CZ Warns Users After Coldcard Exploit Tops $70M in BTC Losses

Binance founder Changpeng Zhao said even long-established hardware wallets can contain critical software bugs after researchers linked a Coldcard firmware vulnerability to the theft of more than 1,082 Bitcoin, currently valued at around $70 million.
Summary
- Changpeng Zhao urged users to diversify crypto holdings after a Coldcard firmware flaw enabled one of the largest known hardware wallet thefts.
- Researchers now estimate attackers stole more than 1,082 BTC from nearly 1,200 wallets generated with vulnerable firmware.
- Coinkite has patched the issue for future wallet creation, but existing wallets remain at risk until funds are migrated.
- The incident has renewed debate over whether operational security matters as much as the choice of custody solution.
CZ Calls for Diversification, Not Blind Trust
Responding to reports of the exploit, Zhao said users should avoid assuming any wallet offers perfect protection simply because it has operated reliably for years.
“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs,” Zhao wrote on X.
Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs.
How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%.
Stay informed. Stay SAFU! https://t.co/9CHiNlbJbz
— CZ 🔶 BNB (@cz_binance) August 1, 2026
Rather than recommending a single storage solution, he suggested distributing assets across multiple wallets to reduce concentration risk. Zhao also acknowledged that this approach creates its own trade-offs, noting that “nothing is 100%” and encouraging users to remain informed rather than relying solely on any single security product.
His comments reflect a broader principle in cryptocurrency security: eliminating one risk often introduces another, making operational practices as important as the wallet itself.
Researchers Trace the Attack to 2021 Firmware
According to Galaxy Research and independent blockchain security researchers, the exploit originated from a vulnerability introduced with Coldcard firmware v4.0.0, released in March 2021.
The flaw affected how certain devices generated recovery seeds by relying on weakened pseudo-random number generation under specific conditions. Reduced entropy made some seed phrases substantially easier to brute-force than intended, allowing attackers to reconstruct private keys and drain affected wallets.
Researchers now estimate the coordinated attack compromised approximately 1,082.65 BTC across 1,196 wallet addresses, making it one of the largest publicly documented hardware wallet exploits involving Bitcoin.
On-chain analysis also identified common characteristics across the thefts, including nearly identical transaction fee rates and transaction structures, indicating the campaign was executed through automated tooling rather than isolated attacks.
Updating Firmware Alone Is Not Enough
Coinkite has released updated firmware designed to prevent vulnerable seed generation on newly initialized devices.
However, security experts stress that installing the update does not secure wallets whose recovery phrases were originally created using affected firmware versions.
Instead, users believed to be at risk are advised to:
- Generate a completely new wallet using patched firmware or another verified secure method.
- Transfer all funds to addresses derived from the new seed phrase.
- Verify the migration with a small test transaction before moving larger balances.
Wallets initialized using external entropy, such as manual dice rolls, are generally not considered vulnerable because they bypass the affected random-number generation process.
The Incident Extends Beyond Coldcard
The exploit has sparked a broader discussion about digital asset custody at a time when institutional adoption continues to grow.
While hardware wallets remain widely regarded as one of the most secure methods for self-custody, the Coldcard incident highlights that protecting crypto assets depends not only on offline storage but also on the integrity of key generation software. The episode may strengthen interest in regulated custodians and spot Bitcoin ETFs among more conservative investors, while reinforcing for self-custody users that firmware updates, seed generation methods and ongoing security reviews are critical parts of safeguarding digital assets.
The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.











