For years, hardware wallets have been selling a simple proposition – users who control their private keys control their Bitcoin (BTC). The Coldcard exploit has pulled this promise under scrutiny – those keys are only as secure as the process used to generate them.
Share
Subscribe to the AlphaWire Newsletter
Starting July 30, 2026, attackers drained roughly 1,816 BTC, worth about $116 million, from more than 5,200 addresses linked to wallets affected by a Coldcard seed-generation vulnerability, according to TRM Labs, citing Galaxy Research’s running tally.
The theft unfolded across four coordinated waves. TRM described it as the third-largest crypto hack of 2026, pushing total losses from 276 incidents during the year above $1.2 billion.
The vulnerability traces back to Coldcard firmware version 4.0.1, released in March 2021. A configuration error caused some devices to use a weak random number generator to generate security keys instead of the stronger, built-in hardware tool. The bug affected Mk3 firmware from version 4.0.1 onward, according to an advisory issued by Coldcard on July 30, making affected keys vulnerable to brute-force attacks without physical access to the wallet. The problem prevails in certain Mk4, Mk5, and Q models running older firmware.
Bloomberg Intelligence ETF analyst Eric Balchunas suggested on X that the episode “could boost Bitcoin ETFs.”
NEW: Coldcard hack could spur greater migration to ETFs. What used to be seen as a bug by coiners (dorky boomer TradFi) may all the sudden seem like a feature (large, established financial institutions with decades of experience safeguarding client assets) esp vs a Canadian co w/… pic.twitter.com/k3tFLIiy9Z
— Eric Balchunas (@EricBalchunas) August 4, 2026
His comment raises a broader question beyond the Coldcard vulnerability. If self-custody requires users to trust not only themselves but also the hardware, firmware, and entropy-generation process behind their wallets, it might make them doubtful about the process itself. These users may find investing through a spot Bitcoin exchange-traded fund (ETF) a more acceptable trade-off.
The first attack wave began on July 30, 2026, when an attacker began draining Bitcoin from wallets protected by Coldcard hardware devices. Within about 25 minutes, 594 BTC, worth close to $38 million, was swept from around 500 wallets and consolidated into a single address.

Three additional waves followed over the next four days. By Aug. 5, Galaxy Research’s running tally, cited by TRM, had reached about 1,816 BTC across more than 5,200 addresses. These numbers remain preliminary as more victims could emerge with time.
Before this thread continues, we must disclaim that this data is derived solely from analyzing Bitcoin block data and the unspent-output set. We have not utilized compute to test whether the addresses we have identified as possible victims were indeed generated with low entropy.…
— Galaxy Research (@glxyresearch) August 1, 2026
The attack did not require hackers to physically compromise individual Coldcard devices. Instead, attackers could potentially reconstruct vulnerable private keys by brute-forcing seeds created with insufficient randomness.
A configuration error in Coldcard firmware version 4.0.1 caused seed generation to use a weak True Random Number Generator (TRNG) instead of the intended hardware-based entropy source.

Randomness is essential to wallet security, as a recovery seed must be unpredictable enough that an attacker cannot feasibly enumerate possible combinations.
On older affected devices, the vulnerability could reduce effective key strength from 128 bits to as little as 40 bits. This sharply reduced the search space and made brute-force attacks feasible with modern computing resources, without any need for physical access to the hardware wallet.
Updating the firmware does not repair a seed created under vulnerable firmware, as a fragile seed remains frail regardless of the software now running on the device.
For users who generated a Coldcard seed between March 2021 and the recent patch, TRM advised treating that seed as compromised, generating a new seed using updated hardware, and migrating the funds.
The Coldcard exploit drew significant attention due to the rapid pace and large scale at which funds were drained from affected wallets.
As of Aug. 10, most of the stolen funds had not undergone elaborate laundering. The bulk remained concentrated in a small number of addresses controlled by the attackers, with only limited subsequent movement. Exceptions included a 64.9-BTC deposit into Wasabi and a 200-Ether (ETH) deposit into Tornado Cash on Aug. 4.
When it comes to remaining funds, there has been no evidence of layering or mixing. This pattern suggests that the attacker (or attackers) may still be figuring out how to relocate a sum large enough to escape scrutiny.
The reputational impact of the theft on Coldcard could prove substantial. Hardware wallets are expected to reduce dependence on third-party custodians. This incident underscores that the entropy-generation process used for producing private keys for users could be compromised.
Bloomberg Intelligence ETF analyst Eric Balchunas suggested that the Coldcard incident “could boost Bitcoin ETFs.”
Balchunas’ logic is primarily regarding custody of Bitcoin. When investing in Bitcoin, users face a direct trade-off between control and operational risk. Self-custody grants holders direct ownership of their private keys, yet places full responsibility on them for seed generation, secure backups, hardware integrity, and protection against theft or loss. Third-party custody transfers those responsibilities to exchanges, institutional custodians, or ETF structures, though it brings in counterparty and operational risks in their place.
The Coldcard incident adds a further dimension: Even diligent users become exposed if a vulnerability exists in the technology used to generate or safeguard their keys.
Spot Bitcoin ETFs give investors exposure to Bitcoin without the need to generate recovery seeds, store seed phrases, or manage hardware wallets themselves. The onus for securing the underlying assets rests instead with institutional custodians.

This makes the Coldcard episode relevant to the wider discussion around self-custody. An investor might stick to optimal practices while using a hardware wallet and yet face risk if the technology behind it has vulnerabilities.
The incident does not imply that Coldcard users will necessarily sell their Bitcoin and move to ETFs. An affected investor may simply create a new, secure seed, transfer the funds, and continue holding in self-custody. More advanced users can further reduce reliance on any single wallet implementation by opting for multisignature arrangements that use several signing devices with independently generated entropy.
Balchunas’ observation is best understood as a hypothesis about investor preferences. Operational complexities and vulnerabilities of self-custody may lead some investors to favor professionally managed custody solutions.
Even if some Bitcoin holders decide they prefer ETFs, moving from directly owned Bitcoin into an ETF is not necessarily a simple transfer.
A typical retail investor would generally have to sell Bitcoin, move the proceeds through the banking or brokerage system, and then purchase shares of a spot Bitcoin ETF. Depending on the investors’ jurisdiction, selling Bitcoin may also trigger tax consequences.
Moreover, an ETF does not eliminate custody risk; it changes who bears and manages that risk.
Instead of safeguarding private keys themselves, ETF investors depend on the fund’s sponsor, custodian, authorized participants, brokerage infrastructure, and other financial intermediaries.
The underlying Bitcoin held by US spot ETFs is safeguarded by institutional custodians. Concentration among custodians can therefore create another form of operational and counterparty exposure.

Investors consequently exchange some self-custody risks for risks associated with the traditional financial system, including:
The choice is less about eliminating risk than deciding which risks an investor is willing and equipped to manage.
Whether the Coldcard incident actually prompts investors to shift toward Bitcoin ETFs requires evidence beyond the vulnerability itself.
Spot Bitcoin ETF flows are one obvious metric to watch. Sustained inflows following the Coldcard disclosures could be consistent with Balchunas’ argument, although flows alone would not prove causation because ETF demand is influenced by Bitcoin prices, macroeconomic conditions, institutional allocation decisions, and broader market sentiment.

Onchain activity could provide more direct clues. Analysts can track whether Bitcoin leaving potentially vulnerable Coldcard wallets is sent to regulated exchanges and institutional custodians or simply transferred into newly generated self-custody wallets.
The latter would weaken the idea that the exploit is triggering a meaningful shift toward ETFs. It would suggest that affected users remain committed to self-custody but are replacing compromised seeds with secure ones.
Demand for institutional custody services could provide another signal if larger holders decide they no longer want to depend entirely on consumer hardware wallets.
The incident could also raise questions about security standards for hardware wallet manufacturers.
Unlike banks and regulated financial custodians, hardware wallet providers operate across jurisdictions with varying security standards and consumer protections. A vulnerability affecting the generation of private keys is particularly serious because it undermines security at the point where custody begins.
The Coldcard episode could increase calls for stronger independent testing, more rigorous firmware audits, and better verification of entropy-generation systems.
It could also strengthen the case for security designs that do not depend on one device or implementation. TRM specifically pointed to multisignature setups combining independently designed devices and independently generated entropy as a way of reducing reliance on a single point of failure.
Any push toward greater oversight would nevertheless raise a familiar Bitcoin debate: how far regulators can go in protecting consumers without making permissionless self-custody harder.
The Coldcard incident is ultimately about more than one hardware wallet.
Self-custody remains one of Bitcoin’s defining features because it allows users to own and transfer Bitcoin without depending on a bank, exchange, or investment fund. But eliminating a financial intermediary does not eliminate every technological dependency.
Users may control their private keys, but they still need a secure way to generate those keys.
Coldcard demonstrates what can happen when that process fails. A wallet can remain physically secure, while the secret protecting the Bitcoin is vulnerable from the moment it is created.
That gives Balchunas’ argument some weight, but it does not establish that investors will migrate from hardware wallets to ETFs.
The aftermath may instead divide investors into different custody models. Some may prefer regulated ETFs and institutional custody; others may remain committed to self-custody while adopting stronger practices, such as multisignature wallets, independent entropy sources, and greater scrutiny of wallet firmware.
The real test will not simply be whether Bitcoin ETF inflows increase; it will be whether the Coldcard exploit materially changes how Bitcoin holders choose to manage custody risk.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share
