Alex Bergeron: You Are Your Own Single Point of Failure
The ColdCard vulnerability cracked open something I'd been building toward for months: the 'no trusted third parties' dogma wasn't just philosophically incomplete, it was actively dangerous at scale. Alex Bergeron came on to talk about what comes next.

↓ Jump to the video and timestamps
The ColdCard vulnerability hit like a cold bucket of water. Not just because of the exploit itself, but because of what it revealed underneath: a Bitcoin security culture shaped by hubris, peer pressure, and a dogma that had long since stopped serving the people it was supposed to protect. When I looked around in the weeks after it broke, I kept coming back to the same uncomfortable truth, the "no trusted third parties" doctrine, applied rigidly to self-custody security infrastructure, had left billions of dollars in life savings guarded by small teams operating without the institutional framework that kind of responsibility demands.
That's what I wanted to talk through with Alex Bergeron. Alex runs Arc Labs and is the person behind Arcade, and he's been doing the most interesting frontier work in Bitcoin security and payments for the past couple of years in near-total obscurity. The timing felt right: the ColdCard reckoning had just cleared the air, Arcade Vault had just gone live as a proof of concept, Arcade Intents had just launched in the wake of Boltz going down, and Prem AI had announced their CyberScam security agent that morning in partnership with Arc Labs and Breeze. There was a lot to get into.
What came out of the conversation is something I've been thinking about ever since. Self-custody doesn't mean doing it alone. Distributed trust isn't a betrayal of Bitcoin's ethos. And the builders who understand that collaborative finance, Alex's coinage, and the right one, is the productive middle ground are the ones who will own the application layer when this market is ten times larger.
Key takeaways
- The ColdCard incident was a reckoning with the "garage band shop" security model. A small team managing the security infrastructure for what are now life-savings-scale amounts was defensible in 2018. It stopped making sense long before this broke. Hubris and groupthink suppressed anyone from saying so out loud.
- Self-custody doesn't mean doing it alone. Distributing trust across a mobile passkey, a vault co-signer, and a hardware wallet with a time-locked escape hatch eliminates single points of failure without surrendering sovereignty. You are most likely your own biggest single point of failure, and that's the lesson.
- Arcade Vault gives Bitcoin companies a white-label collaborative custody layer. River, Bull Bitcoin, and others could deploy this so customers get institutional-grade security while keeping their keys. The worst-case scenario is your checking account gets drained, not your life savings.
- Arcade Intents replaces the Boltz single-API model with an open marketplace. An RFQ-based protocol lets wallets ping a marketplace of Lightning swap providers rather than a single central endpoint, making the infrastructure censorship-resistant and resilient to the AI-driven attacks that took Boltz offline.
- AI is simultaneously the attack surface and the fix. Permanent automated auditing of every pull request is replacing the quarterly security review. Competing frontier models cross-checking each other's code is the new security floor, and formally verified systems are the ceiling we should be building toward.
- The builders who reject identity-politics Twitter in favor of shipping are the ones who survive bear markets. The ROI on engaging in Bitcoin Twitter wars is very low, if positive at all. Vibe-coded prototypes that a developer can evaluate are a legitimate contribution. There has never been a better time to build.
The ColdCard Reckoning, What Actually Went Wrong
Alex put it plainly: everyone was swimming naked. What made that especially stinging was that Bitcoiners had spent years mocking DeFi protocols for their security failures, laughing at the shitcoin code bases, feeling righteous. Turns out we had comparable exposure baked into fundamental infrastructure that hadn't received the scrutiny it deserved.
The part that stuck with me most from Alex's telling, and from what I was hearing in real time during Spaces in the days after, was the number of people who had hundreds of thousands of dollars secured on ColdCard devices and genuinely did not know how to move their own funds when the moment came. Something went deeply wrong upstream, in how people were put in that situation to begin with.
My own read on how we got here: hubris and peer pressure. The "no trusted third parties" doctrine became a totem. Questioning it got you socially penalized in the OG maxi community. Innovation that looked like it introduced any form of trust, even bounded and engineered trust, got dismissed before it could prove itself.
That suppressed a decade of creative thinking that could have given people much better options. The ColdCard entropy bug that went unguarded is the bill for that era finally coming due.
Alex's framing is the right one: a 3-4 person shop managing security infrastructure for what are now life-savings-scale amounts may have made sense in 2018 or 2020, when the dollar value of what those devices held was significantly lower. It stopped making sense as Bitcoin's price ran. The reckoning was overdue. And one of the things this cracked open, which Alex put well, is that we needed new leaders to emerge and say: okay, this was the garage band era, and the garage band era is over.
The "No Trusted Third Parties" Dogma and Its Cost
Here's the thing about the dogma: it wasn't wrong about the base layer. Bitcoin was invented because you cannot trust any single entity with the issuance and management of a reserve currency. But somewhere along the way, "don't trust the money printer" became "all forms of trust must be eliminated from every layer of the stack," and that's where things broke down.
Alex walked me through a piece of history worth sitting with. GreenAddress, which became what is now Blockstream Green, was advertising a 2-of-2 co-signing model back in 2014. The GreenAddress server would co-sign your transactions, enforcing daily spending limits you set at account creation. And critically, if the server refused to sign for any reason, you had a time-locked backup transaction you could broadcast yourself. The server could never steal your money. It just provided valuable services: spending policy enforcement and a recovery path.
That model fell out of favor not because it failed, but because it looked centralized. Lightning came along and captured everyone's imagination with the vision of a fully distributed payment network where nobody holds funds and there's no central node that can censor you. We poured all our resources into that.
Then, without quite noticing it, we walked it back. What is an LSP? It's the admission that not everyone is going to run a Lightning node. We shifted the burden back to a server.
Arcade formalizes that client-server reality and makes it modular, open, and honest about what it is.
I noted on tape that this same lesson applies to borrowing good ideas from DeFi. There's been real dogma about even attempting that in Bitcoin circles. It's time to brush it away and look with clear eyes.
Not every DeFi idea is worth importing. But refusing to even look is how you end up behind.
Arcade Vault, A Blueprint for Collaborative Self-Custody
The closest thing that existed before Arcade Vault was BitKey, Block's self-custody product. Alex uses it himself and says the UX bar it sets is the right one to target: no seed phrases, passkey and Face ID as key material, a co-signing server that enforces spending policies, and a hardware wallet as the sovereign recovery path. It's a real product with open-source code and a screen on the latest device so you're not blind-signing.
Arcade Vault takes that model and makes it modular and white-labelable. Here's how the architecture actually works.
You have two Taproot accounts. The spending account is your checking wallet: weekly or daily allowances you negotiate with the server when you set up. That account is 3-of-3: your mobile device via passkey, the vault operator (say, River or Bull Bitcoin deploying their own instance), and Arcade as a global coordinator. All three need to sign for spending transactions to go out.
Arcade itself enforces your spending policies. Even if the vault operator is compromised and tries to push a transaction that bypasses the limit, Arcade will catch it.
If all the servers go dark, you still have access to your money. Your device plus your hardware wallet can spend from the vault, it just takes more time, there's a time delay built in. That delay is the key feature: if your hardware wallet is compromised and an attacker tries to drain the wallet (exactly the ColdCard scenario), you have the window to claw back the transaction before the funds are gone.
The worst-case scenario in this setup is that your spending account gets drained. Your life savings, in the savings Taproot path with hardware-wallet-only access, are never reachable by the co-signers. The checking account takes the hit. The life savings don't.
Companies like Unchained have been building collaborative multisig models since 2016 and proved out the core thesis. What Alex is doing with Arcade Vault is making that infrastructure composable for any Bitcoin company that wants to offer it to their own customers, without those customers having to know the underlying plumbing.
Arcade Intents, Decentralizing the Swap Layer After Boltz
Boltz was, by any fair measure, the gold standard for Lightning swaps. They ran a clean operation, had a long track record, and no customer funds were lost on their end. But their architecture carried a structural vulnerability: open-source code plus a central API endpoint equals a massive, well-documented target. The moment AI-driven attack tooling matured enough to probe that surface systematically, they were exposed.
Boltz wasn't alone. By Bergeron's account, LNP2P had to shut down. Garden Finance had issues. Zeus was also affected.
The pattern is clear: any service running a public-facing swap or bridge endpoint became a priority target for AI-assisted attackers who could find and probe vulnerabilities faster than any human red team could defend against them.
Arcade Intents is a direct response. Instead of routing all swap requests through a single API, it creates an RFQ marketplace, request for quote, where wallets ping a pool of pre-approved service providers and select the best available route. Voltage, Zeus, Amboss: any Lightning provider can advertise into the marketplace by running a lightweight server interface attached to their node.
They don't have to publish a public endpoint. They don't have to maintain an integration with every wallet in the ecosystem. They show up in the marketplace once, and the wallets find them.
Everything is HTLC-atomic. No chain of custody. If one provider blacklists an address, the marketplace routes around it. If one provider goes offline entirely, the wallet selects another.
The single point of failure is gone by design.
Alex also mentioned that Intents extends naturally into credit markets. Rather than shopping individually between Bitcoin lenders, and here he named companies like Ledn and Lago as examples of the type of participants who could plug in, a wallet using Intents could surface the best loan terms across all participating originators in a single interface. The user gets a competitive market. The originators get distribution without surrendering their client relationships.
Collaborative Finance, Not DeFi, Something Better
Alex coined the phrase "collaborative finance" in this conversation, and I think he's right to reach for it. It's not decentralized finance. DeFi, at its ideological core, treats every counterparty as an enemy to be eliminated from the equation. What Alex is describing is something different: parties agreeing to a set of rules, collaborating within them, and retaining individual escape hatches if the collaboration breaks down.
He reached for Nick Szabo's framing: smart contracts as elevated business logic, not trustless utopias. Szabo was writing about how to take the kind of flowchart processes that live in accounting textbooks, auditor signs off, transaction routes here, treasurer reviews, and so on, and lift them into software. The goal was never to eliminate trust. It was to make trust legible, bounded, and auditable.
The Morpho comparison that came up is instructive. The pool model in DeFi lending creates shared bad-debt exposure: if someone in your pool borrows against a shitcoin collateral that goes to zero, the pool can't liquidate it, and every participant in the pool absorbs that hole. Bitcoin-native credit markets built on something like Arcade Intents don't have that problem, because the collateral quality is set by Bitcoin and the isolation between borrowers is structural.
Alex's read on where Arc Labs is heading is that they're moving from pure protocol research toward being first-to-market on the applications they think are best built on Arcade. Open credit markets, hash rate derivatives, options on Bitcoin treasuries. The infrastructure exists. The question is who ships it first.
AI as Attack Vector and Security Floor
At the time of recording, Prem AI had just announced CyberScam, their proprietary security agent for vulnerability detection, built in partnership with Arc Labs and Breeze. The announcement was that morning. The broader context it sits in is worth understanding.
The AI-driven attacks we saw hit Boltz and others in this cycle weren't random. Open-source code plus a public endpoint is now a recipe for systematic probing at machine speed. Every dependency in your stack is a potential vector. The attack surface got much larger, much faster, than the Bitcoin security community had planned for.
The response Prem is building, and that the Bitcoin Red Team (supported by individual donors and OpenSats) is doing from a different angle, is a permanent audit rather than a quarterly one. An agent runs continuous scans. Every new pull request gets cross-checked before it merges.
The quarterly security review model doesn't work against an adversary that can probe continuously. So the defense has to be continuous too.
Andrew Cooks, Arc Labs' CTO and one of the maintainers of BTCPay Server, had a front-row seat to this. BTCPay Server was hit. Andrew has been doing remediation work while simultaneously helping Alex build out new architecture. That's the reality on the ground: the people hardening the ecosystem are the same people who got hit.
Alex's broader thesis on the AI security trajectory is one I share. Competing frontier models cross-auditing each other's code as it's written is the new security floor. Formally verified systems, where you can mathematically prove the integrity of the codebase, are the ceiling.
AI may actually make that ceiling reachable for more of the stack than anyone thought possible a year ago.
The degradation cycle in frontier models is real and I've seen it firsthand. You get addicted to the crack of whatever the current frontier model is. Then massive demand hits, GPUs get diverted to training the next one, and you watch the thing you were relying on visibly degrade. Then a new model drops and the cycle resets.
It's not conspiracy, it's just the economics of compute. But the trend line on what open-source local models can do keeps going up, and that's the part that matters for sovereignty. AI reasoning infrastructure has its own vulnerabilities, and local models running on your own hardware are the hedge against that concentration risk too.
Alex built the Arcade Vault proof of concept in 4-5 days. A complex Bitcoin-interaction codebase that would have taken a small team two years before. That's the actual state of the tool.
The attack capability improved dramatically, and the build capability improved alongside it. The same force that made Boltz vulnerable is the force that lets a founder vibe-code a working vault prototype in under a week.
What This Means for How You Hold Bitcoin
I told Alex on tape that the last three weeks have involved a lot of introspection and reflection, and that lessons have been taken very seriously. I'm not going to get specific on tape about what I've changed personally, that's not the kind of thing you broadcast. But I'll say this: the conversation changed how I think about risk at a pretty fundamental level.
The practical shift is this: if you are the only entity standing between an attacker and your life savings, you are your own single point of failure. That was always true in theory. ColdCard made it undeniably true in practice for a lot of people.
The right response is to architect your custody so that no single compromise, not your hardware wallet, not your phone, not any co-signing server, can drain your life savings before you have a chance to respond.
On the AI side: most people I talked to last week are using ChatGPT and Claude as a slightly better Google search. That leaves enormous value on the table. The productive use is building agents, seeing how they interact with each other, and integrating them into your actual systems. Once you see it working, once you watch something get built in four days that would have taken two years, pessimism becomes very hard to maintain.
And on the building side: you don't have to ship a production product. A vibe-coded proof of concept that a developer can evaluate and say "that's actually pretty cool, here's how we make it viable" is a legitimate contribution. That's exactly what Alex has done with Arcade Vault. The alternative is yapping about it on Bitcoin Twitter, and the ROI on that is very low, if positive at all.
About Alex Bergeron
Alex Bergeron is the co-founder of Arc Labs and the person driving Arcade, a Bitcoin application and protocol stack built around programmable co-signing infrastructure and the ARK batching protocol. Arc Labs built one of the first mainnet implementations of the ARK Protocol and has since expanded into collaborative custody tooling (Arcade Vault) and Lightning swap markets (Arcade Intents). Alex is a recurring voice on Bitcoin's application layer and has been working on Arc Labs through the full duration of the most recent bear market.
Sources mentioned
- Coldcard's Source-Available License Left a $100M Entropy Bug Unguarded (TFTC): the ColdCard vulnerability, what was exposed, and the license model that left it unguarded
- Every Major AI Lab's Reasoning Was Exposed by a Single Bad Key (TFTC): AI infrastructure concentration risk and the security implications of centralized reasoning systems
Watch the conversation
Timestamps
- 0:07 - Intro: Bitcoin wins when central banks lose their minds
- 1:09 - Catching up: quantum fud and price action since March
- 4:30 - The ColdCard reckoning and what it revealed
- 15:37 - Stripe's Tempo stablecoin rails and why Bitcoin has to respond
- 20:00 - The client-server reality: GreenAddress 2014 to Arcade today
- 32:36 - SigBash, AnchorWatch, and the programmable co-signer design space
- 40:00 - Arcade Vault: the two-account Taproot structure explained
- 50:21 - Arcade Intents: rebuilding the swap layer after Boltz
- 1:06:52 - Collaborative finance vs. DeFi: the Morpho comparison
- 1:23:12 - AI as attack vector and permanent security audit
- 1:36:12 - The frontier model degradation cycle
- 1:45:12 - Building in public: vibe-coded prototypes as legitimate contributions
- 1:49:36 - Closing thoughts: bear market survival and what comes next
Sponsors
- Cash App: For a limited time, new customers can get $21 added to their balance. Just use code TFTC10 when you sign up, and send at least $5 to a friend in the first two weeks. cash.app/app/TFTC
- Square: For up to $200 off eligible Square hardware. square.com/go/tftc
- Bitkey: Use code TFTC10 for 10% off the new Bitkey. bitkey.world
- Aven: aven.com/bitcoin
- CrowdHealth: joincrowdhealth.com/tftc
- Unchained: unchained.com/tftc
- Salt of the Earth: drinksote.com/tftc
Frequently Asked Questions
The exploit itself exposed a critical entropy issue in ColdCard's design, details are in Coinkite's own disclosure. But the deeper issue it surfaced was structural: a small team was managing security infrastructure relied upon for what are now life-savings-scale amounts of Bitcoin, without the institutional audit frameworks that kind of responsibility demands. The incident revealed how many users had significant funds on these devices and did not know how to move them when the moment came, a systemic failure compounding the technical one.
It means distributing your signing authority across multiple independent parties in a way that no single compromise can drain your holdings. Arcade Vault's model is a concrete example: your mobile passkey, a vault operator like River or Bull Bitcoin, and Arcade as a coordinator each hold a key in a 3-of-3 spending setup, while your hardware wallet holds a sovereign escape hatch with a time delay. If your hardware wallet is compromised, the time delay gives you a window to claw back any unauthorized transaction. No single entity, including any co-signer, can move your life savings.
Both use a co-signing server to enforce spending policies and a hardware wallet as a sovereign backup path, and both are structured so the server can never unilaterally spend your funds. BitKey is Block's own vertically integrated product. Arcade Vault is a modular, open-source framework that any Bitcoin company, River, Bull Bitcoin, or any exchange or custody provider, can deploy as a white-labeled service for their own customers. The vault operator in Arcade's model can be the Bitcoin company the customer already has a relationship with, rather than Block specifically.
No, under properly designed collaborative custody. The co-signing server holds one key in a multisig setup, it can only sign transactions in combination with your other keys. By design, the server can refuse to co-sign (enforcing your spending policies), but it cannot initiate a spend on its own. The hardware wallet escape path, with its time-lock delay, exists precisely so that even if every server in the arrangement goes offline or is compromised, you can always recover your funds independently.
Boltz was taken offline by AI-assisted attacks that systematically probed their open-source codebase via their public central API. No customer funds were lost, but the infrastructure went down. The fundamental vulnerability was architectural: one public endpoint processing all swap requests is a clearly defined target.
Arcade Intents replaces that model with an RFQ marketplace where wallets select from a pool of Lightning swap providers, none of whom need to expose a public endpoint. Everything is HTLC-atomic, so there's no chain of custody. If one provider is attacked or goes offline, the marketplace routes around them.
Both, simultaneously. Open-source models are being used to probe codebases and find vulnerabilities at machine speed. That attack capability hit Boltz and others hard. The same capabilities are being used defensively: permanent automated auditing of every pull request, security agents running continuous scans of production codebases, and frontier models being used to cross-audit each other's output.
Alex Bergeron's read, and mine, is that the net direction is toward more security. AI-assisted formal verification could make provably secure Bitcoin software achievable for more of the stack than ever before. But the transition period is rough.
Alex Bergeron coined the term to capture something DeFi gets wrong. DeFi's premise is that every counterparty is an adversary to be eliminated from the equation through smart contract logic. Collaborative finance is the opposite premise: parties agreeing to a shared set of rules, collaborating efficiently within them, and retaining individual escape hatches if the arrangement breaks down. The goal is aligned incentives and efficient markets, not trustless utopias. Bitcoin's consensus rules are the only truly trustless layer. Everything built on top involves some degree of collaboration, and pretending otherwise is what left people stranded during the ColdCard incident.


