All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Binance founder CZ advises wallet diversification after $70 million Coldcard exploit

Created at 1 Aug · 9:06 AM1 source↑ Market-relevant
IN SHORT

Binance founder Changpeng Zhao, known as CZ, urged crypto holders to diversify their funds across multiple wallets following a $70 million exploit of Coldcard hardware devices. The exploit targeted a firmware flaw that weakened seed generation, allowing attackers to reconstruct private keys and steal Bitcoin from dormant wallets.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$70 milliontotal value stolen from Coldcard wallets
1,196addresses affected by the exploit
1,082.65 bitcointotal bitcoin stolen
March 2021date of firmware flaw
41 minutesduration of fund drain

Who's Involved

Changpeng Zhao
Binance founder, advised wallet diversification
CZ
Binance founder, advised wallet diversification
Coinkite
Coldcard maker, acknowledged bug and released updates
Galaxy Research
Provided analysis on the scope of the exploit
Binance founder CZ advises wallet diversification after $70 million Coldcard exploit

↳ Why This Matters

The exploit highlights that even widely-trusted hardware wallets can have critical security flaws, prompting a re-evaluation of self-custody strategies and potentially increasing demand for diversified wallet approaches.

Key facts

  • A $70 million exploit targeted Coldcard hardware wallets, stealing Bitcoin from over 1,000 addresses.
  • The exploit exploited a firmware flaw weakening the randomness used for generating recovery seeds.
  • Binance founder Changpeng Zhao (CZ) advised crypto holders to diversify funds across multiple wallets.
  • Coldcard maker Coinkite has released emergency firmware updates and advised users to migrate funds.
  • The incident has reignited debates about the security limits of self-custody hardware wallets.

Crypto holders are now being advised to diversify their holdings across multiple wallets, a shift in security strategy prompted by a significant exploit targeting Coldcard hardware devices. The incident, which saw approximately $70 million worth of Bitcoin stolen, highlighted vulnerabilities even in established self-custody solutions.

Binance founder Changpeng Zhao, widely known as CZ, recommended splitting funds across several wallets as a mitigation strategy. He noted that even hardware wallets and those with a long history can harbor undetected bugs. The exploit, discovered on July 30, involved a firmware flaw dating back to March 2021 that compromised the randomness of recovery seed generation on certain Coldcard models. This allowed an attacker to reconstruct private keys offline and drain funds from numerous wallets, many of which had been inactive for years.

Initial reports estimated around 594 BTC ($38 million) stolen from about 500 wallets within a 25-minute period. However, further analysis by Galaxy Research expanded the estimated losses to 1,082.65 BTC, valued at approximately $70 million, drained from 1,196 addresses over roughly 41 minutes.

Coldcard's manufacturer, Coinkite, has acknowledged the security flaw, issued an apology, and released emergency firmware updates. The company strongly advises users who generated seeds on affected versions to create new seeds on patched devices and migrate their funds, emphasizing that a simple firmware update does not secure an already compromised seed.

The Coldcard exploit has reignited discussions about the inherent risks and limitations of self-custody, even with hardware wallets considered a robust method for offline Bitcoin storage. CZ's suggestion underscores the practical challenges of diversification, which include more complex key management, and the reality that no security measure is entirely foolproof.

Frequently asked questions

An exploit targeted a firmware flaw in certain Coldcard hardware wallets, weakening the randomness of recovery seed generation and allowing attackers to steal approximately $70 million in Bitcoin.

The attacker exploited a firmware flaw to reconstruct private keys offline, enabling them to drain Bitcoin from affected wallets without physical access to the devices.

Binance founder CZ advised crypto holders to split their funds across multiple wallets to mitigate the risk of a single point of failure.

Coinkite acknowledged the bug, apologized, released emergency firmware updates, and advised users to create new seeds on patched devices and migrate their funds.

What Happens Next

01Users are advised to create new seeds on patched Coldcard devices and migrate funds.
02The crypto community will likely continue debating the best practices for securing digital assets.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Bitcoin users discovered funds stolen from Coldcard wallets on July 30.
An attacker exploited a firmware flaw dating to March 2021 that weakened seed generation.
Initial reports indicated $38 million in Bitcoin stolen from approximately 500 wallets.
Subsequent analysis revealed $70 million in Bitcoin stolen from 1,196 addresses.
Coldcard maker Coinkite acknowledged the bug, apologized, and released emergency firmware updates.
CZ advised crypto holders to split funds across multiple wallets to mitigate risks.

Sources

T1
Binance founder CZ calls for wallet diversification after $70 million Coldcard exploitCoinDesk

Related Stories

Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider
31 Jul · 3:25 PM
Bitcoin cold wallets drained of $70M in firmware flaw attack
1 Aug · 6:06 AM
FTX users receive funds, Citadel buys stock, Coldcard warns users
31 Jul · 8:06 PM
Dubai crypto exchange linked to $4B Iran sanctions evasion network
31 Jul · 12:36 PM
Texans Lost $57M to Crypto Kiosk Scams in 2025, Lawmakers Consider Ban
31 Jul · 11:21 AM