The Coldcard incident does not prove self-custody is too difficult. It proves that serious self-custody should probably not depend on outsourced entropy. Coldcard users followed the standard advice, kept their devices offline and protected their seed phrases. The failure was upstream: the device generated predictable keys. A safe can be perfectly locked and still be useless if someone else can reproduce the key.
For meaningful savings, outsourcing private-key generation to a device should make multisig a requirement. The easy end of that spectrum is Bitkey, which uses a two-of-three setup across a phone, a hardware device and a recovery server. The more sovereign end is SeedSigner, where you can bring your own entropy with dice and verify the process yourself. That route is more technical, and generating entropy badly creates its own risk, but SeedSigner's guides make the process straightforward for anyone willing to learn it.
I hope this incident does not scare people back into custodial accounts. Self-custody is a core piece of bitcoin's value proposition because it gives every holder the ability to exit unilaterally. Without that ability, bitcoin becomes another financial claim whose value depends on a counterparty honoring it.