Summary

  • Changpeng "CZ" Zhao advised on X that even reliable hardware wallets can have vulnerabilities, recommending users diversify their holdings across multiple wallets while acknowledging that no wallet is completely secure.
  • This warning comes in the wake of a Coldcard exploit linked to a firmware flaw from March 2021, which allowed private keys to be more easily compromised.
  • According to Galaxy Research, losses related to this incident are now estimated at around 1,082.65 BTC (approximately $70.2 million) across 1,196 addresses, nearly doubling earlier estimates of $38 million.

Binance's founder, Changpeng "CZ" Zhao, has issued a warning to cryptocurrency holders about over-relying on hardware wallets after a significant breach involving Coldcard devices resulted in the loss of millions in Bitcoin.

In a post on X, Zhao emphasized that hardware wallets are not immune to bugs, stating, “Nothing is 100%,” and encouraged users to consider spreading their assets across several wallets to mitigate risks, though he recognized that this strategy has its drawbacks. He concluded with his well-known message to users to remain vigilant and safeguard their assets: “Stay SAFU!”

This caution follows the discovery of a vulnerability in Coldcard devices manufactured by Coinkite. As reported by Decrypt, a firmware issue allowed seed phrases to be generated from a software fallback instead of the secure hardware random-number generator, making it easier to guess private keys. This issue originated from a firmware version released in March 2021, and simply updating the firmware does not rectify compromised seeds.

We traced the fund flows related to the Coldcard vulnerability based on a pattern identified by engineers at Block, as shared by @clay_garrett.

In a 41-minute window on July 30, a total of 1,196 addresses were fully drained of 1,082.65 BTC (approximately $70.2M) between 01:10:20 and 01:51:26 UTC. The transactions were consistent with automated tools rather than individual users moving their own funds. pic.twitter.com/q785paZvMQ

— Galaxy Research (@glxyresearch) July 31, 2026

The extent of the theft has grown significantly since initial reports, which estimated around 594 BTC, or about $38 million, had been stolen from roughly 500 wallets. Galaxy Research's updated findings indicate that the losses now amount to 1,196 drained addresses totaling about 1,082.65 BTC, or around $70.2 million, within a short 41-minute timeframe on July 30, nearly doubling the original estimate.

Galaxy noted that each transaction included a uniform hardcoded fee and did not produce any change, suggesting the use of an automated system to exploit already possessed keys. The victims included both native SegWit and older address types, indicating the use of multi-path key scanning. The stolen Bitcoin was quickly consolidated into a few addresses and, according to Galaxy, has remained inactive since then.

Coinkite has released emergency hotfixes and urged affected users to generate new seeds to secure their holdings.