After eight straight weeks of outflows totaling roughly $8.26 billion through early July, U.S. spot Bitcoin ETFs turned a corner in the first week of August. According to data compiled by The Block and other trackers, the funds pulled in about $853.5 million over the week — their best result since the week ending April 17, which saw $996.4 million in inflows. Spot Ether ETFs also had their best week since April, adding roughly $244.9 million.

The numbers

BlackRock's IBIT dominated the week, capturing around $694 million — more than 80% of total Bitcoin ETF inflows — while Fidelity's FBTC added about $116.5 million. Not every issuer shared in the gains: Invesco and VanEck saw a combined roughly $66 million in net outflows over the same period, and Franklin Templeton and WisdomTree's funds recorded essentially zero net flow. Bitcoin itself traded near $65,000 into the weekend, up modestly on the week.

What the Coldcard exploit actually was

The backdrop to this rebound is a security incident that surfaced around July 30, involving Coldcard, a popular Bitcoin hardware wallet made by Coinkite. Researchers identified a flaw in how certain affected devices generated wallet seeds, which allowed attackers to identify and target vulnerable wallets without needing physical access to the hardware itself. Estimates of the damage vary by source, ranging from roughly $111 million to $130 million stolen from more than 7,700 wallets, according to different analyses from Galaxy Research and other trackers. Coldcard has since released emergency firmware updates, and affected users have been urged to migrate funds to newly generated wallets immediately.

The timing argument — and its holes

Bloomberg Intelligence's senior ETF analyst, Eric Balchunas, was among the first to flag the correlation, noting on social media that several major Bitcoin ETFs had recorded inflows every day since the hack. "Would be ironic, but somehow on brand, if the hack of BTC in cold storage... marked the beginning of next run," he wrote — while explicitly cautioning that correlation doesn't prove causation.

A closer look at the daily breakdown complicates a clean cause-and-effect story. By Friday morning, roughly 88% of the week's inflows — about $754.7 million — had already arrived, with Wednesday, August 5 standing out as the single biggest inflow day, two full days before Friday's weaker-than-expected jobs report. That report is widely credited with fueling Friday's broader market rally, including Bitcoin's own gain that day — but Friday's ETF inflow was actually the smallest of the week, at roughly $98.9 million. In other words, the jobs data appears to explain Friday's price action, but not the bulk of the week's ETF buying, which had already happened. The Coldcard hack, which predated the buying by about three days, remains the most-cited explanation, even though several analysts stress it isn't proven.

Adding a further wrinkle: Ether ETFs posted a similarly strong week despite the fact that Ether holders had no direct exposure to a Bitcoin-specific hardware wallet exploit — a reminder that broader market sentiment and fund flows rarely have a single, clean explanation.

Not every fund benefited equally

The concentration of inflows into IBIT and FBTC — with smaller issuers seeing flat or negative flows — is itself a notable pattern. It suggests that whatever drove this week's buying (whether the Coldcard exploit, the softer jobs data, or some combination of both) disproportionately favored the largest, most liquid funds rather than lifting the category broadly. That's a common feature of ETF inflow surges generally: liquidity and brand recognition tend to concentrate flows in leading products during periods of renewed interest.

The broader lesson on custody

Regardless of whether the Coldcard exploit directly caused this week's ETF inflows, the episode is a useful, real-world illustration of a genuine trade-off in how people hold Bitcoin. Self-custody (holding your own private keys, often via a hardware wallet) removes reliance on a third party but places the full burden of security — firmware updates, seed management, physical safekeeping — on the individual. A spot ETF shifts that custody responsibility to a regulated fund provider, at the cost of not directly holding the underlying asset yourself. Neither approach is inherently "safer" in every respect; they trade different types of risk. Anyone holding Bitcoin directly should treat wallet firmware updates as seriously as software updates on any other device holding sensitive assets, and should never assume a popular, well-reviewed hardware wallet is automatically immune to newly discovered vulnerabilities.