Binance founder Changpeng Zhao said crypto users should consider spreading assets across multiple wallets after a reported $70 million exploit involving Coldcard, a reminder that hardware storage is not immune to software flaws.
In comments highlighted by CoinDesk, Zhao said hardware wallets can still have bugs and suggested diversification at the wallet level as a practical risk-management step. The remarks followed the major Coldcard security failure referenced in the report, which has drawn attention to the operational risks that can affect even widely used self-custody tools.
The episode underscores a basic tension in digital-asset storage. Hardware wallets are designed to reduce exposure to online attacks, but they remain dependent on software, device security and user practices. When those systems fail, losses can still be significant. Zhao’s comments did not introduce a new product or policy proposal, but they added a high-profile voice to a familiar industry warning: self-custody lowers certain risks, yet it does not eliminate them.
The reported exploit also arrives at a time when wallet security continues to be a recurring theme across the crypto market. Users often focus on whether to hold assets on exchanges, in hardware wallets or through other forms of custody. Zhao’s point suggests that concentration risk applies not only to counterparties, but also to storage methods themselves. Spreading assets across more than one wallet may reduce the impact of a single failure, though it can also add complexity for users managing recovery phrases, device integrity and transaction workflows.
No further technical details about the Coldcard failure were included in the source metadata, and the exact scope of the incident was not provided beyond the reported $70 million figure. CoinDesk identified the remarks as coming from Zhao in response to the exploit.
For the broader market, the takeaway is less about a single wallet brand than about the fragility of any custody setup. Even hardware products marketed for security can contain vulnerabilities, and high-value users may need to think in terms of layered defenses rather than a single point of protection. Zhao’s comments fit that view, though they should not be read as investment advice or as a complete security blueprint.
Project Visibility on ChainBrief
Sponsored coverage and project placements for Web3 teams.



