CZ says exchanges are safer than your own wallet
One figure counts dormant coins, the other counts court cases. Let's find out.
Crypto spent the week arguing about two numbers: 1.57 million BTC lost in your own wallet against 1.51 million lost on exchanges. Six percent apart, which read as a tie. It is not a tie. The first number comes from asking which coins went quiet. The second comes from asking which thefts reached a court. Different instruments, different decades, opposite error. And nobody divided either one by how many coins were sitting in each place.
- The claim. Binance's founder said it is statistically safer to keep bitcoin on an exchange than in your own wallet. His evidence is two numbers: 1.57M BTC lost in private wallets against 1.51M lost on exchanges.
- The numbers are not his. Analyst Willy Woo published them from River's 2025 report. The same day, he was arguing the opposite: only your own wallet delivers sovereignty.
- They do not compare. Wallet losses come from an on-chain heuristic that reads an unmoved coin as a lost one. Exchange losses come from a census of hacks and bankruptcies that reached a court. The first can only overstate, the second can only understate, and River says so itself.
- Nobody divided by the stock. Exchanges have held 2.2 to 3.3 million BTC, everyone else holds over 17 million. Per thousand coins held, exchanges lose five to eight times more.
- The argument is about the past. 98% of the wallet losses happened before 2020, and the exchange losses in coin terms before 2013. Neither number describes 2026.
- The live case fits neither. The COLDCARD theft: 1,596 BTC from over 5,200 addresses, above $116M since 30 July. The coins moved, so the heuristic will not see them, and it was not an exchange, so the census will not either.
- The desk view. The question is not "exchange or own wallet", it is which failure you can survive. An exchange removes operational risk and adds counterparty risk; your own wallet does the reverse. An estimate whose error exceeds its margin cannot decide where your coins live.
Who is arguing, and what each side stands to lose
This is not an academic dispute. On one side, the founder of the largest exchange, whose revenue grows with the balances users leave on it. On the other, companies selling devices and multisig, and analysts whose reputations rest on sovereign storage. Both sides are interested parties and both know it.
The trigger was not a statistic. COLDCARD wallets started being drained on 30 July, and for four days CZ posted about how hard it is to hold your own keys. On the fifth post he picked up somebody else's number and drew a line under it.
| When (UTC) | Who | What was said | Views |
|---|---|---|---|
| 30 Jul | — | First COLDCARD draining wave: 1,196 addresses, 1,082.65 BTC in 41 minutes | — |
| 1 Aug 06:55 | @cz_binance | "Even hardware wallets can have bugs. Nothing is 100%" | 1.11M |
| 1 Aug 18:32 | @cz_binance | "I'm a believer in self custody, but it puts the burden on you" | 850K |
| 2 Aug 20:48 | @cz_binance | "Securing the backup seed phrase is hard" | 1.21M |
| 3 Aug 06:16 | @willywoo | "Sobering numbers": 1.57M against 1.51M, sourced to River's 2025 report | 1.13M |
| 4 Aug 06:48 | @cz_binance | Quotes Woo: "It is statistically safer to store coins on exchanges than to self custody." Then four caveats | 798K |
| 4 Aug 07:55 | @willywoo | Answers CZ: "use self custody to unlock the unique protection BTC can give your family" | 22.9K |
| 4 Aug 11:24 | @CoinDesk | "@cz_binance argues it may be 'statistically safer' to store crypto on exchanges" | 114K |
The claim was credited to the wrong person
Willy Woo published the numbers a day earlier, under the words "Sobering numbers". Woo does not own an exchange, he is an on-chain analyst. The same day he wrote that bitcoin is the only mature digital property that is truly sovereign, and that only learning the ropes of self custody can deliver that to you.
So he published a statistic that works against his own position. That is exactly why it deserves a serious look.
CZ quoted the post next morning and attached four qualifications to his own headline. That the data is assumed correct. That hack data is easier to collect on the exchange side because it is usually major news, and harder on the self-custody side where hacks and lost coins often go unreported. That some dead exchanges drag the data down. And that he is not saying one approach is better than the other.
Read whole, CZ is making a narrower claim: self-custody failures are undercounted because nobody files a police report over a lost seed phrase. True. It is also the reason his headline number cannot sit next to the other one, and he is the one who said it. CoinDesk kept the sentence and dropped the caveats.
One instrument counts dormant coins, the other counts court cases
River's Navigating Bitcoin Storage does not hide the method. For self-custody it uses an on-chain heuristic, treating coins that have remained unmoved since a certain date as likely lost. The report's own wording: a conservative estimate of 1.57 million bitcoin permanently lost, with 98% of those losses before 2020. Then the sentence that did not travel with the number: it is impossible to determine how much was lost due to self-custody specifically.
