$70M Coldcard Breach Prompts CZ to Push for Multi-Wallet Strategy

Binance founder Changpeng Zhao (CZ) has warned that hardware wallets are not immune to flaws, encouraging crypto users to spread their holdings across multiple wallets after a major Coldcard security breach.

Posting on X, CZ noted that even long-standing and widely trusted wallets can contain hidden bugs. He suggested diversifying funds as a way to reduce risk, while stressing that no security method is perfect and each approach carries its own trade-offs.

The issue stems from a firmware vulnerability introduced in March 2021, which weakened the randomness used to generate recovery seeds on certain Coldcard devices. This flaw allowed attackers to reconstruct private keys offline, giving them access to funds without needing physical control of the wallets.

Early on-chain data showed that roughly 594 BTC—worth about $38 million at the time—was drained from around 500 wallets in just 25 minutes on July 30. Later analysis by Galaxy Research expanded the scale of the attack to 1,082.65 BTC, or about $70 million, taken from 1,196 addresses over roughly 41 minutes. Many of the compromised wallets had been inactive for years.

Coldcard maker Coinkite has since acknowledged the vulnerability, apologized, and released emergency firmware updates. The firm advised users who generated seeds on affected versions to create entirely new seeds on updated devices and carefully move their funds, warning that updating firmware alone does not secure previously compromised seeds.

The incident has renewed debate around the limits of self-custody. While hardware wallets are generally seen as one of the safest ways to store bitcoin offline, the Coldcard case highlights that even established devices can carry long-undetected risks. CZ’s call for diversification reflects a broader reality: reducing exposure often comes at the cost of increased complexity in managing multiple wallets and private keys.