CZ urges wallet diversification after Coldcard flaw linked to $70 million BTC theft

CZ urges wallet diversification after Coldcard flaw linked to $70 million BTC theft

N
News Editor
2026-08-03 00:38:51
A security flaw in older Coldcard firmware has drawn renewed scrutiny to hardware wallet safety after attackers were found to have reconstructed private keys through offline computation. According to on-chain data and analysis from Galaxy Research, the exploit stemmed from a weakness in the randomness used to generate recovery seed phrases in firmware released in March 2021. The report said 1,082.65 BTC were drained from 1,196 addresses in about 41 minutes, with losses valued at roughly $70 million and a number of long-dormant wallets affected. In response, Binance founder Changpeng Zhao, known as CZ, said on X that no storage method is absolutely secure. He urged crypto holders to stay alert and consider spreading funds across multiple wallets to reduce concentration risk. Zhao also noted that such an approach raises the complexity of private key management, leaving users to deal with the operational burden that comes with self-custody. Coldcard maker Coinkite has apologized publicly and released an emergency firmware update. The company warned that updating firmware alone does not fix seed phrases created on affected versions, and said users who generated seeds on the vulnerable firmware need to create entirely new seed phrases on repaired devices and move their assets.

Coldcard, a hardware wallet widely used for Bitcoin storage, has come under renewed scrutiny after a major security flaw in older firmware was linked to unauthorized fund transfers from some users’ wallets. Investigators said the issue involved insufficient randomness in the generation of recovery seed phrases, allowing attackers to reconstruct private keys through offline computation without obtaining the physical device.

Binance founder Changpeng Zhao, or CZ, responded on X by saying there is no absolutely secure storage mechanism. He urged crypto holders to remain cautious and consider distributing assets across multiple wallets to reduce risk.

Firmware weakness traced to seed phrase randomness issue

According to on-chain data and an analysis report from Galaxy Research, the attack stemmed from a firmware vulnerability released for Coldcard devices in March 2021. The flaw weakened the randomness required when generating recovery seed phrases, making it possible for attackers to rebuild private keys through offline calculation even without touching the hardware wallet itself.

The analysis said attackers moved 1,082.65 BTC from 1,196 addresses in about 41 minutes. The stolen funds were valued at roughly $70 million, and many of the affected wallets had been inactive for years.

Coinkite issues apology and emergency update

Coldcard manufacturer Coinkite has publicly apologized for the incident and released an emergency firmware update. The company said a firmware upgrade by itself cannot repair mnemonic seed phrases that were originally generated on affected versions.

Coinkite warned that any user who created a seed on the vulnerable firmware must generate a completely new seed phrase on a repaired device and transfer funds to that new wallet.

CZ says spreading funds can reduce concentration risk

Zhao said even long-established cold wallets that have earned broad trust can still contain undiscovered security flaws, and that no system offers absolute safety.

He said users may want to spread holdings across different wallets as a way to diversify risk. At the same time, he acknowledged that this makes private key and credential management more complicated, adding to the burden of self-custody and requiring users to stay vigilant at all times.

Incident revives debate over self-custody risk

Cold wallets have long been treated as one of the safest ways to protect Bitcoin offline. This Coldcard case, however, shows that even offline hardware devices can still be exposed if a firmware version contains exploitable weaknesses. The report also said some experts believe the attack may have been linked to artificial intelligence technology, though no further detail was provided.

The incident has reopened debate across the crypto community over the idea of complete self-custody. Whether users rely on hardware wallets or software wallets, they still face the risks that come with code vulnerabilities and the complexity of key management. In that context, spreading assets rather than concentrating funds in a single channel has become one response to potential threats.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
640

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.