Bitcoin ETF Inflows Accelerate Following Coldcard Hack, Renewing Self-Custody Debate
Key Takeaways
- •Major U.S. spot Bitcoin ETFs recorded approximately $620 million in cumulative inflows in the week following the Coldcard wallet hack.
- •The Coldcard exploit resulted in the theft of more than $116 million in Bitcoin from over 5,200 wallet addresses.
- •The hack has renewed industry debate over the safety of self-custody compared to using centralized exchanges and institutional ETFs.
- •Binance co-founder Changpeng Zhao argued that centralized exchanges may now be statistically safer than self-custody based on cumulative loss data.
- •Bitcoin swap service Boltz temporarily suspended its non-custodial bridge due to an increase in sophisticated AI-assisted cyberattacks.

Demand for U.S. spot Bitcoin exchange-traded funds (ETFs) has accelerated over the past week, with a series of daily inflows coinciding with the Coldcard wallet hack — timing that has fueled speculation about whether some investors are reconsidering self-custody.
Bloomberg senior ETF analyst Eric Balchunas reported that BlackRock's iShares Bitcoin Trust (IBIT), Fidelity Wise Origin Bitcoin Fund (FBTC), Bitwise Bitcoin ETF (BITB), ARK 21Shares Bitcoin ETF (ARKB), and Defiance Daily Target 2X Long MSTR ETF (MSBT) have all recorded inflows every trading day since the weekend exploit, totaling approximately $620 million. The cumulative figure aligns with Cointelegraph's recent reporting on the ETF inflow streak. Since their January 2024 approval by the SEC, spot Bitcoin ETFs have absorbed tens of billions in assets, offering investors exposure to Bitcoin without the burden of managing private keys — a proposition that becomes more attractive each time a self-custody failure surfaces.
According to blockchain intelligence firm TRM Labs, the Coldcard exploit drained more than $116 million worth of Bitcoin from over 5,200 wallet addresses.
"I'm not saying it's connected, we just don't know," Balchunas said in a post on X. "[Although] long-term I can't imagine there aren't some who migrate over." (Source: Eric Balchunas)
Related: Bitcoin Red Team reports 5K findings in sweeping security audit
Coldcard Exploit Renews Debate Over Self-Custody Risks
The Coldcard hack has renewed concerns that even hardware wallet users can be exposed to firmware flaws and software vulnerabilities, underscoring the operational risks inherent in self-custody. Coldcard, produced by Canada-based Coinkite, has been widely regarded as one of the more security-focused hardware wallets on the market, making the breach particularly notable within the self-custody community.
The incident also reignited debate over the trade-offs between holding Bitcoin directly and gaining exposure through regulated investment products such as spot Bitcoin ETFs, where asset custody and security are managed by institutional providers like Coinbase Custody and Fidelity Digital Asset Services. That trade-off cuts to the core of Bitcoin's founding ethos — the promise of trustless, self-sovereign money — and raises the question of whether practical security concerns may push a growing share of holders toward the very financial intermediaries the technology was designed to bypass.
Binance co-founder Changpeng "CZ" Zhao weighed in on the discussion, arguing that storing crypto on centralized exchanges may now be "statistically safer" than self-custody. He cited data from analyst Willy Woo indicating that cumulative Bitcoin losses from self-custody incidents have surpassed those from exchange hacks. (Source: Changpeng Zhao)
"Hack data is easier to collect on the CEX side, usually major news. It is harder on the self-custody side, where hacks, lost coins, etc are often not reported," CZ said.
The debate unfolds as AI-assisted cyberattacks grow increasingly sophisticated. On Monday, Bitcoin swap service Boltz suspended its non-custodial bridge, citing a steady rise in AI-assisted exploits that enabled attackers to identify and exploit vulnerabilities faster than the team could patch them.
Magazine: Do the Coldcard attacks mean all hardware wallets are now insecure?