Notice: Editorial analysis for informational purposes; does not constitute financial or operational security advice. This article does not recommend any exchange-traded fund, wallet manufacturer, or custody model: it presents the arithmetic, and the decision rests with the reader. The flow series is sourced from Farside Investors and was extracted on August 13, 2026; the last session with published data is August 12, and August 13 appears in the provider's table without figures. Theft figures remain open as the incident is ongoing. CleanSky does not receive commissions or referral payments from any fund issuer or wallet manufacturer.

Bitcoin's share of the combined net flow of spot Bitcoin and Ether ETFs rose from 67.7% to 71.2% as of July 30, 2026—the day the entropy flaw in Coldcard wallets was made public—according to the Farside Investors daily series. Three and a half points, with both assets rising simultaneously—Bitcoin multiplied its daily average by 2.16 and Ether by 1.83—is the signature of a market condition rather than a flight from self-custody toward Bitcoin funds. There is more: in the 61 previous sessions, Bitcoin averaged outflows of $110.0 million per day, and in the eleven sessions prior to the disclosure, it was already seeing inflows of $29.4 million. The money had turned before the event. This analysis audits that causal narrative with a control group that anyone can reproduce—Bitcoin as the treatment, Ether as the control, with July 30 as the boundary—and devotes the rest to what actually repriced: the promise of verifiability, the premium paid for open source, and the exact arithmetic of what it costs to buy peace of mind in a fund.

Can the flight to ETFs be audited with a control group?

Since July 31, coverage of the Coldcard case has layered a second story on top of the first. The first—a March 2021 compilation error that silently degraded seed randomness and allowed thousands of addresses to be swept—is reconstructed with technical detail in our August 4 analysis and is not reopened here. The second claims that the scare pushed investors from self-custody toward spot ETFs, accompanied by real figures: over $850 million in one week, $1.1 billion counting Ether—the best week since April.

The inflows are real. The attribution of cause is what can be tested, and the case offers a rare natural experiment. A Coldcard stores Bitcoin and nothing else: there is no chain of events by which a seed generation flaw in a Bitcoin-only device would shift capital toward an Ether fund. Both products, however, share session calendars, macroeconomic conditions, trading desks, and a large portion of the investor base. This makes Bitcoin the treated group and Ether the control group, with July 30 as the boundary.

The deciding metric is not absolute volume—which rises and falls for reasons unrelated to the case—but the distribution: what proportion of the combined net flow Bitcoin captures before and after the boundary. If the disclosure had moved money from hardware wallets into Bitcoin funds, that share should jump. The full Farside Investors daily series, with 648 published Bitcoin sessions and 516 Ether sessions, allows for calculation across three windows.

Window (boundary: July 30, 2026)SessionsBitcoin, daily averageEther, daily averageBitcoin share of combined flow
Previous quarter (May 1 to July 29)61−$110.0 million−$12.2 millionnot interpretable (both in outflows)
Pre (July 15 to July 29)11+$29.4 million+$14.1 million67.7%
Post (July 30 to Aug 12)10+$63.5 million+$25.7 million71.2%

The jump is three and a half points: 67.7% to 71.2%. Bitcoin multiplied its daily average by 2.16 and Ether by 1.83—nearly the same push on different bases. The difference-in-differences—how much the treatment rises above the control's rise—stands at $22.5 million per day, well within what a single session moves due to noise in this series. Based on this test, the effect attributable to the Coldcard flaw is indistinguishable from the tide that lifted both assets simultaneously.

Two limitations must be placed on the table before proceeding. First: ten sessions do not constitute a trend, and a share calculated over short windows moves significantly with a single large day. Second, and more uncomfortable: ETF flow is not clean directional demand, as it includes creations linked to basis arbitrage and desk hedging that express no opinion on custody. The test rules out a massive, visible shift; to measure intent, one would need a breakdown by participant type, which no issuer publishes.

Why had the money already turned before the disclosure?

