Hackers stole over $130 million in Bitcoin from Coldcard hardware wallets this week, exploiting a firmware vulnerability that allowed them to guess weak private keys. The attack has drained millions from affected wallets daily since it began, and Bitcoin still traded above $65,170 on Friday, up nearly 4% over the past week.
The vulnerability
Coldcard wallets, built by Coinkite, contained a firmware flaw that let an attacker guess private keys that were too weak. The exploit has been running for days, with millions of dollars in Bitcoin moving out of compromised wallets each day. Cautious investors have been shifting their coins to other storage solutions, including exchanges, while they wait for a patch or a clearer picture of the damage.
ETF inflows pick up
The hack comes as investors keep pouring cash into Bitcoin ETFs. Since the beginning of the week, $763.6 million in fresh money has hit these products, with significant inflows into BlackRock's iShares Bitcoin Trust and Morgan Stanley's fund. Eric Balchunas, a senior ETF analyst, said the flows might not be directly tied to the Coldcard hack, but it would make sense for investors to rotate into the products as a safer way to hold Bitcoin exposure.
Clarity Act delayed
Separately, the crypto market structure bill known as the Clarity Act is now expected to be delayed until September. Lawmakers are in recess, pushing back any vote or further debate. The delay adds another layer of uncertainty for an industry already dealing with the fallout from the Coldcard exploit.
Bitcoin's price has held up despite the hack, but the steady drain of funds from Coldcard wallets is a reminder of the risks that come with self-custody. For now, the exchange-traded funds are absorbing some of that nervous money, and the next concrete step is Coinkite's response to the vulnerability — and whether the Clarity Act moves forward when Congress returns.




