Coldcard's "random" seeds weren't, and CZ just told everyone to stop putting all their BTC in one basket 🧺
Binance founder Changpeng "CZ" Zhao is urging crypto holders to spread their funds across multiple wallets after a firmware flaw in Coinkite's Coldcard hardware devices enabled the theft of roughly 1,082.65 BTC, valued at about $70.2 million, from 1,196 addresses in a 41-minute window on July 30. In a Saturday post on X, Zhao wrote: "Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!" The post did not single out any manufacturer and acknowledged that diversification carries its own trade-offs.
The flaw originated in Coldcard firmware shipped in March 2021. According to a report from Decrypt, a build error caused seeds on affected units to be drawn from a software fallback rather than the device's hardware random-number generator, leaving the resulting private keys far easier to guess than intended. The issue remained undetected for years; some of the compromised wallets had sat dormant since that period before being drained. Coinkite has shipped emergency hotfixes, apologized to users, and instructed anyone who generated a seed on an affected version to create an entirely new seed on a patched device and migrate funds manually, noting that updating the firmware does not secure a seed already created on a compromised unit.
The scope of the theft has grown considerably since initial reporting. Early estimates, including from CoinDesk, placed losses at about 594 BTC, or roughly $38 million at the time, drained from around 500 wallets in a 25-minute window. Subsequent analysis from Galaxy Research, which mapped the flow of funds based on a pattern identified by engineers at Jack Dorsey's Block, revised the figure upward to 1,082.65 BTC (~$70.2 million) across 1,196 addresses between 01:10:20 and 01:51:26 UTC on July 30. Galaxy said every sweep paid an identical hardcoded fee and left no change output, a signature it described as consistent with an automated tool spending keys it already held rather than owners moving their own funds, and that victims spanned native SegWit and older address types, pointing to multi-path key scanning.
The stolen Bitcoin was consolidated within minutes into a handful of addresses and, per Galaxy, has not moved since. CZ's call for wallet diversification reflects a wider debate over the limits of self-custody: hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard episode shows that even long-established devices can harbor critical flaws that remain undetected for years, and spreading funds across multiple wallets introduces more complex key-management requirements. Coinkite and outside researchers have not publicly identified the attacker, and no funds have been recovered.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.