Loading article…
Bitcoin hack loses $130 million (≈2,000 BTC) after Coldcard flaw, driving $626 million ETF inflows and reigniting custody debates.
The Bitcoin network lost roughly $130 million—about 2,000 BTC from more than 5,200 addresses—after a Coldcard firmware bug that generated weak seed phrases was exposed, prompting a scramble for safer custody solutions and a surge of $626 million into U.S. spot Bitcoin ETFs [1].
| At a glance | |
|---|---|
| Hack loss | $130 million (≈2,000 BTC) |
| ETF inflow | $626 million in days after hack |
| Faulty firmware | Coldcard versions 4.0.1‑4.1.9 (Mar 2021‑July 2025) |
| Catalyst | Disclosure of seed‑generation flaw |
The flaw originated in Coldcard firmware released in March 2021, which bypassed the device’s hardware random‑number generator and fell back to a deterministic MicroPython routine. This reduced seed entropy to a searchable set, allowing attackers to reconstruct private keys years after the wallets were created [2]. Coinkite estimates the exploit drained about $130 million from over 5,200 addresses, a loss comparable to roughly 2,000 BTC [1]. The compromised seeds affect both Mk2 and Mk3 devices, while later models retain only about 72 bits of entropy—still well below the 128‑bit design target [2].
In the days following the hack, U.S. spot Bitcoin ETFs attracted $626 million of new capital, a flow that analysts say could accelerate migration from self‑custody to institutional products [1]. The incident has revived the long‑standing “who should hold the keys?” argument. Onramp co‑founder Michael Tanguma warned that relying solely on a single custodian or an ETF creates a new single point of failure, especially given Coinbase’s $77 billion custody footprint [1]. By contrast, self‑custody advocates such as Casa co‑founder Jameson Lopp and Bitcoin Core veteran Peter Todd argue that decentralized storage has a superior track record, noting that even custodians depend on random‑number generators that can be compromised [1].
Onramp proposes a multisig vault that distributes signing authority across three regulated entities—BitGo, Coincover, and Tetra Trust—plus the platform itself. The design eliminates seed phrases, requiring video verification and liveness checks for withdrawals, and is backed by a $100 million Lloyd’s insurance facility arranged in 2025 [1]. While the model aims to avoid a single point of failure, critics point out that it reintroduces a permissioned layer that the original Bitcoin ethos sought to bypass [1].
The $130 million hack underscores that hardware‑wallet flaws can undermine the “not your keys, not your coins” mantra, forcing the ecosystem to reconsider whether self‑custody, multi‑institution vaults, or regulated ETFs best protect Bitcoin holdings. The next weeks will reveal whether institutional products gain lasting traction or if the community doubles down on decentralized safeguards.
Coverage is mostly measured — 282 of 300 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 12, 2026 · How we report
Both assets are viewed as having a supply that cannot be increased at the discretion of a government, as Bitcoin's monetary rules were set at its launch.
While the base Bitcoin network allows for permissionless transactions, centralized entities like exchanges or stablecoin issuers can freeze assets if they are subject to regulatory or sanction requirements.
Analysts point to renewed optimism regarding U.S. crypto regulation, a short squeeze liquidating over $4 billion in bearish positions, and concerns over global financial infrastructure.