Crypto holders used to focus on diversifying their coins. Now, following a $70 million Coldcard exploit, they’re being told to diversify their wallets as well.
On Saturday, Binance founder Changpeng Zhao, known as CZ, asked crypto holders to split their funds across multiple wallets following a major security failure in popular Coldcard hardware devices.
“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!,” he said.
On July 30, some bitcoin users discovered that funds from their Coldcard wallets had been stolen in a series of unexpected transactions. The attacker exploited a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. By reconstructing private keys offline, the attacker was able to drain funds without ever physically accessing the devices.
Initial reports said about 594 BTC, worth $38 million at the time, were drained from around 500 wallet in a 25-minute window. Subsequent analysis by Galaxy Research expanded the scope to 1,082.65 bitcoin, valued at approximately $70 million, drained from 1,196 addresses over about 41 minutes. Many of the affected wallets had sat dormant for years.
Coldcard maker Coinkite has acknowledged the bug, apologized, and released emergency firmware updates. The company has advised users who generated seeds on affected versions to create entirely new seeds on patched devices and carefully migrate funds, noting that simply updating firmware does not secure an already-created vulnerable seed.
The episode has renewed debate over the limits of self-custody. Hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard case shows that even long-established devices can harbor critical flaws that remain undetected for years.
CZ’s suggestion of diversification acknowledges that spreading risk comes with its own practical challenges, including more complex key management.
