/*tt-topics-css*/
NOTE — MARKET STRUCTURE ·

CZ says exchanges are safer than your own wallet

One figure counts dormant coins, the other counts court cases. Let's find out.

Crypto spent the week arguing about two numbers: 1.57 million BTC lost in your own wallet against 1.51 million lost on exchanges. Six percent apart, which read as a tie. It is not a tie. The first number comes from asking which coins went quiet. The second comes from asking which thefts reached a court. Different instruments, different decades, opposite error. And nobody divided either one by how many coins were sitting in each place.

WHAT EACH NUMBER ACTUALLY MEASURES1.57M BTCown wallet: coins that went quietceilingdormant ≠ lost1.51M BTCexchanges: thefts in the public recordfloorquiet failures never filedThe gap between them: 60,000 BTC.The error on each is larger than the gap.Source: River, Navigating Bitcoin Storage 2025. Method quoted from the report itself.
Two instruments, one scale. The own-wallet figure is an on-chain heuristic: a coin has not moved, so it is probably lost. That can only overstate. The exchange figure counts losses that produced a lawsuit or a bankruptcy. That can only understate. Source: River, Navigating Bitcoin Storage 2025.
Key takeaways
  • The claim. Binance's founder said it is statistically safer to keep bitcoin on an exchange than in your own wallet. His evidence is two numbers: 1.57M BTC lost in private wallets against 1.51M lost on exchanges.
  • The numbers are not his. Analyst Willy Woo published them from River's 2025 report. The same day, he was arguing the opposite: only your own wallet delivers sovereignty.
  • They do not compare. Wallet losses come from an on-chain heuristic that reads an unmoved coin as a lost one. Exchange losses come from a census of hacks and bankruptcies that reached a court. The first can only overstate, the second can only understate, and River says so itself.
  • Nobody divided by the stock. Exchanges have held 2.2 to 3.3 million BTC, everyone else holds over 17 million. Per thousand coins held, exchanges lose five to eight times more.
  • The argument is about the past. 98% of the wallet losses happened before 2020, and the exchange losses in coin terms before 2013. Neither number describes 2026.
  • The live case fits neither. The COLDCARD theft: 1,596 BTC from over 5,200 addresses, above $116M since 30 July. The coins moved, so the heuristic will not see them, and it was not an exchange, so the census will not either.
  • The desk view. The question is not "exchange or own wallet", it is which failure you can survive. An exchange removes operational risk and adds counterparty risk; your own wallet does the reverse. An estimate whose error exceeds its margin cannot decide where your coins live.

Who is arguing, and what each side stands to lose

This is not an academic dispute. On one side, the founder of the largest exchange, whose revenue grows with the balances users leave on it. On the other, companies selling devices and multisig, and analysts whose reputations rest on sovereign storage. Both sides are interested parties and both know it.

The trigger was not a statistic. COLDCARD wallets started being drained on 30 July, and for four days CZ posted about how hard it is to hold your own keys. On the fifth post he picked up somebody else's number and drew a line under it.

When (UTC)WhoWhat was saidViews
30 JulFirst COLDCARD draining wave: 1,196 addresses, 1,082.65 BTC in 41 minutes
1 Aug 06:55@cz_binance"Even hardware wallets can have bugs. Nothing is 100%"1.11M
1 Aug 18:32@cz_binance"I'm a believer in self custody, but it puts the burden on you"850K
2 Aug 20:48@cz_binance"Securing the backup seed phrase is hard"1.21M
3 Aug 06:16@willywoo"Sobering numbers": 1.57M against 1.51M, sourced to River's 2025 report1.13M
4 Aug 06:48@cz_binanceQuotes Woo: "It is statistically safer to store coins on exchanges than to self custody." Then four caveats798K
4 Aug 07:55@willywooAnswers CZ: "use self custody to unlock the unique protection BTC can give your family"22.9K
4 Aug 11:24@CoinDesk"@cz_binance argues it may be 'statistically safer' to store crypto on exchanges"114K
Four days, one sentence, three owners. Post IDs and metrics read from the X API on 5 August 2026, view counts are X's own. Full quotes appear in the two-sides section below. Source: X API, read 5 August 2026.

The claim was credited to the wrong person

Willy Woo published the numbers a day earlier, under the words "Sobering numbers". Woo does not own an exchange, he is an on-chain analyst. The same day he wrote that bitcoin is the only mature digital property that is truly sovereign, and that only learning the ropes of self custody can deliver that to you.

So he published a statistic that works against his own position. That is exactly why it deserves a serious look.

CZ quoted the post next morning and attached four qualifications to his own headline. That the data is assumed correct. That hack data is easier to collect on the exchange side because it is usually major news, and harder on the self-custody side where hacks and lost coins often go unreported. That some dead exchanges drag the data down. And that he is not saying one approach is better than the other.

Read whole, CZ is making a narrower claim: self-custody failures are undercounted because nobody files a police report over a lost seed phrase. True. It is also the reason his headline number cannot sit next to the other one, and he is the one who said it. CoinDesk kept the sentence and dropped the caveats.

One instrument counts dormant coins, the other counts court cases

River's Navigating Bitcoin Storage does not hide the method. For self-custody it uses an on-chain heuristic, treating coins that have remained unmoved since a certain date as likely lost. The report's own wording: a conservative estimate of 1.57 million bitcoin permanently lost, with 98% of those losses before 2020. Then the sentence that did not travel with the number: it is impossible to determine how much was lost due to self-custody specifically.

For exchanges it counts events. Large losses that reach lawsuits or bankruptcies are typically documented in the public record. River puts the all-time exchange total above 3 million BTC and warns, in the same register, that it is impossible to determine the full extent of bitcoin lost by exchanges.

The errors on those two estimates do not cancel. They run in opposite directions, and both run in the direction that flatters exchanges. A dormant coin counts as a private loss even if the owner is alive and simply not trading. An exchange that ran fractional and closed quietly counts nowhere.

A 60,000-coin margin between two estimates whose stated error is "impossible to determine" is not a result.

Nobody divided

Set the methods aside and take both numbers at face value. They still do not say what they were used to say. A loss count without a stock is not a rate.

Bitcoin on exchanges peaked above 3.3 million coins in early 2022. It stood near 2.718 million in January 2026 and fell to about 2.21 million by April, as spot ETFs pulled coins into separate custody. Circulating supply is roughly 19.9 million. Whichever exchange-stock figure you pick, everyone else holds between 16.6 and 17.7 million coins.

COINS LOST PER 1,000 HELD0200400600800458 … 683 across the stock rangeexchangesstock ~2.7M559own walletsstock ~17.2M91Exchanges lose 6.1× more per thousand coins held.Cumulative losses against today's stock. An order-of-magnitude check, not a hazard rate.
Same absolute loss, one-seventh the base. 1.51M BTC against an exchange stock of about 2.7M is 559 coins lost per 1,000 held. 1.57M against 17.2M held elsewhere is 91. The 2022 peak stock gives 458, April 2026's 2.21M gives 683. Source: River 2025 for losses, published exchange-reserve series for the stock. The division is ours.

Losing 1.51 million coins from a pile that never exceeded 3.3 million, and losing 1.57 million from a pile of seventeen million, are different events. They were presented as a tie.

What the calculation is not. It divides fifteen years of cumulative loss by today's stock. Exchange balances were smaller in 2013 and larger in 2022. This is an order-of-magnitude check on a claim that had no denominator at all. We ran it across the whole range so the answer does not depend on which reserve print you prefer: it lands between five and eight either way.

Both figures describe the decade before last

River says 98% of private losses happened before 2020. It also says exchange losses are decelerating, with the bulk of the coin-denominated damage before 2013, which means Mt. Gox.

WHEN THE LOSSES HAPPENED2011201420202026own wallets: 98% of the 1.57M sits left of 2020exchanges: coin-denominated bulk before 2013COLDCARD, 20261,596 BTC, in neither figureSource: River 2025 for both distributions. Coinkite advisory and incident trackers for the 2026 event.
Both estimates describe a closed era. Private losses are dominated by the years when a hard drive full of bitcoin was worth less than the drive. Exchange losses are dominated by one bankruptcy. The live incident sits outside both windows. Source: River 2025, Coinkite advisory.

For anyone taking these numbers as advice, that difference decides everything. In 2013 the main way to lose your own coins was a discarded laptop. In 2026 it is a firmware bug from a respected vendor, found by an attacker before a researcher, worked across thousands of addresses in under an hour. Not the same risk in different clothes.

Satoshi is sitting inside the private figure

There is one cohort inside the 1.57 million large enough to flip the comparison on its own, and nobody in the argument mentioned it.

These are the coins mined in the first year by bitcoin's creator. Researchers identify them by a distinctive fingerprint his miner left in the blocks, and put the total at roughly 1.1 million BTC. Not one of them has ever moved. Under a rule that reads "unmoved since a certain date" as "probably lost", the whole stack qualifies. River publishes no cohort breakdown and does not say whether those coins are excluded.

If they are inside, roughly seventy percent of that figure belongs to someone who lost nothing. He simply stopped moving coins. If they are excluded, the 1.57 million sits on top of his stack and the picture shifts the other way. This is the largest open question in the comparison, and River can close it in one sentence.

What broke this week

Coinkite's COLDCARD, one of the most respected bitcoin-only wallets, generated seeds with broken randomness for five years.

The bug is not in the bitcoin code. In affected builds ngu.random fell through to MicroPython's deterministic Yasmarang generator instead of the STM32 hardware RNG. The fallback derived its state from the microcontroller UID and timer values. An attacker who constrains the UID and the timing window can reproduce candidate streams offline, derive addresses and check them against the public chain. No device access required.

The build dates to March 2021. The advisory covers Mk3 firmware 4.0.1 through 4.1.9 and earlier, and trackers list Mk2 through Mk5 and Q. Draining began on 30 July 2026.

COLDCARD DRAINING, FROM 30 JULY 20261,082.65BTC in the first 41 minutes1,196 addresses, about $70.2M1,596BTC as of 4 Augustover 5,200 addresses, above $116MFirmware shipped March 2021, exploited July 2026.Five years and four months between the bug and the theft.Sources: Coinkite advisory, Galaxy Research, Forbes, TechCrunch, 30 Jul – 4 Aug 2026.
The live datapoint. 1,596 BTC from over 5,200 addresses on Galaxy Research's count as of 4 August, of which 1,082.65 came from 1,196 addresses inside a single 41-minute window on 30 July. Researchers expect the eventual total near $130M. Waves were still running on 5 August, and roughly 90% of the stolen coins still sit at the attacker's addresses. Source: Coinkite advisory, Galaxy Research, TechCrunch, CBC.

What saved people was entropy the device did not generate: dice rolled by hand, or a strong BIP-39 passphrase acting as a 25th word. Coinkite shipped a patch within about two days. NVK, Coinkite's founder, posted the migration instruction himself and did not soften it: treat this as urgent, move your funds, the threat is still ongoing.

The event breaks the statistic that was used to explain it. Those 1,596 coins moved, and a dormancy heuristic will never file them as lost: stolen and spent look identical on-chain. They were not on an exchange, so the incident census misses them too. The largest private-storage failure of the decade falls through the gap between the two measurements at the exact moment they are being compared.

Wallets have always broken, and always the same way

Jameson Lopp, CTO of Casa, published the list: thirteen products with a failed random number generator. Browser generators, mobile wallets, developer libraries, a vanity-address tool, and now a hardware wallet.

The mechanism repeats. Instead of a system entropy source, something predictable gets used, usually the system clock, and the key space collapses from 2256 to a size that brute-forces in hours.

YearProductWhat brokeOutcome
2013Android SecureRandomFlaw in Android's system generator, affecting every wallet on the platformEmergency key migration at Bitcoin Wallet, Mycelium, BitcoinSpinner
2022ProfanityVanity-address generator with a 32-bit seedKeys recoverable by brute force; the same class took Wintermute's admin key
2022Trust Wallet, extensionMersenne Twister on a 32-bit seed: about 4 billion possible mnemonics. Addresses created 14–23 November 2022Thefts in December 2022 and March 2023, post-mortem April 2023, vendor reimbursed (CVE-2023-31290)
2023Libbitcoin Explorer, bx seedMersenne Twister seeded with 32 bits of system timeOver 2,600 wallets, about $900K (CVE-2023-39910, "Milk Sad")
2026COLDCARD Mk2–Mk5, QFallback to deterministic Yasmarang instead of the STM32 hardware RNG1,596 BTC, over 5,200 addresses, above $116M
The same bug, thirteen times in twelve years. Five documented cases from Lopp's list with confirmed detail. The full list of thirteen products is in his post of 2 August 2026. The Trust Wallet for iOS row was pulled: the product is on the list, but the desk could not tie a date or an amount to a source. Source: CVE-2023-31290, CVE-2023-39910, milksad.info, Coinkite advisory.

In defence of the custodial model CZ pointed at Binance's own wallet: "this exact same bug years ago, a pseudo-random number generator, $12m in losses. They covered every user."

Trust Wallet has had two separate failures over these years, and they should not be confused.

1. THE GENERATOR BUG, CVE-2023-31290

  • What broke. The browser extension, versions 0.0.172 to 0.0.182, drew randomness from a 32-bit Mersenne Twister instead of a proper source.
  • Who was hit. Wallets created between 14 and 23 November 2022.
  • When the thefts happened. December 2022 and March 2023.
  • How it ended. The incident write-up came out in April 2023 and affected users were reimbursed in full.

2. THE CHROME WEB STORE COMPROMISE, DECEMBER 2025

  • What broke. No generator involved: attackers reached a developer key in the Chrome Web Store and shipped a tampered build that captured seed phrases as users typed them.
  • When. The malicious build was distributed 24 to 26 December 2025.
  • Scale. Roughly 2,520 wallets, about $7M taken.
  • How it ended. Losses were covered from the SAFU fund; CZ puts the payout at $12M, which is the figure he cites in the argument.

What the two have in common works in CZ's favour: a corporate balance sheet stood behind both, and users got their money back. When a custodian's software breaks, a company stands behind it. When yours breaks, you do.

The counter comes from the same thread. Lopp on why nobody found the bug: it was non-obvious, it lived in the build system rather than the main code, most language models miss it because they do not pull in full submodule context, and critical vulnerabilities have gone undetected for a decade in SSL, SSH and Linux. A five-year-old entropy bug in a bitcoin-only device is an argument against trusting any single implementation. It is not an argument for concentrating into the implementations that publish the least about their own internals.

For years there has been a narrative that "bitcoin-only" products are inherently more secure due to a smaller attack surface. I hope it's clear now that you can't judge a product's security posture upon that single point. — @lopp

The two sides

The burden is on you

for the custodian

Devs patching the bug won't fix previously generated wallets. And devs have no way to reach users on air-gapped devices. Your wallet stays open to hackers until you act. I'm a believer in self custody, but it puts the burden on you.

@cz_binance

Securing the backup seed phrase is hard. Can't have someone else read it. Can't have it destroyed by fire, flood. Can't have a hacker gain access. And most importantly, can't lose it yourself.

@cz_binance

Software will always have bugs. What matters is who's behind it. Trust Wallet faced this exact same bug years ago, $12m in losses. They covered every user.

@cz_binance

The coldcard compromise is being somewhat shrugged off, correctly, since it revealed nothing new. But what it reminded us of is that there is simply no way to secure crypto. If you custody it with Coinbase or another custodian, they're frequently hacked and you get no compensation. Custody it yourself, perfectly, and you may lose it to coldcard-like compromises.

@AriDavidPaul

The burden is the product

for sovereignty

Bitcoin is unique because it's the only mature digital property that's truly sovereign. It has no nationality, it cannot be blocked by a nation state, nor debased, or seized. Only learning the ropes of SELF CUSTODY can deliver this to you.

@willywoo

Sure there is no way to perfectly secure crypto, but there is no way to perfectly secure anything in life. Empirically, hundreds of billions of dollars of crypto has been stored securely for years. Every system has tradeoffs. They are not "equivalent" in tradeoffs, but disparate.

@ErikVoorhees

Blaming folks who make a mistake that leads to a security incident doesn't actually help anyone. No one is infallible; the key is to learn from mistakes so that we stop repeating them.

@lopp

If you didn't warn against the usage of Coldcard before this exploit (you had 10 years) you don't get to project superiority now. Everyone in the hardware wallet and multisig space knew of Coldcard and did not warn against using it.

