Key facts
- A $70 million exploit targeted Coldcard hardware wallets, stealing Bitcoin from over 1,000 addresses.
- The exploit exploited a firmware flaw weakening the randomness used for generating recovery seeds.
- Binance founder Changpeng Zhao (CZ) advised crypto holders to diversify funds across multiple wallets.
- Coldcard maker Coinkite has released emergency firmware updates and advised users to migrate funds.
- The incident has reignited debates about the security limits of self-custody hardware wallets.
Crypto holders are now being advised to diversify their holdings across multiple wallets, a shift in security strategy prompted by a significant exploit targeting Coldcard hardware devices. The incident, which saw approximately $70 million worth of Bitcoin stolen, highlighted vulnerabilities even in established self-custody solutions.
Binance founder Changpeng Zhao, widely known as CZ, recommended splitting funds across several wallets as a mitigation strategy. He noted that even hardware wallets and those with a long history can harbor undetected bugs. The exploit, discovered on July 30, involved a firmware flaw dating back to March 2021 that compromised the randomness of recovery seed generation on certain Coldcard models. This allowed an attacker to reconstruct private keys offline and drain funds from numerous wallets, many of which had been inactive for years.
Initial reports estimated around 594 BTC ($38 million) stolen from about 500 wallets within a 25-minute period. However, further analysis by Galaxy Research expanded the estimated losses to 1,082.65 BTC, valued at approximately $70 million, drained from 1,196 addresses over roughly 41 minutes.
Coldcard's manufacturer, Coinkite, has acknowledged the security flaw, issued an apology, and released emergency firmware updates. The company strongly advises users who generated seeds on affected versions to create new seeds on patched devices and migrate their funds, emphasizing that a simple firmware update does not secure an already compromised seed.
The Coldcard exploit has reignited discussions about the inherent risks and limitations of self-custody, even with hardware wallets considered a robust method for offline Bitcoin storage. CZ's suggestion underscores the practical challenges of diversification, which include more complex key management, and the reality that no security measure is entirely foolproof.
