
Ledger CEO Pascal Gauthier calls for better cooperation and standards adoption across the hardware self-custody industry
In the aftermath of the recent Coldcard hack, with BTC losses estimated at above $150 million, Pascal Gauthier (pictured), CEO and Chairman of Ledger, has called for better cooperation and standards adoption across the hardware self-custody industry.
On Bitcoin’s promise, security by design, and the responsibility our industry shares.
If you are new to all of this, start here.
Bitcoin is money you can hold yourself, the way you hold cash. No bank account, no company in the middle. What makes that possible is a key: a secret that lives with you, backed up by a short list of words called a seed. Whoever holds the key holds the money. That is the whole system.
It is a beautiful idea with a hard edge. Because no one stands in the middle, no one can freeze your money or deny you access. And because no one stands in the middle, no one can rescue you if the key is lost. Everything below flows from that trade.
Two parts follow: what our industry must build, and how we must behave while building it.
Part one – How we build
Bitcoin promised money that doesn’t ask anyone’s permission. That promise only works if you hold your own keys.
Two of the most common ways users lose funds are through their own mistakes—a seed written down wrong, a password forgotten—or through a flaw in the design of the tools they trusted, which they had no way to see. Either way, it is always the user who suffers the consequences.
Discipline cannot fix a flawed design. And good design removes the mistake instead of demanding a lifetime of perfect discipline. Making the setup more complex, or pushing more responsibility onto the user, is not security. It is security theater. And this matters beyond any product. Holding your own keys is digital private property: owning something without anyone’s permission. A right only experts can exercise is a right most people don’t have. So safe and easy have to coexist. Digital private property cannot stay a niche.
Our industry has to build security design that scales to ordinary people. And no one’s design should be taken at their word, ours included. Open what can be open, so anyone can check it. What must stay closed for security, hand it to independent experts to test. And the proof is time: still standing years later, with real money inside.
Total safety does not exist. Anyone who promises it is selling something. Security is a direction: safer every year, easier every year, tested by people who try to break it. And the destination has never changed since the first nine pages: a billion people holding their own keys, and actually using them. Send, sign, transact, live with it. Money, and soon your identity too.
The only security is security by design. So here is the bar, for every wallet, ours included: no compromise.
Not on security to make it easy. Not on ease to make it secure. Not on sovereignty to make it safe. The moment we ask users to compromise, we have failed at the design. That is the bar. That is the whole fight, true to the original promise of those nine pages.
Part two – How we behave
That was about how we build. One more thing, about how we behave. The standard I just described is bigger than any one company, and so is the responsibility.
Every time security fails in crypto, the timelines fill with vendors dunking on each other. It’s petty, and it’s free labor for the thieves: state-sponsored teams, criminal groups, lone scammers. A whole economy of them, stealing billions.
Cooperation between companies already works. Our part: the Donjon, our security team, finds vulnerabilities in other companies’ products, and our own, and shares the findings before any thief knows. Trezor patched. Trust Wallet’s users were protected months before disclosure. We wrote the open standard for clear signing, so users stop approving blindly, then gave it to the Ethereum Foundation so anyone could adopt it, competitors included. They did.
And we’re not alone. SEAL 911 runs a free 24/7 rescue line for anyone under attack. Kraken’s security lab finds and responsibly discloses flaws across the industry. Free education is everywhere, from Ledger Academy to Binance Academy to MIT’s free courses. Many others do this work every day; I can’t name them all. That is the standard.
So here is a direct invitation to my fellow industry CEOs: wallets, exchanges, custodians, all of us. Let’s keep competing hard on products, and stand together on simple principles:
- Responsible disclosure between our security teams as the norm.
- Open standards adopted even when a rival wrote them.
- Education for every user, not just our own.
- Honest security claims: every design has trade-offs, so name your own, not just your rival’s. A setup only experts can operate is not safer for the person who can’t operate it, and a rival’s bad week is not proof that your product has no weaknesses of its own.
- Leading in public: no dunking, no selling on other people’s losses.
Ledger holds itself to these, publicly; judge us on them. Users should watch their leaders protect them, not referee our fights.
The industry only wins if we defend it together.


