The Zhitong Finance App learned that a Bitcoin exchange-traded fund (“Bitcoin ETF”) listed and traded on the US stock market recorded the strongest weekly capital inflow since April. An earlier hacking attack once again triggered the market's focus on risks related to the safe storage of digital assets. By contrast, these ETF products allow investors to gain exposure to cryptocurrency prices such as Bitcoin without personally holding or storing Bitcoin or other cryptocurrency assets. Last week, these Bitcoin ETF products attracted a net inflow of over $850 million, the biggest in four months in one fell swoop.
The surge in Bitcoin ETF capital inflows occurred after a security flaw involving a Coldcard wallet produced and manufactured by Coinkite Inc. in Canada was revealed. The incident caused the instantaneous theft of bitcoins with an estimated value of 130 million US dollars, and prompted some analysts in the cryptocurrency sector to believe that investors may be turning to regulated cryptoasset investment tools provided by Wall Street.
Eric Balchunas, a senior research analyst at Bloomberg Intelligence, said, “Coldcard's hacking may make these spot Bitcoin ETFs in the stock market more attractive to some investors, even those who have held Bitcoin for a long time.”

As shown in the chart above, the US Bitcoin ETF's weekly capital inflow was the highest since April.
Cold wallet “security myth” bust! $130 million in Bitcoin was stolen, and capital is rapidly flocking to the Wall Street ETF escrow system
According to information, cold wallets have long been regarded by cryptocurrency investors as one of the safest ways to store digital assets. These physical devices stay offline and use secret codes that have been specially designed to give their owners the ability to conduct cryptocurrency transactions. A novel design isolated from the internet to make assets held within it less vulnerable to cyber attacks.
The Coinkite incident challenged the perception of the nature of this traditional dogma. There is a major flaw in some versions of Coinkite's firmware, making the information used for security protection in some wallets easier to predict than the originally designed model, allowing attackers to take control of affected wallets and steal bitcoins from them without touching the physical terminal devices surrounding Coldcard.
“We're doing everything we can to help affected customers,” Coinkite said in an emailed statement to the media last Thursday.
This hacking attack is the latest and most severe attack on Bitcoin and other cryptocurrency holders in recent times. Previously, they had seen the price of this cryptocurrency plummet by about 50% from its all-time high in October last year. Since June, Bitcoin's trading price has been trading in a narrow range of $60,000 to $67,000, with relatively moderate price fluctuations.
This also makes the jump in demand for Bitcoin ETFs in the US stock market over the past few days even more noteworthy, because this round of capital inflows has not been accompanied by a sharp rise in Bitcoin prices.
Rajiv Sawhney, head of international portfolio management at Wave Digital Assets, said that this strong demand for Bitcoin ETFs means “cryptocurrencies such as marginal Bitcoin are migrating from self-custody to institutional investment tools, where they are shifting to a locked and configured market supply.”
Switching to ETFs does not eliminate position risk in the broad sense. ETF cryptocurrency custodians are still likely to encounter security breaches, although many large Wall Street investors, including BlackRock, usually have dedicated security teams and take extensive cybersecurity measures to protect clients' assets.
Some investors, smelling the risk of cryptocurrency assets, have also relinquished the autonomous control they had by directly holding Bitcoin. Many investors are already wary of the cryptocurrency industry after years of exchange failures, bankruptcies, and financial fraud.
Balchunas said, “If Wall Street ETF custodians are hacked on a large scale one day, there is no guarantee that investors will never lose money, but such incidents are likely to immediately trigger regulatory scrutiny and law enforcement investigations.” He added that this may give some investors more confidence when leaving Bitcoin prices and pricing exposures to large financial institutions to manage.
Coinkite Firmware Vulnerability Explodes Billion-Dollar Bitcoin Theft, Self-Custody Risks Surfaced
Coinkite is a Canadian Bitcoin security hardware company founded in 2012. Its core position is a “Bitcoin-only” self-hosted infrastructure vendor. Its most famous product is the Coldcard hardware wallet, which focuses on offline storage of private keys, air-gapped (or “physical isolation”) signatures, dual security chips, and verifiable firmware; in addition, it also provides Bitcoin physical security products such as OPENDIME, TAPSIGNER, and SATSCARD.
Coinkite is not an exchange or custodian, but a hardware security company that helps users “own private keys,” so the impact of this accident was particularly severe: the problem was the key generation process for offline cold wallets that the market has long considered the most secure.
The root cause of the incident was not that the Bitcoin protocol was broken, nor did hackers remotely hack Coldcard devices; rather, some Coldcard firmware mistakenly bypassed the real hardware random number generator when generating wallet seeds and fell back to a predictable software pseudo-random number path.
According to Block's technical investigation, this regressive error can be traced back to the firmware change in March 2021: although a certain compilation configuration set the hardware RNG to “off,” the underlying library only checked whether the macro “exists” and did not check whether it was actually enabled. As a result, the randomness required to generate the private key was replaced by speculative states such as the device UID and timer.
For some Mk2/Mk3 versions, the seeds may even be highly deterministic; although Mk4/Q/Mk5 adds security chip entropy, the effective safety space is still compressed. As a result, attackers can enumerate candidate seeds in an offline environment, then use a public address or xpub to verify whether they hit, and once they match, they can rebuild the private key and directly transfer bitcoins — without touching a physical wallet at all.
This accident changed the “self-hosted = definitely safer” narrative. Coinkite has released repair firmware, but the official one clearly states that upgrading the firmware does not fix old seeds that have already been generated using weak random numbers; affected users must create new seeds and migrate assets; at least 50 independent dice entropy inputs or strong BIP-39 passphrase can reduce the risk, but it does not change the fact that the vulnerable seeds themselves already exist.
For the crypto asset market, this incident extended security risks from “will the exchange go out of business” to “whether the hardware wallet code actually generated an unpredictable key”, so it's not surprising that some of the funds were transferred to spot Bitcoin ETFs — that is, the ETF sacrificed self-custody control in exchange for large custodian institutions, compliance audits, insurance, and regulatory accountability mechanisms.