Binance founder Zhao Changpeng warns that hardware wallets are not absolutely safe.
Binance founder Zhao Changpeng (CZ) reminds cryptocurrency holders not to blindly trust hardware wallets. Previously, Coldcard devices were exploited due to vulnerabilities that resulted in the theft of tens of millions of dollars worth of bitcoins.
Zhao Changpeng posted a post on platform X (formerly Twitter) pointing out that even hardware wallets may have loopholes, and old wallets with a long history are not immune. "Nothing is 100% safe," he wrote.
He advised holders to consider spreading funds in multiple wallets to reduce risk exposure, while acknowledging that this approach also has its own trade-offs and that no settings are foolproof. Zhao Changpeng used his usual concluding remarks to remind users to stay well-informed and ensure the safety of funds: "Stay SAFU!"
Bug details: Coldcard device seed generation flaw
His comment stems from a vulnerability found in Coldcard devices produced by manufacturer Coinkite. The vulnerability stems from a build error that causes the seeds of the affected device to come from a software alternative rather than the device's own hardware random number generator, making the private key easier to guess than expected. The issue can be traced to firmware released in March 2021, but updating firmware cannot repair seeds that have been generated on damaged devices.
The scale of losses increased significantly
The scale of the theft was much higher than originally estimated. Early reports stated that about 500 wallets were stolen and about 594 bitcoins (about $38 million) were lost. According to an analysis based on the pattern of capital flows identified by engineers at Jack Dorsey's Block company, the loss has now expanded to 1196 addresses. In a 41-minute window on July 30, approximately 1,082.65 bitcoins (approximately US$70.2 million) were stolen, almost double the original figure.
The analysis pointed out that the same hard-coding fee was paid for each sweep and no change output was generated. This feature is consistent with automated tools using held keys to transfer funds, rather than users transferring funds themselves. Victims cover both native SegWit and older address types, indicating the existence of multipath key scanning. The stolen bitcoins were consolidated into a few addresses within minutes, and according to the analysis, the funds have not moved since.
Coinkite releases emergency fix
Coinkite has released emergency fix patches and urged affected users to migrate to newly generated seeds.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC