
Binance founder CZ recommends splitting crypto across multiple wallets after $70 million Coldcard exploit drained 1,082 BTC. The attack exploited a 2021 firmware flaw in recovery seed generation.
The $70 million Coldcard exploit has changed how people think about storing bitcoin. Binance founder Changpeng Zhao, known as CZ, told holders to split funds across multiple wallets after attackers drained over 1,000 bitcoin from nearly 1,200 addresses.
"Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!" CZ wrote on X Saturday.
The attack exploited a firmware bug from March 2021 that weakened the randomness Coldcard used to generate recovery seeds. The attacker reconstructed private keys offline and drained wallets without ever touching the devices.
On July 30, initial on-chain data showed about 594 BTC (roughly $38 million at the time) swept from around 500 wallets in a 25-minute window. Galaxy Research later found 1,082.65 BTC, worth about $70 million, taken from 1,196 addresses over 41 minutes. Many of those wallets had sat untouched for years.
Coldcard maker Coinkite acknowledged the flaw, apologized, and pushed emergency firmware updates. The company told users who created seeds on affected versions to generate entirely new seeds on patched devices and migrate funds carefully. Simply updating firmware does not protect an already-created vulnerable seed, the company said.
The incident has revived debate about self-custody limits. Hardware wallets are widely seen as one of the strongest ways to secure bitcoin offline. The Coldcard case shows that even long-established devices can hide critical flaws for years before discovery.
CZ's diversification advice comes with its own trade-offs. Spreading funds across multiple wallets means more complex key management and a larger attack surface if any single seed is mishandled. The recommendation reflects a broader shift in thinking: security now depends not just on the wallet brand but on how many independent keys a holder manages.
For affected users, recovery options remain limited. The stolen bitcoin moved through multiple addresses after the initial sweep, making tracing difficult. Coinkite said it is working with blockchain analytics firms to track the funds but has not offered compensation.
The exploit targeted a specific weakness in Coldcard's random number generation. Other hardware wallet makers, including Ledger and Trezor, have not reported similar vulnerabilities, though security researchers say any device running closed-source firmware carries some risk. Coldcard has since open-sourced its firmware code to allow broader auditing.
CZ's post drew mixed reactions. Some praised the practical advice. Others noted that splitting funds increases the chance of losing a seed phrase or forgetting where assets sit. "Nothing is 100%" was his own caveat.
The incident may accelerate demand for multi-signature setups and smart-contract-based custody solutions that distribute control across several keys or parties. Those options add complexity but reduce the single point of failure that Coldcard users just learned about the hard way.
Binance remains crypto's largest exchange, expanding from spot and derivatives into payments, savings, yield, and broader financial services through its platform.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.