The data point that most damages the causal hypothesis lies outside the window. In the previous quarter—61 sessions between May 1 and July 29—Bitcoin funds accumulated $6,710.6 million in net outflows, an average of $110.0 million daily; the June episode we analyzed at the time belongs to that phase. Yet in the eleven sessions prior to the boundary, from July 15 to 29, the average was already positive: +$29.4 million per day, $323.8 million accumulated. The bleeding had stopped and reversed before Coinkite's warning about the Coldcard flaw even existed.

The daily series of the window shows the texture of this turn better than any average, including the two rejection sessions on July 23 and 24, which together wiped out $465.2 million.

SessionBitcoin ($ millions)Ether ($ millions)
July 15+107.7+53.9
July 16+79.1−28.0
July 17+132.3+36.7
July 20+226.8+38.0
July 21+203.2+37.5
July 22+69.1+72.7
July 23−225.1+26.3
July 24−240.1−70.7
July 27−11.6+11.7
July 28−49.7+9.4
July 29+32.1−32.9
July 30 — disclosure and sweep+233.1+12.8
July 31−265.4+9.0
Aug 3+170.1−11.9
Aug 4+211.5+53.1
Aug 5+244.4+60.8
Aug 6+137.6+92.1
Aug 7+101.7+49.6
Aug 10−144.6−14.6
Aug 11+7.8−1.7
Aug 12−61.1+7.4

On July 30, the day of the sweep, Bitcoin funds captured $233.1 million. The following day, they saw $265.4 million in outflows. If anyone was looking for the reflex reaction of a frightened market migrating to delegated custody, the first full session after the scare ended in the red with the largest net redemption of the entire window.

Furthermore, the subsequent rise did not hold. From July 30 to August 7, Bitcoin funds added $833.0 million over seven sessions; from August 10 to 12, they gave back $197.9 million in three sessions—23.8% of what had entered—without any new custody news to justify it.

Who drove the ETF's "best week since April": Bitcoin or Ether?

The headline for the week of August 3 to 7, 2026, circulated as a Bitcoin data point. In the daily series, it breaks down as follows: $865.3 million in Bitcoin funds and $243.7 million in Ether funds, totaling $1,109.0 million. This is exactly the "$1.1 billion" cited by The Block, and 22.0% of that figure belongs to Ether.

That 22.0% carries the full weight of the argument. A seed generation flaw in a Bitcoin-only wallet has no mechanism to push $243.7 million into Ether products in the same week. Either there is a common factor that lifted both—rates, risk appetite, repositioning after a quarter of outflows—or one must explain the mechanism by which fear of a Bitcoin wallet buys shares in an Ether fund. The former is what the numbers show; the latter has not been formulated by anyone.

It is also wise not to read weekly flow as a measure of conviction. In the three weeks of $996 million we analyzed previously, the same pattern appeared: inflow streaks that the press associates with a dominant narrative but which, when viewed alongside the control, follow the general market beat. Correlation does not prove causation in either direction. If Bitcoin were to decouple from Ether tomorrow, that wouldn't prove Coldcard was the cause either.

Did the $620 million day in Bitcoin ETFs actually happen?

One specific figure was repeated more than any other following the Coldcard flaw disclosure: approximately $620 million across the BlackRock, Fidelity, ARK 21Shares, and Morgan Stanley ETFs. It circulates in headlines as if it corresponded to a single session, and it is necessary to untangle that knot, as the source publishing it presents it as an aggregate of the post-disclosure window and details individual sessions ranging from $91.8 to $244 million. A daily net flow series cannot support both readings simultaneously. The largest net flow session for Bitcoin funds since June 1, 2026, was $265.7 million, occurring on July 6—twenty-four days before the disclosure.

