Data indicates that a single unverified media report, first published by a mid-tier crypto outlet and then amplified through social media, claims the Coldcard Bitcoin hardware wallet was compromised in an exploit that drained $70 million. Binance CEO Changpeng Zhao, the report says, responded by advising users to split their funds across multiple devices. The report concludes that this incident highlights the need for diversified custody strategies. That is the entire factual payload. No CVE identifier appears. No attack vector is described. No transaction hash is presented. No victim has spoken publicly. No statement from Coinkite, the company behind Coldcard, appears in any version of the story. Assumption is the adversary of verification.
The baseline is: a hardware wallet is a single-purpose computer designed to keep private keys in a secure element and sign transactions in an isolated environment. Coldcard, specifically, has earned a reputation as the serious user's wallet. It is not a consumer gadget. It is a niche tool for people who understand the difference between a hot wallet and cold storage. The product's design philosophy assumes that the host computer is compromised. That assumption is what makes it strong, and it is also what makes a reported exploit so strange. If true, the attack would have broken through one of the few security postures that has survived repeated market cycles without a mass draining event.
I have spent decades in and around this industry, from ICO due diligence to post-mortem analysis of failed yield farming contracts. In 2020, I traced a $2.3 million exploit in a Mumbai staking contract to an ordinal overflow. The evidence was on-chain, and the transaction graph told the entire story. That is how real security incidents look. They leave marks. The $70 million Coldcard claim leaves nothing. No on-chain marks. No vendor response. No independent reproductions. A $70 million theft would require the movement of roughly 1,500 Bitcoin, depending on the price at the time. On a transparent blockchain, that scale of movement cannot vanish.
The Missing Technical Classification
The first problem is the missing technical classification. There are four plausible attack vectors that could produce large losses from a hardware wallet: supply chain tampering, malicious firmware updates, side-channel extraction, and physical interference or man-in-the-middle attacks. The report does not say which one occurred. That is a fatal omission. A supply chain incident would target a specific batch of devices. A firmware attack would require either a compromised signing key or a compromised update channel. A side-channel attack would need physical access to the device, which means it would not scale to $70 million unless the attacker had access to many devices in a supply chain. In other words, every vector has a different footprint, a different fix, and a different set of victims. Without that information, the claim is not a security report. It is a rumor.
The second problem is the absence of vendor response. In my work, I have never seen a confirmed hardware vulnerability lack a vendor response. Coinkite is a small team with a strong engineering culture. If a vulnerability of this scale existed, the expected sequence would be: emergency firmware release, coordinated disclosure, notice to affected users, third-party audit confirmation, and a public statement. None of that exists in the reported story. This is not merely suspicious. It contradicts the basic operational rhythm of the industry.
The third problem is the timeline. CZ is referred to as CEO of Binance in the report. He left that position in November 2023. The report does not provide a date, which means the reader cannot know whether the event supposedly occurred before or after his departure. If the story emerged during his tenure, the absence of coverage from larger and more reliable outlets is a serious credibility problem. If the story emerged after his departure, the reference to CEO is inaccurate. Either way, the report fails a basic fact-check that any serious publication should have performed.
This is not the first time a report has tried to convince the market that a supposedly secure product was broken. In 2021, I examined the generative algorithm of an NFT collection that claimed random trait distribution. The minting script was not random. It favored early buyers in ways that were statistically significant. I published the analysis. The project's floor price dropped by roughly 40 percent. That was an evidence-based result. The key point: I had data. The $70 million Coldcard report has no data. Every assertion is unverified.
I keep returning to a phrase I have used in every audit I have completed: Assumption is the adversary of verification. This report is built on assumptions. It assumes that a media outlet with a small reach got the details right. It assumes that an unnamed source had access to a $70 million exploit. It assumes that CZ's warning was tied to a confirmed incident. Not one of those assumptions has been verified.
Let me be precise about the size of the claim. Coldcard is a Bitcoin-only hardware wallet. It is not the default choice of retail users. Its users are concentrated among investors and technologists who are more likely to hold significant amounts of Bitcoin and to use advanced custody arrangements. A $70 million loss from Coldcard is not a consumer incident. It is an institutional-level incident. It would imply that someone stored a substantial amount of Bitcoin on a single hardware wallet, or that a small number of large holders were hit. But no specific individual, fund, or entity has complained publicly. In a market where people report lost passwords for wallets holding tiny amounts, the silence around a $70 million loss is deafening.
The report tries to make diversification the answer. CZ's alleged advice to split funds is presented as a practical response. The advice is common sense, but it is also under-specified. Splitting funds across two Coldcards does nothing if the vulnerability is in the hardware itself. Splitting funds across two devices from the same manufacturer does nothing if the vulnerability is in firmware code shared by both. Splitting funds across one Coldcard and one Ledger may help if the vulnerability is vendor-specific, but it still does not address a user error, a physical attack, or a supply chain incident that affects both suppliers. If the intended advice is to use multiple custody methods, including a multi-signature wallet or a qualified custodian, then the report should say so.
The Shape of a Real Exploit Disclosure
A real exploit disclosure has a shape. It includes a technical advisory, a severity rating, affected versions, a patch, and a list of detection methods. When the Bitcoin network has faced critical bugs in the past, developers have gone to extreme lengths to release patches before attackers could exploit them. The same discipline applies to hardware wallets. If a legitimate exploit were discovered, the industry would not learn about it through a single article and a social media warning. It would learn about it through a coordinated disclosure. The absence of that shape is a powerful negative signal.
I have also learned to watch the liquidity. In a real theft, the thief must move the funds. That movement creates a pattern. It might go through a mixer. It might be deposited to an exchange. It might remain dormant. But it will exist. The $70 million report does not ask where the money went. A forensic story would include a chain analysis, even if the funds had not moved yet. Instead, the report treats the alleged exploit as a thought exercise. That is not security journalism.
From a market microstructure standpoint, the absence of price reaction is also telling. If a credible claim of a $70 million hardware wallet exploit circulated during a normal market, the price of Bitcoin would likely show at least an intraday dip. The report does not provide any price data. A story about a major theft without market context is like a weather report without a temperature reading. It is incomplete.
Could the impact be on BNB instead? Binance's platform token has historically reacted to negative news involving the exchange. But this story does not involve Binance itself. It involves CZ's advice. If investors believed that a hardware wallet was compromised, they might move funds to Binance, which would be a short-term neutral or positive flow for Binance. If they believed that CZ was hiding a larger problem, BNB could suffer. Neither belief is supported by evidence. The market is unlikely to price a story this weak, and smart traders should not trade it.
There is also a regulatory dimension. Regulation requires that a material security incident affecting a financial custody device, once confirmed, be disclosed in a structured way. Regulators in the United States, Canada, and the European Union have issued guidance on ransomware and exchange failures, but hardware wallets exist in a gray zone. If an incident of this size were real, the affected jurisdiction would need some regulator to get involved. There is no mention of any regulatory inquiry in the report. That is another missing block in a structure that is already collapsing under the weight of its omissions.
The original report also fails to explain how the vulnerability was found. Was it a white-hat researcher? A black-hat group? A government agency? An insider? The motivation matters. If a black hat found a vulnerability that could drain $70 million, why would the loss be limited to $70 million? Why not drain the entire manufacturer's user base? The claim implies either a highly selective attacker or an exploit that is still not understood. Neither possibility is comforting, and both require a response beyond a one-line warning.

What if the story is false? There is real precedent for false security alarms in crypto. I have seen a single misleading tweet cause a panic that lasted longer than the refutation. There have been reports of exchange hacks that did not happen, of protocol bugs that were already patched, and of wallets being stolen when the actual cause was a leaked seed phrase. This story may be a similar failure: a confused report that took a small incident, extrapolated it to $70 million, and attached CZ's name to make it credible. If that is the case, the damage is not financial but informational. It teaches the market to ignore real alarms because of false ones.
I have also considered the possibility that this story was planted. In a competitive hardware wallet market, spreading an unverified story about a rival can shift market share. The report's silence on Coinkite's response is convenient for anyone who wants to move users away from Coldcard. But I am not making that accusation. I am noting that the report's structure is consistent with a narrative attack, not with forensic reporting. The burden of proof lies with the outlet and its source.
What the Bulls Got Right
The contrarian angle is important. Let me say it plainly: the idea that hardware wallets are absolutely secure is a belief, not a fact. Hardware wallets are excellent tools, but they are not magic. They reduce the attack surface. They do not eliminate it. There have been historical incidents in the wider hardware wallet category, including a supply chain event in 2023 involving a Ledger-related service. So the general claim that self-custody hardware can fail is not unreasonable. The problem is not the thesis. The problem is the evidence.
What the bulls got right in this story is the conclusion. Diversification is necessary. I have said for years that no single custody method should hold a lifetime of savings. A multi-signature wallet, a hardware wallet, and a trusted custodian can be used together to reduce single-point failure. This advice is sound even if the $70 million claim turns out to be false. The report, for all its flaws, points in a direction that serious security professionals already endorse. That does not make the report accurate. It only means that its final recommendation happens to be correct.
Still, the way that recommendation is delivered is dangerous. A user who reads the story and immediately tries to move funds from a Coldcard to a software wallet, or to a multi-sig setup they have never tested, is taking on a new set of risks. I have seen more funds lost through migration errors than through any exploit. Transferring Bitcoin is irreversible. A mistyped address, a forgotten passphrase, or a compromised desktop wallet can destroy value faster than any hardware vulnerability. In that sense, the report is not merely unhelpful. It is potentially harmful.
The industry needs to understand what this story is really about. It is about the relationship between media, fear, and unverified claims. The $70 million figure is the hook. The CZ warning is the authority gesture. The diversity strategy is the conclusion. But none of this is rooted in verifiable data. A security incident is a technical event. It has a hash. It has a block number. It has a victim. It has a timeline. The report provides none of these.
I have reviewed the available claims side by side with what I know about Coldcard, Coinkite, and the broader hardware wallet market. Nothing fits. The technical details do not fit. The scale does not fit. The lack of response does not fit. The lack of regulatory attention does not fit. There is an alternative explanation that fits all of the data: the report is poorly sourced, exaggerated, or entirely wrong.
This is where the discipline of verification matters more than ever. Assumption is the adversary of verification. In 2024, I was asked to review the infrastructure supporting a Bitcoin ETF application. I found discrepancies in the multi-signature thresholds. My report delayed approval until the custodian upgraded its security. That process worked because everyone involved demanded evidence. The same standard should apply here. If a journalist or a social media account tells you that $70 million has been stolen from Coldcard users, the correct response is not to panic. The correct response is to ask for the transaction hash. The correct response is to wait for Coinkite to speak. The correct response is to verify before acting.
The takeaway is not that Coldcard is safe or unsafe. It is that this story, in its current form, is not actionable. A user with a Coldcard should review their own security habits. They should consider whether their threat model includes physical access. They should consider whether they need a multi-signature wallet. They should not, however, change their custody arrangement based on a report that cannot name a vulnerability, identify a victim, or produce a single item of on-chain evidence.
The next phase of this story depends on disclosure. If the report is true, the source must provide the details. If the report is false, Coinkite should issue a denial, CZ should clarify his statement, and the outlet should retract. Without one of those outcomes, the $70 million Coldcard exploit will become another unsubstantiated panic in a long line of them. I will not treat it as fact. Neither should you.
Until evidence arrives, the only responsible position is to maintain skepticism. Assumption is the adversary of verification. The ledger may be silent today, but the industry's credibility is not. Demand the proof. Everything else is noise.