Sunday, August 9, 2026 Latest news About 📈 Live coin prices →
Bitcoin

CZ Says Spread Your Crypto Across Wallets — Here’s the $88M Reason Why

A Coldcard hardware wallet flaw let hackers guess Bitcoin private keys, draining over $88M. CZ says no single wallet is ever 100% safe.

Marcus Whitfield4 min read
CZ Says Spread Your Crypto Across Wallets — Here’s the $88M Reason Why

If you keep your Bitcoin on a hardware wallet, you probably assumed it was one of the safest places on earth for your money. A newly uncovered flaw in Coldcard devices just proved that assumption wrong for thousands of people — and it’s why Binance founder Changpeng “CZ” Zhao is now telling crypto holders not to put all their coins in one basket.

Researchers say attackers exploited a weakness in how some Coldcard wallets generated their recovery “seeds” — the master password behind every wallet’s private keys. Across three separate waves of attacks, Galaxy Research now estimates that 1,367.05 BTC, worth roughly $88.6 million, was drained from 4,585 wallet addresses. An earlier snapshot of the same event had put the toll at 1,082.65 BTC (about $70 million) from 1,196 addresses stolen in just 41 minutes on July 30.

How thieves cracked wallets without ever touching them

This wasn’t phishing, malware, or a stolen device. According to Block’s Bitcoin security team, the problem traces back to a firmware integration error introduced in March 2021. Instead of always using the hardware’s true random-number generator to create an unpredictable seed, affected firmware could fall back to a predictable method based on chip identifiers and timing data.

That predictability let attackers narrow down possible seeds offline, generate the matching public addresses, and check them against real funded wallets visible on the Bitcoin blockchain. Once they found a match, they could recreate the private key and simply move the coins.

Coinkite, the company behind Coldcard, said Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9 may have generated critically weak seeds. Even newer Mk4, Mk5, and Q models made before emergency patches reportedly had only around 72 bits of entropy — far below the 128 bits they were designed to provide, making the key space much easier to search.

Here’s the catch for anyone affected: a firmware update can’t retroactively fix a seed that was already created weak. If your wallet fell into that window, Coinkite says you need to generate an entirely new seed on updated firmware and move your funds to fresh addresses — the old keys may still be guessable.

Why CZ says “nothing is 100%”

Reacting to the incident on X on August 1, CZ wrote: “Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs… How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!”

In plain terms: instead of trusting one device to protect your entire life savings, spreading funds across a few independently created wallets — ideally from different manufacturers — means a single flaw or mistake can’t wipe out everything at once.

But this isn’t a free lunch. More wallets mean more seed phrases to back up, more devices to keep firmware-updated, and more room for human error — like losing a backup or forgetting where you stashed a smaller stack of coins. Multisig setups, which require several keys to approve a transaction, add another layer of protection, but only if each key comes from a genuinely independent, uncompromised source. If every key in a multisig arrangement comes from the same vulnerable device model, the extra layer offers less protection than it looks like on paper.

What this means if you hold crypto

The bigger lesson isn’t about Coldcard specifically — it’s that “cold storage” only works if the wallet generated a truly random seed in the first place. Keeping a device offline protects it from hackers reaching in remotely, but it can’t protect you from a flaw baked in at setup.

If you own an affected Coldcard, check for firmware updates and consider moving funds to a freshly generated seed. For everyone else, the takeaway is simpler: don’t assume any single device, brand, or backup method is bulletproof. A little diversification, paired with careful record-keeping, is looking like the more realistic version of “safe” in crypto self-custody.

Read more: If You Own a Coldcard Wallet, Block Says Move Your Bitcoin Now

Sources

More Bitcoin