TLDR:
- CZ said spreading funds across independent wallets can reduce losses when one device or seed is compromised.
- Galaxy Research linked three Coldcard attack waves to 1,367.05 BTC across 4,585 total affected addresses.
- A firmware flaw weakened seed generation, allowing attackers to reconstruct keys without phishing or malware.
- Multi-wallet security lowers concentration risk but increases backup, recovery, and operational complexity.
Binance founder Changpeng “CZ” Zhao reopened debate after a Coldcard flaw showed that hardware wallets can fail before transactions even begin. The incident exposed a security problem as affected devices could create weak recovery seeds, leaving funds vulnerable without phishing, malware, or theft.
Zhao said no crypto wallet is secure and advised dividing holdings across several wallets to limit losses from one failure. However, he warned that spreading assets creates risks, including lost backups, poor recovery planning, and mistakes across devices.
Galaxy Research raised losses to 1,367.05 BTC across 4,585 addresses, worth about $88.6 million. Its earlier analysis traced 1,082.65 BTC from 1,196 addresses during a 41-minute sweep on July 30.
Coldcard Seed Flaw Exposed Weakness at Key Creation
Block’s Bitcoin engineering and security teams traced the weakness to a firmware integration error introduced in March 2021. Affected software could use a deterministic fallback instead of consistently relying on the hardware random-number generator for unpredictable recovery seeds.
That fallback used chip identifiers and timing data, allowing an attacker to narrow possible inputs and generate candidate seeds offline. The attacker could then derive public addresses and compare them with funded addresses visible on Bitcoin’s blockchain.
Once a match appeared, the corresponding private keys could transfer the funds. Coinkite said Coldcard Mk2 and Mk3 seeds created on firmware versions 4.0.1 through 4.1.9 may contain critically weak entropy.
It also warned that seeds generated on Mk4, Mk5, and Q devices before emergency updates could contain about 72 bits of entropy. Those devices were intended to provide 128 bits, making the affected seed space easier to search.
Coinkite issued firmware patches, but an update cannot strengthen an old seed already created by vulnerable software. Users must therefore update the device, generate a new seed, and move funds to addresses controlled by replacement keys.
Multi-Wallet Security Limits Risk but Adds Complexity
CZ’s multi wallet approach changes the security goal from finding one perfect device to limiting damage when one system fails. Basically, separate wallets with independently generated seeds can prevent one compromised recovery phrase from exposing an entire portfolio.
Using products from different manufacturers can also reduce dependence on one codebase, firmware design, or random-number process. Yet a multi wallet setup is safer only when each seed is created independently and every backup remains protected.
As a result, splitting funds across several wallets derived from the same vulnerable root seed would not remove the underlying exposure. Multisignature custody adds another safeguard by requiring several keys before funds can move.
However, Block warned that arrangements built entirely from vulnerable devices may still fail if compromised keys control the required quorum. A stronger structure requires independently generated keys, tested recovery procedures, and regular attention to vendor security notices.
Overall, the Coldcard case shows that a crypto wallet can protect keys offline yet still fail during key creation. Hardware wallets, on the other hand, remain useful, but the incident demonstrates that self-custody depends on secure generation, careful diversification, and rapid user response.
For users, multi wallet security may reduce concentration risk, although it increases the burden of protecting and recovering every key.
The post CZ Warns No Crypto Wallet Is Fail-Proof: Is Multi-Wallet Security the Future? appeared first on Blockonomi.

2 hours ago
25
BNB (@cz_binance) 








English (US) ·