Key Highlights
- CZ warned crypto users that hardware wallets can still have security flaws, saying users should not rely on any wallet as completely risk-free.
- The Coldcard hack grew to 1,158.66 BTC worth about $75.1 million, with the stolen funds still sitting in wallets controlled by the attacker.
- The exploit was linked to a Coldcard Mk3 firmware bug that weakened recovery seed security and put some users’ Bitcoin at risk.
Binance founder Changpeng “CZ” Zhao has warned crypto users to stay careful with hardware wallets after a Coldcard wallet attack grew into a much bigger security incident. This is shortly after an exploit linked to Coldcard devices drained more than 1,158.66 BTC, worth about $75.1 million.
In a Saturday post on X, CZ said crypto users should not place complete trust in hardware wallets because they can still contain bugs. He explained that older wallets with years of history are not automatically free from security problems, reminding users that no system is perfect.
“Nothing is 100%,” CZ wrote.
The Binance founder suggested that users consider spreading their crypto holdings across multiple wallets as one way to reduce risk. Instead of keeping all funds in one wallet, dividing assets across different wallets could limit losses if one wallet is compromised.
However, CZ also acknowledged that this approach has its own challenges and does not completely remove risks. He ended his message by encouraging users to stay alert and protect their funds, repeating his well-known message to the crypto community: “Stay SAFU!”
Coldcard hack expands as stolen Bitcoin hits $75 million
CZ’s warning came after Canadian hardware wallet maker Coinkite disclosed a serious security issue affecting some Coldcard Mk3 devices. The company released an urgent security advisory on July 30 after researchers linked a series of Bitcoin wallet drains to a possible weakness in the device’s seed generation process.
The attack first came to attention after around 594 BTC, worth about $38 million, was taken from roughly 500 Bitcoin addresses within a short period. Blockchain research firm Galaxy Research later reported that the total amount stolen had grown to 1,158.66 BTC, valued at around $75.1 million.
Galaxy Research tracks the Bitcoin still held by the attacker
Galaxy Research said the stolen Bitcoin remains untouched across seven addresses controlled by the attacker.
The firm said the lack of movement is unusual for a theft of this size and suggested the attacker may be waiting for attention around the incident to decrease or may not yet have a clear way to move the funds without being tracked.
A firmware bug put some Coldcard wallets at risk
The security issue was connected to certain Coldcard Mk3 firmware versions released between March 2021 and the final supported version 5.0.3. Coinkite explained that a bug prevented the device’s hardware random number generator from providing enough randomness when creating wallet recovery seeds.
A wallet seed is a set of words that gives users access to their crypto funds. Normally, these words are created using strong randomness, making them almost impossible to guess. However, researchers found that the affected firmware could produce weaker seeds with much lower security, making it possible for attackers to reconstruct wallet keys using powerful offline searches.
Researchers also found that many affected wallets held Bitcoin that had remained untouched since 2021, matching the period when the vulnerable firmware was released. Galaxy Research said this connection suggests the stolen funds were linked to the same seed generation weakness.
The firm also warned that other attackers may attempt to exploit the flaw now that details are public. It advised users who created single-signature Coldcard wallets with affected firmware to move their Bitcoin into a new wallet created with a fresh recovery seed.
Also Read: Bitcoin Price Watch: Lower $60,000s Range Holds Amid Security Concerns
