In February 2025, Bybit’s authorised signers approved what appeared to be a routine internal transfer from cold storage. They were using hardware wallets, multisig protection, and the operational protocols considered industry best practice. The transaction they signed was not the one displayed on their screens. The result, $1.4 billion gone in a single afternoon, became the largest cryptocurrency theft in history and a working demonstration that even self-custody, when built on a compromised software stack, is only half a security decision.
That gap, between choosing self-custody and actually achieving it, is quietly driving a new conversation in crypto security circles. Most users still evaluate wallets the way they evaluate apps: interface, supported tokens, and ease of use. What's getting harder to ignore is what lies beneath the surface. The way a wallet manages key storage, transaction signing, and network exposure matters far more than it once did, and not every wallet approaches those fundamentals in the same way.