The headline says $1.9 million in Bitcoin. At spot of $83,000 per BTC — the price as of this writing, against an all-time high of $109,000 set on 20 January 2025 — that is 22.89 coins, give or take rounding on the dollar conversion. The case is a Miami IT worker, arrested for moving Bitcoin out of a former employer's wallet. I have read variations of this story for nine years now: the privileged-access insider, the silent transfer, the eventual arrest, the headline that names the dollar figure and almost nothing else. The conventional reading writes itself in the comments under the article. Hardware wallet. Cold storage. Self-custody. Not your keys, not your coins. The reading is correct, narrowly. It is also where most of the analysis stops, and where the part worth writing about begins.

Why This Is Actually True — The Self-Custody Reading Of The Miami Case Is Not Wrong

Let me concede the conventional view in its strongest form before I touch it.

If you hold Bitcoin on an exchange — any of them, the Tier 2 names with the audits and the licenses included — your asset is a database entry that resolves to a private key controlled by someone other than you. Binance is the largest. Daily spot-plus-derivatives volume of $18.5 billion. CER security score of 9.4. Proof-of-reserves audit dated 1 March 2025. Reserve status: verified. None of that changes the underlying mechanic. The keys live behind their operational perimeter, not yours.

The Miami case is, on the surface, a textbook argument for moving past that mechanic. An IT worker with privileged access — by definition, somebody on the trust side of an operational perimeter — moves coins out of a wallet that was someone else's. The victim, by all available accounts, had outsourced custody of his Bitcoin to an infrastructure he did not personally control. The insider walked through it. The headline followed.

Take this lesson at face value and the answer is mechanically clean. A hardware wallet — Trezor, Ledger, Coldcard, whatever — costs between $80 and $250. A passphrase is free. A seed-phrase backup, written on paper or stamped into steel, costs another $0 to $80. You generate keys offline, you sign transactions on the device, the seed never touches a network-connected machine. An IT worker — anybody's IT worker — cannot move Bitcoin he cannot sign. The mathematics here are not in dispute. A 12-word or 24-word BIP39 seed, custody-side, ends the attack vector the Miami case demonstrates.

This is why the comments under the article are unanimous, and why they are difficult to argue with directly. The bare claim — *single signer, self-custody hardware wallet, attack surface closed* — is technically correct. I want to be unambiguous about that. If the choice on offer is "leave 22.89 BTC sitting in a hot wallet managed by your IT contractor" versus "buy a $120 device and write down 24 words", the device wins every round. It is the right answer to the question the conventional reading asks.

The conventional reading just asks the wrong question.

Self-custody changes who holds the keys. It does not change how much custody costs to operate at $1.9M in BTC, and that is the line where the comment-section consensus quietly stops thinking.

Where It Breaks Down — What Real Insider-Proof Opsec Costs Per Year At $1.9M In BTC

Here is the gap. The comment-section consensus treats "self-custody" as a binary toggle: device acquired, problem solved, end of analysis. The Miami victim's mistake is reframed as a single wrong decision rather than a sustained operational failure. That framing is convenient. It is also wrong about how 22.89 BTC actually gets held.

Run the actual cost stack for self-custody at a $1.9M position. Not the theoretical version. The version where you take the insider threat — the same insider threat the Miami case demonstrates — seriously enough that it does not happen to you in 2027 under a different headline.

Hardware wallet: $120 retail for a current-generation device. Doubled — a backup device matching the primary, identical seed, stored separately — call it $240. A single hardware wallet at $1.9M is single-point-of-failure custody, and the people who treat single-device custody as adequate at this size are the same people who later show up in the headline. So: $240 in hardware, year one.

Steel seed-phrase backup, redundant, geographically separated: $80 to $160 per unit, two units minimum, one offsite. Call it $240, year one, amortized to zero in years two through five.

Now multi-signature. A single-signer setup at $1.9M is a wrench-attack honeypot — the term of art for what happens when somebody physically coerces the holder. Two-of-three multisig spreads the signing keys: typically one local, one at a bank safe-deposit box, one with a designated co-signer or a custody service like Casa or Unchained. Casa's "Gold" tier — the level appropriate for a position this size — runs roughly $250 per month, or $3,000 per year, billed annually. That is the lower bound. The "Platinum" tier with white-glove key replacement and dedicated specialist support sits closer to $5,000 per year.