@michaelfolkson

The most useful voice of the week belonged to neither camp. Samson Mow, one of the loudest advocates for holding your own keys, spent two days without sleep moving other people's coins and then wrote the sentence an advocate is not supposed to write.

He did not conclude that anyone should surrender to an exchange. His next moves were adding Blockstream Jade to the recommendation list and continuing to push people onto other self-custodied devices. From one vendor's failure he drew vendor diversification.

What the comparison cannot see

Both figures count one kind of failure: coins going missing. The week produced four others, and none of them land in either number.

EventScaleWhy it does not land
COLDCARD RNG, Jul–Aug 20261,596 BTC, over 5,200 addressesThe coins moved, so dormancy will not flag them. Not an exchange, so the census misses them
Boltz halts swaps, 3 AugustLightning went dark in AQUA, Bull Bitcoin, Blockstream Wallet, ArkadeNo coin was lost, but nobody could move one
Satora pauses operationsSame 24 hoursSame class: availability, not custody
Quiet fractional reserveUnknown by definitionNo lawsuit, no bankruptcy, no public record
Exchange freezes withdrawalsRoutine, never countedThe coins are there and you cannot use them
Five failures, zero rows in the statistic. Compiled by the desk from the definitions River publishes for each estimate, and from events between 30 July and 5 August 2026. Source: River 2025, statements from Boltz, AQUA and Satora.

If your test of a custody model is "can I move my money when I need to", then a week in which a self-custodied wallet's swap rail went dark is data. Unflattering data. It is also precisely the failure an exchange does not have, because it substitutes a different one, where the exchange decides.

The genuinely new part

One development this week will outlast the custody argument entirely. Coinkite says it ran the vulnerability past frontier models after the fact, Kimi K3, Claude Fable and Codex 5.6, and none of them found it. The company's explanation is that the flaw lived at the boundary between two unrelated firmware submodules rather than in cryptographic code, which is exactly the seam both human and AI-assisted review skip.

The response outran the disclosure. The volunteer Bitcoin Red Team has scanned roughly 150 repositories, privately disclosed more than a dozen vulnerabilities, and burned about $20,000 of AI compute doing it, with OpenSats covering the bill. Lopp put the economics in one line.

To give some perspective of how AI tooling has also accelerated defender capabilities: before this year, $50K–$100K and a month. Now I can do it for $1K in 1 day. — @lopp

It cuts both ways. The same cost collapse that lets volunteers audit 150 repositories in a week gives an attacker the same reconnaissance at the same price. Boltz shut down citing AI-assisted attacks inside the same 72 hours. What changed this cycle is not that holding your own keys got riskier or that exchanges got safer. What changed is that the cost of finding a latent bug fell two orders of magnitude for both sides at once. Neither headline number represents that.

What we can't see

The uncomfortable half: this desk publishes referral links to exchanges, and every extra coin sitting on a venue is indirectly in our interest. That is the argument we are declining to make.

What would make this wrong

The TT desk view

The numbers cannot be compared, and a decision still has to be made. Here is ours.

The question is framed wrong. It is not "exchange or own wallet", it is "which failure can you survive". An exchange removes your operational risk and adds counterparty risk. Your own wallet does the reverse: no counterparty, and you alone against the hardware, a firmware bug, a burnt scrap of paper, your own carelessness. That is not a scale from bad to good, it is a choice of how you are willing to lose.

WHAT AN EXCHANGE ADDS

Withdrawals halt. Accounts freeze. The venue collapses. The venue gets hacked.

What we do. The desk left Binance back in 2024, and the 10 October crash confirmed the reasons rather than creating new ones. We wrote up why separately.

Trading now runs on DEX venues: Hyperliquid, Lighter, the VOOI terminal, cross-chain swaps. The list has changed, the principle has not: a venue gets exactly the balance a trade needs.

Storage is Trust Wallet and Ledger. Two vendors rather than one, which is the same conclusion Mow reached: Trust Wallet had its own generator failure in 2022, Ledger had its own recovery-service episode. Diversification here is not about returns, it is about one firmware bug not taking everything. The COLDCARD week did not change that rule, it tested it: among the affected, the seeds generated with dice survived.

home status x.com/toptraders0x toptraders0x.t.me terms privacy risk compliance marketing © 2026 Top Traders. All rights reserved. v2.0.130-alpha