Coldcard Bitcoin Wallet Exploit: $70M BTC Stolen, CZ Warns
A Coldcard Bitcoin wallet exploit reportedly grew to about 1,082.65 BTC (around $70.2M) stolen from 1,196 addresses within 41 minutes on July 30. Binance founder CZ Zhao said even established hardware wallets can have bugs, stressing “Nothing is 100%” and urging traders and holders to avoid single-custody assumptions.
New details trace the issue to a March 2021 firmware build error. A seed-generation fallback pulled randomness from a software path instead of Coldcard’s hardware RNG, making private keys easier to guess. Loss estimates were previously near 594 BTC, but Galaxy Research later revised the scope upward using a fund-flow pattern identified by Block engineers.
Galaxy Research also reported consistent sweep behavior (fixed fee, no change outputs). Coinkite shipped emergency hotfixes and advised exposed users to migrate to newly generated seeds. For markets, this Coldcard Bitcoin wallet exploit reinforces “custody and key hygiene” risk pricing, which can weigh on short-term sentiment around BTC despite limited direct protocol impact.
Bearish
The expanded scale of the Coldcard Bitcoin wallet exploit and CZ’s warning can increase perceived custody and operational risk for BTC holders. Even if the incident is device-specific, traders often react by repricing “wallet safety” and may reduce risk appetite around self-custody narratives in the short term. That said, the report suggests fast consolidation and a targeted mitigation path (hotfix + seed migration), which can limit longer-term contagion to the broader BTC market. Net effect: likely bearish sentiment for BTC near-term, with potential stabilization if follow-up audits and fixes reassure users.