Bank safe-deposit box for the offsite key: $75 to $200 per year, depending on the institution and the city. Miami is not the cheap end of that range.

Operational time — and this is the cost the comment-section reading never includes — runs to roughly 8 to 12 hours per year if you do this correctly. Annual signing-key rotation drill. Recovery test on the backup device. Verifying that the offsite copy is still intact and the safe-deposit institution has not changed its access procedure. At any reasonable hourly rate for someone with $1.9M in Bitcoin to protect — I will use $200/hour, which is below market for the demographic — that is another $1,600 to $2,400 in opportunity cost.

Year-one all-in: roughly $5,200 to $8,000. Steady-state, years two through five: $3,300 to $5,500 per year.

That is the actual price of doing what the comment section says to do. And it is the price of doing it for one person, with no co-signer salary, no jurisdictional spread across legal entities, no fiduciary structure for inheritance. Add any of those and the number moves into five figures.

The Miami victim — by all reporting available — was running a business, not a custody operation. The implicit choice was never "hardware wallet versus convenience." It was "deploy and maintain an institutional-grade custody stack, in addition to running the company that generated the Bitcoin in the first place, versus delegate the custody operationally and accept a known attack surface." Most people choose the second path. Most of them never make the headline. One does, and the comment section reads the outcome backwards.

Free Download
Crypto Market Cycle Cheat Sheet 2026
Entry signals, exit rules & DCA calculator — based on 3 previous cycles.

The Rule I Use Instead — Threshold Custody Sized To The Holdings, Not To The Narrative

Here is the framework I use, and I am borrowing it from a place I have written about before but never named so directly: the practice that operational risk scales with position size, not with the narrative around it.

Below 0.5 BTC — roughly $41,500 at current spot — single-signer hardware wallet, single seed-phrase backup, end of structure. The cost stack ($120 device, $80 steel backup, ~1 hour/year of maintenance) is proportionate to the asset. Multisig at this size is theater dressed as discipline.

Between 0.5 and 5 BTC — roughly $41,500 to $415,000 — two-of-three multisig, self-managed, with one key in a bank safe-deposit box and one with a trusted co-signer who knows what they are holding. No custody service. The structural cost ($300 in hardware, $150/year safe-deposit, ~4 hours/year drill time) is proportionate. The wrench-attack surface starts to matter at the upper end of this range, and the multisig structure absorbs it.

Above 5 BTC and up to roughly 25 BTC — the range the Miami case lives in — two-of-three or three-of-five multisig with a paid custody service holding one key, geographically distributed key storage, an annual recovery drill that is actually executed and not just intended, and a written successor protocol. Casa Gold at $3,000/year or the equivalent. This is where the cost stack jumps into the thousands annually and stops being optional.

Above 25 BTC — institutional custody enters the conversation. Coinbase Custody, BitGo Trust, Anchorage Digital. Insured cold storage, qualified custodian status, SOC 2 audits. Annual fees in the 0.10% to 0.50% range of assets under custody. The trade-off is no longer "your keys versus their keys" — it is "your operational competence versus their operational competence, audited."

The rule is not "self-custody good, exchange custody bad." The rule is "match the operational sophistication of your custody to the dollar value at risk, recalibrate quarterly as the position size changes, and accept that the answer at $1,900 looks nothing like the answer at $1.9 million."

The Miami case, read through this framework, is not a parable about exchanges. It is a parable about a position that had outgrown the custody arrangement that originally held it. Operational sophistication did not scale with the dollar value. The insider walked into the gap between them. That gap is where almost all of these headlines live, and "buy a hardware wallet" is the answer to a question one tier below the one being asked.

When The Old Rule Still Wins — Under Roughly 0.5 BTC, A Single Hardware Wallet Is Enough

I want to close on the case where the comment-section consensus is fully correct, because I have spent the bulk of this piece dismantling it and the symmetry matters.

Under 0.5 BTC — call it $41,500 at $83,000 spot — single-signer hardware wallet is not a compromise. It is the right structural answer. The cost stack stays proportionate. The attack surface — losing the device, losing the seed phrase, $5 wrench attack — exists, but the expected loss multiplied by the probability of each scenario is small enough that the additional friction of multisig is genuinely not worth the operational overhead. Below this threshold, MEXC at 0% maker fees or Binance with PIX onramps and verified proof of reserves dated 1 March 2025 is also a reasonable custody choice for the active-trader fraction of holdings, with the cold-storage fraction on a single device. The math works.

