By : Lockridge Okoth
Publisher : beincrypto
Date : August 1, 2026

$70 Million Gone in 40 Minutes: CZ Weighs in on Coldcard Fallout

Changpeng Zhao (CZ) has a warning for Bitcoin holders. Hardware wallets can fail too. He spoke days after a Coldcard firmware bug let thieves work out private keys and take $70 million.

Researchers at Galaxy and Block tracked the theft. Attackers emptied 1,196 wallets in 41 minutes on July 30. Nobody touched a single device.

CZ Points to the Limits of Cold Storage

CZ, the founder and former CEO of Binance exchange, says a wallet can be old, trusted, and still broken.

When he posted, early reports put the loss at $38 million. The real figure turned out to be almost double that.

“Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!” wrote CZ.

Follow us on X to get the latest news as it happens

His advice was to spread coins across several wallets. He also admitted that this brings new risks of its own.

CZ has been candid lately about calls he got wrong. One was the stablecoin market he dismissed, now worth over $300 billion.

How the Coldcard Firmware Bug Made Seeds Guessable

Every wallet starts with one huge secret number. It is called a seed. Every key and address grows out of it. That number has to be random. Coldcard used a dedicated chip to make it random.

Then came a coding mistake in March 2021. The job quietly passed to a weak backup instead. That backup leaned on the device serial number and its clock. Both can be worked out.

So the number stopped being huge. Block’s engineers put the range at roughly four billion options on newer models. A computer can chew through that.

Thieves simply built the seeds themselves. They turned each one into addresses. Then they scanned the public blockchain for funded matches.

Galaxy mapped the sweeps. Every one paid the exact same fee, far above normal. None left change behind. That is software, not a person.

The Coldcard Incident Reportedly Happened Within 41 Minutes
The Coldcard Incident Reportedly Happened Within 41 Minutes. Source: Galaxy research

“The full event spans six blocks and 41 minutes. Three intervening blocks contain no sweep activity at all, suggesting the transactions were broadcast in batches rather than streamed,” Galaxy Researchers indicated.

Owners Still Cannot Test Their Own Seeds

Coinkite has shipped fixed firmware for every model. An update cannot repair a seed that already exists.

If yours is exposed, you need a fresh seed and a new wallet. BeInCrypto’s earlier Coldcard theft coverage walks through the steps.

Two things help. The advisory says 50 or more private dice rolls at setup keep a seed strong. A good passphrase adds another wall, the same gap flagged over missing BIP39 passphrase support on phones.

There is still no test you can run at home. Block also lists the older Mk2 as at risk. Coinkite’s advisory does not name it.

The stolen coins have not moved. They sit in four wallets.

Galaxy says more sweeps are possible while weak seeds hold money. Block traced the thief through a paid data account and passed its findings to authorities.

While it has been a record year for crypto breaches, this one still stands apart. Storing a key safely was meant to be the easy part.

The post $70 Million Gone in 40 Minutes: CZ Weighs in on Coldcard Fallout appeared first on BeInCrypto.

Read more

Latest News

ARK Invest buys $6.8M in Circle sh...
By Lawrence Mondal
Publisher : crypto
Date : August 1, 2026
DOJ Files to Recover $47K in Crypt...
By Kevin Helms
Publisher : news
Date : August 1, 2026
Strategy stock sinks as Saylor put...
By Lawrence Mondal
Publisher : crypto
Date : August 1, 2026
America Broke a 28-Year Rule to Sa...
By Lockridge Okoth
Publisher : beincrypto
Date : August 1, 2026
Binance founder CZ calls for walle...
By Omkar Godbole
Publisher : coindesk
Date : August 1, 2026