Binance founder CZ advises wallet diversification after $70 million Coldcard exploit
window 24h
IN SHORT
A firmware flaw in Coldcard hardware wallets, stemming from a March 2021 release, has led to the exploitation of thousands of wallets, resulting in the loss of nearly $89 million in bitcoin. Attackers reproduced keys generated with weak software-based randomness to systematically drain funds. Binance founder Changpeng Zhao (CZ) is advising crypto holders to diversify their holdings across multiple wallets following this incident, which underscores the risks of self-custody solutions.
✉Newsletter
PiQ Daily
Pick your topics. Get only what matters, on your cadence.
Key Numbers
$89 milliontotal bitcoin stolen from Coldcard wallets
1,367 bitcointotal bitcoin stolen
4,585 addressesaddresses affected by the exploit
March 2021Coldcard firmware release date
threewaves of attacks
Who's Involved
Coldcard
hardware wallet manufacturer affected by firmware exploit
Changpeng Zhao (CZ)
Binance founder advising crypto holders on wallet diversification
A vulnerability in a March 2021 Coldcard firmware release has been exploited.
Attackers reproduced keys generated with weak software-based randomness.
Thousands of Bitcoin cold wallets have been drained.
Nearly $89 million in bitcoin has been stolen.
A total of 1,367 bitcoin was stolen.
The attacks affected 4,585 addresses.
There have been three waves of attacks.
Binance founder Changpeng Zhao (CZ) is advising wallet diversification.
The exploit highlights risks associated with self-custody solutions.
A significant exploit targeting Coldcard hardware wallets has resulted in the loss of nearly $89 million in bitcoin due to a vulnerability in a March 2021 firmware release. Attackers exploited a flaw related to weak software-based randomness used in key generation, enabling them to reproduce private keys and systematically drain bitcoin from affected wallets. This attack has impacted 4,585 addresses, with a total of 1,367 bitcoin stolen across three waves of attacks. The incident has prompted Binance founder Changpeng Zhao (CZ) to advise cryptocurrency holders to diversify their assets across multiple wallets. This event highlights the inherent risks associated with even established self-custody solutions within the cryptocurrency space. The exploit specifically targeted keys generated using compromised randomness, allowing attackers to gain unauthorized access to the bitcoin held within these wallets. The scale of the loss, amounting to approximately $89 million, underscores the potential financial ramifications of such security breaches. The advice from CZ emphasizes a proactive approach to risk management for crypto investors, suggesting that relying on a single hardware wallet may not be sufficient to protect against sophisticated exploits.
Frequently asked questions
An exploit targeted a firmware flaw in certain Coldcard hardware wallets, weakening the randomness of recovery seed generation and allowing attackers to steal approximately $70 million in Bitcoin.
The attacker exploited a firmware flaw to reconstruct private keys offline, enabling them to drain Bitcoin from affected wallets without physical access to the devices.
Binance founder CZ advised crypto holders to split their funds across multiple wallets to mitigate the risk of a single point of failure.
Coinkite acknowledged the bug, apologized, released emergency firmware updates, and advised users to create new seeds on patched devices and migrate their funds.
What Happens Next
01Users are advised to create new seeds on patched Coldcard devices and migrate funds.
02The crypto community will likely continue debating the best practices for securing digital assets.
Get the newsletter.
Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.