Notice: Editorial analysis for informational purposes; does not constitute financial or operational security advice. This article does not recommend any exchange-traded fund, wallet manufacturer, or custody model: it presents the arithmetic, and the decision lies with the reader. The flow series is sourced from Farside Investors and was extracted on August 13, 2026; the last session with published data is August 12, and August 13 appears in the provider's table without figures. Theft figures remain open as the incident is ongoing. CleanSky does not receive commissions or referral payments from any fund issuer or wallet manufacturer.
Losing the entire average position of a Coldcard swept on July 30, 2026—0.905 Bitcoin, approximately $57,800—costs the same as 400 years of fees in Bitcoin ETFs at 0.25% annually, and 714 years in the cheapest one on the market. That is half of the arithmetic that a self-custody failure places before the holder; the other half is the risk purchased when delegating: around 84% of the assets in U.S. spot Bitcoin ETFs—roughly $77 billion out of $91.7 billion—resides under a single custodian, Coinbase Custody. The Coldcard entropy flaw disclosed on July 30 also provided, albeit unintentionally, a way to count how many people actually made the switch: a Coldcard only holds Bitcoin, so Bitcoin remains the treated group and Ether serves as the control group, with an exact boundary on the calendar. The result of that count: Bitcoin's share of the combined net flow rose from 67.7% to 71.2%, with Bitcoin multiplying its daily average by 2.16 and Ether by 1.83—nearly the same push on different bases—and the money had already turned before the disclosure, moving from average outflows of $110.0 million daily in the previous quarter to inflows of $29.4 million in the eleven preceding sessions. Staying and verifying or buying peace of mind in a fund: both sides of that scale have numbers, and the probability—and the decision—is up to each individual.
What decision does a failure like Coldcard's put on the table?
The Coldcard case carries two stories. The technical one—a March 2021 compilation error silently degraded seed randomness and allowed thousands of addresses to be swept—is reconstructed in detail in our August 4 analysis and is not reopened here. The second story is that of the holder who learns of the flaw with the device in a drawer and faces the usual dilemma: continue with self-custody—verify, migrate the seed, diversify providers—or buy peace of mind in an exchange-traded fund, which delegates keys to a custodian in exchange for an annual fee.
The immediate reading of the episode was that the scare would push capital from the former to the latter. This shift can be measured, and the case—rare for this type of event—provides numbers for both sides of the scale: how much it costs to delegate custody, what new risk is purchased by doing so, how many people actually made the switch, and what was damaged on the side of staying. The complete arithmetic fits on a spreadsheet with two public series; the probability each person assigns to their own operations is their own business.
How many years of Bitcoin ETF fees does a total loss cost?
The annual fee of an ETF is the known price of delegating custody. The total loss of the balance is the unknown price of not delegating it. The relationship between the two is obtained by dividing one by the other, and the result is uncomfortable for both sides of the debate.
The sweep of affected Coldcards on July 30 left an average position of 0.905 Bitcoin per address, about $57,800 at the reference price of $63,900 per Bitcoin used by the forensic analysis firm TRM Labs. With that position as the unit of account, the fees in effect on August 13, 2026, for the main U.S. spot funds are as follows.
| Fund | Annual Fee | Annual Cost on $57,800 | Years of Fees Equivalent to Total Loss |
|---|---|---|---|
| IBIT (BlackRock) | 0.25% | $145 | 400 |
| FBTC (Fidelity) | 0.25% | $145 | 400 |
| ARKB (ARK 21Shares) | 0.21% | $121 | 476 |
| BITB (Bitwise) | 0.20% | $116 | 500 |
| BTC (Grayscale Mini) | 0.15% | $87 | 667 |
| MSBT (Morgan Stanley) | 0.14% | $81 | 714 |
At the cheapest fee on the market as of August 13, 2026—the 0.14% annual fee of MSBT, the Morgan Stanley Bitcoin ETF—losing the entire position costs the same as 714 years of fees; that 0.14% is the nominal rate, as the fund also maintains a temporary 0% waiver on the first $5 billion since its launch in April 2026. At the 0.25% fee of the two largest funds, it is 400 years. Put another way: the 0.25% annual fee buys coverage against an event that must be assigned an annual probability higher than one in four hundred to be worthwhile in purely expected terms.
That number is what turns the discussion into arithmetic. The question, posed this way, is an estimation: what annual probability of total loss does each person assign to their own operations, accounting for manufacturer flaws, personal errors, poorly planned inheritances, and fires. The calculation is not symmetrical either, because an exchange-traded fund does not deliver Bitcoin to the bearer nor does it operate outside market hours—the breakdown of exactly what is being bought is in our explanation of what a crypto ETF is—and because the fee is paid every year while a total loss occurs once or never. We provide the arithmetic; the reader provides the probability.
How much Bitcoin in ETFs sits with a single custodian?
The exchange-traded fund side carries its own risk, and it is also measurable. As of August 13, 2026, according to data from Bitwise and CryptoSlate, U.S. spot Bitcoin ETFs have accumulated about $91.7 billion in assets, and approximately $77 billion of that—nearly 84%—is under a single custodian, Coinbase Custody, which serves nine of the eleven Bitcoin funds and eight of the nine Ether funds. Diversification exists but is slow: BlackRock's fund added Anchorage Digital Bank as a second custodian, and 21Shares added Anchorage and BitGo alongside Coinbase.
Every episode like Coldcard's, regardless of whether it moves flows in the following week, pushes Bitcoin into fewer hands. The concentration that the original design intended to avoid progresses without the need for regulatory coercion or prohibition: it is driven by the security failures of the self-custody tools themselves. A single custodian with 84% of a category's assets exactly reintroduces the single point of failure that justifies the network's existence, and it does so with the enthusiastic consent of those who have just lost trust in the device in their drawer.
The distinction that organizes this side of the scale separates a model from an implementation. A manufacturer's compilation chain failed for five years and four months; the principle that whoever controls the keys controls the funds remained intact. Confusing the two inverts the conclusion, because the response to an implementation failure is diversity of implementations, yet 84% of the category's assets are currently under a single custodian.
Furthermore, the balance in the hands of custodians is an imperfect proxy in both directions. Self-custody is not measured directly: exchange balances are merely a hint, and fund assets include arbitrage positions that do not express a custody preference. Trust is not measured either. Everything this analysis says about it—flows, custodial share, fee arithmetic—are approximations, and they must be named as such so the reader can discount them.
How many people actually swapped self-custody for an ETF?
We are left with the central count of the scale, and the case itself brings the instrument to perform it. A Coldcard stores Bitcoin and nothing else: there is no chain of events by which a seed generation failure in a Bitcoin-only device would shift capital toward an Ether fund. The two products, however, share session calendars, macroeconomic conditions, trading desks, and much of the investor base. This makes Bitcoin the treated group and Ether the control group, with July 30 as the boundary: a natural experiment that no one designed.
The deciding metric is the split: what proportion of the combined net flow Bitcoin takes before and after the boundary. Absolute volume rises and falls for reasons unrelated to the case; the share, if the disclosure had moved money from hardware wallets to the Bitcoin fund, should jump. The full daily series from Farside Investors, 648 published Bitcoin sessions and 516 Ether sessions, allows it to be calculated across three windows.
| Window (Boundary: July 30, 2026) | Sessions | Bitcoin, Daily Average | Ether, Daily Average | Bitcoin Share of Combined Flow |
|---|---|---|---|---|
| Previous Quarter (May 1 to July 29) | 61 | −$110.0 million | −$12.2 million | not interpretable (both in outflows) |
| Pre (July 15 to July 29) | 11 | +$29.4 million | +$14.1 million | 67.7% |
| Post (July 30 to Aug 12) | 10 | +$63.5 million | +$25.7 million | 71.2% |
The jump is three and a half points: 67.7% to 71.2%. Bitcoin multiplied its daily average by 2.16 and Ether by 1.83—nearly the same push on different bases. The difference-in-differences—how much the treatment rises above the control—stands at $22.5 million per day, well within what a single session moves as noise in this series. Based on this evidence, the effect attributable to the Coldcard failure is indistinguishable from the tide that lifted both assets simultaneously.
Two caveats before proceeding. First: ten sessions do not make a trend, and a share calculated over short windows moves significantly with a single large day. Second, more uncomfortably: an ETF flow includes creations linked to basis arbitrage and desk hedging that do not express any opinion on custody, thus mixing directional demand with market machinery. The test rules out a massive and visible shift; to measure intent, a breakdown by participant type would be needed, which no issuer publishes.
Furthermore, the money's turn preceded the event. In the previous quarter—61 sessions between May 1 and July 29—Bitcoin funds accumulated $6,710.6 million in net outflows, an average of $110.0 million daily; the June episode we analyzed at the time belongs to that phase. In the eleven sessions prior to the boundary, from July 15 to 29, the average was already positive: +$29.4 million per day, $323.8 million cumulative. The bleeding had stopped and reversed before Coinkite's warning about the Coldcard flaw even existed.
What does the daily flow series show around July 30?
The daily series of the window shows the texture of that turn better than any average, including the two rejection sessions on July 23 and 24, which together wiped out $465.2 million.
| Session | Bitcoin (million $) | Ether (million $) |
|---|---|---|
| July 15 | +107.7 | +53.9 |
| July 16 | +79.1 | −28.0 |
| July 17 | +132.3 | +36.7 |
| July 20 | +226.8 | +38.0 |
| July 21 | +203.2 | +37.5 |
| July 22 | +69.1 | +72.7 |
| July 23 | −225.1 | +26.3 |
| July 24 | −240.1 | −70.7 |
| July 27 | −11.6 | +11.7 |
| July 28 | −49.7 | +9.4 |
| July 29 | +32.1 | −32.9 |
| July 30 — disclosure and sweep | +233.1 | +12.8 |
| July 31 | −265.4 | +9.0 |
| Aug 3 | +170.1 | −11.9 |
| Aug 4 | +211.5 | +53.1 |
| Aug 5 | +244.4 | +60.8 |
| Aug 6 | +137.6 | +92.1 |
| Aug 7 | +101.7 | +49.6 |
| Aug 10 | −144.6 | −14.6 |
| Aug 11 | +7.8 | −1.7 |
| Aug 12 | −61.1 | +7.4 |
On July 30, the day of the sweep, Bitcoin funds captured $233.1 million. The following day, they returned $265.4 million. If anyone was looking for the reflex reaction of a scared market migrating to delegated custody, the first full session after the scare ended in the red with the largest net redemption of the entire window.
The subsequent rise didn't hold either. From July 30 to August 7, Bitcoin funds added $833.0 million in seven sessions; from August 10 to 12, they returned $197.9 million in three—23.8% of what had entered—without any new custody news to justify it.
The week of August 3 to 7, 2026, the best for the group since April, moved $1,109.0 million, split into $865.3 million in Bitcoin funds and $243.7—22.0%—in Ether funds. That 22.0% carries the full weight of the causal argument: a seed generation failure in a Bitcoin-only wallet has no way to push $243.7 million into Ether products in the same week. Either there is a common factor that lifted both—rates, risk appetite, repositioning after the quarter of outflows—or one must explain the mechanism by which fear of a Bitcoin wallet buys shares in an Ether fund. The former is what the numbers show; the latter has not been formulated by anyone.
Weekly flow also does not measure conviction. In the three weeks of $996 million we analyzed previously, the same pattern appeared: streaks of inflows that, with the control group alongside, follow the general market beat. Correlation does not prove cause in either direction: if Bitcoin were to decouple from Ether tomorrow, that wouldn't prove Coldcard was the cause either.