Largest Bitcoin fund net flow sessions since June 1, 2026Net Flow ($ millions)Position relative to disclosure
July 6, 2026265.724 days before
Aug 5, 2026244.46 days after
July 30, 2026233.1day of the sweep
July 20, 2026226.810 days before
July 2, 2026223.528 days before
Aug 4, 2026211.55 days after

No single session approaches $620 million, and the source's own breakdown aligns with this: summed across the window's sessions, the aggregate appears; distributed in one day, it does not exist. The figure is correct in its original formulation and ceases to be so when headlines compress it into a single day. This article uses it only as an aggregate. Anyone wishing to verify the rest of the numbers here only needs the public Farside table for Bitcoin and the one for Ether, and sum the columns.

There is a third control obtained for free: the size of the theft versus the size of the flow. Even if every stolen Bitcoin had ended up entirely buying shares in a fund, the needle would barely move.

Reference price per BitcoinValue of 1,816 BTC (TRM Labs confirmed count)Value of July 30 sweep (approx. 1,082 BTC)
$60,000$109.0 million$65.0 million
$63,900$116.0 million$69.2 million
$70,000$127.1 million$75.8 million

At $63,900 per Bitcoin, the 1,816 BTC from the confirmed count by forensic analysis firm TRM Labs is worth $116.0 million—13.9% of the $833.0 million that flowed in between July 30 and August 7. The entire loot fails to explain even a seventh of the inflow, and that assumes the impossible: that a thief sells their stolen Bitcoin and uses the proceeds to buy shares of a regulated fund in their own name.

What did the Coldcard flaw reprice if capital barely moved?

The interesting finding from the control group is that trust moved while money did not. And what moved has three identifiable pieces, none of which can be read in an ETF flow series.

The first is the promise of verifiability. Self-custody is sold with a slogan—don't trust, verify—and this case identifies a layer where the holder could never verify anything. There was no intrusion or behavioral error, and that is the part that doesn't fit any standard warning: the failure was finalized upon generating the key, before the owner had anything to decide. Between March 2021 and July 2026, no holder could check the randomness of their own seed, because a low-entropy output is statistically indistinguishable from a good one. Trust never shifted from the custodian to the user: it was always deposited in the manufacturer's compilation chain, and the new development is that this is now known. Those wishing to review the full doctrine can find it in our self-custody guide and the explainer on what a hardware wallet is.

The second is the auditability premium. Coldcard is open source, with reproducible builds, and is the reference device for those who take that property seriously. The flaw lived from March 2021 to July 2026 in firmware that anyone could read. What was repriced by this episode is not a specific manufacturer: it is the belief that open and auditable equals secure—a belief that sustains the price and commercial argument for the entire hardware wallet category. Repricing it does not invalidate it. Closed source would not have even provided the possibility of finding it.

The third is irreversibility. Almost any vulnerability is closed by patching code; this one is not, because the damaged object ceased to be software the moment it was generated. The seed is inert data that the owner copied by hand and stored where they keep things they don't intend to touch again. There exists a dated and closed cohort of poisoned seeds, and anyone who does not migrate remains exposed indefinitely. The patch protects new seeds and none of the old ones.

There is a fourth repricing that affects the position this site previously established on multisig. In the analysis of multisig security theater, we argued that a multi-signature scheme protects precisely against one scenario—the compromise of a single key—and that attackers in 2025 and 2026 stopped attacking there. This case extends that argument to the other extreme. The security of a two-of-three scheme rests on the three failures being independent; an error in the manufacturer's compilation chain correlates them. Three keys generated by three devices of the same family and generation share the same degraded search space, and an attacker who has already traversed it once does not pay three times to gather two keys. The defense that remains standing is diversity of providers and device generations—a requirement that lives outside the cryptographic threshold and that multisig guides often relegate behind the choice of scheme.

Why does the Coldcard theft counter remain open as of August 13, 2026?

Because the private key remains derivable by whoever traversed the search space—the arithmetic of that space is in the August 4 analysis—any Bitcoin that returns to an affected address is stolen again. The incident therefore lacks a final figure: it has a curve that does not close, which is the mechanical reason why published counts diverge.

