BTCLoading…

$70 Million Gone in 40 Minutes: CZ Weighs in on Coldcard Fallout

A Coldcard firmware bug let thieves rebuild seeds and drain $70 million in BTC. CZ says no wallet is fully safe. The post $70 Million Gone in 40 Minutes: CZ…

LO
Lockridge Okoth
Wire content from BeInCrypto

Changpeng Zhao (CZ) has a warning for Bitcoin holders. Hardware wallets can fail too. He spoke days after a Coldcard firmware bug let thieves work out private keys and take $70 million.

Researchers at Galaxy and Block tracked the theft. Attackers emptied 1,196 wallets in 41 minutes on July 30. Nobody touched a single device.

CZ Points to the Limits of Cold Storage

CZ, the founder and former CEO of Binance exchange, says a wallet can be old, trusted, and still broken.

When he posted, early reports put the loss at $38 million. The real figure turned out to be almost double that.

“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!” wrote CZ.

Follow us on X to get the latest news as it happens

His advice was to spread coins across several wallets. He also admitted that this brings new risks of its own.

CZ has been candid lately about calls he got wrong. One was the stablecoin market he dismissed, now worth over $300 billion.

How the Coldcard Firmware Bug Made Seeds Guessable

Every wallet starts with one huge secret number. It is called a seed. Every key and address grows out of it. That number has to be random. Coldcard used a dedicated chip to make it random.

Then came a coding mistake in March 2021. The job quietly passed to a weak backup instead. That backup leaned on the device serial number and its clock. Both can be worked out.

So the number stopped being huge. Block’s engineers put the range at roughly four billion options on newer models. A computer can chew through that.

1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source… https://t.co/l5McyhhcNn

— Clay Garrett (@clay_garrett) July 31, 2026

Thieves simply built the seeds themselves. They turned each one into addresses. Then they scanned the public blockchain for funded matches.

Galaxy mapped the sweeps. Every one paid the exact same fee, far above normal. None left change behind. That is software, not a person.

The Coldcard Incident Reportedly Happened Within 41 Minutes
The Coldcard Incident Reportedly Happened Within 41 Minutes. Source: Galaxy research

“The full event spans six blocks and 41 minutes. Three intervening blocks contain no sweep activity at all, suggesting the transactions were broadcast in batches rather than streamed,” Galaxy Researchers indicated.

Owners Still Cannot Test Their Own Seeds

Coinkite has shipped fixed firmware for every model. An update cannot repair a seed that already exists.

If yours is exposed, you need a fresh seed and a new wallet. BeInCrypto’s earlier Coldcard theft coverage walks through the steps.

Two things help. The advisory says 50 or more private dice rolls at setup keep a seed strong. A good passphrase adds another wall, the same gap flagged over missing BIP39 passphrase support on phones.

There is still no test you can run at home. Block also lists the older Mk2 as at risk. Coinkite’s advisory does not name it.

The stolen coins have not moved. They sit in four wallets.

At this time, the funds identified in this wave are sitting in 4 addresses:

bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r
bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3
bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q
bc1qnk4zh9qcnap2mycp56qjrgza3cc8ylrh8fecp0

We are monitoring these…

— Galaxy Research (@glxyresearch) July 31, 2026

Galaxy says more sweeps are possible while weak seeds hold money. Block traced the thief through a paid data account and passed its findings to authorities.

While it has been a record year for crypto breaches, this one still stands apart. Storing a key safely was meant to be the easy part.

This article originally appeared on BeInCrypto. Read the full article at the source: https://beincrypto.com/coldcard-firmware-bug-cz-warning/

More from Bitcoin News

Leave a Reply

Your email address will not be published. Required fields are marked *