What actually happened?
Two things converged in the same week, and together they paint the tension that has followed crypto from the start: institutional demand is rising, while the question of secure storage (custody, meaning the management and safekeeping of private keys) remains open.
On one side, US spot bitcoin ETFs recorded a net inflow of 382 million dollars over two days, according to Cointelegraph. This figure comes from a single source [1] and we have not verified it independently. According to the same source, Galaxy's bitcoin ETF returned to positive numbers, though the source does not specify exactly what that means (whether it refers to a resumption of inflows or some other metric) [1]. On the other side, the incident with the Coldcard hardware wallet reopened the debate over how reliable self-custody really is.
How much was stolen and what is happening with the attacker's wallet?
According to CoinDesk, the wallet linked to the attack holds roughly 36 million dollars in bitcoin [2]. This amount is also reported by a single source and we did not verify it ourselves. What is interesting is how people are reacting to it: the address has become something like a public message board. Victims and casual contributors alike are paying to attach permanent messages to transactions, ranging from pleas to return part of the funds to their own self-promotion [2].
The term "cold wallet" refers to a device that keeps private keys offline, that is, out of reach of the internet. That is exactly why a hack of this type of storage is a sensitive topic: cold storage is generally considered the safer option.
Why does artificial intelligence come into this?
Ledger CTO Charles Guillemet, according to Decrypt, argues that the Coldcard exploit shows why certified hardware randomness matters (that is, the quality of the random number generator inside the device), and that AI is changing the way wallet security needs to be approached [3].
This is the opinion of a maker of competing hardware, which is worth keeping in mind while reading. The technical details of the Coldcard exploit itself are not described in the sources well enough for us to reconstruct them independently here.
How does Cloudflare and wallets for AI agents fit in?
A separate but thematically related move: Cloudflare, according to The Block, has begun rolling out stablecoin wallets designed for AI agents, which would use them to pay for APIs and online content [4]. For now, users can claim handles for their wallets, while the funding and payment features are set to come later [4].
The common thread in both stories: wallets are ceasing to be just a tool for humans, and there is increasing attention on how keys are held and used by software, hardware, and now automated agents as well.
What to take away from this
| Topic | Source | Status |
|---|---|---|
| Inflows into BTC ETFs of 382 million USD over 2 days | Cointelegraph [1] | reported by a single source |
| Attacker's wallet holds about 36 million USD | CoinDesk [2] | reported by a single source |
| AI changes wallet security requirements (Ledger's opinion) | Decrypt [3] | one side's opinion |
| Cloudflare wallets for AI agents | The Block [4] | announced, features rolling out gradually |
Charliedesk does not give advice on what to buy or sell. What to watch with stories of this kind: whether ETF inflows continue in the coming days, whether a verified technical analysis of the Coldcard exploit emerges, and how much of the stolen funds, if any, ends up moving.

