Binance founder Changpeng “CZ” Zhao warned crypto holders against placing blind trust in hardware wallets after a Coldcard-related exploit was linked to tens of millions of dollars in stolen Bitcoin.

In a Saturday post on X, Zhao said hardware wallets can still contain bugs, and that older products with long operating histories are not immune. “Nothing is 100%,” he wrote.
Zhao said one way to reduce exposure is to spread holdings across several wallets. He also noted the trade-offs in that approach and said no arrangement is completely foolproof. He ended the post with a familiar signoff: “Stay SAFU!”
Flaw traced to firmware shipped in March 2021
Zhao’s comments came after a vulnerability was uncovered in Coldcard devices made by Coinkite. As Decrypt previously reported, a build error caused seeds on affected units to be generated from a software fallback instead of the device’s hardware random-number generator, making the resulting private keys much easier to guess than intended.
The issue was traced back to firmware shipped in March 2021. Updating the firmware does not fix a seed that was already created on a compromised device.
Galaxy Research raised the loss estimate
The scale of the theft has expanded well beyond the earliest estimates. Initial reports put the losses at about 594 BTC, or roughly $38 million, drained from around 500 wallets.
Galaxy Research later mapped the flow of funds using a pattern identified by engineers at Jack Dorsey’s Block. According to that report, 1,196 addresses were drained in full for about 1,082.65 BTC, worth roughly $70.2 million, between 01:10:20 and 01:51:26 UTC on July 30. That 41-minute window nearly doubled the initial tally.
Galaxy said every sweep used the same hardcoded fee and produced no change output. It said that signature was consistent with an automated tool spending keys it already controlled, rather than wallet owners moving their own coins.
The affected wallets included both native SegWit and older address formats, which Galaxy said pointed to multi-path key scanning. The stolen Bitcoin was consolidated within minutes into a small number of addresses and, according to Galaxy, has not moved since.
Coinkite issued emergency hotfixes
Coinkite has shipped emergency hotfixes and urged exposed users to migrate to newly generated seeds.

