A firmware flaw in Coldcard wallets enabled attackers to steal $70 million in Bitcoin (BTC), prompting Changpeng Zhao to warn that cold storage is not fail-safe.
Key Points:
- Researchers traced 1,082.65 BTC from 1,196 wallets during a 41-minute sweep on Jul. 30.
- CZ advised holders to divide funds across several wallets.
- The manufacturer released corrected firmware, but users must replace seeds created by affected versions.
Coldcard Bitcoin Drain
Researchers at Galaxy Research and Block traced the theft from 1,196 wallets during a sweep that ran from 1:10 a.m. to 1:51 a.m. UTC on Jul. 30. The total reached 1,082.65 BTC, nearly double the early estimate.
Galaxy said the activity covered six blocks, with three blocks showing no related transfers, indicating that attackers broadcast transactions in batches. The attacker never touched the devices. The stolen funds remained in four addresses as of Aug. 1.
The weakness began when a March 2021 software change routed seed generation away from the intended hardware random-number generator and into a predictable fallback. Coinkite estimated roughly 40 bits of effective security on Mk3 devices and about 72 bits on later affected models.
Also Read: SpaceX Braces For A Supply Shock As 911.5M Shares Come Unlocked
CZ Wallet Warning
Changpeng Zhao, founder and former CEO of Binance, said the incident showed that a long operating history does not eliminate software risk. “Even hardware wallets can have bugs,” he wrote. He advised users to split funds among several wallets, while acknowledging that the approach introduces different risks.
That approach is not risk-free. More wallets require extra backups and recovery procedures, so diversification can reduce concentration while increasing the chance of operational mistakes.
Coinkite released fixed firmware for Mk3, Mk4, Mk5 and Q devices, but an update cannot repair an existing weak seed. The company said at least 50 private dice rolls protected seeds from this flaw alone. Other affected users should create a new seed, verify it with a test transaction and then move the remaining funds.
Block also listed the older Mk2 as potentially exposed, while Coinkite's advisory did not name that model. Owners cannot test a seed directly, and researchers warned that further sweeps remain possible while vulnerable wallets hold funds.
The flaw entered Coldcard seed generation in March 2021 and remained across affected releases until emergency fixes arrived in late July 2026. That five-year span explains why the incident threatens older wallets whose owners may have treated long inactivity as proof of safety.
Read Next: OpenAI Shows Senators New Model Astra Days Before A 30-Day Review Framework Lands






