Binance founder Changpeng Zhao said hardware wallets remain vulnerable to critical bugs and recommended spreading cryptocurrency holdings across multiple devices following a $70 million theft from Coldcard users last month.

Zhao's warning came after attackers exploited a firmware vulnerability in Coldcard hardware wallets to drain funds from approximately 1,196 wallets between July 30 and July 31. The exploit did not compromise the physical devices themselves but instead targeted a flaw in how the wallet's firmware handled private key material, according to Galaxy Research analysis. Chainalysis separately identified $30 million stolen within a 10-minute window during the attack.

Coldcard wallets have long been favored by institutional and high-net-worth holders for their perceived security benefits as an offline, air-gapped storage device. The theft exposed a gap between the physical security model and the firmware layer that manages cryptographic operations. Attackers gained access to seed phrases or private keys through the vulnerability without requiring the devices themselves, making the attack possible remotely once a user connected their Coldcard to a computer or network.

Zhao's recommendation to diversify across multiple wallet types follows a principle already common among large holders. The attack shows that no single hardware wallet brand or design is immune to exploitation, even those marketed as having eliminated network exposure. Security audits and firmware reviews do not guarantee protection against zero-day vulnerabilities or implementation flaws discovered after deployment.

MSB Intel

Coldcard's manufacturer, Coinkite, has not issued a public response to the exploit as of publication. The company previously patched vulnerabilities in its firmware update cycle, but the July attack struck before security researchers disclosed the flaw to the manufacturer through responsible disclosure channels.

The $70 million loss ranks among the largest single cryptocurrency security incidents tied to a hardware wallet. The scale reflects both the concentration of assets in Coldcard wallets among experienced users and the attack's speed, which allowed the exploit to drain high-value wallets before users or the manufacturer could respond. At 1,196 compromised wallets, the average loss per account totaled roughly $58,500.

Zhao's statement carries institutional weight given Binance's size and his influence within crypto markets, though as the founder of the world's largest centralized exchange, his recommendation to hold funds in hardware wallets rather than on platforms represents a departure from his commercial interests. Wallet diversification alongside institutional-grade security infrastructure is now standard practice for custodial arrangements.