Denominators require care, as coverage mixes two different magnitudes. The initial sweep on July 30 affected 1,196 addresses and took about 1,082 Bitcoin, an average of 0.905 BTC per address. The cumulative total from at least three documented waves is another matter: as of August 13, 2026, it exceeds 7,300 confirmed emptied wallets and $130 million in Bitcoin, with TRM Labs attributing the activity to at least fifteen different actors, some likely opportunists who arrived later. Comparing 1,196 to 7,300 without specifying which is which produces an invented growth rate.

A rarely cited forensic detail illuminates the real state of the case: observed laundering to date is limited to a single deposit of 64.9 Bitcoin into the Wasabi coinjoin wallet and 200 Ether sent to the Tornado Cash mixer on August 4, 2026. Against a cumulative loot exceeding $130 million, this means the vast majority of the theft proceeds remain stationary. Stationary loot remains inventory in waiting: it has not entered any ETF or anywhere else, keeping both the count and attribution open.

This is also where the cruelest asymmetry of the episode stems from. The sweep started from the top and was exhausted in minutes, before any public warning existed. What remains active today are small-amount addresses, and their owner profile is exactly the one not reading crypto news this week: people who left the device in a drawer years ago, which was exactly the behavior the industry recommended.

How many years of Bitcoin ETF fees does a total loss cost?

The annual fee of an ETF is the known price of delegating custody. The total loss of the balance is the unknown price of not delegating it. The relationship between the two is obtained by dividing one by the other, and the result is uncomfortable for both sides of the debate.

The sweep of affected Coldcards on July 30 left an average position of 0.905 Bitcoin per address, about $57,800 at the reference price of $63,900 per Bitcoin used by the TRM Labs count. With that position as the unit of account, the fees in effect on August 13, 2026, for the main US spot funds are as follows.

FundAnnual FeeAnnual cost on $57,800Years of fees equivalent to a total loss
IBIT (BlackRock)0.25%$145400
FBTC (Fidelity)0.25%$145400
ARKB (ARK 21Shares)0.21%$121476
BITB (Bitwise)0.20%$116500
BTC (Grayscale Mini)0.15%$87667
MSBT (Morgan Stanley)0.14%$81714

At the cheapest fee in the market on August 13, 2026—the 0.14% annual fee of MSBT, Morgan Stanley's Bitcoin ETF—losing the entire position costs the same as 714 years of fees; that 0.14% is the nominal rate, as the fund also maintains a temporary 0% waiver on the first $5 billion since its launch in April 2026. At the 0.25% fee of the two largest funds, it's 400 years. Put another way: a 0.25% annual fee buys coverage against an event that must be assigned an annual probability higher than one in four hundred to break even in purely expected terms.

That number is what turns the discussion into arithmetic. The question stops being an identity choice and becomes an estimate: what annual probability of total loss does each person assign to their own operations, accounting for manufacturer flaws, personal errors, poorly planned inheritances, and fires. The calculation is also not symmetrical, because an ETF does not deliver Bitcoin to the bearer nor function outside market hours—the breakdown of what exactly is being bought is in our explanation of what a crypto ETF is—and because the fee is paid every year while total loss occurs once or never. We provide the arithmetic; the reader provides the probability.

Where does each custody scare push?

The third-order effect is the most uncomfortable, and it is measurable. As of August 13, 2026, according to compilations by Bitwise and CryptoSlate, US spot Bitcoin ETFs accumulate about $91.7 billion in assets, and approximately $77 billion of those millions—nearly 84%—are under a single custodian, Coinbase Custody, which serves nine of the eleven Bitcoin funds and eight of the nine Ether funds. Diversification exists but is slow: BlackRock's fund added Anchorage Digital Bank as a second custodian, and 21Shares added Anchorage and BitGo alongside Coinbase.

