The $70 million Coldcard exploit prompts CZ to urge wallet diversification.

Abstract:Following a roughly $70 million Coldcard exploit, Binance founder Changpeng Zhao advised crypto holders to split funds across several wallets, acknowledging that no solution is risk-free. The attack stemmed from a firmware flaw dating to March 2021 that weakened randomness in recovery seeds on certain Coldcard models, allowing the attacker to reconstruct private keys offline and drain 1,082.65 bitcoin from 1,196 addresses, many dormant for years. Maker Coinkite apologized, released emergency firmware updates, and stressed that users with vulnerable seeds must create new seeds on patched devices, since updating alone does not secure existing seeds. The incident has renewed debate about self-custody limits and the trade-offs of wallet diversification.

Crypto holders used to focus on diversifying their coins. Now, following a $70 million Coldcard exploit, theyre being told to diversify their wallets as well.

On Saturday, Binance founder Changpeng Zhao, known as CZ, asked crypto holders to split their funds across multiple wallets following a major security failure in popular Coldcard hardware devices.

“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!,” he said.

On July 30, some bitcoin users discovered that funds from their Coldcard wallets had been stolen in a series of unexpected transactions. The attacker exploited a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. By reconstructing private keys offline, the attacker was able to drain funds without ever physically accessing the devices.

Initial reports said about 594 BTC, worth $38 million at the time, were drained from around 500 wallet in a 25-minute window. Subsequent analysis by Galaxy Research expanded the scope to 1,082.65 bitcoin, valued at approximately $70 million, drained from 1,196 addresses over about 41 minutes. Many of the affected wallets had sat dormant for years.

Coldcard maker Coinkite has acknowledged the bug, apologized, and released emergency firmware updates. The company has advised users who generated seeds on affected versions to create entirely new seeds on patched devices and carefully migrate funds, noting that simply updating firmware does not secure an already-created vulnerable seed.

The episode has renewed debate over the limits of self-custody. Hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard case shows that even long-established devices can harbor critical flaws that remain undetected for years.

CZs suggestion of diversification acknowledges that spreading risk comes with its own practical challenges, including more complex key management.

Disclaimer

The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
Previous Post

From crypto treasury to AI data centers: Inside the aggressive 4,375 ETH selloff that just hit a massive collateral wall

Next

Double-Digit Gains From These 2 Altcoins, Bitcoin Struggles at $63K: Weekend Watch