Coldcard wallet flaw pushes Bitcoin holders back toward exchange custody
OKX reports record inflows after the Coldcard exploit, as Galaxy Research confirms 1,596 BTC stolen and calls grow for firmware audits.

A security failure in the Coldcard hardware wallet, now ranked among the largest known breaches of Bitcoin self-custody, has triggered a measurable shift of assets back onto centralised exchanges. OKX told The Block it has recorded record inflows since the exploit came to light, as users weigh the risks of holding their own private keys against the managed protections offered by regulated platforms.
Custody behaviour reverses post-FTX pattern
OKX Chief Compliance Officer Jonathan Brockmeier said the exchange has observed a marked change in customer behaviour since the Coldcard attacks became public. “We’re seeing record levels of inflows now to centralised exchanges post-Coldcard,” he told The Block. “It’s interesting — it’s sort of the flip side of FTX. FTX happens, and everybody moves their money into self-custody, and it’s coming back now.”
Brockmeier argued that self-custody places the entire burden of security on individual holders, whereas exchanges can deploy dedicated security teams and automated monitoring. He said OKX uses layered controls supported by artificial intelligence to flag suspicious activity before customers are affected, while still permitting clients to self-custody if they choose. According to figures the exchange shared with The Block, OKX prevented $26.3 million in scam-related losses and safeguarded more than $1.1 billion in customer assets during the first half of 2026.
Galaxy Research narrows theft figures
The scale of the underlying incident has been detailed by Galaxy Research, which said on 4 August that it has confirmed the theft of 1,596 BTC from roughly 7,300 addresses across three verified attack waves linked to flawed seed generation on Coldcard devices. The firm said the total could rise to around 2,055 BTC — close to $130 million at current prices — should a fourth suspected wave receive enough confirmation from affected wallet owners.
Earlier blockchain analysis had pointed to larger on-chain figures across four observed waves, but Galaxy said it narrowed its confirmed numbers after separating verified victim reports from raw blockchain observations. The researcher added that investigators are continuing to refine address mapping in coordination with exchanges, cyber-investigation groups and US law enforcement agencies. Notably, around 90% of the stolen Bitcoin has not moved since the attacks, giving investigators an extended window to track the funds if they are eventually routed through exchanges or other services.
Pressure builds for firmware scrutiny
The episode has renewed calls from security researchers for independent testing of hardware wallet firmware and seed-generation processes, an area of the crypto industry that has largely relied on vendor self-certification. For a sector courting institutional and retail savers alike on the promise of self-sovereign custody, a flaw of this scale in a widely used device raises pointed questions about how such assurances are verified in practice.
The shift back toward exchange custody, however temporary, illustrates how quickly confidence in decentralised storage can erode when a single hardware vulnerability is exposed — even as regulators and industry bodies have spent recent years pushing custody standards in the opposite direction, encouraging users away from centralised platforms after collapses such as FTX.
Read more: Coldcard drain nears $89m, reviving debate over Bitcoin self-custody risk


