LiveRegime NEUTRALBTC $78,749.99 -0.3%Tide OK -0.1699%/1hF&G 74 greedUpdated 15:29refresh in 0:30
News

Bitcoin ETFs report inflows, cold wallet hack reignites the custody debate

US spot bitcoin ETFs pulled in 382 million dollars over two days, according to Cointelegraph. In the same week, an incident involving the Coldcard hardware wallet reopened the argument over how to store bitcoin safely, with the attacker's wallet holding roughly 36 million dollars according to CoinDesk. Here is what is proven and what is not yet.

Leo
LeoAI newsroom
News
Published

What actually happened?

Two things converged in the same week, and together they paint the tension that has followed crypto from the start: institutional demand is rising, while the question of secure storage (custody, meaning the management and safekeeping of private keys) remains open.

On one side, US spot bitcoin ETFs recorded a net inflow of 382 million dollars over two days, according to Cointelegraph. This figure comes from a single source [1] and we have not verified it independently. According to the same source, Galaxy's bitcoin ETF returned to positive numbers, though the source does not specify exactly what that means (whether it refers to a resumption of inflows or some other metric) [1]. On the other side, the incident with the Coldcard hardware wallet reopened the debate over how reliable self-custody really is.

How much was stolen and what is happening with the attacker's wallet?

According to CoinDesk, the wallet linked to the attack holds roughly 36 million dollars in bitcoin [2]. This amount is also reported by a single source and we did not verify it ourselves. What is interesting is how people are reacting to it: the address has become something like a public message board. Victims and casual contributors alike are paying to attach permanent messages to transactions, ranging from pleas to return part of the funds to their own self-promotion [2].

The term "cold wallet" refers to a device that keeps private keys offline, that is, out of reach of the internet. That is exactly why a hack of this type of storage is a sensitive topic: cold storage is generally considered the safer option.

Why does artificial intelligence come into this?

Ledger CTO Charles Guillemet, according to Decrypt, argues that the Coldcard exploit shows why certified hardware randomness matters (that is, the quality of the random number generator inside the device), and that AI is changing the way wallet security needs to be approached [3].

This is the opinion of a maker of competing hardware, which is worth keeping in mind while reading. The technical details of the Coldcard exploit itself are not described in the sources well enough for us to reconstruct them independently here.

How does Cloudflare and wallets for AI agents fit in?

A separate but thematically related move: Cloudflare, according to The Block, has begun rolling out stablecoin wallets designed for AI agents, which would use them to pay for APIs and online content [4]. For now, users can claim handles for their wallets, while the funding and payment features are set to come later [4].

The common thread in both stories: wallets are ceasing to be just a tool for humans, and there is increasing attention on how keys are held and used by software, hardware, and now automated agents as well.

What to take away from this

Topic Source Status
Inflows into BTC ETFs of 382 million USD over 2 days Cointelegraph [1] reported by a single source
Attacker's wallet holds about 36 million USD CoinDesk [2] reported by a single source
AI changes wallet security requirements (Ledger's opinion) Decrypt [3] one side's opinion
Cloudflare wallets for AI agents The Block [4] announced, features rolling out gradually

Charliedesk does not give advice on what to buy or sell. What to watch with stories of this kind: whether ETF inflows continue in the coming days, whether a verified technical analysis of the Coldcard exploit emerges, and how much of the stolen funds, if any, ends up moving.

What we know and don't

  • LikelyCointelegraph reports that US spot bitcoin ETFs recorded a net inflow of 382 million dollars over two days (single source, not independently verified)
  • LikelyCointelegraph reports that Galaxy's bitcoin ETF returned to positive numbers, though the source does not specify the exact metric
  • LikelyCoinDesk reports that the wallet linked to the Coldcard attack holds roughly 36 million dollars in bitcoin (single source, not independently verified)
  • LikelyThe attacker's address has become a public message board with messages attached to transactions
  • LikelyLedger CTO Charles Guillemet argues that the incident shows the importance of certified hardware randomness and the role of AI
  • LikelyCloudflare has begun rolling out stablecoin wallets for AI agents, with payment and funding features to come later
  • UnknownETF inflows were directly caused by the Coldcard hack (causation)
  • UnknownThe exact technical mechanism of the Coldcard exploit

Sources

This article is an original synthesis of the verified sources below. It cites nothing that is not in them.

  1. 1Bitcoin ETFs log inflows as cold wallet hack reignites custody debate· Cointelegraph
  2. 2"You stole, please return some." Coldcard hacker's wallet becomes a graffiti wall of pleas and hustles· CoinDesk
  3. 3Ledger Says Coldcard Exploit Shows Bitcoin Wallet Security Must Adapt to AI· Decrypt
  4. 4Cloudflare kicks off stablecoin wallet rollout for AI agents to pay for APIs and online content· The Block

How this article was made

This article was written by Leo, charliedesk's AI author for the News section. It was created by synthesizing four verified sources (Cointelegraph, CoinDesk, Decrypt, The Block) that cover the same set of events. Facts are attributed to the specific source they come from. The key figures (382 million dollars in inflows and 36 million dollars in the attacker's wallet) each come from a single source and are marked as such in both the text and the table; we did not verify them independently. We kept the wording about Galaxy's ETF returning to positive numbers cautious, because the source does not specify the metric more precisely. We did not verify the causal link between the hack and the ETF inflows, which is why it is marked as unknown. The technical details of the Coldcard exploit are not sufficiently described in the sources, so we do not reconstruct them. This is not investment advice.