Coldcard, a hardware wallet widely used for Bitcoin storage, has come under renewed scrutiny after a major security flaw in older firmware was linked to unauthorized fund transfers from some users’ wallets. Investigators said the issue involved insufficient randomness in the generation of recovery seed phrases, allowing attackers to reconstruct private keys through offline computation without obtaining the physical device.
Binance founder Changpeng Zhao, or CZ, responded on X by saying there is no absolutely secure storage mechanism. He urged crypto holders to remain cautious and consider distributing assets across multiple wallets to reduce risk.
Firmware weakness traced to seed phrase randomness issue
According to on-chain data and an analysis report from Galaxy Research, the attack stemmed from a firmware vulnerability released for Coldcard devices in March 2021. The flaw weakened the randomness required when generating recovery seed phrases, making it possible for attackers to rebuild private keys through offline calculation even without touching the hardware wallet itself.
The analysis said attackers moved 1,082.65 BTC from 1,196 addresses in about 41 minutes. The stolen funds were valued at roughly $70 million, and many of the affected wallets had been inactive for years.
Coinkite issues apology and emergency update
Coldcard manufacturer Coinkite has publicly apologized for the incident and released an emergency firmware update. The company said a firmware upgrade by itself cannot repair mnemonic seed phrases that were originally generated on affected versions.
Coinkite warned that any user who created a seed on the vulnerable firmware must generate a completely new seed phrase on a repaired device and transfer funds to that new wallet.
CZ says spreading funds can reduce concentration risk
Zhao said even long-established cold wallets that have earned broad trust can still contain undiscovered security flaws, and that no system offers absolute safety.
He said users may want to spread holdings across different wallets as a way to diversify risk. At the same time, he acknowledged that this makes private key and credential management more complicated, adding to the burden of self-custody and requiring users to stay vigilant at all times.
Incident revives debate over self-custody risk
Cold wallets have long been treated as one of the safest ways to protect Bitcoin offline. This Coldcard case, however, shows that even offline hardware devices can still be exposed if a firmware version contains exploitable weaknesses. The report also said some experts believe the attack may have been linked to artificial intelligence technology, though no further detail was provided.
The incident has reopened debate across the crypto community over the idea of complete self-custody. Whether users rely on hardware wallets or software wallets, they still face the risks that come with code vulnerabilities and the complexity of key management. In that context, spreading assets rather than concentrating funds in a single channel has become one response to potential threats.

