A firmware vulnerability in Coldcard hardware wallets that had gone unnoticed since 2021 has been exploited to drain an estimated $89 million in funds, reigniting debate over the tradeoffs between self-custody and regulated custodial products like spot Bitcoin ETFs. The flaw affected devices made by Coinkite Inc., a Canadian manufacturer that Bloomberg senior ETF analyst Eric Balchunas noted has only about five employees — a detail he called "crazy low for such an important job."

QR code screenshot
Photo by Eftakher Alam on Unsplash

According to the report, the vulnerability stemmed from how the wallets generated private keys. Rather than producing them within an isolated secure hardware chip, affected Coldcard devices relied on a predictable software-based algorithm, which allowed attackers to calculate the keys offline and then execute automated withdrawals once they had reconstructed a target wallet's credentials.

Balchunas Uses Breach to Make the ETF Case

Balchunas argued that the incident illustrates why the vast majority of Bitcoin investors are better served by regulated, custodial products rather than managing hardware wallets themselves.

"True if you want to use btc to transact then ETF is bad option but for all the investor ppl i think it's by far the best choice," he wrote, drawing a distinction between using Bitcoin as a transactional currency and holding it purely as an investment.

His argument centers on the institutional-grade custody infrastructure that regulated spot Bitcoin ETFs rely on, typically through custodians such as Coinbase or Ledger, which maintain dedicated security teams and audited processes far beyond what a five-person hardware wallet manufacturer can offer. For the growing pool of investors who view Bitcoin primarily as a portfolio asset rather than a medium of exchange, Balchunas suggested that tradeoff tips clearly in favor of ETFs.

The Tradeoffs Cut Both Ways

The comparison isn't without its limitations. Spot Bitcoin ETFs don't allow holders to withdraw actual Bitcoin around the clock, and shares can't be used directly to transact on-chain the way self-custodied coins can. For users who need direct access to their Bitcoin for payments or on-chain activity, the Coldcard breach doesn't change the calculus — but for investors whose primary concern is safeguarding value, the episode adds fresh weight to the case that outsourcing custody to a regulated, well-resourced institution may carry less risk than managing hardware keys independently.