EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

CZ supports wallet diversification, Coldcard vulnerabilities exposed...

2026-08-03 00:12:36
Bookmark

Why did Zhao Changpeng advise Bitcoin holders to split their assets?

Binance founder Zhao Changpeng recently urged cryptocurrency holders to spread funds into multiple wallets, after more than 1000 bitcoins were stolen due to firmware flaws in some Coldcard hardware devices. "Hardware wallets may also have loopholes," Zhao Changpeng said on Saturday. Old wallets (which have been used for a long time) can also be vulnerable. How to avoid risks? Maybe you could consider spreading your funds among several wallets? But this will also bring a series of new risks. No plan is absolutely safe. Please keep the information updated to ensure asset safety! "

This proposal subverts the traditional concept of" diversification "in the cryptocurrency field. In the past, investors often spread their funds in different currencies to reduce the risk of price fluctuations. The Coldcard incident shows that holders also need to consider: Does relying all assets on a single seed generation process, the same wallet model or firmware version constitute a "single point of failure"? Spreading funds across multiple wallets limits losses if a wallet is breached, but it also creates new risks-users must protect more recovery phrases, maintain accurate records, and avoid mistakes during transfers or recovery. Therefore, diversification at the wallet level reduces concentration risks, but does not eliminate the operational risks inherent in self-custody.

How did the Coldcard theft happen?

On July 30, Bitcoin users began reporting unauthorized transactions in Coldcard wallets. The attacker took advantage of a firmware vulnerability dating back to March 2021 that caused some devices to reduce randomness when generating recovery seeds. The recovery seed is used to generate the private key that controls the wallet. When the seed generation process lacks sufficient randomness, an attacker may deduce possible seeds and reconstruct the corresponding private key. In this incident, the attacker did not need to physically touch the hardware wallet because the private key could be rebuilt offline. Preliminary blockchain analysis showed that approximately 594 bitcoins (worth approximately $38 million at the time) were transferred from approximately 500 wallets within 25 minutes. Subsequent research expanded the loss estimate to 1,082.65 bitcoins (approximately US$70 million), involving 1196 addresses, and the entire theft lasted about 41 minutes. Many of the affected wallets have not been active for years. This is particularly damaging for users who believe that long-term offline storage is immune to exchange failures, phishing attacks and online account intrusions.

Investor advice

Hardware wallets protect assets from numerous online threats, but they do not eliminate risks in device firmware or seed generation. Large holders may need to assess their concentration among wallet brands, devices and recovery seeds, and should not view a single hardware wallet as a panacea.

Why is it not enough to just update firmware?

Coldcard maker Coinkite has admitted the vulnerability and apologized, while releasing an emergency firmware update. However, installing patch software will not fix fragile seeds generated under the affected firmware version. Recovery phrases created under weak randomness, even if the device has been updated, the underlying private key has not changed, so the risk still exists. Coinkite advises affected users to generate new seeds on patched devices and migrate Bitcoin to addresses generated based on the new phrase. The migration process requires extreme caution: Transferring funds from a potentially compromised wallet may draw the attention of attackers monitoring the address; and typing a recovery phrase into an insecure device or application may open up an alternative path for theft. Users must also verify the destination address and retain access to new backups before transferring money. This incident fully demonstrates the importance of firmware sources and seed generation history. Control of a seemingly secure wallet may still be exposed to risk through keys created years ago under the vulnerable software version.

Can decentralization of wallets improve the security of self-hosting?

Using multiple wallets reduces the risk of exposure to a single hardware failure, software defect, or recovery phrase leak. Rather than relying on a single seed, holders can spread funds across different equipment, manufacturers or adopt multi-signature schemes. However, if you only purchase multiple wallets of the same model and use the same affected firmware or seed generation method, the protection will be limited. Effective decentralization requires isolating sources of risk rather than just increasing the number of equipment. Multi-signature wallets provide another option: more private keys are needed to authorize transactions. These private keys can be stored on devices from different manufacturers or in different locations. But higher security is also accompanied by a more complex setup process and a greater risk of permanent loss of access if backup is not managed properly. The Coldcard theft does not deny the value of self-custody, but rather shows that self-custody transfers responsibility from the exchange to the asset owner and the technology of its choice. Hardware wallets remain valuable in resisting online theft, but their security ultimately depends on firmware quality, production controls, backup processes, and how users decentralize access to their assets. For holders of large bitcoins, the lesson is no longer limited to "taking the coin out of the exchange" but to avoid letting a single device, single seed, or one unnoticed software flaw control the entire portfolio.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP