New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

The Custody Paradox: Security, Usability, and Who Gets to Verify | ETHSofia 2026

ETHSofiaTue, Oct 6, 2026, 12:00 AM

With Steffen Kux (Corpuscore.tech, moderator), Nikita Eriashev (Tangem), Skas (Trezor) and Nicolas Bacca (ZKNOX). Self-custody promises full control, yet every wallet still asks users to trust something. Moderated by Steffen Kux, hardware wallet builders from Tangem, Trezor and ZKNOX discuss what the recent Coldcard incident teaches, why open source is a means to verification rather than an end in itself, and why entropy is so hard to check. Nicolas Bacca argues the biggest competition to self-custody is now ETFs and banks and makes the case for multisig setups that grow with the user, Nikita Eriashev argues that simplicity is security for mass adoption, and Skas focuses on clear signing and showing actual balance changes. The panel closes on the future of self-custody and audience questions on Bitcoin multisig and hardware wallets. Panel at ETHSofia 2026, 24 September 2026, Sofia Tech Park, Sofia. Part of Blockchain Week Bulgaria 2026. Speakers ▸ Steffen Kux, Co-CEO & Co-Founder, Corpuscore.tech (moderator) Steffen is Co-Founder and Co-CEO of corpus.core, building trustless blockchain infrastructure. With 25+ years in software and distributed systems, he leads the development of Colibri, an open-source stateless client for trustless blockchain verification and pragmative adaptive privacy. LinkedIn: https://www.linkedin.com/in/steffen-kux X: https://x.com/steffenkux ▸ Nikita Eriashev, DACH Growth Lead, Tangem Nikita Eriashev has been with Tangem for more than three years, driving self-custody adoption and expanding the product's reach across Europe, America, and the Middle East. He believes Tangem Wallet is uniquely positioned to build a bridge between blockchain and everyday users worldwide, and he's extremely proud to have been part of that endeavor. LinkedIn: https://linkedin.com/in/nik-eri-755726271 ▸ Skas, Software Engineer, Trezor Fin-tech raised neo-cypherpunk worked for several software wallets, researcher, hackathon enthusiast, CROPS builder, EIP-nerd X: https://x.com/0xskas ▸ Nicolas Bacca, Chef at ZKNOX Nicolas is a co-founder of Ledger and researcher at ZKnox - interested in making hardware security open, understandable and affordable to all, currently accelerating this with AI LinkedIn: https://linkedin.com/in/nbasim X: https://x.com/BTChip Chapters 00:00 The panelists and their work 01:52 From Mt. Gox to today: the state of self-custody 04:20 Lessons from the Coldcard incident 07:04 How far can we trust our wallets? 09:08 Don't be evil vs can't be evil 10:14 Software wallets vs hardware wallets 12:09 Screens, clear signing and knowing what you sign 17:00 Does Web3 complexity hold back self-custody? 19:18 CROPS and self-custody for everyone 22:16 The future of self-custody 25:45 Closing thoughts 27:56 Q&A: Multisig on Bitcoin 29:03 Q&A: Why still use a hardware wallet? 30:22 Closing titles Blockchain Week Bulgaria: https://www.blockchainweek.bg ETHSofia: https://www.ethsofia.com Future Finance Forum: https://www.blockchainweek.bg/f3 Follow Blockchain Week Bulgaria X: https://x.com/BWBulgaria LinkedIn: https://www.linkedin.com/company/blockchain-week-bulgaria Follow ETHSofia X: https://x.com/EthSofiaBG LinkedIn: https://www.linkedin.com/company/ethsofia Telegram: https://t.me/+b-33LJUpAB5iODNk Nothing in this video is financial advice. About the organiser Blockchain Week Bulgaria, ETHSofia and the Future Finance Forum are organised by the Bithope Foundation, founded in 2014 by Vladislav Dramaliev. Inspired by Andreas Antonopoulos, it is Europe's first non-profit operating exclusively with bitcoin donations. Over more than ten years, it has supported 50+ charitable campaigns, and in January 2016 it co-founded the Sofia Crypto Meetup, now the region's longest-running monthly crypto event. https://bithope.org

Transcript

[music]

I'm going to be epic. Thank you.

