Demand for US spot Bitcoin exchange-traded funds (ETFs) picked up over the past week, according to Bloomberg ETF analyst Eric Balchunas, with multiple products posting inflows on every tradin
Demand for US spot Bitcoin exchange-traded funds (ETFs) picked up over the past week, according to Bloomberg ETF analyst Eric Balchunas, with multiple products posting inflows on every trading day since the Coldcard wallet exploit. The timing has sparked fresh discussion about whether some investors are reassessing the risks of self-custody.
Balchunas said that BlackRock’s iShares Bitcoin Trust (IBIT), Fidelity’s Fidelity Wise Origin Bitcoin Fund (FBTC), Bitwise’s Bitcoin ETF (BITB), ARK 21Shares’ Bitcoin ETF (ARKB), and Defiance Daily Target 2X Long MSTR ETF (MSBT) all recorded inflows every day since the weekend breach. The combined total was roughly $620 million, aligning with Cointelegraph’s earlier reporting on an ETF inflow streak.
Key takeaways
- Bloomberg’s Eric Balchunas attributes the latest run of daily inflows (about $620 million) to several major spot Bitcoin ETFs starting after the Coldcard exploit.
- TRM Labs estimates the Coldcard attack drained more than $116 million in Bitcoin from over 5,200 wallet addresses.
- Balchunas cautioned that a direct connection between the hack and ETF buying is unproven, but acknowledged some investors may be shifting toward regulated custody.
- Industry figures including Binance co-founder Changpeng Zhao argued that, based on available data, exchange custody may be “statistically safer” than self-custody—though underreporting remains a concern.
- Broader security debates are intensifying as AI-assisted exploits accelerate the pace at which vulnerabilities are identified and attacked.
Spot Bitcoin ETFs see daily inflow streak after Coldcard exploit
In his update shared on X, Balchunas highlighted a multi-day pattern of inflows across several leading spot Bitcoin ETFs. The list included large, established issuers (including BlackRock and Fidelity) as well as other active fund providers. Per Balchunas, inflows have continued every trading day since the weekend of the Coldcard exploit, with the group’s cumulative figure landing at roughly $620 million.
Cointelegraph previously reported on the continuation of a Bitcoin ETF inflow streak, noting that the latest totals were consistent with that trend. Together, the data suggest that recent capital flows have been persistent rather than limited to a single “reaction” day after the incident.
Still, Balchunas explicitly framed the connection as speculative. “I’m not saying it’s connected, we just don’t know,” he wrote, while adding that over the long term he can’t imagine there aren’t investors who choose to migrate away from self-custody after incidents like this.
Coldcard hack highlights exposure even for hardware wallet users
The renewed self-custody debate traces back to the Coldcard wallet exploit. Cointelegraph reported that the incident involved an attack against the Coldcard ecosystem, draining more than $116 million worth of Bitcoin from over 5,200 wallet addresses, according to blockchain intelligence firm TRM Labs.
For many participants in the market, hardware wallets are viewed as a last line of defense—designed to keep private keys offline and reduce the risk of direct theft through compromised online environments. However, the Coldcard incident underscored that end-to-end security still depends on firmware integrity and operational handling, and that even users of advanced self-custody tools may be vulnerable if software components are compromised.
Self-custody vs regulated custody: CZ’s “statistically safer” argument
The Coldcard hack fed into a longer-running argument about the relative risks of self-custody and centralized exchange (CEX) custody. Binance co-founder Changpeng “CZ” Zhao weighed in, suggesting that storing crypto on centralized exchanges could now be “statistically safer” than self-custody.
Zhao pointed to analysis by Willy Woo, claiming that cumulative Bitcoin losses from self-custody incidents have surpassed losses from exchange hacks. In his X post, Zhao also argued that differences in reporting make direct comparisons difficult: “Hack data is easier to collect on the CEX side, usually major news. It is harder on the self-custody side, where hacks, lost coins, etc are often not reported.”
That framing matters for investors because it shifts the conversation from a purely technical question (“Which custody model is more secure?”) to an evidentiary one (“Which system’s failures are more visible and therefore easier to measure?”). Until self-custody incidents are tracked with the same completeness as major exchange events, any conclusion about relative safety remains inherently asymmetric.
Security pressure is mounting as AI-assisted attacks evolve
Beyond the Coldcard case, the broader cyber threat landscape is intensifying. Cointelegraph earlier reported that on Monday, Bitcoin swap service Boltz suspended its non-custodial bridge after citing a steady rise in AI-assisted exploits. The service said attackers were using artificial intelligence to identify and exploit vulnerabilities faster than its team could patch them.
While that suspension does not confirm a direct link to the Coldcard incident, it reinforces a common theme across current security discussions: defenders face a faster and more adaptive attack cycle. For ordinary users, this can translate into a growing sense that the gap between “known risks” and “unknown vulnerabilities” is narrowing.
For ETF investors, the implication is more indirect but still important. Regulated investment products typically centralize custody with institutional providers and established operational controls, meaning some risks are moved away from individual users and into broader compliance and security frameworks. Whether that results in higher safety in practice is difficult to quantify, but the market’s recent capital flows suggest that at least some investors are paying close attention to custody trade-offs after high-profile self-custody failures.
Going forward, readers should watch whether the daily inflow pattern persists beyond the immediate post-incident window, and whether additional analysis clarifies how (or if) the Coldcard exploit influenced investor behavior. The key open question is whether the ETF buying reflects a short-term narrative shift or a longer-term reallocation toward regulated custody.
This article was originally published as Bitcoin ETF Inflows Rise After Coldcard Hack as Link Remains Unclear, Bloomberg on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.