Via ark-invest.com
ARK 21Shares Bitcoin ETF sees $620M inflows after Coldcard hack rattles self-custody community
A firmware flaw in older Coldcard hardware wallets drained millions in Bitcoin, sending investors toward regulated ETF products
When hardware security fails, money moves. That appears to be the lesson from a significant vulnerability disclosed in older Coldcard hardware wallets in late July 2026, which sent a wave of capital flowing into spot Bitcoin ETFs including $IBIT, $FBTC, $BITC, $ARKB, and $MSBT, with combined daily inflows totaling $620 million following the breach.
What actually happened with Coldcard
On July 30, 2026, Coinkite, the Canadian company behind the Coldcard hardware wallet, disclosed a firmware vulnerability affecting older models, including the Mk3 series.
The flaw was not about someone physically stealing a device. It was subtler and, in some ways, scarier. The vulnerability reduced the entropy used during seed phrase generation to approximately 40 bits. In English: the randomness baked into creating a wallet’s master key was dramatically weaker than it should have been, making it mathematically feasible for an attacker to reconstruct private keys from scratch.
Galaxy Research estimated that between 1,367 and 1,816 BTC were drained from over 5,200 wallet addresses in the days following the exploit’s discovery. At prices prevailing around the time of the breach, that translates to roughly $89 million to $116 million in losses.
The thefts moved fast. Most of the damage occurred between late July and early August 2026, with Galaxy Research pinpointing approximately 1,367 BTC drained from 4,585 affected addresses by the time early tallies were published. Coinkite CEO Rodolfo Novak responded publicly on July 31, advising users whose seed phrases were generated on affected devices to transfer their funds immediately.
Newer Coldcard models experienced a lesser degree of exposure. The entropy reduction was partial rather than complete on more recent hardware, which limited but did not eliminate their vulnerability relative to older units.
Bitcoin’s price shrugged. ETF flows did not.
Bitcoin’s price reaction was notably muted. Despite a breach that wiped out tens of millions of dollars for thousands of wallet holders, the broader market registered only a minor dip of approximately 3% before stabilizing close to prior levels.
The more interesting signal came from ETF flows. Spot Bitcoin ETFs recorded a combined $620 million in daily inflows during the period following the Coldcard disclosure, across tickers including the iShares Bitcoin Trust, Fidelity Wise Origin Bitcoin Fund, ARK 21Shares Bitcoin ETF, and others. Individual session inflows within that window ranged from $91.84 million on the lower end to totals in the $170 million to $244 million range on stronger days.
The research notes that reports of a direct correlation between the hack and the $620 million inflows into Bitcoin ETFs remain unratified, though the timing suggests a potential flight to safety among investors aware of the risks posed by hardware vulnerabilities. The $620 million figure spans multiple products, which means this was not a single-fund anomaly driven by one large institutional ticket.
What this means for the self-custody debate
A firmware flaw that compromises entropy generation does not just affect the people who lost funds. It introduces doubt into the broader population of hardware wallet users who have no idea whether their own seed phrase was generated with sufficient randomness.
For investors currently holding Bitcoin in self-custody on older hardware, the immediate practical question is whether their seed phrase was generated on a device or firmware version affected by the reduced entropy flaw.