[applause]

Thank you very much for this kind introduction. I think we don't need to introduce ourselves anymore. But I want us to have at least a very short introduction what we are doing and what is the the wish of our heart what we what should be done in our industry. So my name is Stefan Cooks. I'm the leader of the Code pre-team.

We're building this stateless client. And my wish of the heart is that we really enter or really bring to practice the manifesto or the trustless manifesto so that we have trustless data and privacy for all things we are doing in Web3.

Hi, my name is Nick. And yeah, I'm with Tangem. Tangem is a Swiss provider of hardware wallets. And our primary goal is bringing self-custody to the masses with our easy-to-use devices.

Yeah, so I'm Nikola. And at DKN Labs we are working on optimizing the crops primitive for self-custody both in software and hardware. We focus on cryptography so zero-knowledge proof, post-quantum crypto, everything that we find is not optimized we try to optimize it. Initially there are so that's just three people, two mathematicians. And right now we are basically our job is to optimize the number of tokens that we take from Claude.

So Claude is doing all the work and we are just optimizing tokens. So I can say I'm a token optimizer.

Hey everyone. I'm Scoss. I'm working on building future financial systems. Ideally they would be free, not free like beer but free like freedom. Yes, so working for Trezor as engineer.

Who of you was in this industry 15 or 14 years ago when there was this interest in hack on Mount Gox? Who was already there and did experience what happened there? Yes, some hands. So, I was there as well. So, actually this was the start.

It was for me it was the start to really think about self-custody. Now, people thought, "Okay, there is a nice exchange. We can keep our tokens there." And then they learned this doesn't work. So, let's start in our discussion to see So, what is the state of self-custody right now?

And what What does it mean at the moment for for the industry to have self-custody?

Well, I would say that self-custody that the topic in general in the industry has experienced a number of hits in the last year with the uh wallet vulnerabilities and hacks. And this is the first time I see uh like a small one but a backlash in terms of like uh users driving uh from back from self-custody to custodial services.

Yeah. So, maybe I will say I will say that today where self-custody has been the basis of our industry, it's facing two threats. Uh the first one is well, maybe the most uh the less obvious. I mean, people are trying to redefine what self-custody means. Uh so, today I mean, you have people that can block you from sending transaction and they will still tell you that you are using self-custody because you own your keys.

Uh but if you own your keys and you can't send transaction, then you are not really you're not really doing self-custody. Uh and the second one is that well, there are a lot of other solutions today for people that just want to be exposed to the value of the assets. Uh so, the worst competition we get from self-custody is actually the ETF and the banks. Uh so, we won on adoption but maybe we lost our soul. Uh we can discuss that.

Um I think a important thing about the self-custody that attracts a lot of people is the seamless user experience that custody can offer, and I think actually that uh a lot of things happened in the past couple of years on the uh base layer of Ethereum that unlocks uh much better use cases for uh self-custodial access to financial tools as well.

I don't know who recognized some of the hacks in the last weeks and months. So, it's not long ago we had something what was not anticipated for a lot of people. So, I talk from the cold case, a cold card hack. So, people doing exactly what they learned, they did not have their keys on an exchange, they did it store in a hardware wallet. And then it happened that nevertheless there was a problem.

So, what have people to learn when when it's about wallets? So, what is important to have your wallets, and what should we think about when we see these hardware wallets?

Um I think one of the very simple ways to for wallet to be more transparent to the user is to obviously be open source. Uh that let people uh verify and see uh the actual implementation, but it also should not give the fake uh feeling of security out of that because the code for the cold card was open out of there for a while, and nobody was just really looking inside of it. So, I would say that having open source definitely helps with this. Um Yeah.

Yeah. I would say that probably yeah, as I will I agree. So, we we have seen that things are very hard to verify even when they are open source. So, I think that one of the things that we can remind that we can learn from the Coldcard experience is that since entropy is super hard to verify for everybody, I mean, and even after the fact, if you look at the device as a black box, you can't really say if the random is really random. Uh so, the best lesson is probably just to mix your solution.

Uh we have nice ways to use uh multi-signature on Ethereum. I think it's probably the chain where this is the most developed. Uh so, if you have a doubt when using one solution, you can just add multiple solutions. And so, uh you have more security just because you know that you are not putting all your trust in the hand of something that maybe you are not able to fully verify.

Yeah, agree on that. But, I also think that the lesson another lesson that we should draw from it is that uh open source is is not a mean is not an end in itself, but rather a means to verification, yeah? And if not no one is doing that verification, if no one reads and inspects the code, and they do not have incentives to do that, then uh the whole security model breaks. Uh to avoid that, we need audits, and we also need bug like functional bug bounty programs.

I think So, I mentioned the beginning that that's one of my passions is to have trustless information or to have trustless things. And all we know there is no trustless thing. We always have to trust something. So, how good can we trust the wallets and the hardware we have already on the market? Is it possible that we really trust them?

Or do we have some reasons to mistrust them?

Mhm. I think being able to trust, but verify is really important. Um definitely with um with what you said and the wallets may ask users to trust all the things. I guess what matters is if the wallet is providing the alternative way which would allow users to do what they wish without the defaults of the wallet to be enforced.

Yeah, I think the most important factor to consider is time because now with time you can verify pretty much everything. I mean you have those wonderful tools. I mean with AI today that can basically let you reverse engineer anything you want. So maybe not hardware yet but all software is open source now because of AI. So that's something which is super interesting but again you don't want probably to learn new stuff and you don't want to spend a lot of time on it.

So I would say that the level of trust you can give in one solution is basically the amount of time you're ready to spend on it. So it's really it's really really personal but in my opinion it's very difficult to it's very difficult to fully trust something and that's the reason why we have multi-sig. So just to get back to practical things.

Yeah, there is always a certain element of trust not just in in in in in the wallet industry generally in our life but yeah, just minimize the the the scope of that trust to to the bare essentials like and everything else should be examinable.

So maybe some of us remember when Google started 20 years or 25 years before they had this rule don't be evil. And in the in the blockchain in the web three world we changed it to can't be evil. I think this is a much stronger mechanism than do not something bad because you decided instead of you cannot the software and the hardware cannot. And I think this is the very important thing when we talk about wallets so that we produce technology which can't be evil, which is by design secure. Of course, we have to trust nevertheless some of the hardware things.

So myself, I cannot evaluate the chip. That's not something I know. But I can evaluate if the concept, if the whole structure is something which really can work and is by design secure. So when we see today we have always software wallets, we have these hardware wallets. So what are the benefits for from each of them?

So where should I use a software wallet and where should I decide to have a hardware wallet?

Well, uh let me begin. Um I would draw that discussion uh to the like usability and security paradox here. Those two things need to be combined in a neat way so that you provide the best user experience and but not at the same time not at the at the expense of uh the security.

Yeah, so I think that might tell something that all the three participants on this panel uh worked on hardware wallets. So maybe uh I think for security hardware wallets are absolutely essential. Uh I would say that nobody should be using uh the signing function of a software wallet. So software wallet can offer a very good interface. Uh but no with AI again, uh sorry, I'm speaking a lot about AI.

Uh anybody can basically hack you uh and if they hack you the first thing they will they will do is steal your keys because uh there is an immediate revenue uh when you steal keys. So the only way to protect against this is to use hardware wallets. And today I don't really see how you can handle crypto without using hardware wallet.

Um yes, the exact distinction would be uh that in case of um somebody malicious trying to compromise a user, they would uh need to separately, uh depending on the user setup, either compromise the computer together with the device to trick user into uh doing something malicious. But, I would also want to say that ideally users would have all the solutions composed and um just trying to make the uh way much harder for the attackers. Like, using multi-sig setup as uh yeah, people can create pretty safe setups even with the software wallets.

So, now we have some representatives of representatives of different approaches on the stage. Let's say we have hardware wallets which have displays, we have some which have no displays. So, what would you say is the best approach? Maybe there are not one single best approach, maybe there are different applications, but from your view, what is the best approach and why does it really help the user to know what he signs?

Um I would say kind of trying to highlight a situation that everybody probably realize what I'm talking about, but having a device having a screen is quite useless if you don't understand the information that is being displayed on the screen. And um in addition to the clear signing issue, I would say that um the industry is also uh can potentially improve of uh what users can actually trust and what they see on the device. For example, the changes of the balances that they can see and assert that that's the exact change of balance that would um happen for the user, but at least being able to uh catch something malicious as the last line of defense, I think it's already definitely worth it. As I described, our goal is mass adoption of self-custody. That's why we will look at the problem through through that lens.

And for us, like from our experience, uh simplicity is in fact security. So, we try to abstract as much technology for the end user so that you Yeah, you are preoccupied with the central things of really retaining control over your crypto and yeah, using it for for everyday transactions.

Yeah, and I would say it's really it's really depends. Again, it's very personal depending on the amount that you are holding, the the trust that you are putting in different things. But yeah, I will I will still advertise for multi-sig with hardware wallets because I think the great thing with a multi-sig setup is that you can make it evolve as you learn and depending on on how much how many assets you hold as well. So, it's a very powerful thing that you can start doing with only one key and then you can make it evolve a little bit later. I will definitely support most solutions using that and making them as easy to use as possible as you mentioned because of course if your solution is not easy to use then nobody is going to use it.

So, when I have my wallet and see on the wallet or on the software what I have to sign. So, this So, I remember some years before we had hardware wallets with very small displays where I only could see some letters. It was sometimes really difficult to see what I'm signing. Also, especially when we talk about bigger transactions, interacting with smart contracts, it's hard to see what I'm really signing. So, how can I trust the wallet when I not really understand what I'm signing?

Um yes, exactly. Up to the point, that's what I mentioned as this case of trying to make the user experience understandable for the user. And instead of providing the description of the smart contract function that has been called, user would see the actual balance changes, which uh what user is looking for, probably. Um.

Mhm. Yeah, so there has been a lot of evolution in in what we call now clear signing. So, there is still a research group, but I would say that it will program is leading the way on that and making transactions easier to understand for people. Of course, this still doesn't solve the problem that you might not be able to verify the transaction on all your devices. But, I think that on the in the future, verifying everything might not be the best approach.

The way I picture the future, I mean, is working with devices that would basically validate your user profile and enforce it. For example, you would say, "I'm going to invest. I'm going to rebalance my yield." And in that case, the device will lock you in functionalities that can only be used to rebalance your yield and not send your assets to someone else. So, that that's one way I think that we can manage to overcome that because even if we manage to make it very very clear to understand what you're signing, it will still be hard to understand.

Mhm. Yeah, correct. And also transaction simulation tools are evolving and wallets are implementing them. So, it it it's it's also kind of fits in that philosophy of meeting the user halfway and helping them to um, yeah. Um.

Overcome the the technical difficult difficulties if they do not have the expertise.

So, I personally I have a a good benchmark to evaluate web three software. So, this is my brother. So, he's an engineer, but he has nothing to do with the web three world. And always when I have some ideas in the web three world, I pitch it to him. And then we talk about it and I try to see if he understands it.

So, and when we see a lot of things in the Web3 world, it's still very complicated. Not to understand where I I I have here I have to connect the wallet to it. So, do you think that this complexity of Web3 stops [snorts] people from using things like wallets to have self-custody because they are lazy or don't understand it?

Um I think yes, and that's one of the reasons why users are choosing uh user experience that is more trustful. But the best thing about self-custody is that if you do it once, you can like repeat it for any any of the chain. And the upside that you actually learn is very useful for the rest of the activity in the industry, I'd say.

Yeah, I think what we offer is pretty unique. I mean, we offer people to own their own money and there is not really any solution that would provide that in the world. And this comes with a little bit of friction, but that's probably the price of freedom, at least in my opinion. So, we can make the UX better, of course, but it will never be as good as a UX which is completely centralized. And yeah, I'm okay with that and I think people who see the value of crypto will be okay with that as well.

And we have seen that in countries where the money is basically crashing, people have absolutely no problem using crypto. I mean, they are not asking themselves any questions. They are just using it because they can't live without it.

Yeah, like returning to your question, there are different people, yeah, of course. A lot of the developers among us, they will not be deterred by uh complexity of any kind. But if we speak about mass adoption, yeah, then uh it will be achieved not by educating people, but rather than but rather by removing the need to be educated whatsoever.

Today, some presentations earlier we we heard about crops. So, that's a very important thing that to think about censorship resistance, about privacy. And when we now combine this with self-custody, so I have to look for my keys by myself, I have to do things for privacy, I have to use software which makes it secure that I I'm not censored. Does or do we have ways that we make this easy available for our users? Or is there something that we need to live with the compromise that self self-custody will be the fear for people who are educated and willing enough to use it?

Or can we yeah, bring this somehow together?

I think depending on the what people actually what's the use case, the level of privacy they're trying to achieve would be really fun for somebody. That would be the whole network stack. For somebody it would be just the confidentiality. But it definitely unfortunately cost with at least the cost that people need to invest into learning things as well as sometimes their user experience. But like honestly, the situation is getting much better.

And I personally believe that if you have will have unconditional native privacy.

I would say that crops begin with self-custody. You can't really achieve crops without self-custody. So, for the complexity of self-custody, see the previous question.

Yeah, my take is there is always a certain level of complexity and we need to get users on this learning curve and we do that by uh simplifying onboarding and there are already like nice solutions to that. We have our own proprietary uh like onboarding uh mechanism. There are MPC wallets, there are um social recovery tools. Yeah, so we are closer to that uh and rather well than several years before.

Yeah, I I really think it in the same direction. We need to simplify these processes. We need to verify everything as automatically as possible without the user having to interact. We have to bring privacy in our products without the user having to decide what have I do to have it private. And I think if we can bring this together and then build products on top of it, we could have much better products which hopefully begin to be uh usable by the mainstream.

So, and this leads us to the last topic we have to discuss today. So, we have now interesting wallet solutions. We have interesting software solutions. The best thing is when we uh bring it together. Uh so, when I have my multi-sig and my keys in a hardware wallet, this often is the best situation.

So, but what do we really need to develop for the next generation of self-custody that we really can take the users where they are and help them to use it without risk not to understand what they are doing. So, what or how has the future of self-custody to look like when we start from where we are now and look into the future.

I think the complexity definitely going to go down. It's just impossible to like make it even worse than now for users. So I'm sorry. I think it's only going to get um eventually better. We also have an interesting task of the post-quantum migration in the next 5 to 10 years.

So it's also going to be interesting challenge. Um I think also we can expect a lot of innovation on the programmability layer and the counter-abstraction for providing similar use cases that Nicholas described for this kind of enforcing certain specific rules uh for the users.

Yeah, I think I think on the good news side is that we have worked a lot on tech, and today we have the best tech possible to offer all this. I mean, without too many too much complexity to the user. Uh one thing that we need is a push, and maybe to show the way, I mean, a little bit more to users. And for that, I'm very happy to see that the Ethereum Foundation has decided to enter the wallet space uh with something like Kwaku. Um because we need we need to have something that shows to the users that privacy can be easy, and maybe, I mean, offer different protocols access to different protocols in the same way.

Uh there will still be a little bit of friction, but yeah, as I said before, we can't really remove it. And I spoiled you with that answer, but for me, the future of self-custody is that in the end, you will switch between profiles, and the way those profiles are implemented will be very likely with zero-knowledge proofs, but that's well, that's pretty I mean, that's pretty technical. Uh but the idea is that you will still own your money, but you will be able to say that for an operation that you are doing, you are going to use a given profile that protects all your assets. And this is also very compatible with AI agents, uh because I think that more and more people will use AI to manage their finances, uh their assets in the future. Uh and so crypto needs to work along with that, and this is, in my opinion, the best way to achieve it.

