, APAC
Photo by rawpixel.com via Magnific

Bitcoin’s latest hacks expose where trust really sits in Asia

By Eleanor Gaywood

Trust has dispersed into a collection of smaller, more transparent assumptions.

As Asia’s financial centres push further into digital assets, the question of how bitcoin is safely held and used is becoming increasingly important. In Hong Kong, for example, regulators have been steadily developing the framework around institutional participation in digital assets, with the Hong Kong Monetary Authority (HKMA) updating its guidance on the provision of digital-asset custody services by authorised institutions earlier this year.

That regulatory attention is timely. Recent security incidents have provided another reminder that owning bitcoin and securing bitcoin are two very different things.

The recent COLDCARD incident, where a flaw in entropy generation left hundreds of Bitcoin wallets vulnerable, quickly reignited a familiar debate. For some, it’s evidence of the risks involved in holding your own keys, for others it’s an implementation error in a security model that remains fundamentally sound.

It has now been followed by another incident involving Liquid Network, where around US$320m ($409m) in bitcoin was moved following the exploitation of a vulnerability, before most of the funds were subsequently returned. The two incidents occurred at different points in the bitcoin ecosystem, but together they expose the same underlying issue.

The real lesson is that bitcoin has changed where we place trust, but it never meant operating without trust altogether. Even the most technically capable rely on assumptions about the software, hardware, and cryptography protecting their assets.

Bitcoin didn't eliminate trust, it redistributed it
One of bitcoin's greatest achievements was removing the reliance on a central bank to issue money responsibly or a commercial bank to honour a balance. Consensus is instead established through mathematics, cryptography, and distributed networks. Over time, however, ‘don’t trust, verify’ morphed into the belief that bitcoin users no longer need to trust anyone or anything. In reality, trust has dispersed into a collection of smaller, more transparent assumptions.

The hardware wallet, for example, is bought because the customer has good reason to believe that the entropy generation and firmware have been implemented properly and scrutinised by people with the expertise to do so. Rarely will the customer inspect or test those things themselves because that purchasing decision still relies on trust, even if it looks different to how one might trust a bank.

Similar to a bank faltering and customers rushing to protect their assets and questioning their trust in said institution, the COLDCARD incident illustrates perfectly how an invisible assumption suddenly becomes visible. Entropy generation, key derivation, compiler reproducibility, cryptographic libraries, and code review rarely become topics of public discussion precisely because they usually work.

This distinction matters increasingly as more investors and financial institutions across Asia participate in digital assets. The question is moving beyond whether an investor wants exposure to bitcoin towards how that bitcoin is held, transferred, and protected.

Decentralisation doesn't remove responsibility
This is where discussions around bitcoin security often become unnecessarily binary. The temptation is to conclude that because one implementation failed, an entire custody model must be flawed, whilst others rush to defend the model by dismissing the incident as an isolated bug.

Neither response captures the broader lesson that implementation risk exists everywhere, and every approach creates its own dependencies.

A hardware wallet gives the holder direct control over their private keys but is still reliant on the security of the device. Multisignature custody can spread control across several keys but the security of the arrangement still depends on how those keys are generated and managed. Multi-party computation distributes the process used to authorise a transaction across multiple parties, useful for organisations that don’t want a private key sitting in one place, but introduces reliance on software and system design.

The mechanisms differ, but human judgement never disappears from the equation. Bitcoin holders have to decide which responsibilities they want to carry themselves and which they are comfortable placing elsewhere, a decision that should be based on the risks they can understand and manage themselves.

That is increasingly reflected in Asia's regulatory approach. Hong Kong's latest guidance for banks providing digital-asset custody places emphasis on areas including governance, risk management, and due diligence where custody functions are delegated or outsourced. The underlying principle is significant: choosing a third party does not eliminate the need to understand how assets are ultimately being protected.

The infrastructure we depend on
The same principle extends beyond custody. The ecosystem is supported by wallet developers, cryptographers, auditors, researchers, and maintainers whose work is rarely visible outside technical circles. Their contributions aren't measured in daily transactions or market capitalisation, yet they shape the resilience of the entire network. And whilst the same rules apply to visibility when something works, it also makes it difficult to fund.

Recent events have made the importance of that work unusually visible. Whether the weakness emerges in a hardware wallet or software underpinning a bitcoin-linked network, vulnerabilities ultimately have to be identified, disclosed, patched, and reviewed by people. Decentralised infrastructure still needs maintenance.

As bitcoin continues to mature as a global financial system, investment in public infrastructure cannot remain an afterthought. Security cannot be taken for granted as a feature of the protocol for it’s an ongoing process of engineering, review, and maintenance carried out by people whose names most users will never know.

A different way of thinking about trust
Perhaps the lasting lesson from the COLDCARD incident and the latest liquid exploitation isn’t that bitcoin failed, nor that self-custody is inherently flawed, but that decentralisation changes where trust lives.

For some, that trust is placed in a hardware wallet and for others it’s distributed across multisignature wallets or MPC. For those using the broader Bitcoin ecosystem, it can also sit in the software and infrastructure through which assets are transferred and used. Even opting to trust yourself ultimately means trusting the software, hardware and cryptography you’ve chosen to rely on.

Fundamentally, bitcoin gives users far more choice over where responsibility sits but requires a need to understand the systems they depend on. That question will become more important as Asian financial centres deepen their involvement in digital assets.

Join Asian Banking & Finance community
Join Asian Banking & Finance community
Since you're here...

...there are many ways you can work with us to advertise your company and connect to your customers. Our team can help you design and create an advertising campaign, in print and digital, on this website and in print magazine.

We can also organize a real life or digital event for you and find thought leader speakers as well as industry leaders, who could be your potential partners, to join the event. We also run some awards programmes which give you an opportunity to be recognized for your achievements during the year and you can join this as a participant or a sponsor.

Let us help you drive your business forward with a good partnership!