A sensible self-custody setup begins by naming the adversaries it defends against. The most rigorous treatment comes from Blockchain Commons' Smart Custody, which personifies twenty-seven adversaries; the LegacyCipher synthesis distills these into six categories — yourself (forgetfulness, novel schemes, dying without documentation), environmental (fire, flood, hardware failure, degraded backups), remote attackers (phishing, malware, supply chain, leaked KYC), local physical attackers (burglary, the "$5 wrench," coercion), socially close parties (family, roommates, ex-spouses, heirs), and institutional and legal (custodian failure, court orders, capital controls). Different holders should adopt different setups depending on which categories rank highest: a young anonymous holder with modest holdings is dominated by yourself / remote / environmental; an older identifiable holder with family and a substantial stack is dominated by socially close / local physical / yourself. Writing down a top-three priority order is what shapes every subsequent decision, and the threat-modelling lens recurs across Practical self-custody and sovereignty.


Why this note matters

Threat modelling is the second of the three foundational framings for self-custody. Where Loss vs exposure failure modes names what a custody setup defends against — the two structural directions in which Bitcoin can disappear — naming adversaries identifies the who driving each loss or exposure event.

Three structural points matter:

  • The defence-without-target failure mode. Generic security practices (“use multisig because it’s more secure”) often defend against threats the holder doesn’t realistically face while leaving the threats they do face unaddressed.
  • Defence calibrated to threat. Different threat models legitimately produce different custody setups. The top-three exercise determines where on the Self-custody configuration ladder a holder should sit, which hardware-wallet features matter, which operational practices apply, and how to plan inheritance.
  • The asymmetry behind most real-world losses. Every practitioner the synthesis reviews — Lopp, Unchained, Nunchuk, Blockchain Commons — ranks user error above all other categories in observed frequency. A threat model that doesn’t centre yourself is mis-calibrated.

A custody setup is only as good as the threat model it was built against. Setups without an explicit threat model tend to be over-engineered against threats the holder doesn’t face and under-engineered against the ones they do.


The Blockchain Commons framework

The most rigorous published treatment of self-custody threat modelling is the Blockchain Commons Smart Custody project, which formalizes the discipline as a structured cold-storage scenario underpinned by a personification of 27 distinct adversaries. The adversaries range from low-cinematic ones — “Loss by Mistake,” “Death,” “Loss of Habituated Storage” — to dramatic ones — “Institutional Theft,” “Coercion,” “Nation-State Actor.”

The personification matters. Naming an adversary forces a specific defensive question: What would defeat the Loss-by-Mistake adversary? (Documentation, rehearsal, the no-novel-schemes rule.) What would defeat the Death adversary? (Inheritance documentation, executor coordination, the rehearsal walkthrough with the heir.) What would defeat the Nation-State Actor? (Probably nothing at the individual scale — which itself is a defensible answer.)

You do not need to work through all twenty-seven adversaries to build a sensible setup. The Blockchain Commons exercise is exhaustive because it is comprehensive; most holders only need the subset that matches their realistic threat surface. The synthesis distills the 27 into six categories that cover the bulk of what individual holders should engage.


The six adversary categories

Every operational note in the section that discusses a defence should make explicit which of these categories the defence targets. Holders should write down their personal top three in priority order; the order shapes every subsequent decision.

1. Yourself

The largest single category. Every practitioner ranks user error above all other categories in observed frequency.

Specific instances:

  • Forgetting the location of a backup
  • Writing down the wrong words
  • Storing a seed digitally “just for a minute” — the photo then syncs to iCloud, Google Photos, or a Dropbox the holder forgot was running
  • Testing a recovery incorrectly and overwriting a working setup
  • Choosing a passphrase you cannot reliably reconstruct under stress years later
  • Inventing a novel obfuscation scheme whose failure modes you have not analyzed
  • Dying or becoming incapacitated without documentation
  • Operating the wallet under emotional duress or time pressure and making an irreversible mistake

Lopp’s phrasing, repeated throughout his work: “The biggest risks in self-custody are not from hackers but from mistakes and environmental failures.”

The yourself-defences are: write everything down in physical form, in language a non-technical person can understand; test your recovery at least once before you trust it; do not improvise; do not invent novel schemes; operate the wallet in peak cognitive condition only; plan for your own absence.

2. Environmental

Physical-world failures that are not adversarial in the moral sense but are real threats to the security of any backup that exists in physical form.

Specific instances:

  • Fire (the canonical environmental threat; metal backups are partial protection only — Lopp’s stress tests show roughly half of products marketed as “indestructible” fail one or more of heat, corrosion, or deformation tests)
  • Flood (drowning the basement safe, the document box, the off-site backup)
  • Earthquake (mechanical destruction of storage, displacement of stored items)
  • Hard-drive failure (for any digital component of the setup)
  • Paper degradation, ink fade (a backup written in pen on standard paper has a multi-decade horizon at best)
  • Theft by environmental displacement (renovation, moving, estate cleanup, a partner or family member discarding items “we don’t need”)

The environmental-defences are: geographic redundancy, fire-resistant storage where reasonable, metal backups that have been independently stress-tested, written documentation that survives the death of the holder’s living memory.

3. Remote attackers

Adversaries operating at scale through digital channels. Remote attackers scale well — a single phishing kit can target tens of thousands of victims — which is why they dominate incident counts even though their per-target success rate is modest.

Specific instances:

  • Phishing — the single most common real-world attack vector against self-custodians, per every source the synthesis reviews. Email, SMS, and direct-message campaigns impersonating exchanges, hardware-wallet companies, or Bitcoin services.
  • Clipboard malware — replacing a copied destination address with the attacker’s address at the moment of paste.
  • Fake wallet apps in app stores
  • Compromised firmware — the attacker has tampered with the device before it reached the holder
  • Supply-chain attacks on hardware wallets — the most-cited concern after the Ledger 2020 data leak made hardware-wallet purchasers identifiable
  • Leaked seeds from cloud backups — the holder photographed the seed “temporarily” and it ended up in iCloud or Google Photos
  • Compromised computer used as the host for hardware-wallet signing (the attacker manipulates the transaction the holder is asked to confirm)

The remote-attacker defences are: never enter a seed phrase into any software interface for any reason; never click links in emails from exchanges or wallet vendors; verify any unusual request through a separate channel; use a password manager that refuses to autofill on spoofed domains; never photograph or digitally copy a seed; use air-gapped or QR-code-only signing where the threat model warrants. The chain-analysis industry is a remote-attacker subcategory in its own right — commercial firms that resolve on-chain clusters to real-world identities and feed the results into compliance, prosecution, and (per Lopp’s database) opportunistic-targeting pipelines. See Address reuse and chain analysis for the threat surface and KYC leakage for the principal identity-resolution channel; the Privacy practice cluster (CoinJoin, PayJoin, Silent Payments, Lightning) is the operational response.

4. Local physical attackers

Adversaries with physical access. Until recently this category was rare enough to treat as theoretical. The synthesis reports a 169% year-over-year jump in 2025 per Lopp’s Physical Bitcoin Attack database; attacks now cluster around identifiable holders, not random victims.

Specific instances:

  • Burglary targeting a known or suspected Bitcoin holder
  • The “$5 wrench attack” — the attacker abandons cryptography and threatens the holder
  • Coerced access — the attacker forces the holder to unlock the device or reveal the passphrase
  • Kidnapping — including kidnap-and-ransom for very large holdings
  • Home invasion at a suspected holder’s residence
  • Theft during travel — particularly relevant for holders crossing borders with hardware wallets

The local-physical defences are: do not be identifiable as a Bitcoin holder (the dominant prevention strategy); geographic distribution of keys so that no single physical location compromises the setup; time-locked transactions or multisig with remote confirmer so that the holder genuinely cannot move funds unilaterally under coercion; plausible-deniability setups (decoy wallets) as one layer among several rather than the primary defence.

5. Socially close parties

The most-overlooked category. Adversaries who are not adversaries in the conventional sense but who have privileged access through trust or proximity, and who can produce loss or exposure events through ordinary human dynamics rather than malice.

Specific instances:

  • A family member who finds your backup while tidying and photographs it “in case it’s important”
  • A roommate who accesses your home unsupervised
  • An ex-spouse during a contentious separation
  • A child too young to understand what they are handling
  • An heir who makes custody decisions you would not have made
  • A divorced or estranged trusted party who held a multisig share and now no longer cooperates
  • A business partner with privileged knowledge of the holder’s holdings
  • A previously-trusted advisor who discloses or leverages the relationship

The socially-close defences are: compartmentalize knowledge of holdings; treat backup locations as security-sensitive even from family; plan inheritance such that the documents reveal what is needed at the moment they are needed (not before); avoid quorum arrangements where the social fabric is uncertain to hold for decades; revisit the social map of your custody setup periodically as relationships change.

Adversaries that operate through the legal-institutional system rather than through cryptography or coercion. These are not threats that self-custody eliminates — self-custody shifts the blast radius rather than removing it.

