CZ calls for wallet diversification after $70 million Coldcard exploit
After a $70 million hardware wallet drain, the Binance founder says nothing is completely safe and recommends splitting funds.
YayaNews contributes financial news and market context through the YayaNews editorial workflow.

After a $70 million hardware wallet drain, the Binance founder says nothing is completely safe and recommends splitting funds.
CZ calls for wallet diversification after $70 million Coldcard exploit
Markets
Binance founder CZ calls for wallet diversification after $70 million Coldcard exploit
Binance founder Changpeng Zhao says hardware wallets can still have bugs and suggests spreading funds across multiple wallets after the major Coldcard security failure.
By
Omkar Godbole
Updated
Aug 1, 2026, 9:23 a.m.
Published
Aug 1, 2026, 9:01 a.m.
2
min read
Make
preferred on
Share
Share this article
Copy link
X icon
X (Twitter)
Make
preferred on
CZ urges wallet diversification after Coldcard exploit. (Nikhilesh De/Modified by CoinDesk)
Summary
Show
Crypto holders used to focus on diversifying their coins. Now, following a $70 million Coldcard exploit, they’re being told to diversify their wallets as well.
On Saturday, Binance founder Changpeng Zhao, known as CZ, asked crypto holders to split their funds across multiple wallets following a major security failure in popular Coldcard hardware devices.
“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!,” he said.
On July 30, some bitcoin users discovered that funds from their Coldcard wallets had been stolen in a series of unexpected transactions. The attacker exploited a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. By reconstructing private keys offline, the attacker was able to drain funds without ever physically accessing the devices.
Initial reports said about 594 BTC, worth $38 million at the time, were drained from around 500 wallet in a 25-minute window. Subsequent analysis by Galaxy Research expanded the scope to 1,082.65 bitcoin, valued at approximately $70 million, drained from 1,196 addresses over about 41 minutes. Many of the affected wallets had sat dormant for years.
Coldcard maker Coinkite has acknowledged the bug, apologized, and released emergency firmware updates. The company has advised users who generated seeds on affected versions to create entirely new seeds on patched devices and carefully migrate funds, noting that simply updating firmware does not secure an already-created vulnerable seed.
The episode has renewed debate over the limits of self-custody. Hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard case shows that even long-established devices can harbor critical flaws that remain undetected for years.
CZ’s suggestion of diversification acknowledges that spreading risk comes with its own practical challenges, including more complex key management.
Binance founder Changpeng Zhao, known as CZ, has urged crypto holders to split their funds across multiple wallets following a major security failure in popular Coldcard hardware devices.
In a post on X Saturday responding to reports of the theft, CZ wrote: “Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!”
The incident involved a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. An attacker was able to reconstruct private keys offline and drain funds without ever physically accessing the devices.
Initial on-chain reports flagged about 594 bitcoin (roughly $38 million at the time) swept from around 500 wallets in a roughly 25-minute window on July 30. Subsequent analysis by Galaxy Research expanded the scope to 1,082.65 bitcoin—valued at approximately $70 million—taken from 1,196 addresses over about 41 minutes. Many of the affected wallets had sat dormant for years.
Coldcard maker Coinkite has acknowledged the bug, apologized, and released emergency firmware updates. The company has advised users who generated seeds on affected versions to create entirely new seeds on patched devices and carefully migrate funds, noting that simply updating firmware does not secure an already-created vulnerable seed.
The episode has renewed debate over the limits of self-custody. Hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard case shows that even long-established devices can harbor critical flaws that remain undetected for years. CZ’s suggestion of diversification acknowledges that spreading risk comes with its own practical challenges, including more complex key management.
Binance
CZ
Latest Crypto News
1
XRP Ledger upgrade brings back features once pulled over critical bugs
4 hours ago
2
How bitcoin cold wallets lost $70 million in an attack that never touched the devices
4 hours ago
3
Bitcoin holds monthly gain, faces 'choppy' August as 'forced-selling' exhausted, analysts say
13 hours ago
4
Tether posts $1.5 billion operating profit in Q2 as reserve buffer falls by half
16 hours ago
5
The good and the bad of perps, according to crypto traders
16 hours ago
6
Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs
17 hours ago
7
Quantum computing nears commercial breakthrough, IBM CEO says
19 hours ago
8
Crypto faces 3 barriers to next bull run, STS Digital CEO says
19 hours ago
9
Circle secures New York trust charter as crypto regulatory push accelerates
21 hours ago
10
Coinbase's weak quarter leaves Wall Street split on timing of a recovery
21 hours ago
Latest Research
The Evolution of the Crypto CEX Landscape: A Case Study on Binance
The Evolution of the Crypto CEX Landscape: A Case Study on Binance
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
By
CoinDesk Research
Jun 29, 2026
Commissioned by
Binance
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Why it matters
:
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
View Full Report
More From
Markets
Bitcoin holds monthly gain, faces 'choppy' August as 'forced-selling' exhausted, analysts say
Quantum computing nears commercial breakthrough, IBM CEO says
Crypto faces 3 barriers to next bull run, STS Digital CEO says
Crypto
CD20
$1,724.12
CD20 down 1.05 percent
1.05%
BTC
$62,973.51
BTC down 1.38 percent
1.38%
ETH
$1,863.17
ETH down 1.17 percent
1.17%
XRP
$1.06
XRP down 0.97 percent
0.97%
SOL
$72.76
SOL down 0.97 percent
0.97%
Original YayaNews editorial coverage, published for informational purposes.
This article is sourced from CoinDesk. It is for informational purposes only and does not constitute investment advice.
Topics & Symbols
Continue Reading
Related Reading
Russia Expands Crypto Mining Ban to Moscow
Russia’s government has approved a cryptocurrency mining ban in Moscow and other areas, with restrictions set to run from 2026 through 2032 under a new resolution.

Galaxy Maps Coldcard Bitcoin Losses After Wallet Incident
Galaxy Research identified more than $70 million in Bitcoin losses linked to the Coldcard wallet incident and warned users to move funds from vulnerable addresses.

How bitcoin cold wallets lost $70 million in an attack that never touched the devices
Galaxy Research said weak seed generation let an attacker recreate likely private keys offline, sweep more than 1,000 BTC from nearly 1,200 wallets and continue searching without ever accessing the devices.

Ripple news: XRP Ledger upgrade brings back features once pulled over critical bugs
The xrpld 3.3.0 release is expected next week with five proposed amendments, including two revised features that were previously withdrawn after researchers found bugs that could have allowed unauthorized transactions or fee draining.