For exchanges it counts events. Large losses that reach lawsuits or bankruptcies are typically documented in the public record. River puts the all-time exchange total above 3 million BTC and warns, in the same register, that it is impossible to determine the full extent of bitcoin lost by exchanges.
The errors on those two estimates do not cancel. They run in opposite directions, and both run in the direction that flatters exchanges. A dormant coin counts as a private loss even if the owner is alive and simply not trading. An exchange that ran fractional and closed quietly counts nowhere.
A 60,000-coin margin between two estimates whose stated error is "impossible to determine" is not a result.
Nobody divided
Set the methods aside and take both numbers at face value. They still do not say what they were used to say. A loss count without a stock is not a rate.
Bitcoin on exchanges peaked above 3.3 million coins in early 2022. It stood near 2.718 million in January 2026 and fell to about 2.21 million by April, as spot ETFs pulled coins into separate custody. Circulating supply is roughly 19.9 million. Whichever exchange-stock figure you pick, everyone else holds between 16.6 and 17.7 million coins.
Losing 1.51 million coins from a pile that never exceeded 3.3 million, and losing 1.57 million from a pile of seventeen million, are different events. They were presented as a tie.
What the calculation is not. It divides fifteen years of cumulative loss by today's stock. Exchange balances were smaller in 2013 and larger in 2022. This is an order-of-magnitude check on a claim that had no denominator at all. We ran it across the whole range so the answer does not depend on which reserve print you prefer: it lands between five and eight either way.
Both figures describe the decade before last
River says 98% of private losses happened before 2020. It also says exchange losses are decelerating, with the bulk of the coin-denominated damage before 2013, which means Mt. Gox.
For anyone taking these numbers as advice, that difference decides everything. In 2013 the main way to lose your own coins was a discarded laptop. In 2026 it is a firmware bug from a respected vendor, found by an attacker before a researcher, worked across thousands of addresses in under an hour. Not the same risk in different clothes.
Satoshi is sitting inside the private figure
There is one cohort inside the 1.57 million large enough to flip the comparison on its own, and nobody in the argument mentioned it.
These are the coins mined in the first year by bitcoin's creator. Researchers identify them by a distinctive fingerprint his miner left in the blocks, and put the total at roughly 1.1 million BTC. Not one of them has ever moved. Under a rule that reads "unmoved since a certain date" as "probably lost", the whole stack qualifies. River publishes no cohort breakdown and does not say whether those coins are excluded.
If they are inside, roughly seventy percent of that figure belongs to someone who lost nothing. He simply stopped moving coins. If they are excluded, the 1.57 million sits on top of his stack and the picture shifts the other way. This is the largest open question in the comparison, and River can close it in one sentence.
What broke this week
Coinkite's COLDCARD, one of the most respected bitcoin-only wallets, generated seeds with broken randomness for five years.
The bug is not in the bitcoin code. In affected builds ngu.random fell through to MicroPython's deterministic Yasmarang generator instead of the STM32 hardware RNG. The fallback derived its state from the microcontroller UID and timer values. An attacker who constrains the UID and the timing window can reproduce candidate streams offline, derive addresses and check them against the public chain. No device access required.
The build dates to March 2021. The advisory covers Mk3 firmware 4.0.1 through 4.1.9 and earlier, and trackers list Mk2 through Mk5 and Q. Draining began on 30 July 2026.
What saved people was entropy the device did not generate: dice rolled by hand, or a strong BIP-39 passphrase acting as a 25th word. Coinkite shipped a patch within about two days. NVK, Coinkite's founder, posted the migration instruction himself and did not soften it: treat this as urgent, move your funds, the threat is still ongoing.
The event breaks the statistic that was used to explain it. Those 1,596 coins moved, and a dormancy heuristic will never file them as lost: stolen and spent look identical on-chain. They were not on an exchange, so the incident census misses them too. The largest private-storage failure of the decade falls through the gap between the two measurements at the exact moment they are being compared.
Wallets have always broken, and always the same way
Jameson Lopp, CTO of Casa, published the list: thirteen products with a failed random number generator. Browser generators, mobile wallets, developer libraries, a vanity-address tool, and now a hardware wallet.
The mechanism repeats. Instead of a system entropy source, something predictable gets used, usually the system clock, and the key space collapses from 2256 to a size that brute-forces in hours.
| Year | Product | What broke | Outcome |
|---|---|---|---|
| 2013 | Android SecureRandom | Flaw in Android's system generator, affecting every wallet on the platform | Emergency key migration at Bitcoin Wallet, Mycelium, BitcoinSpinner |
| 2022 | Profanity | Vanity-address generator with a 32-bit seed | Keys recoverable by brute force; the same class took Wintermute's admin key |
| 2022 | Trust Wallet, extension | Mersenne Twister on a 32-bit seed: about 4 billion possible mnemonics. Addresses created 14–23 November 2022 | Thefts in December 2022 and March 2023, post-mortem April 2023, vendor reimbursed (CVE-2023-31290) |
| 2023 | Libbitcoin Explorer, bx seed | Mersenne Twister seeded with 32 bits of system time | Over 2,600 wallets, about $900K (CVE-2023-39910, "Milk Sad") |
| 2026 | COLDCARD Mk2–Mk5, Q | Fallback to deterministic Yasmarang instead of the STM32 hardware RNG | 1,596 BTC, over 5,200 addresses, above $116M |
In defence of the custodial model CZ pointed at Binance's own wallet: "this exact same bug years ago, a pseudo-random number generator, $12m in losses. They covered every user."
Trust Wallet has had two separate failures over these years, and they should not be confused.
1. THE GENERATOR BUG, CVE-2023-31290
- What broke. The browser extension, versions 0.0.172 to 0.0.182, drew randomness from a 32-bit Mersenne Twister instead of a proper source.
- Who was hit. Wallets created between 14 and 23 November 2022.
- When the thefts happened. December 2022 and March 2023.
- How it ended. The incident write-up came out in April 2023 and affected users were reimbursed in full.
2. THE CHROME WEB STORE COMPROMISE, DECEMBER 2025
- What broke. No generator involved: attackers reached a developer key in the Chrome Web Store and shipped a tampered build that captured seed phrases as users typed them.
- When. The malicious build was distributed 24 to 26 December 2025.
- Scale. Roughly 2,520 wallets, about $7M taken.
- How it ended. Losses were covered from the SAFU fund; CZ puts the payout at $12M, which is the figure he cites in the argument.
What the two have in common works in CZ's favour: a corporate balance sheet stood behind both, and users got their money back. When a custodian's software breaks, a company stands behind it. When yours breaks, you do.
The counter comes from the same thread. Lopp on why nobody found the bug: it was non-obvious, it lived in the build system rather than the main code, most language models miss it because they do not pull in full submodule context, and critical vulnerabilities have gone undetected for a decade in SSL, SSH and Linux. A five-year-old entropy bug in a bitcoin-only device is an argument against trusting any single implementation. It is not an argument for concentrating into the implementations that publish the least about their own internals.
For years there has been a narrative that "bitcoin-only" products are inherently more secure due to a smaller attack surface. I hope it's clear now that you can't judge a product's security posture upon that single point. — @lopp
The two sides
The burden is on you
for the custodian
Devs patching the bug won't fix previously generated wallets. And devs have no way to reach users on air-gapped devices. Your wallet stays open to hackers until you act. I'm a believer in self custody, but it puts the burden on you.
@cz_binanceSecuring the backup seed phrase is hard. Can't have someone else read it. Can't have it destroyed by fire, flood. Can't have a hacker gain access. And most importantly, can't lose it yourself.
@cz_binanceSoftware will always have bugs. What matters is who's behind it. Trust Wallet faced this exact same bug years ago, $12m in losses. They covered every user.
@cz_binanceThe coldcard compromise is being somewhat shrugged off, correctly, since it revealed nothing new. But what it reminded us of is that there is simply no way to secure crypto. If you custody it with Coinbase or another custodian, they're frequently hacked and you get no compensation. Custody it yourself, perfectly, and you may lose it to coldcard-like compromises.
@AriDavidPaulThe burden is the product
for sovereignty
Bitcoin is unique because it's the only mature digital property that's truly sovereign. It has no nationality, it cannot be blocked by a nation state, nor debased, or seized. Only learning the ropes of SELF CUSTODY can deliver this to you.
@willywooSure there is no way to perfectly secure crypto, but there is no way to perfectly secure anything in life. Empirically, hundreds of billions of dollars of crypto has been stored securely for years. Every system has tradeoffs. They are not "equivalent" in tradeoffs, but disparate.
@ErikVoorheesBlaming folks who make a mistake that leads to a security incident doesn't actually help anyone. No one is infallible; the key is to learn from mistakes so that we stop repeating them.
@loppIf you didn't warn against the usage of Coldcard before this exploit (you had 10 years) you don't get to project superiority now. Everyone in the hardware wallet and multisig space knew of Coldcard and did not warn against using it.
@michaelfolksonThe most useful voice of the week belonged to neither camp. Samson Mow, one of the loudest advocates for holding your own keys, spent two days without sleep moving other people's coins and then wrote the sentence an advocate is not supposed to write.
He did not conclude that anyone should surrender to an exchange. His next moves were adding Blockstream Jade to the recommendation list and continuing to push people onto other self-custodied devices. From one vendor's failure he drew vendor diversification.
What the comparison cannot see
Both figures count one kind of failure: coins going missing. The week produced four others, and none of them land in either number.
| Event | Scale | Why it does not land |
|---|---|---|
| COLDCARD RNG, Jul–Aug 2026 | 1,596 BTC, over 5,200 addresses | The coins moved, so dormancy will not flag them. Not an exchange, so the census misses them |
| Boltz halts swaps, 3 August | Lightning went dark in AQUA, Bull Bitcoin, Blockstream Wallet, Arkade | No coin was lost, but nobody could move one |
| Satora pauses operations | Same 24 hours | Same class: availability, not custody |
| Quiet fractional reserve | Unknown by definition | No lawsuit, no bankruptcy, no public record |
| Exchange freezes withdrawals | Routine, never counted | The coins are there and you cannot use them |
If your test of a custody model is "can I move my money when I need to", then a week in which a self-custodied wallet's swap rail went dark is data. Unflattering data. It is also precisely the failure an exchange does not have, because it substitutes a different one, where the exchange decides.
The genuinely new part
One development this week will outlast the custody argument entirely. Coinkite says it ran the vulnerability past frontier models after the fact, Kimi K3, Claude Fable and Codex 5.6, and none of them found it. The company's explanation is that the flaw lived at the boundary between two unrelated firmware submodules rather than in cryptographic code, which is exactly the seam both human and AI-assisted review skip.
The response outran the disclosure. The volunteer Bitcoin Red Team has scanned roughly 150 repositories, privately disclosed more than a dozen vulnerabilities, and burned about $20,000 of AI compute doing it, with OpenSats covering the bill. Lopp put the economics in one line.
To give some perspective of how AI tooling has also accelerated defender capabilities: before this year, $50K–$100K and a month. Now I can do it for $1K in 1 day. — @lopp
It cuts both ways. The same cost collapse that lets volunteers audit 150 repositories in a week gives an attacker the same reconnaissance at the same price. Boltz shut down citing AI-assisted attacks inside the same 72 hours. What changed this cycle is not that holding your own keys got riskier or that exchanges got safer. What changed is that the cost of finding a latent bug fell two orders of magnitude for both sides at once. Neither headline number represents that.
What we can't see
- Whether bitcoin's creator's coins sit inside the 1.57 million. There is no cohort breakdown, and that single fact moves the figure by seventy percent in either direction.
- How much exchange loss never reached the public record. There is no way to size what is missing, so we treat 1.51 million strictly as a floor.
- The current private loss rate. 98% of the estimate predates 2020, and nobody quoting it knows the 2021 to 2026 rate.
- The final COLDCARD total. Waves were running on 5 August. 1,596 BTC is Galaxy Research's count as of 4 August, and other researchers put the eventual figure near $130M.
- How good our denominator is. Dividing fifteen years of cumulative loss by today's stock is crude, which is why the full range is shown.
The uncomfortable half: this desk publishes referral links to exchanges, and every extra coin sitting on a venue is indirectly in our interest. That is the argument we are declining to make.
What would make this wrong
- River publishes a cohort breakdown showing the private estimate excludes the ancient coins and the creator's stack, and that the remaining losses are mostly post-2020. Then it is a live rate rather than a historical artefact, and the era argument here collapses.
- An exchange-reserve series shows the coin-weighted average stock across 2011 to 2026 was materially above 3.3 million. Then the per-thousand gap narrows below 3× and stops being a difference in kind.
- A comparable census of self-custody theft, not dormancy, is published and comes in above the exchange figure on the same basis. Then both sides are finally measured with one instrument.
The TT desk view
The numbers cannot be compared, and a decision still has to be made. Here is ours.
The question is framed wrong. It is not "exchange or own wallet", it is "which failure can you survive". An exchange removes your operational risk and adds counterparty risk. Your own wallet does the reverse: no counterparty, and you alone against the hardware, a firmware bug, a burnt scrap of paper, your own carelessness. That is not a scale from bad to good, it is a choice of how you are willing to lose.
WHAT AN EXCHANGE ADDS
Withdrawals halt. Accounts freeze. The venue collapses. The venue gets hacked.
What we do. The desk left Binance back in 2024, and the 10 October crash confirmed the reasons rather than creating new ones. We wrote up why separately.
Trading now runs on DEX venues: Hyperliquid, Lighter, the VOOI terminal, cross-chain swaps. The list has changed, the principle has not: a venue gets exactly the balance a trade needs.
Storage is Trust Wallet and Ledger. Two vendors rather than one, which is the same conclusion Mow reached: Trust Wallet had its own generator failure in 2022, Ledger had its own recovery-service episode. Diversification here is not about returns, it is about one firmware bug not taking everything. The COLDCARD week did not change that rule, it tested it: among the affected, the seeds generated with dice survived.