EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

CZ warns Bitcoin holders after $70 million wallet breach: "Nothing is 100% safe"

2026-08-02 00:57:28
Bookmark

Binance founder Zhao Changpeng warns that hardware wallets are not absolutely safe.

Binance founder Zhao Changpeng (CZ) reminds cryptocurrency holders not to blindly trust hardware wallets. Previously, Coldcard devices were exploited due to vulnerabilities that resulted in the theft of tens of millions of dollars worth of bitcoins.

Zhao Changpeng posted a post on platform X (formerly Twitter) pointing out that even hardware wallets may have loopholes, and old wallets with a long history are not immune. "Nothing is 100% safe," he wrote.

He advised holders to consider spreading funds in multiple wallets to reduce risk exposure, while acknowledging that this approach also has its own trade-offs and that no settings are foolproof. Zhao Changpeng used his usual concluding remarks to remind users to stay well-informed and ensure the safety of funds: "Stay SAFU!"

Bug details: Coldcard device seed generation flaw

His comment stems from a vulnerability found in Coldcard devices produced by manufacturer Coinkite. The vulnerability stems from a build error that causes the seeds of the affected device to come from a software alternative rather than the device's own hardware random number generator, making the private key easier to guess than expected. The issue can be traced to firmware released in March 2021, but updating firmware cannot repair seeds that have been generated on damaged devices.

The scale of losses increased significantly

The scale of the theft was much higher than originally estimated. Early reports stated that about 500 wallets were stolen and about 594 bitcoins (about $38 million) were lost. According to an analysis based on the pattern of capital flows identified by engineers at Jack Dorsey's Block company, the loss has now expanded to 1196 addresses. In a 41-minute window on July 30, approximately 1,082.65 bitcoins (approximately US$70.2 million) were stolen, almost double the original figure.

The analysis pointed out that the same hard-coding fee was paid for each sweep and no change output was generated. This feature is consistent with automated tools using held keys to transfer funds, rather than users transferring funds themselves. Victims cover both native SegWit and older address types, indicating the existence of multipath key scanning. The stolen bitcoins were consolidated into a few addresses within minutes, and according to the analysis, the funds have not moved since.

Coinkite releases emergency fix

Coinkite has released emergency fix patches and urged affected users to migrate to newly generated seeds.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP