Bitcoin ETF inflows surge after Coldcard hack, but link is unclear: Bloomberg analyst

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- BlackRock's IBIT, Fidelity's FBTC, Bitwise's BITB, ARK 21Shares' ARKB, and Defiance's MSBT recorded inflows every trading day since the Coldcard exploit, totaling roughly $620 million, according to Bloomberg senior ETF analyst Eric Balchunas.
- The Coldcard exploit drained more than $116 million worth of Bitcoin from over 5,200 wallet addresses, per blockchain intelligence firm TRM Labs.
- Balchunas declined to draw a direct causal link, stating on X: "I'm not saying it's connected, we just don't know," while adding that "long-term I can't imagine there aren't some who migrate over."
- Changpeng "CZ" Zhao argued centralized exchanges may now be "statistically safer" than self-custody, citing Willy Woo data showing cumulative Bitcoin losses from self-custody incidents have surpassed those from exchange hacks.
- Boltz, a Bitcoin swap service, suspended its non-custodial bridge on Monday, citing a steady rise in AI-assisted exploits that let attackers identify and exploit vulnerabilities faster than its team could patch them.
- CZ noted that exchange-side hack data is easier to collect because incidents typically make major news, while self-custody losses are often unreported — potentially understating the self-custody risk total.
Why it matters: The $620 million ETF inflow streak landing in the same week as a $116 million self-custody hack gives ETF issuers like BlackRock and Fidelity the clearest data point yet that retail capital will move into regulated wrappers after high-profile wallet failures. CZ's claim that CEXs are now "statistically safer" than self-custody, backed by Willy Woo's loss tally, directly challenges the crypto community's foundational "not your keys, not your coins" doctrine and pressures hardware wallet vendors to defend their security model.




