Via bitrawr.com
Binance’s CZ warns users to split funds after $70M Coldcard exploit
A firmware bug in Coldcard Mk3 devices drained roughly 1,082 BTC from nearly 1,200 wallets in under an hour, rattling confidence in hardware self-custody.
Hardware wallets were supposed to be the safe answer. Air-gapped, offline, immune to the hacks that plague exchanges. Then July 30, 2026 happened, and about 1,196 Bitcoin wallets found out the hard way that “offline” and “safe” are not the same word.
A firmware flaw buried inside Coldcard Mk3 devices since March 2021 allowed attackers to drain approximately 1,082.65 BTC, worth roughly $70 million at the time of the attack, in a window spanning just 41 minutes between 1:10 and 1:51 AM UTC. Galaxy Research later revised that figure to approximately 594 BTC, or around $38M, across roughly 500 addresses, suggesting some initial tallies captured transactions that were not all attributable to the exploit.
What actually went wrong
The flaw lived in the random number generation process that Coldcard Mk3 devices used to build recovery seeds. In plain terms: the seeds were not actually random.
The compromised firmware builds dated back to March 2021, which means wallets created during that window were vulnerable for over five years before the exploit landed.
Coinkite, the Toronto-based manufacturer behind Coldcard, acknowledged the vulnerability and released a patched firmware version, labeled 4.2.0 and above, alongside a security advisory. The company was clear on one critical point: updating firmware alone does not fix the problem. Funds secured under a compromised seed remain at risk regardless of firmware version. Affected users need to generate entirely new seeds on patched hardware and move their assets to those new addresses before considering themselves safe.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The newer Coldcard models, specifically the Mk4, Q, and Mk5, were not affected by this specific flaw.
CZ’s response and what it actually means
Changpeng Zhao, the Binance founder who goes by CZ, weighed in quickly. His advice was blunt: split your funds across multiple wallets.
CZ also acknowledged the uncomfortable flip side. More wallets mean more complexity, more seed phrases to manage, and more opportunities to make a mistake. Diversifying hardware storage is not a free lunch. It trades one category of risk for another.
What this means for self-custody and the broader market
For retail holders, particularly those who set up Mk3 devices during the 2021 bull cycle and have not touched them since, the immediate priority is verifying which firmware version their device was running at the time of wallet creation. Coinkite’s advisory provides the specific affected build range. If your wallet falls in that window, moving funds to a freshly generated address on patched hardware is not optional, it is urgent.
The attackers specifically hit addresses that had been inactive for extended periods, suggesting they had time to identify and target vulnerable seeds before executing the sweep.