Specific instances:

  • A custodian you entrusted with some portion of your setup goes bankrupt
  • A custodian gets hacked and your funds are commingled with the loss
  • A court orders the freezing of your funds (US 2022 Tornado Cash precedent; multiple state-level enforcement actions since)
  • A country imposes new capital controls that affect your ability to move or hold Bitcoin
  • A tax authority demands disclosure of holdings under threat of penalty
  • A jurisdiction reclassifies Bitcoin in a way that changes its legal status
  • A hardware-wallet or software vendor that holds critical infrastructure (firmware update channels, recovery services) becomes non-compliant or shuts down

The institutional-defences are: minimize reliance on any single custodian, including any single hardware-wallet vendor; favour open-source firmware where possible (avoids vendor lock-in); maintain a viable sovereign-recovery path independent of any partner; pay attention to jurisdictional risk for the specific holdings (KYC, AML, capital controls); consider trust structures and legal wrappers where appropriate (drawing on the broader trust-and-estate-planning literature). KYC records themselves are the principal institutional-exposure surface; see KYC leakage for the activation mechanisms (court orders, breaches, regulatory data-sharing, dark-market sales) and operational defences (compartmentalised KYC identities, withdrawal hygiene, non-KYC acquisition channels).


The “name your top three” exercise

The Blockchain Commons-via-synthesis exercise: write down which three of the six categories are most likely to affect you personally, in priority order. The exercise is short — five minutes of honest reflection — and the order shapes everything else.

Two illustrative profiles from the synthesis:

Profile A — young, single, anonymous, modest holdings:

  1. Yourself
  2. Remote attackers
  3. Environmental

This profile is most threatened by personal mistakes (forgetting things, novel schemes), then by the scale-of-attack phishing/malware vector, then by environmental events. Local physical attackers and socially close parties are minor concerns; institutional risk is also minor at this scale. The appropriate setup is single-sig on a tested hardware wallet, with substantial attention to operational discipline and the inheritance plan being light-touch (perhaps an envelope with the heir).

Profile B — older, public profile, family, substantial stack:

  1. Socially close parties
  2. Local physical attackers
  3. Yourself

This profile is most threatened by the dynamics within the family and social circle, then by the elevated risk of identification-driven physical attacks, then by personal mistakes (which scale with age and cognitive load). Remote attackers and environmental events are still concerns but secondary. The appropriate setup is 2-of-3 collaborative multisig with a reputable partner, geographic distribution of keys, careful management of public profile, and substantial attention to the inheritance plan with documented procedures.

These two profiles would not adopt the same setup. The threat-model exercise is what makes that legible.

How threat models change over time

The exercise is not one-time. Threat profiles drift:

  • Holdings grow (or fall) — the dollar amount changes which categories matter
  • Profile changes — a private holder takes a public role; a public holder retires
  • Family changes — marriage, divorce, children, deaths
  • Geographic changes — moves, travel patterns, jurisdictional shifts
  • Cognitive changes — aging, health events, life-stage transitions
  • Technical landscape changes — new attacks emerge, defences evolve

A periodic threat-model refresh — annually or at major life events — is the discipline that keeps the setup aligned with the actual threat surface. Many setups become inappropriate not because they were wrong at the time but because the threat profile shifted and the setup did not.


How the threat model interacts with the Tier framework

The Tier 0–3 holding-size framework codified in _Brief.md §12 is one input to the threat model, not a substitute for it. The synthesis explicitly: “A young, single, unknown holder with modest Bitcoin holdings might reasonably rank their list as: yourself, remote attackers, environmental. An older holder with a public profile, a family, and a significant stack might rank it: socially close parties, local physical attackers, yourself. These two people should not necessarily adopt the same setup.”

The interaction works in both directions:

  • Holding size shapes threat surface. Larger holdings attract local physical attackers and increase the per-incident cost of any failure. Larger holdings also justify more operational investment.
  • Threat surface shapes appropriate tier. A Tier 1 holder (single hardware wallet) with a Tier 3 threat surface (public profile, family wealth target, identifiable) is under-defended. A Tier 3 holder (multisig with geographic distribution) with a Tier 1 threat surface (anonymous, modest holdings) is over-engineered.

The matrix decision is: take the higher of (a) the tier suggested by your holdings and (b) the tier suggested by your threat surface. Set up at that level. Do not exceed it just because the literature describes more elaborate setups — every additional rung of the configuration ladder introduces complexity, which itself becomes a yourself-category failure mode.