The $620 million concentrated by BlackRock, Fidelity, ARK 21Shares, and Morgan Stanley ETFs after the disclosure is the aggregate of a multi-session window, with individual sessions ranging between $91.8 and $244 million. No session in the series approaches that figure in a single day: the largest for Bitcoin funds since June 1, 2026, is $265.7 million, occurring on July 6, twenty-four days before the disclosure.
| Largest Net Flow Sessions for Bitcoin Funds since June 1, 2026 | Net Flow (million $) | Position Relative to Disclosure |
|---|---|---|
| July 6, 2026 | 265.7 | 24 days before |
| Aug 5, 2026 | 244.4 | 6 days after |
| July 30, 2026 | 233.1 | day of the sweep |
| July 20, 2026 | 226.8 | 10 days before |
| July 2, 2026 | 223.5 | 28 days before |
| Aug 4, 2026 | 211.5 | 5 days after |
Anyone wishing to verify any of these numbers only needs the public Farside table for Bitcoin and the one for Ether, and sum the columns.
There is a third control obtained for free: the size of the theft versus the size of the flow. Even if every stolen Bitcoin had ended up entirely buying shares in a fund, the needle would barely move.
| Reference Price per Bitcoin | Value of 1,816 BTC from TRM Labs Confirmed Count | Value of July 30 Sweep, approx. 1,082 BTC |
|---|---|---|
| $60,000 | $109.0 million | $65.0 million |
| $63,900 | $116.0 million | $69.2 million |
| $70,000 | $127.1 million | $75.8 million |
At $63,900 per Bitcoin, the 1,816 BTC from the TRM Labs confirmed count are worth $116.0 million, 13.9% of the $833.0 million that entered between July 30 and August 7. The entire loot doesn't even explain one-seventh of the inflow, and that assumes the impossible: that a thief sells their stolen Bitcoin and uses the proceeds to buy shares of a regulated fund in their own name.
What did the Coldcard flaw reprice if the money didn't move?
The interesting finding of the experiment is that trust moved while the money did not. What moved has three identifiable pieces, none of which can be read in an ETF flow series, and all three belong to the side of staying: they are what the holder who continues with self-custody must now discount.
The first is the promise of verifiability. Self-custody is sold with a slogan—don't trust, verify—and this case identifies a layer where the holder could never verify anything. There was no intrusion or behavioral error, and that is the part that doesn't fit into any standard warning: the failure was finalized when the key was manufactured, before the owner had anything to decide. Between March 2021 and July 2026, no holder could check the randomness of their own seed, because an output with low entropy is statistically indistinguishable from a good one. Trust, at that layer, was placed from the start in the manufacturer's compilation chain, and the new reality is that this is now known. Anyone wishing to review the full doctrine can find it in our self-custody guide and in the explainer on what a hardware wallet is.
The second is the auditability premium. Coldcard is open source, with reproducible builds, and is the reference device for anyone who takes that property seriously. The flaw lived from March 2021 to July 2026 in firmware that anyone could read. The repricing therefore affects the entire category of hardware wallets, beyond any specific manufacturer: it touches the belief that open and auditable equals secure, the belief that sustains the price and the commercial argument of the entire segment. Repricing it does not negate it, however. Closed code would not have even provided the possibility of finding the flaw.
The third is irreversibility. Almost any vulnerability is closed by patching the code; this one is not, because the damaged object ceased to be software the moment it was generated. The seed is inert data that the owner copied by hand and stored where they keep things they don't intend to touch again. There is a dated and closed cohort of poisoned seeds, and anyone who does not migrate remains exposed indefinitely. The patch protects new seeds and none of the old ones.
There is a fourth repricing that affects the position this site previously established on multisig. In the analysis of multisig security theater, we argued that a multi-signature scheme protects precisely against one scenario—the compromise of a single key—and that attackers in 2025 and 2026 stopped attacking there. This case extends that argument from the other end. The security of a two-out-of-three scheme rests on the three failures being independent; an error in the manufacturer's compilation chain correlates them. Three keys generated by three devices of the same family and generation share the same degraded search space, and an attacker who has already traversed it once does not pay three times to gather two keys. The defense that remains standing is diversity of providers and device generations, a requirement that lives outside the cryptographic threshold and that multifirma guides often relegate behind the choice of scheme.
