EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

CZ Warning: No wallet is absolutely safe. Is multi-wallet security the future?

2026-08-02 12:11:32
Bookmark

Binance founder Zhao Changpeng (CZ) reignited discussions about the security of hardware wallets after a vulnerability was exposed in a Coldcard hardware wallet. The vulnerability suggests that hardware wallets can fail even before transactions begin. The incident exposed a security issue: Affected devices could generate weak recovery seeds, allowing funds to be attacked without the need for phishing, malware or theft.

Zhao Changpeng said that no encrypted wallet is absolutely safe and suggested spreading assets among multiple wallets to limit losses when a single device or seed is leaked. However, he warned that spreading assets also brings risks, including lost backup, imperfect recovery plans and misoperations across devices.

"Even hardware wallets can be vulnerable. Even time-honored old wallets can have loopholes. How to reduce risks? Maybe spread the money among several wallets? But this brings with it a different set of risks. Nothing is 100% safe. Stay informed and stay safe (SAFU)!"-- CZ BNB (@cz_binance) August 1, 2026

Galaxy Research research shows that the attack affected 4585 addresses, totaling 1,367.05 bitcoins (approximately US$88.6 million). Its early analysis traced a 41-minute attack on July 30 involving 1,082.65 bitcoins in 1196 addresses.

Coldcard seed vulnerability exposes vulnerability in key creation

Block's Bitcoin engineering and security team traced the vulnerability to a firmware integration error introduced in March 2021. Affected software may use a deterministic fallback scheme rather than always relying on hardware random number generators to generate unpredictable recovery seeds. The fallback scheme uses chip identifiers and timing data, allowing attackers to narrow down the range of possible inputs and generate candidate seeds offline. The attacker can then derive the public key address and compare it with a charged address visible on the Bitcoin blockchain. Once the match is successful, the corresponding private key can transfer funds. Coinkite said that Coldcard Mk2 and Mk3 seeds generated on firmware versions 4.0.1 to 4.1.9 may contain extremely weak entropy. It also warned that before the emergency update, seeds generated on Mk4, Mk5 and Q devices might only contain about 72 bits of entropy, which were supposed to provide 128 bits of entropy, making the affected seed space easier to search. Coinkite has released firmware patches, but the update cannot strengthen old seeds that have been generated by fragile software. As a result, users must update their devices, generate new seeds, and transfer funds to addresses controlled by the replacement key.

Multi-wallet security limits risk but increases complexity

Zhao Changpeng's multi-wallet strategy shifts the security goal from finding a perfect device to limiting the loss when a single system fails. Basically, using different wallets that generate seeds independently prevents one recovery phrase from being leaked and exposing the entire asset portfolio. Using products from different manufacturers can also reduce reliance on the same code base, firmware design, or random number generation process. However, a multi-wallet setting is only more secure if each seed is created independently and every backup is protected. Therefore, spreading funds into multiple wallets derived from the same fragile root seed does not eliminate the underlying risk.

Multi-signature escrow adds another layer of protection, requiring multiple keys to transfer funds. However, Block warned that if all devices come from the same source of vulnerability and the compromised key controls the number of multi-signatures required, the arrangement may still fail. A more robust structure requires independently generated keys, a tested recovery process, and continuous attention to vendor security bulletins.

Overall, the Coldcard event shows that although cryptographic wallets can protect keys offline, they may still fail during key creation. On the other hand, hardware wallets still have value, but the incident reminds us that the security of self-hosting depends on a secure generation process, cautious decentralization strategies, and rapid user response. For users, multi-wallet security reduces concentration risks, but it also increases the burden of protecting and recovering each key.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP