Loading prices…
🩸BEARISH

Coldcard exploit drains $114M in BTC; ETF tailwind eyed

The $114M drained from best-practice self-custody users is the strongest argument yet that holding your own keys still means trusting the silicon.

Coldcard exploit drains $114M in BTC; ETF tailwind eyed
Coldcard exploit drains $114M in BTC; ETF tailwind eyed
Coldcard exploit drains $114M in BTC; ETF tailwind eyed
Coldcard exploit drains $114M in BTC; ETF tailwind eyed

A firmware flaw in the Coldcard hardware wallet has drained at least 1,816 bitcoin, worth roughly $114 million, from more than 5,200 addresses since July 30. Investment bank Cantor and broker FRNT Financial both published client notes Wednesday framing the breach as a tailwind for regulated crypto custody providers and spot bitcoin ETFs. The exploit lets attackers steal BTC from users who had opted for self-custody, underscoring a structural risk: holding private keys still means trusting the hardware and software that generate and manage them.

Why it matters

The breach crystallizes a tradeoff bitcoin holders have lived with since self-custody went mainstream. FRNT wrote that "the reaction within the BTC community to the exploit was one of heartbreak," noting that many affected users had followed long-standing best practices around key management. The firm drew a parallel to the 2023 "Milk Sad" exploit, in which flawed key generation led to roughly $900,000 in theft. Both incidents make the same point from opposite ends of the price chart: the weakest link in a self-custody stack sits between the user and the silicon.

Market impact

Cantor's digital asset specialist Nico Pasquariello said the read-through is "second-order but we would expect that token flows to custodians and exchanges will increase following the hack." The bank named Robinhood (HOOD), Coinbase (COIN), BitGo (BTGO), Bullish (BLSH), eToro (ETOR) and Gemini (GEMI) as potential beneficiaries of customer inflows. FRNT framed spot bitcoin ETFs as the cleaner alternative for investors unwilling to take on operational risk around their own keys. Both firms expect adaptation rather than abandonment: wallet makers will harden their products, and a slice of self-custody users will migrate into regulated wrappers.

Related tokens
$BTC

Frequently asked questions

  1. How much bitcoin was stolen in the Coldcard exploit?

    At least 1,816 BTC, worth roughly $114 million, was drained from more than 5,200 addresses between July 30 and the publication of the analyst notes.

  2. What caused the Coldcard wallet exploit?

    Researchers traced the breach to a flaw in the wallet's firmware that allowed attackers to steal BTC from users running self-custody setups, even those following best practices.

  3. How could the Coldcard hack affect spot bitcoin ETFs?

    FRNT Financial wrote that the breach could push some self-custody users toward spot bitcoin ETFs as a regulated alternative to managing private keys themselves.

  4. Which crypto custody firms could benefit from the exploit?

    Cantor named Robinhood (HOOD), Coinbase (COIN), BitGo (BTGO), Bullish (BLSH), eToro (ETOR) and Gemini (GEMI) as potential beneficiaries of customer inflows after the hack.

  5. How does this compare to the 2023 Milk Sad exploit?

    FRNT drew a direct parallel: both incidents stemmed from flawed key generation or wallet firmware, and FRNT expects adaptation rather than abandonment of self-custody in response.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →