US spot Bitcoin ETFs pulled in a combined $382 million in net inflows over two trading days this week, even as Bitcoin itself slipped roughly 0.8% over the previous seven days to trade around $64,113. Tuesday alone brought $211.5 million into the funds, following $170 million on Monday, with BlackRock's iShares Bitcoin Trust leading both days at $111 million and $170 million respectively. Fidelity's Wise Origin Bitcoin Fund added roughly $33 million and $20 million across the same two sessions.

Notably, Invesco Galaxy's Bitcoin ETF logged its first positive daily flow since July 1, pulling in $6.7 million on Monday — a modest sum, but one that pushed the fund's cumulative net inflows to $172 million, with that single day accounting for 3.9% of the total. Bitcoin had touched a seven-day low below $62,500 during the same stretch, with selling pressure compounded by Michael Saylor's Strategy offloading 1,638 BTC.

a pile of coins and a calculator next to it
Photo by rc.xyz NFT gallery on Unsplash

A Five-Year-Old Bug Behind the Custody Scare

The inflows arrived against the backdrop of a rapidly escalating hack tied to Coldcard hardware wallets made by Coinkite. Galaxy Research estimated that roughly 7,300 addresses were affected, with suspected losses of about $130 million in Bitcoin, though other trackers following the incident as it unfolded put the confirmed figure above $116 million across more than 5,200 addresses. In one of the more dramatic episodes, an attacker drained 1,196 addresses in just 41 minutes on July 30, extracting 1,082.65 BTC worth roughly $70.2 million at the time — with reports suggesting at least a dozen different hackers were independently targeting the same flaw.

The root cause traced back to firmware version 4.0.0, in circulation since March 2021, which bypassed the device's dedicated hardware randomness chip during key generation and substituted a predictable software routine instead — making affected seed phrases enumerable by attackers who understood the flaw. Coinkite published an advisory urging users to update firmware and migrate funds to freshly generated seed phrases, and confirmed its TAPSIGNER, OPENDIME, and SATSCARD products were unaffected. Coinkite CEO Rodolfo Novak posted a public apology on X, calling the company "heartbroken" and saying it was taking "full accountability for the firmware bug," adding, "I'm sorry and I'm devastated." The company has said it is assisting affected users but has not offered compensation for losses.

Related: ETF Bitcoin Tarik Inflow $170 Juta, Dana Ether Justru Tergerus

Custody Debate Resurfaces

The timing has renewed a long-running argument inside crypto over self-custody versus institutional custody. Eric Balchunas of Bloomberg Intelligence framed the episode as a point in favor of ETF-based exposure, suggesting that what critics have historically dismissed as a drawback of ETFs — that an outside custodian holds the coins, not the investor — could increasingly read as an advantage. "[What] was once considered a bug...may all the sudden seem like a feature" compared with the operational risk smaller crypto companies and individual holders take on managing their own keys, Balchunas said.

That framing doesn't erase the underlying risk calculus — ETF custodians concentrate assets under a small number of institutions, a different kind of risk rather than an absence of it. But for investors weighing where to hold Bitcoin exposure, a five-year-old firmware flaw draining tens of millions from self-custodied wallets in real time is likely to shape the conversation for some time, even as fund flows suggest institutional buyers were unfazed enough to keep adding to their positions through the same week.