Every episode like Coldcard's, regardless of whether it moves flows in the following week, pushes Bitcoin into fewer hands. The concentration that the original design sought to avoid is not advancing here through regulatory coercion or prohibition: it is advancing through the security failures of self-custody tools. A single custodian with 84% of a category's assets reintroduces exactly the single point of failure that justifies the network's existence, and it does so with the enthusiastic consent of those who have just lost trust in the device in their drawer.

Furthermore, the balance in the hands of custodians is an imperfect proxy in both directions. Self-custody is not measured directly: exchange balances are clues, not a census, and fund assets include arbitrage positions that do not express a custody preference. Trust is also not measured. Everything this article says about it—flows, custodial share, fee premium arithmetic—are approximations, and they must be named as such so the reader can discount them.

The distinction that sustains all the above is the one separating a model from an implementation. A manufacturer's compilation chain failed for five years and four months; the principle that whoever controls the keys controls the funds did not fail. Confusing the two leads to the opposite conclusion of what the data suggests, because the answer to an implementation failure is diversity of implementations, yet 84% of the category's assets are today under a single custodian.

What to check on September 14, 2026, when the Senate returns?

The episode has an extension with a date on the calendar. A retail loss exceeding $130 million, with no possible recourse, no insurer, and no authority to claim to, is the exact case cited when defending mandatory custody rules, licensing requirements for manufacturers, or limits on self-hosting keys. The US Senate is in recess until September 14, 2026, and crypto market structure legislation—the package we follow in our August recess deadline analysis—returns to the table then. An incident with identifiable victims and a round figure is legislative ammunition that does not expire in six weeks.

For flow, the verifiable expectation can be written down with a date. If the migration hypothesis were true, Bitcoin's share of the combined net flow between August 13 and September 14, 2026, should remain above the 71.2% of the post-window and preferably approach 75%, with Ether flat or in outflows. Our expectation is the opposite: that the share will remain in the 65% to 72% range—that is, within the range it already occupied before the disclosure—and that both assets will continue moving in the same direction. The verification will only be interpretable if both aggregate flows are positive; if both return to outflows, as in the previous quarter, the share ceases to mean anything and must be stated as such.

The limits of all the above, gathered so no one has to search for them:

  • Ten sessions following the boundary do not constitute a trend.
  • Correlation does not prove cause in either direction.
  • ETF flow includes basis arbitrage and desk hedging, so it does not express clean directional demand.
  • Trust is not measured: everything this article says about it are declared proxies.
  • The August 13 theft count is the latest available snapshot and not a final total, as the incident remains open.
  • The last session with published data in the Farside series is August 12, 2026, and August 13 still appeared without figures at the time of extraction.

The narrative of the flight to ETFs does not survive a control that anyone can reproduce in a spreadsheet. The episode did reprice three other things: a promise of verifiability that had a layer underneath that no one could verify, the auditability of open source when the flaw lives in the compilation, and what the scenario no one wants to calculate costs in years of fees. A shift in trust that has not yet been collected in flows remains a position that can be taken.

Sources and links: Farside Investors — full daily Bitcoin ETF flow series · Farside Investors — full daily Ether ETF flow series · TRM Labs — forensic analysis of the Coldcard exploit · CoinDesk — the original ETF shift hypothesis (July 31, 2026) · CoinDesk — the first wave, 594 BTC in 25 minutes · The Block — $1.1 billion between Bitcoin and Ether in the best week since April (Aug 8, 2026) · Bloomberg — $850 million following the Coldcard flaw (Aug 10, 2026) · Crypto Briefing — the $620 million aggregate of the post-disclosure window · The Hacker News — technical timeline of the flaw · Fortune — $116 million count (Aug 3, 2026) · TechCrunch — count exceeds $130 million (Aug 4, 2026) · The Cryptonomist — 7,300 emptied wallets (Aug 7, 2026) · CryptoSlate — ETF custodial concentration at Coinbase · Crypto Briefing — Bitwise custodian count · Roll Call — 2026 Senate calendar. Fund fees cross-referenced on August 13, 2026, with compilations from US News, Motley Fool, and Seeking Alpha.