Changpeng “CZ” Zhao says crypto holders should not assume hardware wallets are risk-free after a Coldcard firmware flaw is linked to large-scale thefts of Bitcoin. CZ posted “Nothing is 100%” on X, urging users to stay informed and to consider spreading funds across multiple wallets to reduce exposure, while noting no setup is entirely foolproof.

Multiple reports describe how the issue stems from a firmware change in March 2021 that caused affected Coldcard devices to generate recovery seeds using a software fallback rather than the device’s intended hardware random-number generator. Security researchers say this reduces entropy for vulnerable seeds, making private keys easier to derive. Coinkite confirms the firmware bug and has issued emergency hotfixes, but the fix does not correct seeds already created on compromised firmware. Users are advised to generate new wallets on updated hardware and move funds to them.

Tracing firms report theft activity across many single-signature Coldcard-derived addresses, with early estimates of about 594 BTC rising in later tracking. One timeline described wave-like movements, including consolidation patterns and continued draining over multiple days, with losses reported in the range of roughly $75 million to about $89 million depending on the time window assessed by researchers.