BTC Security

Coldcard's $70M Firmware Blunder: CZ Tells Users to Stop Putting All Eggs in One Wallet

2026-08-01

Changpeng Zhao weighed in on the Coldcard disaster on Saturday. His advice: split your funds across multiple wallets. Which, if you think about it, is the kind of thing we all knew already — but when a hardware wallet supplier manages to leak $70 million worth of bitcoin in forty-one minutes, perhaps the reminder lands harder.

Over 1,000 bitcoin vanished from 1,196 Coldcard devices on July 30. That's the kind of number that makes you read the sentence twice. Galaxy Research tallied it. The attack was surgical: every address got wiped clean, no messy change outputs left behind, elevated fees paid upfront. The attacker had a prepared list. This was automated. Professional.

The culprit was a firmware flaw dating to March 2021. Coinkite — Coldcard's maker — had migrated a software library and muddled two random-number functions. One reached the actual hardware generator, solid and proper. The other was a weak software fallback, meant for older boards that lacked decent hardware entropy. Somewhere in the code shuffle, the wrong function got called.

Result: recovery seed phrases that should have been unguessable became computationally enumerable. The effective entropy topped out at 40 bits. BIP-39, the standard behind 90 percent of self-custody wallets, demands a minimum of 128 bits for a 12-word phrase. The math was broken. Attackers didn't need to touch the devices. They just rebuilt the private keys offline.

Most of the drained wallets belonged to long-term holders. The emptied addresses had sat dormant for years — exactly the kind of cold storage most people assume is untouchable. The attacker moved fast. They knew what they were looking for.

Coinkite's CEO, Rodolfo Novak (NVK), apologized Friday. Called it a review-process failure. Full accountability, he said. The company released emergency firmware updates. Users who generated seeds on vulnerable versions face a grim task: create entirely new seeds on patched devices, then migrate everything off the old keys. Simply updating firmware won't cut it. The seed itself was always compromised.

NVK also floated something interesting: the vulnerability might have been found using AI. He framed it as a warning. AI-assisted code review can identify latent bugs faster than human experts, which means attackers with AI tools can find exploitable weaknesses in public code before defenders know they exist. A sober reality indeed.

The episode has relit the self-custody debate. Hardware wallets are supposed to be fortress-grade security for offline bitcoin. Coldcard has been around for years, long trusted by serious hodlers. Yet here we are: a bug sitting undetected since 2021, eventually exploited, $70 million gone.

Security firm Blockaid points out that most losses in the first half of 2026 came not from smart-contract hacks but from compromised keys and operational failures. This fits that pattern exactly. The exposure originated at key generation. That's about as fundamental as it gets.

CZ's call to split funds across wallets acknowledges something uncomfortable: nothing is 100 percent secure. Diversification across multiple wallets introduces its own risks and complexities, sure. But so does putting everything in one device that might harbour a five-year-old bug.

For affected users, the window is now. Install fixed firmware. Create new seeds. Move the funds. The attackers are still out there hunting for vulnerable seeds on the blockchain.


Source & further reading:

Sources