Bitcoin: "Private keys are the original sin of crypto"
The first person who, having enclosed a piece of land, thought to say: This is mine, and found people simple enough to believe him, was the real founder of civil society. To possess your keys is to possess your bitcoins. This formula has been circulating in the ecosystem for years, wielded as the ultimate argument against centralized exchanges. However, this week, it is precisely this promise that has exploded mid-air.
The exploit that emptied thousands of Coldcard addresses has reminded us how a private key remains, despite all the hardware wallets in the world, a single point of failure. For Ido Ben-Natan, head of the security company Blockaid, this is not a mere accident: it is the original sin of all crypto.
An exploit emptied thousands of Coldcard addresses, revealing a flaw in the generation of recovery phrases, causing estimated losses of over $130 million.
Nearly 75% of crypto losses in 2026 were caused by private key compromises, highlighting the danger of a single point of failure.
The Coldcard is designed for one mission, to keep private keys out of reach of the Internet. The affected versions, running on firmware from 4.0.1 to 5.0.3, nevertheless allowed a flaw to slip through. It did not reside in the connection, but in the generation itself of the recovery phrases (seed phrase in English).
Instead of relying solely on the device's hardware random number generator, some of the affected devices switched to Yasmarang, a deterministic software generator derived from MicroPython, which is significantly less unpredictable. A simple detail was enough to turn everything upside down.
Attackers were thus able to reconstruct entire seeds, and therefore the private keys they protect, without ever physically touching a single device.
Galaxy Research estimated Friday that confirmed losses were at least $111 million, with a projection of over $130 million once all transactions are analyzed. K33, for its part, lists more than 7,000 targeted addresses, and Galaxy mentions "several distinct malicious actors" actively exploiting the flaw in parallel.
A figure that has continued to rise since the initial estimates: the firm Coinkite had initially mentioned 594 BTC diverted in 25 minutes, before the toll doubled in four days.
It is in this context that Ido Ben-Natan detailed his reading of the incident to The Block on Friday. His argument can be summarized in one sentence. Relying access to an asset on a unique secret, historically inherited from the password and then the private key, mechanically creates a single point of failure.
"There is a beauty in the fact that no one else can access these assets. The difficulty is that it remains a single point of failure."
Blockaid, which provides real-time monitoring services to wallets and exchanges such as MetaMask, Coinbase Wallet, Uniswap, and Stellar, quantified the extent of the phenomenon in its first half report: nearly 75% of funds lost during crypto exploits between January and June 2026 come from private key compromises. A semester already labeled as the most attacked in history, with over a billion dollars vanished. The figure speaks for itself.
Ben-Natan goes further by pointing out artificial intelligence as an accelerator of the phenomenon.
"Very soon, everyone on this planet will have access to one of the best hackers in the world, at their fingertips."
His recommendation contrasts with the usual discourse of the sector:
"Leaving your assets somewhere and forgetting about them is not really the solution, because the pace of security is constantly evolving. You either have to remain paranoid all the time or delegate this decision-making to someone else."
The case reignites a debate that the ecosystem usually prefers to avoid. The hardware wallet has long been marketed as the definitive answer to the risk of hacking, the physical barrier that keeps keys out of reach of any remote attacker. The Coldcard episode shows that this barrier is only as strong as the code that generates the key upstream, a software link as fallible as any other.
Holders who protected their seed with an additional phrase (passphrase BIP-39, a secret that the user adds themselves and is never stored on the device) have largely remained unscathed. A detail that shifts the question from blind trust in hardware to a more active security hygiene of the user themselves.
The incident comes during a black week for the security of the Bitcoin ecosystem, amid alerts on payment servers and governance debates on the network, two distinct issues that nonetheless pose the same fundamental question.
The real line of fracture no longer lies between clean custody and hardware wallet, but between active and permanent vigilance, and the assumed delegation of this responsibility to a trusted third party.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Wildberries owes sellers $240 million after warehouse attacks

Robinhood AMC tokens expose limits of short squeezes

AI: Anthropic now aiming for mid-October for its IPO

BCRA Halts Dollar Purchases for the Third Time This Year, Ending a Streak of 27 Consecutive Positive Sessions

AI vs Human Crypto Trading Rewards on WEEX in Sep 2026

Is AI Trading Real or Hype? WEEX AI Wars II Explained

Bitcoin Emerges as a 'Safe Haven' in the Middle East Amid Iran Conflict, Says BPI Analysis

Liquid's Attackers Called Themselves White Hats, Ledger's CTO Isn't Buying It

OpenAI's GPT-6 Astra Is Shockingly Good at Almost Everything

Inside the 15-minute trading pulse that moves $14 billion in Bitcoin perpetual futures

Hargreaves Lansdown Launches Cryptocurrency ETNs for UK Investors

Robinhood Chain activity is mostly ‘degen flow,’ ARK researcher says

Changes in ARCA's Monotributo for September 2026: New Payment Schedule and Quota Scale

Copy Trading: How Does It Work in 2026?

PostGREShell: flaw in PostgreSQL turned backup accounts into backdoors

Namelaka Confectionery in Kyiv Temporarily Closed Due to Employee Poisoning

Should You Invest in Cryptocurrency in 2026-2027: New Rules, Risks, and a Reasonable Portfolio Share

MEME1 Price Prediction After 1,000x Pump: Overvalued or More Upside?

TOKEN2049: Exclusive Info and Promo Code

Bitcoin Price Ahead of Jobs Report: Has Crypto Already Priced In the Fed's Next Move?

Robinhood put stocks on a permissionless blockchain- memecoin traders are stress-testing what happens next

Ukraine exported 646 thousand tons of sugar, increasing shipments by 11%

Bitcoin’s 316-day hashrate drought shows why AI could make this mining downturn harder to reverse

Wall Street Dialogues: Long Rates Challenge Scott Bessent and Trigger Global Alert, What Will the Fed Do?

Tuven Chain: A New Solution to the Gas Fee Payment Dilemma and Analysis of Related Security Risks

Chainlink brings US economic data to 10 blockchains

Where Should Global Crypto Platforms Report CARF? An Analysis of Reporting Nexus Rules

A Practical Guide to FOMO: How to Find People and Coins in Social Trading?

Latest Non-Farm Payroll Forecast: Job Growth May Slow, Fed Faces Complex Choices








