Coldcard exploit drains $70M Bitcoin; CZ warns hardware wallets not immune

Editorial illustration for: CZ warns Bitcoin holders: Coldcard exploit drains $70 million, hardware wallets not immune

In brief

  • Coldcard exploit drained 1,082.65 BTC ($70.2M) from 1,196 addresses in 41 minutes on July 30
  • March 2021 firmware bug in seed generation enabled the theft, nearly double initial $38M estimates
  • CZ urged crypto holders to diversify across multiple wallets to mitigate hardware wallet risks

The Scale of the Exploit

Galaxy Research mapped the Coldcard exploit and determined that 1,196 addresses were drained for approximately 1,082.65 BTC. Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets—meaning the true toll is nearly double the initial count.

The stolen Bitcoin was consolidated within minutes into a handful of addresses and has not moved since, according to Galaxy. Every sweep paid an identical hardcoded fee and left no change output, a signature consistent with an automated tool rather than manual theft.

The Root Cause

The Coldcard exploit involved a build error that caused seeds to be drawn from a software fallback rather than the device's hardware random-number generator. The problematic firmware was shipped in March 2021, and updating the firmware does not fix a seed already created on a compromised device.

Coinkite, the manufacturer, has shipped emergency hotfixes and urged exposed users to migrate to newly generated seeds. But the damage—for those who didn't act—was already done.

CZ's Warning

Zhao cautioned that even hardware wallets can carry bugs, and that older wallets with long histories are not immune. His message was stark: trust no single layer of security.

"Nothing is 100%"

— Changpeng Zhao, Binance founder

He suggested holders consider spreading their funds across several wallets as one way to reduce exposure. The exploit underscores a fundamental tension in crypto security: hardware wallets are widely considered the gold standard for self-custody, yet they're not infallible. A single firmware flaw shipped years ago can compromise thousands of users at once, with no recourse once a seed is compromised.