CZ urges Bitcoin users to rethink hardware wallet safety after $70M Coldcard exploit
Binance founder Changpeng “CZ” Zhao has cautioned Bitcoin holders against relying too heavily on the perceived invincibility of hardware wallets, after a major exploit tied to Coldcard devices was found to have siphoned off around $70 million in BTC.
Research from Galaxy has now put the total losses from the Coldcard-related vulnerability at roughly $70 million-almost twice the size of early estimates. The incident has reignited debates over what “self‑custody” really means and how secure it actually is in practice.
“Nothing is 100%”
Posting on X on Saturday, CZ reminded users that even the most trusted hardware wallets are still pieces of software and hardware, and therefore inherently fallible.
According to Zhao, bugs can exist in any wallet implementation, including long‑standing products that many users consider battle‑tested. Age and reputation, he stressed, do not automatically guarantee absolute safety.
“Nothing is 100%,” he wrote, underscoring that no security setup in crypto can be treated as completely risk‑free.
Spread your risk – but accept the trade‑offs
In his post, CZ recommended that holders avoid concentrating all of their coins in a single wallet-hardware or otherwise. One practical mitigation, he suggested, is to distribute funds across several different wallets, ideally using different vendors or configurations.
Doing so can help limit the blast radius of any single vulnerability: if one wallet type or device is compromised, the attacker cannot immediately access the entirety of a user’s holdings.
However, CZ also acknowledged that fragmentation is not a magical solution. Managing multiple wallets introduces its own risks and complications:
– More seed phrases and backups to protect
– Higher chance of user mistakes or loss of records
– Additional steps when moving funds or rebalancing
The core message: diversify where it makes sense, but don’t confuse added complexity with guaranteed safety.
Coldcard exploit: what’s known so far
The vulnerability associated with Coldcard devices enabled attackers to drain tens of millions of dollars in Bitcoin from affected users’ wallets. While full technical details are still being analyzed and debated, investigators have linked a series of suspicious transactions and drained addresses back to a common flaw tied to the Coldcard ecosystem.
Galaxy’s updated estimate of roughly $70 million in losses suggests that the impact of the exploit was far broader than initial on‑chain observations indicated. Many victims may not have realized immediately that their funds were taken due to the relative opacity of self‑custodied setups and the fact that losses are often discovered only when users next attempt to move coins.
The incident does not automatically mean every Coldcard user has been compromised, but it has raised hard questions about assumptions of safety around specific brands and device configurations.
Reputation is not a security guarantee
Coldcard, widely marketed as a Bitcoin‑only, security‑focused hardware wallet, has historically been popular among users who prioritize cold storage and air‑gapped signing. That reputation led many to treat it as one of the “gold standards” of hardware security.
The exploit demonstrates that reputation and design philosophy-even when genuinely security‑driven-cannot fully eliminate:
– Implementation bugs
– Design oversights
– Interaction issues with other wallet software or tools
– Human error in setup and usage
For experienced users, the lesson is uncomfortable but clear: no single vendor or product is immune. For newcomers, it’s a reminder that “use a hardware wallet and you’re safe” is an oversimplification, not a rule.
The paradox of self‑custody
The Coldcard case also highlights a broader paradox: self‑custody is both safer and riskier than trusting a centralized exchange.
On one hand, self‑custody removes counterparty risk. Your funds are not dependent on the solvency, honesty, or competence of a third party. On the other, it transfers all operational and security responsibilities directly to the user.
That means:
– You must judge which devices and software are trustworthy
– You must understand backup and recovery processes
– You must keep firmware and software updated (without falling for fake update scams)
– You alone are responsible if something goes wrong
Incidents like this show that “not your keys, not your coins” must be balanced with an equally important reality: “your keys, your full responsibility.”
What Bitcoin holders can do now
In light of the exploit and CZ’s warning, Bitcoin users can take several practical steps to reduce risk:
1. Avoid absolute trust in any single wallet type
Treat every wallet-hardware, mobile, desktop, or paper-as having potential failure modes. Design your setup around the assumption that something could go wrong.
2. Use multiple wallets with different threat profiles
– A hardware wallet (or two from different vendors) for long‑term holdings
– A separate wallet app for day‑to‑day spending
– Possibly a multisig solution for larger balances, spread across different devices
3. Keep backups offline and redundant
Store seed phrases and backups in physically separate, secure locations. Avoid digital photos, cloud storage, or easily compromised mediums.
4. Stay current on security advisories
Even if you prefer not to tinker, you should at least monitor major security announcements for the brands and tools you rely on. Many wallet compromises are discovered after years of being live.
5. Consider gradual testing
When using a new wallet or setup, start with small amounts. Move larger sums only after you’ve confirmed that restores, signing, and receiving all work as expected.
Multisig: not a silver bullet, but a useful tool
Some users may look to multisignature wallets as a response to the Coldcard exploit. Multisig-where a transaction requires multiple keys to sign-can indeed reduce reliance on a single device or vendor.
For example, a 2‑of‑3 multisig might use:
– One hardware wallet from vendor A
– One hardware wallet from vendor B
– One software or mobile wallet as a backup signer
This way, a single compromised device or firmware issue is less likely to result in total loss. That said, multisig introduces:
– More complex setup and recovery procedures
– Higher risk of misconfiguration
– Greater need for documentation and careful planning
CZ’s “nothing is 100%” applies here as well: multisig can strengthen security, but only for users prepared to manage its complexity.
Security is a continuous process, not a one‑time purchase
One of the most damaging myths in crypto is that buying a hardware wallet equals being “done” with security. The Coldcard exploit shows security is not an item you purchase once-it’s an ongoing process.
That process includes:
– Periodically reviewing how your funds are stored
– Rotating wallets or keys over time if vulnerabilities or concerns arise
– Educating yourself about common attack vectors like phishing, fake wallet apps, and malicious firmware
– Verifying downloads, checksums, and sources whenever you install or update software
Even a perfectly designed device can be undermined by poor user practices, outdated firmware, or unsafe companion software.
Behavioral risks: where most people slip up
While the Coldcard case centers on a technical flaw, many losses in crypto still stem from user behavior rather than pure code bugs. Common examples include:
– Entering a seed phrase into a “web wallet” or unknown app
– Storing seed words in email, messengers, or phone photos
– Falling for fake support agents or “recovery” services
– Plugging devices into untrusted computers without caution
A robust security posture combines sound tools with disciplined habits. No hardware wallet can compensate for consistently unsafe behavior.
“Stay SAFU” – more than a slogan
CZ ended his post with his trademark reminder: “Stay SAFU!” Once a marketing tagline, the phrase has evolved into a broader call for user‑level risk management.
In the context of the Coldcard exploit, “staying SAFU” means:
– Questioning assumptions about “bulletproof” products
– Acknowledging that trusted brands can still have critical vulnerabilities
– Designing your storage strategy so that a single failure does not wipe you out
– Remaining proactive rather than complacent about how your coins are protected
The $70 million exploit is a costly warning shot to the entire industry: hardware wallets significantly improve security for most users, but they do not deliver absolute protection. Understanding that nuance-and acting on it-is now essential for anyone serious about safeguarding their Bitcoin.