What does not work is taking the framework that applies under 0.5 BTC and extending it linearly to 22.89 BTC because the asset name is the same. The Miami case is, again, exactly that error. The custody arrangement that was probably fine when the position was 2 BTC stayed structurally unchanged when the position became 22.89 BTC, and the operational gap that opened up over that growth curve is where the IT worker — by all available reporting — walked through. The conventional wisdom is right about the small case. It is the wrong tool for the large one, and the headline writes itself either way.

FAQ

Why doesn't a hardware wallet alone fix what happened in the Miami case?

A hardware wallet fixes the specific narrow attack — an insider with database-level access to a hot wallet moving funds. It does not fix the broader operational gap at this position size. At 22.89 BTC, single-signer custody leaves the holder exposed to single-device failure, seed-phrase exposure, and physical coercion. The Miami case demonstrated that custody was outsourced. It does not demonstrate that the correct replacement was a $120 device, because at $1.9M the correct replacement is a multisig structure with geographically separated keys and an annual recovery drill.

What does proper self-custody actually cost per year at this size?

Year one runs roughly $5,200 to $8,000 all-in. That includes two hardware wallets ($240), redundant steel seed backups ($240), a paid custody service like Casa Gold for collaborative multisig (~$3,000/year), bank safe-deposit box for an offsite key ($75 to $200), and 8 to 12 hours of operational time priced at a reasonable opportunity cost. Steady-state years two through five drop to roughly $3,300 to $5,500. Anyone quoting "a hardware wallet costs $120" as the answer at $1.9M is pricing the wrong question.

Is keeping Bitcoin on a major exchange ever reasonable for amounts this large?

Reasonable, no. Common, yes — and that is the point. Binance, Bybit, OKX, and Bitget all hold verified proof-of-reserves audits dated within the last six months. The custody operation is, in narrow operational terms, more sophisticated than what most individual holders run. The trade-off is that you accept counterparty risk and you accept that an insider on their side — exactly the Miami scenario, scaled up — is mathematically possible. For active trading fractions of a portfolio it is acceptable. For the cold-storage portion of $1.9M, it is not.

What is a wrench attack and why does it change the math above five BTC?

The term refers to physical coercion of the holder to obtain keys. The attack surface scales with how visible and how recoverable the position is. At 0.5 BTC, the risk is small enough that single-signer hardware wallet custody is proportionate. Above roughly 5 BTC, multisig — typically two-of-three with one key held by a co-signer or custody service — meaningfully reduces this risk, because a coerced holder cannot unilaterally move funds. This is the structural reason custody arrangements need to change as position size grows, not just because of insider threats.

Why does the article reject the "not your keys, not your coins" framing as incomplete?

It is not wrong. It is incomplete. The phrase implies that custody choice is binary — exchange or hardware wallet — when in practice custody is a multi-tier operational discipline that scales with dollar value at risk. Below 0.5 BTC the binary framing holds. Between 0.5 and 5 BTC it starts to fray. Above 5 BTC and certainly at 22.89 BTC, treating self-custody as a single decision rather than an ongoing operation is what produces the Miami headline a year later — under a different name, with the same root cause.

Does institutional custody solve the insider problem the Miami case demonstrated?

It changes the shape of it. Qualified custodians — Coinbase Custody, BitGo Trust, Anchorage Digital — operate under SOC 2 audits, segregated storage, and statutory insurance. They are not immune to insider risk. They are structured so that insider risk requires collusion across audited control boundaries rather than a single privileged employee. For positions above roughly 25 BTC the structural advantage is real, but it comes with annual fees in the 0.10% to 0.50% range of assets and a different counterparty exposure than holding on an exchange. The decision is not self-custody versus exchange. It is which audited control structure you trust at which dollar level.

What is the single most common mistake holders make as their position grows past five BTC?

They do not change the custody structure when the position changes. The arrangement that was appropriate at 1 BTC stays in place at 10 BTC because there is no specific moment that forces a review. The Miami case, by all available reporting, looks like exactly this — a custody arrangement that was operationally fine at an earlier position size, left structurally untouched as the underlying value grew, and exploited at the point where the gap between arrangement and asset became wide enough for an insider to step into. Quarterly review of custody-to-asset proportion is the unglamorous discipline that prevents this. Almost nobody runs it.