VERSE PRESS

Crypto News, Global First.

Bitcoin and Ether ETFs Pull in $1.1 Billion in Best Week Since April as Coldcard Hack Reshapes Custody Debate

US-listed crypto ETFs recorded their strongest weekly inflows in four months this week, in a week that also saw a hardware wallet exploit drain roughly $116 million in Bitcoin from more than 5,200 addresses and raise urgent questions about the safety of self-custody. The exploit struck Coldcard, widely regarded as one of the most security-conscious self-custody devices on the market, making the breach symbolically significant well beyond its financial toll. Whether the two events are connected remains unconfirmed.

|

Combined inflows into spot Bitcoin and Ether exchange-traded funds reached $1.1 billion for the week ending August 8, 2026, according to data from The Block. The figure is the highest since April and arrives after July tracked as the weakest monthly inflow period on record for the products. Bloomberg Senior ETF Analyst Eric Balchunas noted the timing but stopped short of drawing a firm conclusion. "I'm not saying it's connected, we just don't know," he said.

Balchunas also flagged an unusual pattern: trading volumes remained low throughout the inflow surge, which is atypical for large institutional buy-ins and suggests capital was moving into ETF structures without broader market participation.

The five spot Bitcoin ETFs that logged inflows on every trading day following the disclosure of the Coldcard firmware vulnerability on July 30 were BlackRock's IBIT, Fidelity's FBTC, Bitwise's BITB, ARK 21Shares' ARKB, and Defiance's MSBT. Combined post-exploit Bitcoin ETF inflows across that period reached approximately $620 million. BlackRock's IBIT contributed $170.35 million of that total on a single day, August 5, the largest single-fund daily figure of the stretch.

Changpeng Zhao, co-founder of Binance, added a prominent voice to the custody debate, suggesting on social media that centralized exchange custody may now be "statistically safer" than self-custody in light of the exploit.


What Happened to Coldcard

Coldcard is widely regarded as one of the most security-conscious devices in the self-custody ecosystem, the product of choice for technically sophisticated users who had selected it precisely to avoid the kind of risk that this exploit exposed. The breach is significant not just for its scale but for what it reveals about the limits of any single layer of security.

The exploit traces back to a build configuration error in Coldcard firmware version 4.0.1, released in March 2021 by Canadian manufacturer Coinkite. The flaw caused affected devices to use a weak software random number generator during wallet seed creation instead of the hardware entropy source the device was designed to use. In practical terms, cryptographic randomness collapsed from the intended 128 bits to as little as 40 bits on Mk3 units and around 72 bits on Mk4 and Mk5 devices. At those reduced entropy levels, an attacker can reconstruct private keys through brute-force computation without ever physically handling the device.

Coinkite CEO NVK (Rodolfo Novak) issued a direct warning before the firmware fix was deployed: "If you generated a seed using a Coldcard wallet, move your funds now." The advisory covers three device lines: Mk2/Mk3 firmware versions 4.0.1 through 4.1.9; Mk4/Mk5 standard firmware versions below 5.6.0 and Edge firmware versions below 6.6.0X; and the Coldcard Q model, which requires standard firmware 1.5.0Q or Edge firmware 6.6.0QX or later.

Firmware updates alone do not fix already-generated seeds. Users must generate entirely new seeds on patched hardware and move all funds to new addresses.

Attackers moved across four waves between July 30 and August 4, draining approximately 1,816 BTC across more than 5,200 wallets. TRM Labs, which tracked on-chain activity after disclosure, identified laundering through Wasabi Coinjoin (a privacy-mixing protocol, accounting for 64.9 BTC) and Tornado Cash (a smart-contract mixing service, accounting for 200 ETH). The exploit ranks as the third-largest crypto hack of 2026, pushing the year's total losses past $1.2 billion across 276 incidents.

Bitcoin commentator Guy Swann called it "the worst hit in bitcoin history to the most knowledgeable and 'properly secured' bitcoiners." Lorenzo Valente of ARK Invest framed the structural problem plainly: "Consumers have traded counterparty risk for software risk, hardware risk, supply-chain risk."


Outside the US: What This Means for South Asia and Africa

For the roughly 119 million crypto holders in India (the world's top-ranked country for grassroots adoption for the third consecutive year) and Pakistan (ranked eighth globally), the ETF inflow story has limited direct relevance. US-listed spot ETFs are not accessible to most retail investors in either country without foreign brokerage accounts. The more pressing issue is the hardware wallet angle.

Coldcard devices are used primarily by a technically sophisticated segment of South Asian Bitcoin holders, concentrated in developer communities in India's major cities and Pakistan's urban centres. India's 30% capital gains tax on crypto profits and 1% tax deducted at source on every transaction have pushed many serious holders toward long-term cold storage, making hardware wallet security guidance operationally significant.

Across Africa, stablecoin usage for remittances and payments dominates, a pattern reflected in 180% year-on-year stablecoin growth across Sub-Saharan Africa recorded in the 2026 Global Digital Asset Adoption Index. Hardware wallet penetration is lower than in Western markets. Still, the custody debate carries structural weight. Nigeria, ranked second globally for crypto adoption, is building out an institutional framework under the Investment and Securities Act 2025. In South Africa, draft Capital Flow Management Regulations released in 2026 already restrict inbound transfers from non-custodial wallets, with a consultation period closing September 30. That regulatory direction signals increasing official pressure on self-custody arrangements.

Ethiopia, Kenya, and Ghana have each entered the global top 20 for crypto adoption, reflecting the rapid mainstreaming of digital assets across the continent. Ghana is particularly relevant to the ETF dimension of this week's story: its VASP Bill is actively exploring structured investment products analogous to exchange-traded funds, making the inflow data directly pertinent to policymakers and financial regulators there.


What Comes Next

Cory Klippsten, CEO of Swan Bitcoin, argued the hack is more likely to push users toward stronger setups than to drive them away from self-custody altogether, pointing to multi-signature and multi-party computation (MPC) arrangements as the emerging baseline. Casa CEO Nick Neuman was more blunt: "You just can't ask people to roll dice to be secure with your self custody."

A forward-looking concern raised by multiple security analysts is the role of AI-accelerated computation in shrinking the exploitation window. Entropy weaknesses that previously required weeks of brute-force work can now be targeted within hours, compressing the time between vulnerability disclosure and active theft and raising the urgency of any future firmware advisories.

Whether the ETF inflow surge continues will partly depend on whether this week's capital movement reflects a durable shift in custody preference or simply a short-term reaction to a single incident. What is clear is that the Coldcard exploit has handed a concrete data point to every party in a debate that has been actively contested for years and is now reignited with fresh consequence.