Coldcard Exploit Forces CZ's Warning: Diversify Your Bitcoin Wallets
Binance founder Changpeng Zhao has cautioned cryptocurrency holders to spread their funds across multiple wallets after a firmware flaw in certain Coldcard hardware devices led to the theft of over 1,000 BTC. The incident highlights that even hardware wallets can have vulnerabilities and that self-custody is not foolproof.
The attacker exploited a firmware flaw dating back to March 2021 that reduced the quality of randomness used to generate recovery seeds on certain Coldcard devices. This allowed the thief to calculate possible seeds and reconstruct corresponding private keys, resulting in the theft of approximately $70 million worth of BTC from around 1,196 addresses.
Coldcard maker Coinkite acknowledged the flaw, apologized, and issued emergency firmware updates. However, installing patched software does not repair a vulnerable seed generated under an affected firmware version, emphasizing the importance of seed-generation history and provenance.