Tradeoffs and considerations

The defence-target match

Defences without targets often fail in both directions: they over-secure against threats you don’t face, while leaving the threats you do face unaddressed. Common patterns:

  • A 3-of-5 multisig built by a holder whose top threats are “yourself” and “phishing” — the multisig does not defend against phishing (which targets signed transactions, not key custody), and the additional complexity dramatically increases the yourself-failure surface.
  • A passphrase added by a holder whose top threats are “yourself” and “death without documentation” — the passphrase increases both top threats unless the passphrase backup is itself rigorously planned.
  • Geographic distribution adopted by a holder whose top threat is “becoming unable to travel due to health” — the very mobility constraint the holder fears is what makes geographic distribution costly for them.

The corollary: when adopting a defence, name the specific category it targets. If you cannot, the defence is probably not justified for your threat model.

Yourself is structurally undefendable past a point

The yourself-category includes failures of cognition, judgment, and discipline. No technical setup defends against all of them. The synthesis is direct: at some point the only defence is rehearsal, documentation, and partnered custody where another party can compensate for your mistakes.

This implies a meaningful role for collaborative custody and trusted-party arrangements for holders who recognize that they themselves are their largest threat. The DIY-multisig framework’s exposure-side benefits do not necessarily compensate for the increase in yourself-side risk when the holder is not operationally disciplined enough to sustain the setup. Many holders are better served by 2-of-3 collaborative custody for exactly this reason.

The framework’s limits

The six-category framework is a synthesis — useful, but not exhaustive. Specific threats it does not cleanly address:

  • Long-tail technical risks — quantum computing attacks on ECDSA (currently theoretical for Bitcoin’s signature scheme but not for all stored UTXOs forever), undiscovered cryptographic vulnerabilities, subtle protocol-level attacks. These are difficult to defend against at the individual level; the principal defence is staying informed.
  • Correlation across categories — a single event (a leaked KYC database, for instance) can produce risk in multiple categories at once (remote attackers gain targeting information, local physical attackers gain home addresses, socially close parties may receive targeted social engineering). The categorical framework does not surface these correlations cleanly.
  • The dynamic threat model — threats evolve faster than the framework’s vocabulary. The 2025 surge in physical attacks was not anticipated by the 2018-era framework; the next surge may be similarly unanticipated. The framework provides a vocabulary, not a forecasting tool.

The over-and-under-modelling failure modes

Both ends of the engagement spectrum fail:

  • Under-modelling — adopting a default setup (“everyone uses single-sig,” “everyone with $X switches to multisig”) without examining whether the default matches the personal threat surface. Most common in newer holders.
  • Over-modelling — exhaustive engagement with all 27 Blockchain Commons adversaries plus speculative additions, leading to a setup so complex that it cannot be operated and so paranoid that ordinary spending becomes a project. Most common in technical holders who treat the threat model as an intellectual puzzle.

The defensible engagement is in between: name the realistic top three, defend against those, accept that the long tail of unaddressed threats exists and that some of them will not be defendable at the individual scale.


Tiered application

The threat-modelling discipline applies at all holding sizes, but the depth of engagement scales.

Tier 0 (under $1K) — Implicit threat model is fine. “Mostly yourself and remote attackers” is enough to justify a phone-wallet setup with basic operational hygiene.

Tier 1 (50K) — Explicit but light-touch threat model. Write down the top three categories; pick a setup that addresses them; document for the heir. The exercise should take an hour, not a weekend.

Tier 2 (1M+) — Substantive threat modelling. Engage all six categories; rank them; consider how they have evolved over the past year and how they may evolve over the next. Document the model. Revisit annually. The setup should be defensible against any of the top three threats without exceeding the operational capacity of the holder.

Tier 3 (>$1M) — Threat modelling becomes an ongoing personal-security practice. May involve professional consultation (some collaborative-custody providers offer this; some independent security consultants offer it). The threat model integrates with broader personal-security and estate-planning considerations. Revisits more frequent (semi-annually or on profile-changing events). May warrant compartmentalization (different setups for different portions of the holding) to limit the blast radius of any single threat materializing.


Common pitfalls

Modelling the threats that are newsworthy rather than the threats that are real. Hardware-wallet hacks and exchange breaches dominate the news because they make stories; user error and inheritance failure dominate the losses because they are silent. Threat models built from headlines optimize for the wrong things.

Treating the threat model as a one-time exercise. Threats shift. The threat model from 2020 (light on physical attacks, light on KYC-leak correlation) is not the threat model for 2026. Without periodic refresh, the setup drifts away from the actual threat surface.

