Hackers drained roughly $70 million in Bitcoin from Coldcard hardware wallets on July 30, exploiting a firmware bug that had sat unpatched since March 2021. Binance founder Changpeng Zhao responded on X with blunt advice: spread your holdings across multiple wallets. The breach hit approximately 1,196 addresses in just 41 minutes, according to Galaxy Research.

What the firmware flaw allowed
The vulnerability compromised the randomness used to generate recovery seeds on certain Coldcard models, primarily older Mk3 units. Because the entropy was weak, attackers could reconstruct private keys offline, without ever touching the hardware. Many affected wallets had been dormant for years, their owners unaware they were sitting on ticking bombs.
Early estimates pegged losses at 594 BTC, about $38 million, from around 500 addresses in 25 minutes. Galaxy Research later revised that upward: 1,082.65 BTC from 1,196 addresses over 41 minutes. The attack was surgical and fast.
Coinkite's response and migration warning
Coinkite, the manufacturer behind Coldcard, acknowledged the flaw, apologized, and pushed emergency firmware patches. But here's the catch: updating firmware does not protect seeds already generated under vulnerable versions. Those seeds remain compromised.
The company instructed affected users to generate entirely new seeds on updated devices, then transfer holdings. Newer models like Mk4, Q, and Mk5 were not impacted by this particular defect. Anyone still holding coins in a wallet created on an older device years ago has work to do.
CZ's take: diversify, but know the tradeoffs
Responding to the theft reports, Zhao noted that even hardware wallets with long track records can harbor bugs. His suggestion: divide funds among a few different wallets to limit exposure if one is compromised. He acknowledged this introduces complexity, particularly around managing multiple recovery phrases.
“Nothing is 100%.”
— Changpeng Zhao (CZ), via X
The advice is pragmatic, not revolutionary. Concentrating large holdings in a single device creates a single point of failure. Splitting assets across independent wallets, ideally generated on different hardware or with different methods, caps the damage from any one breach. The cost is operational friction: more seed phrases to secure, more chances for human error.
Related analysis on rising breach costs and attack sophistication
The limits of self-custody
Hardware wallets remain a cornerstone of crypto security because they keep private keys offline, isolated from internet-connected machines. This breach underscores that offline does not mean invulnerable. Firmware flaws, entropy weaknesses, or supply chain issues can surface years after deployment.
For holders, the immediate steps are clear: verify when and how existing seeds were generated, migrate funds from any potentially affected devices following Coinkite's instructions, and consider whether a multi-wallet setup better matches your risk profile. Continuous education and realistic expectations about security remain essential. No single approach eliminates every threat.
Logicity's Take
This breach is a reminder that trust in hardware vendors is not a security model. Coldcard had a strong reputation, yet a five-year-old flaw went unnoticed until attackers exploited it at scale. For fintech teams managing treasury or custody solutions, the lesson is layered defense: hardware diversity, independent seed generation, and ongoing firmware audits. Competitors like Ledger and Trezor use different entropy mechanisms, which may or may not carry their own undiscovered flaws. The safest assumption is that every device has bugs you haven't found yet.
Need Help Implementing This?
Contact Logicity's advisory team for help designing a multi-wallet custody architecture that fits your organization's risk profile.
Source: Crowdfund Insider
Manaal Khan
Tech & Innovation Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.






