U.S. spot Bitcoin ETFs attracted $754.69 million in the week ending August 7, marking their strongest weekly performance since April, according to SoSoValue . BlackRock's iShares Bitcoin Trust (IBIT) dominates every inflow surge. IBIT alone grabbed $319 million of a $499 million weekly total in late July
. The broader seven-day streak from mid-July pulled in roughly $981 million total
.
Context matters heavily here. July's ETF recovery covers only about 15% of June's $4.76 billion in net outflows, meaning institutional demand is returning but has not yet reversed the broader 2026 drawdown .
The on-chain and ETF data have created a genuine debate among analysts with credible arguments on both sides.
Arguments for a durable recovery:
Arguments for tactical positioning:
The consensus among more cautious analysts is that the data offers bullish divergence but not a confirmed bottom — the absence of a clear fundamental catalyst keeps conviction at "medium" .
Starting July 30, 2026, an attacker exploited a permanent firmware bug in Coldcard hardware wallets (manufactured by Canadian firm Coinkite) to drain roughly 1,816 BTC (~$116 million) from over 5,200 individual addresses across four waves .
Root cause: A firmware integration error introduced in March 2021 (version 4.0.0) caused the device to bypass its dedicated hardware randomness chip under certain conditions . Seed entropy collapsed from 128 bits to as low as ~40 bits — making seeds trivially brute-forceable from the outside without physical access, phishing, or malware
.
Execution: The attacker drained 1,196 addresses in just 41 minutes on July 30, taking 1,082.65 BTC (~$70.2 million at the time) in the first wave . Galaxy Research mapped the on-chain sweep and tied it conclusively to the firmware flaw
.
Broader implications: This is the largest hardware wallet exploit on record and severely undermines the "cold storage is unhackable" narrative. Coinkite confirmed the bug, apologized publicly, halted shipments, and released emergency firmware fixes . However, seeds generated on affected Mk2 and Mk3 firmware remain permanently compromised — installing the patched firmware does not protect old addresses
. Users must create entirely new seeds on fixed firmware before moving funds
.
Market context: The theft occurred during the whale/ETF accumulation phase but represents only ~0.009% of Bitcoin's market cap — insufficient on its own to move price. However, it has severely eroded confidence in hardware wallet security at a sensitive moment for the market .
Bitcoin is in a divergent accumulation phase: institutional and whale buyers are absorbing supply from fearful retail holders and from the forced selling created by the Coldcard exploit. ETF inflows have reversed sharply but remain well below the levels needed to offset prior losses. The Coldcard hack is a severe reputational blow to hardware wallet security but a modest direct market impact. Whether this configuration signals a durable recovery or a tactical bear-market rally remains the central unanswered question, with credible arguments and data on both sides.