Changpeng Zhao (CZ) Binance profile displayed on a smartphone screen
SECURITY

CZ Urges Wallet Diversification After Coldcard Exploit Drains $70 Million

Image Credit: Shutterstock

Key Takeaways

  • A Coldcard firmware flaw was linked to the theft of more than 1,000 BTC worth about $70M.
  • The bug weakened seed entropy, allowing attackers to reconstruct private keys without physical access.
  • CZ urged users to split funds across multiple wallets while Coinkite advised moving assets to new seeds after updating.

Binance founder Changpeng Zhao (CZ) called on crypto holders Saturday to split their funds across multiple wallets, following reports that a Coldcard firmware flaw allowed an attacker to drain more than 1,000 BTC without ever touching a device.

CZ Warns Hardware Wallets Are Not Immune to Bugs

CZ posted his response on X after reports of the theft spread.

“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!”

Diversifying across wallets carries its own tradeoffs, including more complex key management and more seeds to secure.

Attacker Swept 1,196 Addresses in 41 Minutes

Initial reports on July 30 counted roughly 594 BTC, worth about $38 million, swept from around 500 single-signature wallets between 01:31 and 01:56 UTC. Every drained wallet held more than 0.15 BTC, and many had been dormant for years.

Later analysis from Galaxy Research widened the figure to 1,082.65 BTC, valued near $70 million, taken from 1,196 addresses over roughly 41 minutes. Roughly 562 BTC were consolidated into a single address that has not moved since. Coinkite says its own analysis remains ongoing.

Block’s Clay Garrett said on X that the attacker used a paid account at a well-known blockchain data provider to query source addresses during the sweeps. The provider’s internal logs matched the suspected workflow down to the number, timing, and sequence of requests.

Weak Seed Generation Exposed Coldcard Private Keys

Affected devices skipped their hardware true random number generator and fell back to a software-based generator seeded with non-secret chip data.

That made private keys computationally enumerable. An attacker could reconstruct them offline using a visible Bitcoin address, a wallet descriptor, or an exported public key, with no physical access required.

Severity varies by model. For Mk2 and Mk3 devices on v4 firmware, Block estimated the search space could fall below 40.7 bits under a broad hidden-timer ceiling. Coinkite said affected Mk4, Q and Mk5 seeds had about 72 bits of entropy rather than the expected 128.

Coinkite’s direct Mk3 warning covers firmware 4.0.1 through 4.1.9 inclusive, and it says seeds generated on Mk4, Mk5 and Q before the fixed releases are affected less severely. Its Tapsigner, Opendime and Satscard products use different codebases and are unaffected.

Firmware Patches Do Not Secure Seeds Already Created

Coinkite released fixed firmware on July 31: version 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for Q. Edge users need Mk4/Mk5 version 6.6.0X or later, or Q version 6.6.0QX or later.

Updating alone does not resolve the exposure. Keys generated under vulnerable firmware remain weak regardless of what version the device runs afterward. Coinkite has advised affected users to generate new seeds on patched devices and migrate funds on-chain to the new addresses.

More For You

Explore More News