The theft of an estimated $130 million in Bitcoin from Coldcard hardware wallet users is putting cybersecurity back in the spotlight, reinforcing the long-term case for ETFs tracking companies that protect digital infrastructure.
Hackers exploited a flaw in how certain Coldcard devices generated seed phrases, letting them reconstruct recovery keys and drain wallets designed to stay offline. It’s the latest in a wave of crypto hacks — TRM Labs counts over 200 incidents and nearly $950 million in losses this year, while Blockaid puts first-half 2026 losses above $1 billion.
The takeaway for investors: escalating attacks keep driving demand for enterprise cybersecurity, a tailwind for cybersecurity-focused ETFs.
Cybersecurity ETFs Remain Strong Performers
The following ETFs provide exposure to an industry expected to benefit from sustained increases in global cybersecurity spending:
- The First Trust NASDAQ Cybersecurity ETF (NASDAQ:CIBR), the largest cybersecurity ETF with roughly $13 billion in assets, has gained about 36% year to date, reflecting investor confidence in the sector’s durable earnings outlook. The fund’s largest holdings include Crowdstrike Holdings Inc (NASDAQ:CRWD), Palo Alto Networks Inc (NASDAQ:PANW), Fortinet Inc (NASDAQ:FTNT), and Cisco Systems Inc (NASDAQ:CSCO), companies providing endpoint security, network protection and identity management. The fund gained 7% since the hacking update came on Sunday evening.
- The Amplify Cybersecurity ETF (NYSE:HACK), managing roughly $2.6 billion, has advanced about 42% this year. Its portfolio includes CrowdStrike, Palo Alto Networks, Check Point Software Technologies Ltd. (NASDAQ:CHKP) and Fortinet, offering diversified exposure to cybersecurity software and services. The fund has gained more than 6% since Monday.
- The Global X Cybersecurity ETF (NASDAQ:BUG), with assets exceeding $1 billion, has climbed roughly 33% in 2026. The fund emphasizes cloud-native security providers such as Cloudflare Inc (NYSE:NET), Zscaler Inc (NASDAQ:ZS), Okta Inc (NASDAQ:OKTA) and SentinelOne Inc (NYSE:S), alongside established cybersecurity leaders. The fund is up almost 8% since the
Hardware Attacks Raise the Stakes
Unlike many crypto thefts that exploit exchange vulnerabilities or phishing schemes, the Coldcard incident targeted the hardware wallet itself.
Security researchers said attackers took advantage of a flaw in the wallet’s seed phrase generation process, allowing them to predict recovery phrases rather than break encryption or physically access devices. Victims who kept wallets permanently offline and securely stored recovery phrases were still affected, highlighting how vulnerabilities can emerge at the hardware and firmware level.
A Long-Term Tailwind for Cybersecurity
Every major cyberattack tends to reinforce spending on security technologies, particularly in sectors handling sensitive financial data.
Companies such as CrowdStrike, Palo Alto Networks, CyberArk, Fortinet, Zscaler and Okta, all prominent holdings across leading cybersecurity ETFs, are positioned to benefit as financial institutions, cryptocurrency firms and enterprises invest more heavily in identity security, endpoint protection, threat intelligence and cloud security.
The Coldcard breach, combined with more than $1 billion in crypto losses this year, adds to a steady stream of incidents that support one of the technology sector’s strongest secular themes. This can act as a steady fuel for cybersecurity ETFs.
Photo:Shutterstock
Recent Comments