During the FTX collapse, users rushed to withdraw their coins; after this $89 million Coldcard vulnerability incident, some Bitcoin has instead flowed back into exchanges.
Given the same security panic, why are funds moving in opposite directions?
Transferring coins back to the exchange does not equate to an immediate sale, nor should it be crudely interpreted as a collective market bearish sentiment. It is more akin to a contingency-driven “switching operation”: when users begin to doubt the security of their devices, private key management, signing processes, or recovery pathways, centralized platforms—once viewed as sources of risk—can quickly become convenient hubs for freezing, coordinating, and managing assets. (Event material, August 2)
Over the past few years, "Not your keys, not your coins" has become one of the most deeply ingrained risk education mottos in the crypto industry. However, the Coldcard incident has brought to light another, more complex question: If you hold your own private key, does that necessarily mean your assets are under your control?
The answer is clearly not that simple.
Self-custody narratives have not been invalidated, but they have undergone an extremely realistic stress test. The premise that users retain control assumes they still trust their signing environment, backup mechanisms, and operational chain. Once this chain is compromised, what many users need first is not philosophical "absolute sovereignty," but a place where they can quickly access their assets, receive support, and execute or convert transactions when necessary.
Funds flowing back to the exchange change the order of disposition.
The facts currently confirmed are not complex: the Coldcard-related vulnerability involved approximately $89 million; following the incident, there were signs of Bitcoin flowing back to exchanges. (Event materials, August 2)
The existing materials do not provide clear answers regarding which technical entry point caused the vulnerability, the extent of affected wallets, how the assets were ultimately handled, or the full scale of this fund flow. At this stage, hastily categorizing it as a specific attack pattern or assuming all addresses that transferred funds to exchanges originated from compromised users is premature.
However, fund movements have already revealed a shift in risk prioritization.
When a self-custodied user suspects issues with their device, mnemonic backup, address management, or transaction confirmation pipeline, they may not immediately sell their assets. Instead, they might prefer to consolidate their holdings into a more accessible location, pause activity on their original wallet, split addresses, switch custody solutions, or even maintain an exit route to quickly convert part of their assets. At this point, the exchange provides not just order matching, but a centralized asset orchestration interface.
This stands in stark contrast to the FTX era.
At that time, the market was concerned about whether the platform would return funds, whether customer assets were still secure, and whether the centralized custodian had the ability to meet its obligations. Withdrawing funds was the most direct way for users to protect themselves. The risks exposed by the Coldcard incident, at least for now, stem more from the user side of the custody chain: when users can no longer be confident that they still control a secure signing environment, exchanges temporarily shift from being objects of suspicion to emergency channels.
The exchange risk has not disappeared; it has simply been pushed behind another risk.
A common mistake in the crypto market is viewing risk as a multiple-choice question: self-custody versus custodial. In reality, it’s more like a bill—listing device risk, operational risk, counterparty risk, and liquidity risk—where users can only decide which cost to pay first.
Self-custody and platform custody entail two distinct sets of responsibilities.
The Coldcard incident struck at the weakest points of each of the two security models.
The appeal of self-custody is clear: users generate and control their own keys, decide independently when to transfer assets, bypass platform approvals, and avoid placing full trust in intermediaries. Control is transparent, rules are open, and users determine where their assets go.
The cost is equally clear: device damage, failed backups, human error, compromised signing environments, and vulnerabilities in the software supply chain—all ultimately result in losses borne by the user themselves. In normal times, this is called freedom; when an incident occurs, it quickly becomes an exam of personal operational and emergency response capabilities.
Exchange custody offers a different set of trade-offs. Users surrender some control in exchange for account management, trading interfaces, asset allocation, customer support, and a relatively mature risk management system. At the same time, users must accept withdrawal rules, account verification, service limitations, and potential operational, security, and liquidity issues that may arise with the platform itself.
The Coldcard incident left both sides unhappy.
The most urgent task for self-custody products and related services is not to repeat again that “you control your private key,” but to clearly define the risk boundaries: Is the issue with key generation, signature confirmation, recovery processes, software supply chain, or the user interface? How should users conduct their own checks? Which assets need to be migrated? And after migration, how should old addresses be isolated and backups updated?
The explanation is unclear; "self-custody" can easily be perceived by users as a slogan that sounds原则上 correct but lacks a practical solution when things go wrong.
The exchange also has no grounds to easily celebrate the return of funds. While increased existing assets and active users undoubtedly present liquidity opportunities, they also bring greater responsibilities—including identifying unusual transfers, strengthening account risk controls, managing withdrawal arrangements, and handling user appeals. If rules are too strict, genuinely urgent users may be locked out; if too loose, the platform’s own risk exposure will expand.
Disputes have never been just about “whether decentralization is right.” The more pressing question is: who ultimately bears the cost of security friction? Users don’t want to be restricted at every step, platforms are reluctant to accept assets with unclear origins and risks, and service providers must rebalance usability with security overhead.
Don't rush to watch the price—first pay attention to changes in the four types of funds and the rules.
The first thing to clarify is the scope of the incident's impact.
Who is affected, what conditions trigger the risk, and how to investigate and resolve it—this information is more important than any short-term emotion. Clear scope enables users to determine whether they need to migrate their assets or simply update their security settings. Ambiguous information amplifies panic and forces funds that don’t need to be moved into the same channel.
Next, let’s examine whether the capital inflow was merely a brief, emergency response.
A concentrated inflow into exchanges during a certain period may simply reflect users making room to dispose of their assets. Only when this flow persists does it more closely indicate the market repricing of self-custody practices. More meaningful than the absolute volume is the subsequent destination: are these coins being withdrawn to new addresses, remaining on the exchange, or being converted into other assets?
The platform’s service boundaries will soon be clarified. Withdrawal processing speed, review of abnormal transfers, account restriction policies, and customer support responsiveness all influence whether users are willing to entrust their assets to a custodian. “Exchange inflows” are not merely a simple indicator of price movements; after a security incident, it’s far more important for the platform to clearly communicate and consistently enforce its rules than to attract a large volume of assets.
A self-custody ecosystem must provide verifiable remediation and migration pathways. Generic warnings like “be careful” are not enough. Users need actionable checklists: how to identify risks, how to migrate assets, how to isolate addresses, and how to update backups. Security products can be complex, but they cannot leave users with nothing more than four words after an incident: “stay vigilant.”
The responsibility for custody has been re-priced.
The lesson FTX left for the market is that holding assets on a platform does not automatically make them safe.
The Coldcard incident offers a stark counter-reminder: holding your private key does not mean the risk has disappeared.
The former refers to counterparty risk, and the latter refers to instrument and operational risk. Mature asset management should not treat centralized and self-custody as ideological labels, but rather acknowledge that different scenarios require distinct risk isolation strategies.
Over the coming weeks, the market will provide more specific answers: whether the scope of the incident can be clearly disclosed, whether funds flowing back to exchanges will continue, whether platform service rules will be tightened, and whether self-custody sides can deliver actionable and verifiable migration and remediation plans.
When a security incident occurs, the path assets take and who bears responsibility along that path is harder to ignore than the day’s Bitcoin price.

