Coldcard Hack Triggers Biggest Sub-1 BTC Move Since FTX

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Coldcard wallets were drained in a suspected hack that CryptoQuant identified as the biggest sub-1 BTC move since the FTX collapse
- Alex Thorn, Galaxy Digital's head of firmwide research, warned on X Sunday that the attack was still ongoing and urged users to move funds from Coldcard-generated addresses if they had not already
- Galaxy Digital's team continued identifying new victim and attacker addresses, with user reports helping researchers and authorities track stolen funds
- Nick Neuman, CEO of Bitcoin security firm Casa, pushed back against claims that "self-custody is over," arguing its distributed nature gave users time to react and estimating roughly 10x more Bitcoin is protected through self-custody than was stolen in the attack
- Eric Balchunas, Bloomberg senior ETF analyst, said Bitcoin ETFs provide a safer, more convenient alternative for many users, pointing to the long operating history of the ETF industry
- Other commentators countered that the incident reflected a failure of one wallet provider rather than a failure of self-custody itself, reigniting a broader debate over Bitcoin custody
Why it matters: The hack is being framed by both sides of the custody debate as vindication: self-custody advocates point to users' ability to move funds as proof of resilience, while ETF advocates led by Bloomberg's Balchunas are using the incident to argue regulated products are safer. With CryptoQuant calling it the largest sub-1 BTC movement since FTX, the episode gives institutional and retail holders fresh ammunition to choose between direct custody and intermediated products.




