Newsroom
1 August, 2026 / News / AI / Tags: firmware, wallets, devices, seeds, coldcard

Binance founder Changpeng Zhao advised spreading funds across multiple wallets following a firmware flaw that enabled the theft of over 1,000 bitcoin from hardware devices without physical access
Binance founder Changpeng Zhao, known as CZ, has called on cryptocurrency holders to avoid concentrating assets in a single wallet after a major security incident involving Coldcard hardware devices. The exploit, which drained roughly $70 million in bitcoin, has prompted renewed scrutiny of self-custody practices and the limits of even offline storage solutions.
On July 30, attackers swept funds from numerous Coldcard wallets in a short window. Initial on-chain observations pointed to about 594 bitcoin, valued at approximately $38 million at the time, taken from around 500 addresses over roughly 25 minutes. Subsequent analysis by Galaxy Research, building on patterns identified by engineers at Block, revised the scale upward. The firm reported that 1,082.65 bitcoin, worth about $70 million, was drained from 1,196 addresses across a 41-minute period between 01:10 and 01:51 UTC.
The vulnerability stemmed from a firmware integration error dating to March 2021. On certain Coldcard models, including affected Mk3 units and some older releases of Mk4, Mk5, and Q devices, seed generation could fall back to a predictable software process instead of relying solely on the hardware random-number generator. This weakness made private keys computationally feasible to reconstruct remotely, without any need to steal a physical device or obtain a recovery phrase.
Manufacturer Coinkite acknowledged the issue, issued an apology, and released emergency firmware updates. The company stressed that simply installing the patched software does not secure seeds already created on vulnerable versions. Affected users must generate entirely new seeds on updated devices and carefully transfer their holdings, starting with small test amounts where practical.
Many of the drained wallets had remained dormant for years. The stolen bitcoin was consolidated quickly into a limited number of addresses and, according to available tracking, has not moved further since the incident.
In a post on X responding to the reports, Zhao emphasized that no wallet solution offers complete protection. He noted that both hardware devices and long-established wallets can contain critical flaws. His suggested mitigation was to distribute funds across several wallets, though he acknowledged this approach introduces separate operational risks such as more complex key management and recovery processes.
Separating holdings across independent seeds, different devices, and varied vendors can limit the impact of any single compromise. Daily spending amounts might sit in more accessible wallets while larger reserves remain under stricter controls, including multisignature arrangements where appropriate. However, true diversification requires independent seeds rather than simply copying one recovery phrase across multiple devices.
Greater numbers of wallets also increase the burden of tracking balances, maintaining backups, performing firmware updates, and arranging for inheritance. Incomplete records can turn an effort to reduce risk into permanent loss of access. Institutions typically layer additional safeguards, such as multi-party computation, geographic key distribution, and tested recovery procedures, reflecting the higher stakes involved with larger balances.
Hardware wallets have long been regarded as among the strongest options for securing bitcoin offline, away from exchange counterparty risks and online threats. The Coldcard incident demonstrates that latent firmware issues can persist undetected for years and enable remote compromise at the point of seed creation rather than during later storage or transaction signing.
Security discussions have shifted toward the importance of coordinated processes over reliance on any single device. Regular software updates, careful seed generation practices, and diversified storage remain central recommendations. The event underscores that self-custody security depends on limiting the damage possible from any one failure point while managing the practical complexities that come with layered defenses.
Coinkite has continued to urge users who generated seeds on the affected firmware versions to migrate promptly. As investigations into the fund flows proceed, the episode serves as a reminder of persistent challenges in maintaining robust digital asset custody amid evolving technical risks.









