A hardware wallet exploit targeting Coldcard devices has ballooned to an estimated $70 million in losses, according to research from Galaxy Research — a figure that is nearly double what analysts initially projected. The revised toll has rattled a corner of the Bitcoin community that believed hardware wallets represented the gold standard of self-custody security, and it drew a pointed public warning from Binance founder Changpeng Zhao, widely known as CZ: "Nothing is 100%."

A Revised Toll That Changes the Conversation

When the Coldcard exploit first surfaced, early damage estimates circulated at a figure roughly half of what Galaxy Research has now calculated. Revisions of this magnitude are not uncommon in the immediate aftermath of on-chain security incidents — blockchain forensics takes time, and wallet addresses connected to a single exploit can emerge in waves as investigators trace fund flows. But the near-doubling of the loss figure carries a specific psychological weight. It transforms what might have been written off as a contained, unfortunate incident into a systemic warning about the limits of any single security solution, hardware or otherwise.

Coldcard has long held a strong reputation among Bitcoin maximalists and technically sophisticated self-custody advocates. Its air-gapped architecture and open-source firmware placed it near the top of the hardware wallet hierarchy for years. That reputation makes the $70 million figure land harder. If a device this trusted can be the vector for eight figures of losses, the industry's default assumptions about hardware wallet safety deserve urgent re-examination.

CZ Steps In — and the Message Matters

Changpeng Zhao is not a disinterested observer in the hardware wallet conversation. As the founder of the world's largest cryptocurrency exchange by volume, his platform profits when users keep funds on custodial infrastructure rather than pulling them into self-custody. That context is worth acknowledging. But it does not invalidate the substance of the advice he offered following the exploit revelation.

CZ's core recommendation was straightforward: spread holdings across multiple wallets rather than concentrating them in any single device or solution. The logic is elementary risk management — the same diversification principle that governs portfolio construction. If no individual security solution is infallible, then concentrating Bitcoin holdings in one hardware wallet, however reputable, creates a single point of catastrophic failure. The $70 million loss figure from the Coldcard exploit is a live demonstration of exactly that principle.

The phrase "Nothing is 100%" reads as a deliberately calibrated statement from someone who has watched the crypto industry absorb some of its most spectacular failures. CZ's own tenure at Binance included navigating the exchange through serious security incidents. He is speaking from institutional memory, not abstract theory, and that gives the warning a credibility that a technical blog post from a lesser-known figure might not carry.

What This Exploit Reveals About Self-Custody Risk

The broader self-custody movement accelerated dramatically after the collapse of FTX in late 2022, when the mantra "not your keys, not your coins" became a kind of rallying cry for millions of retail Bitcoin holders. Hardware wallet sales spiked. The argument was compelling and remains largely valid: custodial risk — the risk that an exchange or platform collapses, freezes withdrawals, or gets hacked at the infrastructure level — is real and has caused devastating losses at scale.

But the Coldcard exploit illustrates that self-custody risk is not zero, either. Hardware wallets are physical objects running firmware. They interact with software interfaces. They can be purchased through supply chains that are not always transparent. They can be exploited through vectors that may involve device compromise, firmware vulnerabilities, or attack surfaces that even diligent users cannot fully audit. The self-custody argument was never "hardware wallets are perfectly safe." It was "this is safer than trusting a third party." The $70 million figure does not demolish that argument, but it does demand more nuance in how the community communicates security tradeoffs.

Practical Takeaways for Holders

CZ's multi-wallet recommendation is sensible but deserves elaboration. Spreading funds across wallets can mean several things simultaneously: using multiple hardware wallet brands rather than a single manufacturer, maintaining some holdings in multisignature setups that require multiple keys to authorize transactions, and periodically auditing device integrity. For larger holders, combining hardware cold storage with time-locked or geographically distributed key setups adds additional layers that a single exploit is unlikely to penetrate entirely.

The Coldcard incident also revives the conversation around multisig solutions — setups where two or three independent signing devices must cooperate to authorize a transaction. Services like Unchained and open-source frameworks like Specter have long offered these architectures, but adoption among retail holders remains limited by complexity. If $70 million in losses from a single hardware wallet exploit does not shift that calculus, it is difficult to imagine what will.

What This Means

The Coldcard exploit — now estimated at $70 million by Galaxy Research, nearly twice the initial figure — arrives as a stark inflection point for the self-custody conversation. CZ's public intervention, whatever its motivations, reflects the practical wisdom that security should never be monolithic. Hardware wallets remain a critical tool in the Bitcoin holder's security architecture. But the era of treating any single solution as categorically safe is, or should be, over. Multi-wallet strategies, multisig setups, and rigorous operational security are not paranoia — they are the minimum viable posture in a threat landscape that continues to find new ways to extract eight-figure sums from the unwary.

Written by the editorial team — independent journalism powered by Bitcoin News.