1
1
Demand for U.S. spot Bitcoin exchange-traded funds (ETFs) has witnessed a significant acceleration over the past week, with a consistent streak of daily inflows occurring concurrently with the Coldcard wallet hack. This timing has fueled speculation among investors and industry observers regarding a potential shift away from self-custody of digital assets towards more regulated investment vehicles.
According to data compiled by Bloomberg senior ETF analyst Eric Balchunas, several prominent spot Bitcoin ETFs, including BlackRock’s iShares Bitcoin Trust (IBIT), Fidelity Wise Origin Bitcoin Fund (FBTC), Bitwise Bitcoin ETF (BITB), and ARK 21Shares Bitcoin ETF (ARKB), along with the Defiance Daily Target 2X Long MSTR ETF (MSBT), have recorded inflows on every trading day since the weekend exploit. These consistent inflows have collectively amounted to approximately $620 million. This cumulative figure aligns with recent reporting by Cointelegraph, which highlighted a three-day inflow streak for Bitcoin ETFs totaling $626 million.
The Coldcard exploit, which occurred recently, resulted in the draining of over $116 million worth of Bitcoin from more than 5,200 wallet addresses. This incident was detailed by blockchain intelligence firm TRM Labs, which provided a comprehensive analysis of the exploit.

While acknowledging the temporal proximity of the ETF inflows and the Coldcard hack, Eric Balchunas stated in a post on X (formerly Twitter) that he could not definitively confirm a direct connection, noting, "I’m not saying it’s connected, we just don’t know." However, he did express a long-term perspective, suggesting, "[Although] long-term I can’t imagine there aren’t some who migrate over." This sentiment hints at a potential, albeit unconfirmed, influence of security concerns on investment decisions.
The Coldcard exploit has effectively reignited a long-standing debate within the cryptocurrency community concerning the risks and benefits associated with self-custody of digital assets. Hardware wallets, once considered the gold standard for secure private key management, have now been brought under scrutiny following this incident. The hack has brought to the forefront the inherent operational risks that can arise even with sophisticated self-custody solutions, such as firmware flaws and software vulnerabilities.
This incident has also intensified discussions surrounding the trade-offs between holding Bitcoin directly and gaining exposure through regulated investment products like spot Bitcoin ETFs. In the case of ETFs, the responsibility for asset custody and security is delegated to institutional custodians, potentially alleviating concerns for investors who are less comfortable managing their own private keys.
Weighing in on this evolving discussion, Binance co-founder Changpeng "CZ" Zhao suggested that storing cryptocurrency on centralized exchanges (CEXs) might now be "statistically safer" than self-custody. CZ cited data compiled by analyst Willy Woo, which indicates that cumulative Bitcoin losses from self-custody incidents have surpassed those attributed to exchange hacks. He further elaborated on the challenges of accurately assessing self-custody risks, stating, "Hack data is easier to collect on the CEX side, usually major news. It is harder on the self-custody side, where hacks, lost coins, etc are often not reported." This perspective highlights a potential data asymmetry that influences perceptions of security.

The ongoing debate unfolds against a backdrop of escalating sophistication in cyberattacks, particularly those augmented by artificial intelligence (AI). This trend was underscored by a recent development on Monday, where the Bitcoin swap service Boltz announced the suspension of its non-custodial bridge. The company cited a consistent increase in AI-assisted exploits, which have enabled attackers to identify and exploit vulnerabilities at a pace that outstrips the ability of their security teams to implement patches. This situation illustrates the evolving threat landscape and the increasing pressure on security protocols across the digital asset ecosystem.
The implications of the Coldcard attack for hardware wallet security have been a subject of intense scrutiny. While the specifics of the exploit are still being investigated, the incident raises broader questions about the resilience of hardware wallets against advanced cyber threats. The cryptocurrency community is actively seeking to understand whether this event signals a fundamental shift in the perceived security of all hardware wallets.
Cointelegraph remains committed to delivering independent and transparent journalism, producing news articles in accordance with its Editorial Policy. The aim is to provide accurate and timely information to readers, who are encouraged to conduct their own independent verification of all reported details.