Yeah, another piece of good news is that blockchain technology itself is becoming mainstream. We see traditional finance going on chain. You're now able to even own stocks in a self-custodial way. And well, another example is in the EU digital identity wallet is being developed. Yeah, so things like zero knowledge proofs and stuff like that allow you to well, basically keep your data locally.

Yeah, referring to the previous speaker and yeah, and only reveal the information that is really relevant when you sign a transaction.

Thank you very much. So, let me round up a little bit our discussion. We discovered self-custody is still very important and it becomes more important when we grow in this industry. And we also discussed that it's really important that we make it more easy to access for our users. So, that we have all the things we we have in this nice papers from trustless information over privacy over all the other security things that we bring this together and then help our users to easily use these the things and to get in web three experience which is much easier than it is now.

So, I think when we really work on this and find these good solutions and bring them together, then we can build things which are really easy to use and still very secure. We have only 2 minutes left. Maybe each of you, if you have something you really want to say to the world regarding self-custody, what would this be in two sentences?

[clears throat]

I like to think about self-custody like checking in at the hotel, getting the keys, and then being asked to leave your key at the receptionist. Uh well, okay. Some people comfortable with that, maybe maybe not me. So, everybody uh gets the right choice, but what's necessary is to provide it as a kind of basic human right. Um to everybody.

Um

Yeah, so to keep the optimistic mood, I would say that I'm afraid that we will need self-custody more and more in the coming years, so better get to it early. So, that's it.

Yeah, do practice it. Maybe it seems uh difficult, but once you start, everything is accomplishable. And we are here, so even after the panel discussion, reach out to us. We will provide more uh information about our solutions if you if you need it.

Okay. Thank you very much. I don't know if we have some time for questions from the audience. Are there any questions?

Let me have a look. I think we do, actually. Very, very interesting questions, and thank you all for engaging. Um we have a question about uh multi-sig on Bitcoin. Does it work, and can a newbie use it, and how?

So, multi-sig on Bitcoin.

Yeah, so maybe I can take this one. Yeah, you can. It's working more it's easier and easier. I mean, with descriptors today, I mean, there uh there are in mini script. I mean, there are a lot of improvement that have been done to multi-sig on Bitcoin.

Uh it's not as as flexible and as easy as Ethereum, because when you have a multi-sig profile on Bitcoin, you can't really change it. I mean, you still have to move your assets. Uh but if you're interested to look into that, I will suggest to look at uh two wallets, uh Sparrow and Niana. Uh, Niana targeting a little bit more inheritance, but yeah, this is definitely possible, just a bit less flexible.

Maybe one of the other gentlemen who wants to add something? If not, there is actually another question. And I think we've already tapped into this a little bit earlier today, but just once again, maybe for those who who weren't there. Someone is asking, "After the cold card incident, why should I use a hardware wallet?" So, some doubts here still, nonetheless.

Um, excuse me, what should I what? What was the

Why should I still use a uh hardware wallet?

Well, there are car accidents in the world, but we still drive cars, yeah? So, because hardware wallets solve the fundamental problem of uh retaining control over your coins, and that is why.

Uh, so, just quickly, it's like in this case of the check-in in the hotel, but imagine you got a bad key, the key that unlocks more room than it's supposed to. So, you just unlucky key.

And?

And the combination of technologies is is a a good solution. Now, if I have my key on a hardware wallet and have a multi-sig wallet where where I use different of these keys, then even if one key would have a problem, I don't have a problem. So, it's not only what techno- or the what hardware I use, it's how I combine the technology.

Yes. Ultimately, how we use it. Indeed. Thank you very much, all gentlemen on stage. Please give them an applause.

[music]

Automatic transcript — names and jargon may be misspelled.