NewsCryptoCZ Warns Bitcoin Holders After $70 Million Coldcard Exploit: 'Nothing Is 100%'

CZ Warns Bitcoin Holders After $70 Million Coldcard Exploit: 'Nothing Is 100%'

Author: Decrypt·

Key Takeaways

  • A firmware build error dating to March 2021 caused Coldcard devices to draw private key seeds from a predictable software fallback instead of the intended hardware random-number generator.
  • Galaxy Research identified 1,196 addresses that were fully drained of approximately 1,082.65 BTC, valued at roughly $70.2 million, during a 41-minute period on July 30.
  • The stolen Bitcoin was consolidated into a small number of addresses within minutes and has not been moved since the attack.
  • Coinkite has issued emergency hotfixes and urged exposed users to migrate to newly generated seeds, as firmware updates cannot remediate seeds already created on compromised devices.
  • Changpeng Zhao advised cryptocurrency holders to spread their funds across multiple wallets to reduce exposure, emphasizing that no hardware wallet is completely immune to vulnerabilities.
CZ Warns Bitcoin Holders After $70 Million Coldcard Exploit: 'Nothing Is 100%'

Binance founder Changpeng "CZ" Zhao is urging cryptocurrency owners not to place blind faith in hardware wallets after an exploit drained tens of millions of dollars in Bitcoin from Coldcard devices.

Coldcard, manufactured by Coinkite, is a widely used air-gapped Bitcoin hardware wallet popular among security-conscious self-custody advocates for its physical isolation from internet-connected devices — a design that makes the exploit especially notable for users who assumed their keys were generated in a tamper-proof environment.

In a Saturday post on X, Zhao cautioned that even hardware wallets can carry bugs and that older wallets with long operational histories are not immune. "Nothing is 100%," he wrote.

He recommended that holders consider spreading funds across several wallets to reduce exposure, while acknowledging the approach carries its own trade-offs and that no setup is entirely foolproof. Zhao closed with his familiar refrain: "Stay SAFU!"

His comments followed the discovery of a critical flaw in Coldcard hardware wallets. As Decrypt reported, a build error caused seeds on affected units to be drawn from a software fallback rather than the device's hardware random-number generator, leaving private keys far easier to guess than intended. The random-number generator is foundational to cryptographic security — if the source of randomness is predictable, the resulting private keys can be reverse-engineered by anyone aware of the pattern.

The problem traces back to firmware shipped in March 2021. Updating the firmware does not fix a seed already created on a compromised device.

We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett

1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks… pic.twitter.com/q785paZvMQ

— Galaxy Research (@glxyresearch) July 31, 2026

The scope of the theft has grown considerably since initial estimates. Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets.

According to a report from Galaxy Research, which mapped fund flows based on a vulnerability pattern identified by engineers at Jack Dorsey's Block and shared by @clay_garrett, the toll now stands at 1,196 addresses drained for approximately 1,082.65 BTC, or roughly $70.2 million, within a 41-minute window on July 30. That figure is nearly double the initial estimate.

Galaxy noted that every sweep paid an identical hardcoded fee and left no change output — a signature the firm described as consistent with an automated tool spending keys it already held, rather than legitimate owners moving their own funds. Victims spanned both native SegWit and older address types, pointing to multi-path key scanning.

The stolen Bitcoin was consolidated within minutes into a handful of addresses and, according to Galaxy, has not moved since.

Coinkite has shipped emergency hotfixes and urged exposed users to migrate to newly generated seeds. The incident underscores a broader challenge for the hardware wallet industry: even devices marketed on the strength of their physical security depend on firmware integrity, and a single build error can undermine years of trust.