Binance founder CZ calls for wallet diversification after $70 million Coldcard exploit
Binance founder CZ is advising crypto holders to diversify their funds across multiple wallets following a $70 million exploit of Coldcard hardware wallets due to a firmware flaw.
Intelligence analysis by Gemini 2.5 Flash Lite

A significant security breach affecting Coldcard hardware wallets, resulting in the loss of approximately $70 million in Bitcoin, has prompted Binance founder Changpeng Zhao (CZ) to advocate for a more diversified approach to crypto storage, suggesting users spread their assets across several wallets.
Imagine you have a special piggy bank that keeps your money super safe. But, a sneaky trick was found in how some of these piggy banks were made, and someone used it to take money from many of them! So, a big crypto boss said it's like putting all your allowance in just one piggy bank; it's safer to share your money between a few different piggy banks, even if managing them is a bit trickier.
Analysis
A Flaw in the Foundation
The recent exploit targeting Coldcard hardware wallets, a device widely regarded for its robust security features, has sent ripples of concern through the cryptocurrency community. The breach, which resulted in the loss of an estimated $70 million worth of Bitcoin, stemmed from a subtle yet critical firmware flaw dating back to March 2021. This vulnerability weakened the randomness used in generating recovery seeds, a fundamental aspect of wallet security. The attacker's ability to reconstruct private keys offline, bypassing the need for physical access to the devices, underscores a sophisticated attack vector that exploited a deep-seated weakness.
CZ's Call for Diversification
In response to the incident, Binance founder Changpeng Zhao, widely known as CZ, has issued a stark reminder about the fallibility of even the most trusted security measures. His advice to "split your funds in a few wallets maybe?" is a direct acknowledgment that no single solution offers absolute protection. While diversification of coins has long been a standard practice, CZ's suggestion extends this principle to the wallets themselves, advocating for a multi-pronged approach to asset storage. This strategy, however, introduces its own set of complexities, particularly in managing multiple private keys and recovery phrases, which can be a significant burden for many users.
Re-evaluating Self-Custody
The Coldcard exploit reignites the ongoing debate surrounding the true extent of self-custody in the crypto space. Hardware wallets are often presented as the gold standard for securing digital assets offline, offering a significant upgrade from exchange-based storage. Yet, this incident demonstrates that even established hardware solutions can harbor vulnerabilities that remain undetected for extended periods. The fact that many of the compromised wallets had been dormant for years suggests that the flaw was latent, waiting for the right conditions or attacker to exploit it. This event compels users to consider not just the brand reputation of their chosen wallet but also the underlying technology and the potential for unforeseen bugs, pushing for a more informed and cautious approach to securing digital wealth.
Key points
- Binance founder CZ advised crypto holders to diversify funds across multiple wallets after a $70 million Coldcard exploit.
- The exploit exploited a firmware flaw in Coldcard devices, allowing attackers to reconstruct private keys offline.
- An estimated $70 million in Bitcoin was stolen from over 1,000 wallets due to the vulnerability.
- Coldcard maker Coinkite acknowledged the bug, apologized, and released firmware updates, advising users to migrate funds to new seeds.
- The incident has reignited discussions about the limitations and risks associated with hardware wallet security and self-custody.
This incident could spur greater innovation in hardware wallet security and prompt users to adopt more robust, multi-wallet storage strategies, ultimately leading to a more resilient crypto ecosystem. Increased awareness of potential vulnerabilities may also drive the development of better auditing and bug-bounty programs for hardware manufacturers.
The exploit could erode trust in hardware wallets, leading some users to revert to less secure storage methods or abandon self-custody altogether, potentially increasing their exposure to exchange hacks or other centralized risks. The complexity of managing multiple wallets might also deter less tech-savvy users, leaving them vulnerable.



