, confirmed at the vendor’s own store.
- New
The interactive “deeper dive” tier grew to 11 demonstrations
The interactive “deeper dive” tier grew to eleven demonstrations, all running real cryptography in your own browser on throwaway keys.
- Price
Wallet prices re-checked against every vendor’s own store
Corrected the Blockstream lineup — the $79 device is the original Blockstream Jade (no camera); Jade Plus moved $149 → $169. Confirmed unchanged: Bitkey $250, Foundation Passport Prime $349, the Coldcards, and the Trezor Safe line.
- Security
Hardened the site and removed visitor analytics
Added strict security headers (CSP, HSTS, and more) and switched off the Cloudflare analytics beacon at the source — so the promise that nothing about your visit is sent, stored, or logged is now literally true, not just intended.
- Devices
Wallet comparison expanded to 11 devices
Added the Coldcard Mk5, the full Trezor Safe line (3, 5, and 7), and both Blockstream Jade models — so the comparison covers every current model from the major independent vendors, not just one per brand.
- Specs
Foundation Passport → Passport Prime
Foundation discontinued the $199 Passport and now sells only the $349 Passport Prime, a multi-function security platform. We re-derived its trust badges honestly: Bitcoin-only and air-gapped both dropped to “partial” (it runs other apps and adds Bluetooth/NFC), while it gained an independent security audit.
- New
BitcoinKeys.guide launched
The readable self-custody guide went live — the configuration ladder, how-to guides, an honest 11-device wallet comparison, the setup quiz, and a Lightning tip jar, all with no affiliate links and nothing to sell you.
A scheduled checker re-reads each vendor's own store and flags us when a price or spec drifts from what's on this site. A human confirms every change before it's published here — so a bad reading never becomes a wrong recommendation. The wallet comparison carries the same “last verified” date you see above.