Crypto

Coldcard bitcoin exploit prompts CZ warning on wallet security

CZ urged crypto holders to spread risk after Galaxy Research traced about $70.2 million in Bitcoin losses tied to a Coldcard flaw.

Sofia Marchetti

By Sofia Marchetti · Columnist

· 3 min read

Coldcard bitcoin exploit prompts CZ warning on wallet security
Photo: Decrypt

The Coldcard bitcoin exploit has put hardware wallet security back in focus for crypto holders after Galaxy Research said it traced about $70.2 million in drained Bitcoin. Binance founder Changpeng “CZ” Zhao responded by warning on X that even devices built for self-custody can contain bugs, a reminder for retail investors that “offline” does not mean risk-free.

In a Saturday post on X, Zhao said hardware wallets and older wallets with long track records can still fail. “Nothing is 100%,” he wrote. He suggested users consider spreading funds across multiple wallets to reduce exposure to any one failure point, while also saying that approach comes with trade-offs and does not make funds fully protected.

A hardware wallet is a physical device used to store crypto keys away from an internet-connected computer. Those keys control access to the coins, so a weakness in how they are created can turn a security product into a target.

What happened in the Coldcard bitcoin exploit?

The issue involved Coldcard devices made by Coinkite, according to Decrypt’s prior reporting cited in the matter. A build error in firmware shipped in March 2021 caused seeds on affected devices to come from a software fallback rather than the wallet’s hardware random-number generator.

A seed is the recovery phrase or underlying secret used to derive a wallet’s private keys. If that seed is generated with weak randomness, attackers may have a much easier path to guessing the private keys that move the Bitcoin.

Updating firmware does not repair a seed that was already created on a compromised device, according to the reporting. That detail is especially important for long-term holders, since a wallet can appear to work normally while still relying on keys generated under flawed conditions.

Galaxy Research said on X that it mapped the movement of funds tied to the Coldcard vulnerability using a pattern identified by engineers at Block and shared by Clay Garrett. The firm estimated that 1,196 addresses were drained in full for 1,082.65 BTC, worth about $70.2 million, between 01:10:20 and 01:51:26 UTC on July 30.

That estimate is nearly twice the earlier loss figure of $38 million cited in Decrypt’s coverage. Galaxy Research’s figure reflects its tracing of fund flows, while the original estimate came before the broader mapping described by the firm.

For everyday crypto investors, the lesson is less about one product and more about concentration risk. Zhao’s suggestion to split holdings across several wallets would limit the damage if one setup fails, but it also adds operational risk: more devices, more seed phrases and more chances to make a mistake.

Zhao ended his warning with his familiar safety refrain, “Stay SAFU.” His broader point was direct: self-custody gives users control of their assets, but it also puts security decisions, backups and wallet choices on the holder.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto