Bitcoin ETFs Pull in $620M as Coldcard Hack Drains $116M, BTC at $64,433
US spot Bitcoin ETFs booked $620M in inflows after a Coldcard wallet exploit drained $116M, as BTC trades near $64,433.

US spot Bitcoin ETFs have pulled in roughly $620 million in net inflows over the past week, a run that began the same weekend a firmware exploit on Coldcard hardware wallets drained more than $116 million in Bitcoin. Bitcoin itself is trading near $64,433, according to market data cited alongside the reports, as investors debate whether the timing is coincidence or a real shift away from self-custody.
Bloomberg Intelligence senior ETF analyst Eric Balchunas flagged the streak on X, noting that funds including BlackRock’s iShares Bitcoin Trust (IBIT), Fidelity’s Wise Origin Bitcoin Fund (FBTC), Bitwise’s BITB, ARK 21Shares’ ARKB and the Defiance Daily Target 2X Long MSTR ETF (MSBT) have logged inflows every single trading day since the exploit. Some reports put fresh capital across Grayscale and Morgan Stanley-managed products as well, with the combined figure landing at $620–$626 million.
What happened to Coldcard
The exploit targeted Coldcard devices running 2021-era firmware built by Canadian manufacturer CoinKite. A software bug allowed attackers to bypass built-in security checks, and blockchain intelligence firm TRM Labs estimated the resulting losses at more than $116 million spread across over 5,200 wallet addresses. Other estimates put total losses as high as $130 million, or roughly 1,800 BTC.
The breach is notable because it hit hardware wallets — long considered the gold standard for self-custody — rather than an exchange or custodial service. That has reignited a familiar argument in crypto circles: is holding your own keys still safer than trusting a regulated custodian with your Bitcoin?
Balchunas: correlation, not proven causation
Balchunas was careful to separate the two data points. “I’m not saying it’s connected, we just don’t know,” he wrote, adding that “long-term I can’t imagine there aren’t some who migrate over.” In a separate post contrasting Coldcard’s parent company with BlackRock, he wrote: “who are you gonna trust to not screw up the security of your bitcoin (or get it back if some scumbag does mess with it): a 5-man boutique in Canada or this guy and his 25,000-employee, $15T by-the-book empire? TradFi doesn’t seem so lame now after all does it?”
Binance co-founder Changpeng “CZ” Zhao also weighed in, arguing that keeping crypto on centralized exchanges may now be “statistically safer” than self-custody — a notable stance from an industry figure whose exchange itself has weathered its own security controversies over the years.
Why the numbers matter for holders
For everyday Bitcoin holders, the episode is a reminder that self-custody removes counterparty risk but does not remove technical risk: firmware bugs, supply-chain flaws and user error can all be exploited regardless of who controls the keys. The $620 million ETF inflow figure shows that at least some capital is choosing to outsource that operational risk to regulated custodians rather than absorb it directly.
Whether this becomes a lasting trend or simply a short-term reaction to a single high-profile hack remains unproven — as Balchunas himself acknowledged. Traders watching ETF flow data in the coming weeks will get a clearer read on whether the Coldcard exploit has genuinely dented confidence in hardware wallets, or whether inflows normalize once the story fades from headlines.
Read more: Whales Add BTC, ETH, XRP as Prices Sit Near Realized Cost, CryptoQuant Says
Sources
Related articles
Brazil to Freeze Crypto Transfers Above $10,000 for 24 Hours From 2027
Banco Central do Brasil will force VASPs to hold transfers over $10,000 to self-custody wallets or foreign platforms starting Jan. 1, 2027.
BIP-110 Bitcoin Fork Stalls at Block 961,633 as Gap Widens to 88 Blocks
Only 2.53% of hashpower backed the anti-spam fork; it mined just two blocks before stalling while Bitcoin's main chain kept moving.
BTCPay Lightning Nodes Drained, BTC at $64,968; Emergency Patch to v2.4.2
Attackers stole LND ".macaroon" credentials to sweep Lightning channels; BTCPay urges v2.4.2 update as Foundation, Citadel21 confirm losses.