CZ warns hardware wallets can have bugs after $70M Coldcard exploit

Editorial illustration for: CZ warns hardware wallets can have bugs, urges diversification after $70M Coldcard exploit

In brief

  • Coldcard firmware flaw from March 2021 weakened recovery seed randomness on certain models
  • Attacker drained 1,082.65 bitcoin ($70M) from 1,196 addresses by reconstructing private keys
  • CZ emphasized hardware wallets can harbor critical bugs and urged splitting funds across devices
  • Coinkite released emergency firmware updates and advised affected users to migrate seeds

The Coldcard Breach

A firmware flaw in Coldcard devices dating to March 2021 weakened the randomness used to generate recovery seeds on certain models. The vulnerability allowed an attacker to reconstruct private keys offline and drain funds without ever physically accessing the hardware wallets themselves.

Analysis revealed the scope of the attack: approximately 1,082.65 bitcoin valued at roughly $70 million was drained from 1,196 addresses over about 41 minutes on July 30. Initial reports had indicated a smaller figure—about 594 bitcoin worth $38 million at the time, drained from around 500 wallets in a 25-minute window. The discrepancy highlighted how quickly researchers expanded their understanding of the breach.

What made the exploit particularly striking was the dormancy of many affected accounts. Many of the affected wallets had sat dormant for years before the attacker struck, suggesting they'd been forgotten or abandoned by their owners.

Coinkite's Response and CZ's Diversification Call

Coldcard maker Coinkite acknowledged the bug, apologized, and released emergency firmware updates. The company advised users who generated seeds on affected versions to create entirely new seeds on patched devices and carefully migrate funds.

CZ's response centered on a practical mitigation strategy. Rather than suggesting users abandon hardware wallets altogether, he emphasized that no security solution is perfect—and that splitting holdings across multiple wallets can reduce exposure if one fails.

"Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!" — Changpeng Zhao, Binance founder

The incident underscores a broader lesson: hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard case demonstrates that even long-established devices can harbor critical flaws undetected for years. Security, it seems, remains a layered game.