Why does the Coldcard theft counter remain open as of August 13, 2026?
Since the private key remains derivable by whoever traversed the search space—the arithmetic of that space is in the August 4 analysis—any Bitcoin that returns to an affected address is stolen again. The incident therefore remains without a final figure: its curve does not close, and that is the mechanical reason why published counts diverge.
The count also handles two denominators that measure different things. The initial sweep on July 30 affected 1,196 addresses and took about 1,082 Bitcoin, an average of 0.905 BTC per address. The cumulative total of at least three documented waves is a different magnitude: as of August 13, 2026, it exceeds 7,300 confirmed emptied wallets and $130 million in Bitcoin, with TRM Labs attributing the activity to at least fifteen different actors, some likely opportunists who arrived later. Comparing 1,196 to 7,300 without specifying which is which produces a fabricated growth rate.
A rarely cited forensic detail illuminates the real state of the case: the laundering observed to date is limited to a single deposit of 64.9 Bitcoin in the Wasabi coinjoin wallet and 200 Ether sent to the Tornado Cash mixer on August 4, 2026. Against a cumulative loot exceeding $130 million, this means the vast majority of the theft proceeds remain stationary. A stationary loot is still inventory waiting: it has not entered any exchange-traded fund or anywhere else, keeping both the count and attribution open.
This is also where the cruelest asymmetry of the episode stems from. The sweep started from the top and was exhausted in minutes, before any public warning existed. What remains active today are small-amount addresses, and their owner profile is exactly the one not reading crypto news this week: people who left the device in a drawer years ago, which was exactly the behavior the industry recommended.
What to check on September 14, 2026, when the Senate returns?
The episode has an extension with a date on the calendar. A retail loss exceeding $130 million, with no possible recourse, no insurer, and no authority to claim to, is the exact case cited when defending mandatory custody rules, licensing requirements for manufacturers, or limits on self-hosting keys. The U.S. Senate is in recess until September 14, 2026, and crypto market structure legislation—the package we follow in our August recess deadline analysis—returns to the table then. An incident with identifiable victims and a round figure is legislative ammunition that does not expire in six weeks.
For the flow, the verifiable expectation can be set in stone and dated. If the migration hypothesis were true, Bitcoin's share of the combined net flow between August 13 and September 14, 2026, should remain above the 71.2% of the post-window and preferably approach 75%, with Ether flat or in outflows. Our expectation is the opposite: that the share will remain in the range of 65% to 72%, i.e., within the range it already occupied before the disclosure, and that both assets will continue to move in the same direction. The verification will only be interpretable if both aggregate flows turn out positive; if both return to outflows, as in the previous quarter, the share ceases to mean anything and that must be stated.
The limits of all the above, gathered so no one has to search for them:
- Ten sessions following the boundary do not constitute a trend.
- Correlation does not prove cause in either direction.
- An ETF flow includes basis arbitrage and desk hedging, so it does not express clean directional demand.
- Trust is not measured: everything this article says about it are declared proxies.
- The theft count as of August 13 is the latest available snapshot and not a final closure, as the incident remains open.
- The last session with published data in the Farside series is August 12, 2026, and August 13 still appeared without figures at the time of extraction.
The scale is served with both sides full: between 400 and 714 years of fees on one; on the other, a custodian with 84% of the category, plus three real repricings for those who stay—a promise of verifiability that had a layer underneath that no one could verify, the auditability of open source when the flaw lives in the compilation, and a cohort of seeds that no patch can cure. Between the two, an experiment whose effect on flows is indistinguishable from noise: almost no one moved their money. The same calculation fits on a spreadsheet with two public series and is set for the window opening now, with the share between August 13 and September 14 as the metric and the thresholds already written. The decision, with the numbers in front of you, remains with the reader.
Related articles: The Coldcard entropy flaw, with the arithmetic of 40 and 72 bits. Multisig security theater. Self-custody: your keys, your crypto. The divergence between ETF outflows and whale accumulation. Track your positions and on-chain balances at CleanSky — no yield promises, just your data.