CZ warned on X that even hardware wallets and long-established wallets can have bugs, suggesting holders split their funds across several wallets to mitigate risk while noting no setup is fully foolproof.
The warning follows a Coldcard exploit stemming from a March 2021 firmware build error that drew seeds from a software fallback instead of the hardware generator, making private keys far easier to guess.
Galaxy Research, mapping the fund flows from a pattern identified by Block engineers, now pegs losses at about 1,082.65 BTC (~$70.2 million) across 1,196 addresses—nearly double the original $38 million estimate.
Binance founder Changpeng “CZ” Zhao is warning crypto owners not to place blind faith in hardware wallets, following an exploit that drained tens of millions of dollars in Bitcoin from Coldcard devices.
In a Saturday post on X, Zhao cautioned that even hardware wallets can carry bugs, and that older wallets with long histories are not immune. “Nothing is 100%,” he posted.
He suggested holders consider spreading their funds across several wallets as one way to reduce exposure, while acknowledging the approach carries its own trade-offs and that no setup is entirely foolproof. CZ closed with his familiar refrain urging users to stay informed and keep their funds safe: “Stay SAFU!”
His comments followed the discovery of a flaw in Coldcard devices made by manufacturer Coinkite. As Decrypt reported, a build error caused seeds on affected units to be drawn from a software fallback rather than the device’s hardware random-number generator, leaving the private keys far easier to guess than intended. The problem traced back to firmware shipped in March 2021, and updating the firmware does not fix a seed already created on a compromised device.
We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett
1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks… pic.twitter.com/q785paZvMQ
— Galaxy Research (@glxyresearch) July 31, 2026
The scope of the theft has grown considerably since the first estimates. Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets. According to a report from Galaxy Research, which mapped the flow of funds based on a pattern identified by engineers at Jack Dorsey’s Block, the toll is now put at 1,196 addresses drained for about 1,082.65 BTC, or roughly $70.2 million, in a 41-minute window on July 30. That is nearly double the initial figure.
Galaxy said every sweep paid an identical hardcoded fee and left no change output, a signature it described as consistent with an automated tool spending keys it already held rather than owners moving their own funds. The victims spanned native SegWit and older address types, pointing to multi-path key scanning. The stolen Bitcoin was consolidated within minutes into a handful of addresses and, per Galaxy, has not moved since.
Coinkite has shipped emergency hotfixes and urged exposed users to migrate to newly generated seeds.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.