Centering “the hacker” and underweighting “yourself.” This is the dominant pattern. The synthesis is explicit and unanimous: yourself is the largest category for nearly every holder. A threat model that does not place yourself in the top three is mis-calibrated.

Importing the threat model of the source you read. Lopp’s model is shaped by his public profile and the specific incidents he documents. Casa’s model is shaped by their customer base. Nunchuk’s model is shaped by their political-philosophical commitments. Adopting any of these wholesale rather than engaging with your own situation produces a setup calibrated for someone else.

Modelling individual threats without modelling correlation. A KYC data leak produces correlated risk across remote, local physical, and socially close categories simultaneously. A setup that handles each category independently may still fail when the threats arrive together.

Treating the “Nation-State Actor” category as a serious individual threat. For nearly every individual holder, nation-state-level adversaries are not realistic threats. The relevant institutional-and-legal threats are routine ones — capital controls, tax disclosure, custodian failure — not bespoke nation-state attacks. Engaging the latter while ignoring the former is a category error.

Modelling yourself only at peak cognitive condition. The yourself-category includes your worst day. A setup that requires you to be sharp and focused to operate safely is brittle. The synthesis’s “cognitive state rule” applies: the threat model should engage you-when-grieving, you-when-sick, you-under-coercion, you-twenty-years-from-now-with-mild-cognitive-decline.


Tooling and resources

The synthesis document (canonical for the section):

  • Bitcoin Self-Custody & Security: A Synthesis of Contemporary Best Practices, LegacyCipher discussion, April 2026 — explicit codification of the six categories and the “name your top three” exercise.

Primary practitioner sources:

  • Blockchain Commons Smart Custody Book (CC-BY-SA, free) — the 27-adversary framework and the cold-storage scenario. The most rigorous published treatment of the discipline.
  • Jameson Lopp’s writing — particularly the Physical Bitcoin Attack database (the empirical record of local-physical-attacker incidents) and “21 tips for securing your bitcoin.” See Jameson Lopp.
  • Unchained — “Securing Your Bitcoin: Threat Modeling for Personal Custody” and the broader operational-security guides.
  • Casa — case studies on specific threat-model engagement patterns, including the “Shamir Secret Sharing Shortcomings” piece that engages the SLIP-39 reconstruction-time exposure threat specifically.
  • Nunchuk — “Bitcoin Self-Custody: A Path Forward” and the political-philosophy-oriented threat-model engagement.

Empirical references:

  • Lopp’s Physical Bitcoin Attack database — annual updates with incident records and trend analysis
  • The Block, TRM Labs, Merkle Science — periodic publications on physical-attack trends and KYC-data-breach correlations
  • Coinbase, Ledger breach disclosures and post-mortems — empirical material on the institutional-and-legal category

As of 2026-05-14: Blockchain Commons’ framework remains the most rigorous public reference. Lopp’s database is the most up-to-date public source on physical-attack trends. The synthesis integrates the major streams.


Open questions for further development

  • The six-category framework is a synthesis distilled from a 27-adversary source. Is there a finer-grained intermediate framework — say, twelve categories — that captures more nuance without becoming exhaustive? Or is six the right Goldilocks level?
  • How should the framework handle threat categories that are jurisdiction-specific? The institutional-and-legal category looks very different in the US vs. EU vs. China vs. El Salvador. A locale-aware framework would refine the analysis but at the cost of generality.
  • The framework treats “yourself” as one category. Within it, there are meaningfully different sub-threats: forgetfulness (manageable through documentation), novel schemes (manageable through discipline), cognitive decline (not fully manageable), death (partially manageable through inheritance planning). Should yourself be subdivided?
  • What is the right framework for team or family threat modelling — setups where multiple parties share responsibility? The current framework is individual-holder-centric.
  • How does the threat model evolve in the medium-of-exchange phase of Bitcoin’s monetization? Routine spending dramatically increases exposure surface (every transaction is a chance for address replacement or phishing); the holder’s threat model may need to differentiate spending wallets from savings wallets more explicitly than the current framework does.
  • The framework underweights long-tail technical threats (quantum, post-quantum migration, undiscovered protocol vulnerabilities). Are these worth including for substantial holdings, or are they better treated as systemic risks rather than individual-threat-model concerns?

The other framing lenses:

The threat surface, treated more concretely:

The configurations themselves:

The moral framing:

The principal practitioners:

  • Jameson Lopp — two decades of empirical threat-surface work

The sub-MOC home: