Community Trust ScoreVerified
Binance founder Changpeng Zhao — CZ to pretty much everyone in crypto — is telling holders to split their funds across multiple wallets. His reason: a $70 million exploit just gutted Coldcard hardware devices, and the damage is worse than first reported.
The numbers kept climbing after the initial shock. On July 30, bitcoin users started noticing unauthorized transactions draining their Coldcard wallets. Early figures put the theft at roughly 594 BTC — around $38 million — pulled from about 500 wallets in under 25 minutes. Bad enough. But later analysis told a grimmer story: 1,082.65 BTC, worth approximately $70 million, was actually taken from 1,196 addresses across a 41-minute window. A lot of those wallets had been sitting inactive for a long time, which probably made them easier targets. The attacker didn’t need physical access to any device. They exploited a firmware flaw buried in the code since March 2021 — a bug that weakened the randomness used when generating recovery seeds. With that randomness compromised, reconstructing private keys offline was doable. And apparently someone did exactly that.
Cold storage. Supposed to be safe.
What Coinkite Said — and What It Means for Users
Coldcard’s manufacturer, Coinkite, admitted to the flaw. They pushed out emergency firmware updates fast, which is the right move. But here’s the part that’s easy to miss: updating the firmware doesn’t fix the problem for wallets that already generated seeds on vulnerable versions. The seeds themselves are compromised. Coinkite’s guidance is clear — users who created recovery seeds on affected firmware need to generate entirely new ones on patched devices, then migrate their funds. It’s not optional. It’s not a “nice to have.” If you skip that step, you’re still exposed.
That’s a lot of work for users who thought hardware wallets were basically set-and-forget. They’re not, clearly.
The flaw apparently sat undetected from March 2021 until now. That’s years of wallets operating with weakened entropy in their seed generation, and nobody caught it — or if someone did, they didn’t say anything publicly. That’s the part of this story that should make people uncomfortable. Hardware wallets have a strong reputation for security, and that reputation is mostly deserved. But “mostly” isn’t “completely,” and this breach is a hard reminder of that gap.
CZ’s Diversification Call and the Tradeoffs It Brings
CZ’s advice sounds simple: don’t keep everything in one wallet. Spread it out. If one device or one seed gets compromised, you haven’t lost everything. It’s the crypto equivalent of not keeping all your savings in a single bank account — basic risk management, really.
But it’s not without friction. Managing multiple wallets means managing multiple private keys, multiple seed phrases, multiple recovery processes. Get any of it wrong — lose a seed phrase, mix up a key, send funds to the wrong address during migration — and you’ve created a different kind of loss. Self-custody is powerful precisely because it cuts out intermediaries, but that power comes with full personal responsibility. There’s no customer support line. No fraud department. No chargeback.
So CZ’s recommendation is sound, but it’s also kind of a double-edged thing. Diversification spreads risk. It also multiplies the surface area where human error can happen.
The broader crypto community has been wrestling with this tension for years. Hardware wallets became popular because they kept private keys offline, away from internet-connected devices where most hacks occur. The Coldcard breach doesn’t invalidate that logic — it just adds a layer. Firmware matters. Seed generation quality matters. And even devices with strong reputations can carry flaws that stay hidden for years before someone finds them.
Coinkite moved quickly once the exploit surfaced. Emergency patches, public acknowledgment, clear instructions for affected users. That’s a reasonable response to a serious failure.
Still, 1,196 addresses drained. 1,082.65 BTC gone. Many of those wallets hadn’t moved funds in a long time, which means some of those losses probably hit people who assumed their cold storage was sitting safely untouched. It wasn’t.
Users who haven’t yet checked whether their Coldcard firmware version falls within the affected range should do that now. Coinkite’s updated firmware is available. New seed generation on patched devices is the required step — not optional, not later.
The $70 million figure is what grabs headlines. The firmware flaw from March 2021 is what should keep hardware wallet users up at night.
Frequently Asked Questions
What caused the Coldcard wallet exploit?
A firmware flaw dating to March 2021 weakened the randomness used in recovery seed generation, letting an attacker reconstruct private keys offline and drain funds without physical access to devices.
How much was stolen in the Coldcard breach?
Later analysis put the total at 1,082.65 BTC — roughly $70 million — taken from 1,196 addresses over a 41-minute window on July 30.
What should Coldcard users do now?
Coinkite says users who generated seeds on vulnerable firmware versions must create new recovery seeds on updated, patched devices and migrate their funds — updating firmware alone is not enough.





