CZ Warns Bitcoin Investors After $70 Million Hardware Wallet Exploit: ‘Nothing Is 100% Secure’
Binance founder Changpeng “CZ” Zhao has urged Bitcoin holders to rethink how they store their assets after a serious security breach of Coldcard hardware wallets led to an estimated loss of around $70 million in BTC-almost double the first public estimates.
In a post on X shared Saturday, Zhao cautioned users against assuming that hardware wallets are infallible. While such devices are widely seen as among the safest options for long-term storage, he reminded followers that every piece of software and hardware can contain vulnerabilities.
“Nothing is 100%,” CZ wrote, emphasizing that time-tested products with long track records can still harbor undiscovered bugs. The Coldcard exploit is now being widely cited as a stark example of that uncomfortable reality.
$70 Million Losses-Nearly Double Initial Estimates
The scale of the incident has grown as investigators continue to trace the stolen funds. Galaxy Research, which has been tracking the aftermath of the exploit, now estimates the total losses at around $70 million in Bitcoin-significantly higher than early projections, which hovered near $37 million.
According to on-chain analysis, funds were drained from multiple Coldcard wallets over a period of time, suggesting that the vulnerability was not an isolated user error but a deeper flaw that could be reliably exploited once discovered. The attack has triggered renewed debate over what “cold storage” actually guarantees and where its limits lie.
CZ: Diversify Wallets, Reduce Single-Point Risk
In his comments, Zhao recommended that users avoid concentrating all of their assets in a single wallet-hardware or otherwise. Spreading funds across multiple wallets, he argued, can significantly reduce the impact if one product, device, or setup is compromised.
However, he was careful to note that diversification is not a magic bullet. Managing several wallets brings its own challenges: more seed phrases to protect, more devices or apps to maintain, and a higher risk of human error in backup or recovery.
“There are always trade-offs,” he implied. Even the most robust configuration can fail if the user’s operational security is weak, or if a critical backup is lost or exposed.
As is typical in his security-focused messages, Zhao ended his post with a familiar reminder to users: “Stay SAFU!”-a call to remain cautious, informed, and proactive about protecting their holdings.
The Myth of Absolute Security in Crypto Storage
The Coldcard incident has underscored a truth that many security professionals repeat but most investors prefer to ignore: no solution is completely risk-free. Hardware wallets minimize exposure to online attacks by keeping private keys offline, but they still depend on firmware, supply chains, and user practices that can all fail in unexpected ways.
Vulnerabilities might arise from:
– Bugs in the device firmware or software
– Flaws in the random number generation used for keys
– Weaknesses introduced by third-party tools or integrations
– Insecure manufacturing or distribution processes
– Poor user handling, such as compromised backups or insecure environments
The combination of any of these factors can turn a “secure” wallet into a ticking time bomb.
Hardware Wallets Are Still Valuable-but Need Critical Use
Despite the exploit, cybersecurity experts are not calling for an abandonment of hardware wallets. On the contrary, they still regard dedicated devices as one of the most effective tools for self-custody-especially compared to storing large balances on centralized exchanges or always-online software wallets.
What is changing is the tone of the discussion. Instead of treating hardware wallets as invulnerable, security professionals are pushing for a more realistic mindset: hardware wallets are one protective layer, not an all-purpose guarantee.
For long-term holders and high-net-worth individuals, this often means combining hardware wallets with additional safeguards, such as:
– Multisignature schemes that require multiple independent keys
– Geographically distributed backups
– Segregation of funds by purpose and risk level
– Routine review of wallet setups as products and threats evolve
Diversification in Practice: How to Spread Risk
CZ’s advice to use multiple wallets is conceptually simple but often poorly implemented. Effective diversification is not just about opening more wallets-it’s about creating separation between them in meaningful ways.
Some practical approaches include:
– Using different wallet brands or models, so a single product flaw cannot drain all holdings
– Allocating funds by time horizon: spending wallet, medium-term savings, and deep cold storage
– Keeping high-value holdings in multisig setups requiring two or more distinct devices or co-signers
– Maintaining small, low-risk balances on more convenient wallets for daily use, with the bulk kept in hardened setups
In other words, investors should not only think about “where” coins are stored, but also “how” those wallets might fail and whether failures could cascade across the entire portfolio.
The Human Factor: Most Setups Fail at the User Level
While a major exploit like the Coldcard case draws attention to technical flaws, most real-world losses still come down to human mistakes: lost seed phrases, poorly stored backups, phishing attacks, or blindly trusting unverified tools.
Even the best wallet design cannot protect users who:
– Photograph or upload recovery phrases to cloud storage
– Store seeds in plain text on computers or phones
– Reuse the same seed phrase across multiple wallets or devices
– Enter seed words into fake apps or malicious browser extensions
The Coldcard exploit is a reminder to review both the technology and the habits surrounding it. Relying purely on device marketing or “reputation” can be as dangerous as leaving funds on an unregulated platform.
What Bitcoin Holders Should Consider Doing Now
In light of this exploit and CZ’s warning, Bitcoin holders-especially those with substantial balances-may want to take several immediate steps:
1. Audit your setup: Identify where all your funds are stored, which devices and software are involved, and how backups are kept.
2. Avoid single points of failure: If a single device, seed phrase, or provider compromise can wipe you out, consider restructuring.
3. Update firmware and software: Ensure any hardware wallets you use are running the latest verified firmware from official channels.
4. Segment funds by risk: Move long-term holdings to more conservative, layered setups; keep only necessary funds in frequently used wallets.
5. Review recovery procedures: Make sure you can safely restore wallets if a device fails, without exposing seed phrases to unnecessary risks.
These are not one-time actions. Security in crypto is an ongoing process, not a box to be ticked and forgotten.
The Trust Problem: Reputation vs. Verifiable Security
Coldcard had built strong credibility among a segment of security-conscious Bitcoiners. Its exploit illustrates the difference between perceived safety based on reputation and actual, verifiable security at a technical level.
Zhao’s “Nothing is 100%” comment cuts to the heart of this problem: even audited or widely used products can contain hidden weaknesses. Overreliance on brand trust, marketing claims, or herd behavior can prevent users from questioning whether their setups are truly resilient.
More sophisticated users are increasingly demanding:
– Open-source firmware and reproducible builds they can verify
– Transparent disclosure of previous bugs and how they were addressed
– Independent code review and ongoing security research
– Clear threat models describing what a device does-and does not-protect against
Not Just a Bitcoin Problem
Although this particular exploit targeted Bitcoin hardware wallets, the implications extend to the broader digital asset ecosystem. Most popular hardware wallet brands and self-custody solutions support multiple blockchains and tokens, meaning a similar flaw could impact users far beyond BTC.
The lesson applies across the board: whether storing Bitcoin, stablecoins, or other assets, assuming that any one tool or vendor provides absolute protection is dangerous. Users need layered security strategies and a willingness to adapt as new vulnerabilities and best practices emerge.
A Wake-Up Call, Not the End of Self-Custody
The Coldcard wallet exploit and the revised $70 million loss estimate are likely to be remembered as a major moment in the evolving story of crypto security. For CZ, the message is clear: self-custody remains essential, but it must be approached with realism and discipline, not blind faith in a single device or brand.
His warning encapsulates the core takeaway for Bitcoin holders:
– Hardware wallets are powerful tools, not silver bullets.
– Security is about reducing risk, not eliminating it.
– The best defense is a thoughtful, diversified setup backed by informed, cautious behavior.
In an industry built on the principle of “not your keys, not your coins,” the corollary is becoming just as important: “Not your security strategy, not your safety.”
