⚡ LIVE
BTC Loading...

CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: ‘Nothing Is 100%’



In brief

  • CZ warned on X that even hardware wallets and long-established wallets can have bugs, suggesting holders split their funds across several wallets to mitigate risk while noting no setup is fully foolproof.
  • The warning follows a Coldcard exploit stemming from a March 2021 firmware build error that drew seeds from a software fallback instead of the hardware generator, making private keys far easier to guess.
  • Galaxy Research, mapping the fund flows from a pattern identified by Block engineers, now pegs losses at about 1,082.65 BTC (~$70.2 million) across 1,196 addresses—nearly double the original $38 million estimate.

Binance founder Changpeng “CZ” Zhao is warning crypto owners not to place blind faith in hardware wallets, following an exploit that drained tens of millions of dollars in Bitcoin from Coldcard devices.

In a Saturday post on X, Zhao cautioned that even hardware wallets can carry bugs, and that older wallets with long histories are not immune. “Nothing is 100%,” he posted.

He suggested holders consider spreading their funds across several wallets as one way to reduce exposure, while acknowledging the approach carries its own trade-offs and that no setup is entirely foolproof. CZ closed with his familiar refrain urging users to stay informed and keep their funds safe: “Stay SAFU!”

His comments followed the discovery of a flaw in Coldcard devices made by manufacturer Coinkite. As Decrypt reported, a build error caused seeds on affected units to be drawn from a software fallback rather than the device’s hardware random-number generator, leaving the private keys far easier to guess than intended. The problem traced back to firmware shipped in March 2021, and updating the firmware does not fix a seed already created on a compromised device.

The scope of the theft has grown considerably since the first estimates. Early reporting pegged losses at roughly 594 BTC, or about $38 million, drained from around 500 wallets. According to a report from Galaxy Research, which mapped the flow of funds based on a pattern identified by engineers at Jack Dorsey’s Block, the toll is now put at 1,196 addresses drained for about 1,082.65 BTC, or roughly $70.2 million, in a 41-minute window on July 30. That is nearly double the initial figure.

Galaxy said every sweep paid an identical hardcoded fee and left no change output, a signature it described as consistent with an automated tool spending keys it already held rather than owners moving their own funds. The victims spanned native SegWit and older address types, pointing to multi-path key scanning. The stolen Bitcoin was consolidated within minutes into a handful of addresses and, per Galaxy, has not moved since.

Coinkite has shipped emergency hotfixes and urged exposed users to migrate to newly generated seeds.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

BTCLFGTEAM
@Bitcoinlfgo

Follow on X →
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always do your own research (DYOR) before making any investment decisions.

Leave a Reply

Your email address will not be published. Required fields are marked *