AI is threatening the security of cryptocurrency hardware wallets. [Photo: Reve AI]

About 1,082.65 bitcoin worth $70.2 million was stolen due to a vulnerability in the Coldcard hardware wallet. Binance founder Changpeng Zhao (창펑 자오), also known as CZ, urged cryptocurrency holders not to let down their guard on wallet security.

Decrypt reported on Aug. 1 that Zhao said hardware wallets can also have bugs, and wallets that have been used for a long time are no exception.

In a post on X, formerly Twitter, he wrote, "Nothing is 100% safe." He said splitting assets across multiple wallets could reduce risk to some extent, but added this is also not 100 percent safe. He also left a message that he often uses: "Stay SAFU."

The warning came shortly after a flaw was disclosed in the Coldcard device made by Canadian developer Coinkite. The core problem was a firmware build error released in March 2021. On affected devices, the seed was generated through a software fallback path rather than a hardware random number generator, making private keys far easier to guess than intended. Seeds created on already compromised devices cannot be restored even after a firmware update.

The scale of losses also grew quickly. Initially, about 594 bitcoin worth roughly $38 million was estimated to have been taken from about 500 wallets. But Galaxy Research said it tracked the flow of funds based on patterns confirmed by blockchain engineers and found a total of 1,082.65 bitcoin was withdrawn from 1,196 addresses in 41 minutes on July 30. That is about double the initial estimate.

Galaxy Research said all withdrawal transactions paid the same fixed fee and had no change output. It said those traces match indications that an automated tool that had already obtained the keys swept the funds, rather than users moving funds themselves. The affected addresses included both native SegWit and legacy address formats. That suggests keys may have been searched via multiple paths rather than a single type.

The stolen bitcoin was consolidated into a small number of addresses within minutes, and Galaxy Research said there were no further movements. The attacker is believed to have emptied multiple addresses at once in a short period on July 30.

Coinkite released an emergency fix patch. The company is advising potentially exposed users to move assets using a newly generated seed rather than a simple update. The incident again shows that even if hardware wallets have been regarded as a relatively safe storage method, flaws in firmware and the seed generation process can lead to large-scale losses. The market is now focusing on distributing storage across wallets and checking existing seeds as key follow-up responses.

Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU! https://t.co/9CHiNlbJbz

Keyword

#Coldcard #Changpeng Zhao #Binance #Galaxy Research #Coinkite
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.