Binance's CZ Warns Against Blind Faith in Hardware Wallets After $70M Coldcard Exploit
Quick Look
- Binance founder Changpeng "CZ" Zhao warned crypto owners about hardware wallet vulnerabilities after a Coldcard exploit drained over $70 million in Bitcoin.
- A flaw in firmware shipped in March 2021 allowed private keys to be guessed, affecting 1,196 addresses, prompting Coinkite to issue hotfixes.
AI-generated summary
Why It Matters
Binance founder CZ issued a warning about hardware wallet vulnerabilities after a Coldcard device exploit led to the theft of over $70 million in Bitcoin. The flaw, stemming from a build error in firmware shipped in March 2021, compromised the generation of private keys.
Binance founder Changpeng "CZ" Zhao is warning crypto owners not to place blind faith in hardware wallets, following an exploit that drained tens of millions of dollars in Bitcoin from Coldcard devices.
In a Saturday post on X, Zhao cautioned that even hardware wallets can carry bugs, and that older wallets with long histories are not immune. “Nothing is 100%,” he posted.
He suggested holders consider spreading their funds across several wallets as one way to reduce exposure, while acknowledging the approach carries its own trade-offs and that no setup is entirely foolproof. CZ closed with his familiar refrain urging users to stay informed and keep their funds safe: “Stay SAFU!”
His comments followed the discovery of a flaw in Coldcard devices made by manufacturer Coinkite. As Decrypt reported, a build error caused seeds on affected units to be drawn from a software fallback rather than the device's hardware random-number generator, leaving the private keys far easier to guess than intended. The problem traced back to firmware shipped in March 2021, and updating the firmware does not fix a seed already created on a compromised device.
The scope of the theft has grown considerably since the first estimates. Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets. According to a report from Galaxy Research, which mapped the flow of funds based on a pattern identified by engineers at Jack Dorsey’s Block, the toll is now put at 1,196 addresses drained for about 1,082.65 BTC, or roughly $70.2 million, in a 41-minute window on July 30. That is nearly double the initial figure.
Galaxy said every sweep paid an identical hardcoded fee and left no change output, a signature it described as consistent with an automated tool spending keys it already held rather than owners moving their own funds. The victims spanned native SegWit and older address types, pointing to multi-path key scanning. The stolen Bitcoin was consolidated within minutes into a handful of addresses and, per Galaxy, has not moved since.
Coinkite has shipped emergency hotfixes and urged exposed users to migrate to newly generated seeds.
What to Watch
AI outlook — possibilities, not facts
Coldcard users will migrate funds from compromised devices to newly generated seeds.
Likely · Within weeks
Open Questions
- Will Coinkite offer compensation to affected users?
- How many more Coldcard devices are vulnerable?
- What specific steps can users take to verify their seed generation?







