Binance Founder CZ Urges Wallet Diversification After $70 Million Coldcard Exploit
Key Takeaways
- •A firmware vulnerability originating in March 2021 compromised the randomness of recovery seed generation on certain Coldcard models, enabling attackers to mathematically reconstruct private keys without physical access to the devices.
- •Galaxy Research analysis found that approximately 1,082.65 bitcoin, valued at roughly $70 million, was stolen from 1,196 addresses during a roughly 41-minute window on July 30, with many affected wallets having been dormant for years.
- •Coinkite acknowledged the bug and released emergency firmware updates, but warned that merely updating firmware does not secure seeds already created on vulnerable versions, requiring users to generate entirely new seeds and migrate funds.
- •CZ recommended diversifying cryptocurrency holdings across multiple wallets as a risk mitigation strategy while cautioning that this approach introduces its own complexities and that no security measure is entirely foolproof.
- •The exploit has highlighted a broader industry concern that hardware wallet firmware undergoes less rigorous independent security auditing than the cryptographic protocols it depends on, allowing vendor-specific bugs to persist undetected for extended periods.

Binance founder Changpeng "CZ" Zhao has urged cryptocurrency holders to spread their funds across multiple wallets following a major security failure in Coldcard hardware wallet devices.
In a post on X on Saturday responding to reports of the theft, CZ wrote: "Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!"
He cautioned that splitting funds introduces a different set of risks and that nothing is 100% safe.
The exploit centered on a firmware flaw dating back to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. An attacker was able to reconstruct private keys offline and drain funds without ever physically accessing the devices. The vulnerability is particularly significant because recovery seeds are the ultimate backstop for hardware wallet users—if a seed can be mathematically reconstructed, no amount of physical device security matters.
Coldcard, manufactured by Toronto-based Coinkite, is a Bitcoin-only hardware wallet widely used by privacy-focused and self-custody enthusiasts, in part because it is designed to operate entirely offline via MicroSD cards rather than USB or network connections. That air-gapped reputation makes the exploit especially notable, as the flaw bypassed the device's core security premise without requiring physical access or network connectivity.
Initial on-chain reports identified approximately 594 bitcoin (roughly $38 million at the time) swept from around 500 wallets within a roughly 25-minute window on July 30. Subsequent analysis by Galaxy Research expanded the scope significantly, finding that 1,082.65 bitcoin—valued at approximately $70 million—was taken from 1,196 addresses over about 41 minutes. Many of the affected wallets had sat dormant for years.
Coinkite has acknowledged the bug, issued an apology, and released emergency firmware updates. The company advised users who generated seeds on affected firmware versions to create entirely new seeds on patched devices and carefully migrate their funds. Coinkite noted that simply updating firmware does not secure an already-created vulnerable seed.
The incident has renewed debate over the limits of self-custody. Hardware wallets are widely regarded as one of the strongest options for securing bitcoin offline, yet the Coldcard case demonstrates that even long-established devices can harbor critical flaws that remain undetected for years. CZ's suggestion of diversification acknowledges that spreading risk comes with practical challenges of its own, including more complex key management.
The exploit also underscores a broader industry challenge: hardware wallet firmware is rarely subjected to the same level of independent, open security auditing as the cryptographic protocols it relies on, meaning single-vendor implementation bugs can persist undetected long after deployment.
Source: CoinDesk