Newsroom

CZ Urges Crypto Holders to Diversify Wallets After $70 Million Coldcard Exploit

1 August, 2026   /   News   /  AI   /   Tags:  firmware, wallets, devices, seeds, coldcard

CZ Urges Crypto Holders to Diversify Wallets After $70 Million Coldcard Exploit

Binance founder Changpeng Zhao advised spreading funds across multiple wallets following a firmware flaw that enabled the theft of over 1,000 bitcoin from hardware devices without physical access

Binance founder Changpeng Zhao, known as CZ, has called on cryptocurrency holders to avoid concentrating assets in a single wallet after a major security incident involving Coldcard hardware devices. The exploit, which drained roughly $70 million in bitcoin, has prompted renewed scrutiny of self-custody practices and the limits of even offline storage solutions.

On July 30, attackers swept funds from numerous Coldcard wallets in a short window. Initial on-chain observations pointed to about 594 bitcoin, valued at approximately $38 million at the time, taken from around 500 addresses over roughly 25 minutes. Subsequent analysis by Galaxy Research, building on patterns identified by engineers at Block, revised the scale upward. The firm reported that 1,082.65 bitcoin, worth about $70 million, was drained from 1,196 addresses across a 41-minute period between 01:10 and 01:51 UTC.

Firmware Flaw Allowed Offline Key Reconstruction

The vulnerability stemmed from a firmware integration error dating to March 2021. On certain Coldcard models, including affected Mk3 units and some older releases of Mk4, Mk5, and Q devices, seed generation could fall back to a predictable software process instead of relying solely on the hardware random-number generator. This weakness made private keys computationally feasible to reconstruct remotely, without any need to steal a physical device or obtain a recovery phrase.

Manufacturer Coinkite acknowledged the issue, issued an apology, and released emergency firmware updates. The company stressed that simply installing the patched software does not secure seeds already created on vulnerable versions. Affected users must generate entirely new seeds on updated devices and carefully transfer their holdings, starting with small test amounts where practical.

Many of the drained wallets had remained dormant for years. The stolen bitcoin was consolidated quickly into a limited number of addresses and, according to available tracking, has not moved further since the incident.

Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!
Changpeng Zhao

Diversification and Its Trade-Offs

In a post on X responding to the reports, Zhao emphasized that no wallet solution offers complete protection. He noted that both hardware devices and long-established wallets can contain critical flaws. His suggested mitigation was to distribute funds across several wallets, though he acknowledged this approach introduces separate operational risks such as more complex key management and recovery processes.

Separating holdings across independent seeds, different devices, and varied vendors can limit the impact of any single compromise. Daily spending amounts might sit in more accessible wallets while larger reserves remain under stricter controls, including multisignature arrangements where appropriate. However, true diversification requires independent seeds rather than simply copying one recovery phrase across multiple devices.

Greater numbers of wallets also increase the burden of tracking balances, maintaining backups, performing firmware updates, and arranging for inheritance. Incomplete records can turn an effort to reduce risk into permanent loss of access. Institutions typically layer additional safeguards, such as multi-party computation, geographic key distribution, and tested recovery procedures, reflecting the higher stakes involved with larger balances.

Broader Implications for Self-Custody

Hardware wallets have long been regarded as among the strongest options for securing bitcoin offline, away from exchange counterparty risks and online threats. The Coldcard incident demonstrates that latent firmware issues can persist undetected for years and enable remote compromise at the point of seed creation rather than during later storage or transaction signing.

Security discussions have shifted toward the importance of coordinated processes over reliance on any single device. Regular software updates, careful seed generation practices, and diversified storage remain central recommendations. The event underscores that self-custody security depends on limiting the damage possible from any one failure point while managing the practical complexities that come with layered defenses.

Coinkite has continued to urge users who generated seeds on the affected firmware versions to migrate promptly. As investigations into the fund flows proceed, the episode serves as a reminder of persistent challenges in maintaining robust digital asset custody amid evolving technical risks.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.