Bitcoin: "Private keys are the original sin of crypto"
The first person who, having enclosed a piece of land, thought to say: This is mine, and found people simple enough to believe him, was the real founder of civil society. To possess your keys is to possess your bitcoins. This formula has been circulating in the ecosystem for years, wielded as the ultimate argument against centralized exchanges. However, this week, it is precisely this promise that has exploded mid-air.
The exploit that emptied thousands of Coldcard addresses has reminded us how a private key remains, despite all the hardware wallets in the world, a single point of failure. For Ido Ben-Natan, head of the security company Blockaid, this is not a mere accident: it is the original sin of all crypto.
An exploit emptied thousands of Coldcard addresses, revealing a flaw in the generation of recovery phrases, causing estimated losses of over $130 million.
Nearly 75% of crypto losses in 2026 were caused by private key compromises, highlighting the danger of a single point of failure.
The Coldcard is designed for one mission, to keep private keys out of reach of the Internet. The affected versions, running on firmware from 4.0.1 to 5.0.3, nevertheless allowed a flaw to slip through. It did not reside in the connection, but in the generation itself of the recovery phrases (seed phrase in English).
Instead of relying solely on the device's hardware random number generator, some of the affected devices switched to Yasmarang, a deterministic software generator derived from MicroPython, which is significantly less unpredictable. A simple detail was enough to turn everything upside down.
Attackers were thus able to reconstruct entire seeds, and therefore the private keys they protect, without ever physically touching a single device.
Galaxy Research estimated Friday that confirmed losses were at least $111 million, with a projection of over $130 million once all transactions are analyzed. K33, for its part, lists more than 7,000 targeted addresses, and Galaxy mentions "several distinct malicious actors" actively exploiting the flaw in parallel.
A figure that has continued to rise since the initial estimates: the firm Coinkite had initially mentioned 594 BTC diverted in 25 minutes, before the toll doubled in four days.
It is in this context that Ido Ben-Natan detailed his reading of the incident to The Block on Friday. His argument can be summarized in one sentence. Relying access to an asset on a unique secret, historically inherited from the password and then the private key, mechanically creates a single point of failure.
"There is a beauty in the fact that no one else can access these assets. The difficulty is that it remains a single point of failure."
Blockaid, which provides real-time monitoring services to wallets and exchanges such as MetaMask, Coinbase Wallet, Uniswap, and Stellar, quantified the extent of the phenomenon in its first half report: nearly 75% of funds lost during crypto exploits between January and June 2026 come from private key compromises. A semester already labeled as the most attacked in history, with over a billion dollars vanished. The figure speaks for itself.
Ben-Natan goes further by pointing out artificial intelligence as an accelerator of the phenomenon.
"Very soon, everyone on this planet will have access to one of the best hackers in the world, at their fingertips."
His recommendation contrasts with the usual discourse of the sector:
"Leaving your assets somewhere and forgetting about them is not really the solution, because the pace of security is constantly evolving. You either have to remain paranoid all the time or delegate this decision-making to someone else."
The case reignites a debate that the ecosystem usually prefers to avoid. The hardware wallet has long been marketed as the definitive answer to the risk of hacking, the physical barrier that keeps keys out of reach of any remote attacker. The Coldcard episode shows that this barrier is only as strong as the code that generates the key upstream, a software link as fallible as any other.
Holders who protected their seed with an additional phrase (passphrase BIP-39, a secret that the user adds themselves and is never stored on the device) have largely remained unscathed. A detail that shifts the question from blind trust in hardware to a more active security hygiene of the user themselves.
The incident comes during a black week for the security of the Bitcoin ecosystem, amid alerts on payment servers and governance debates on the network, two distinct issues that nonetheless pose the same fundamental question.
The real line of fracture no longer lies between clean custody and hardware wallet, but between active and permanent vigilance, and the assumed delegation of this responsibility to a trusted third party.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

DEBIT Airdrop Guide: How to Share 50,000 USDT Rewards on WEEX

What is Bitlayer (BTR)? What Happened with Bitcoin Bridge?

How to Have Internet Abroad Without Spending Hundreds of Dollars: The Difference Between eSIM and Roaming

Chrome and Chromium Test Flatpak to Expand Their Reach on Linux

Ethereum Excites Me More Than Bitcoin: Interesting Situation on the Chart and ETF Fund Data

Swvl Raises $13 Million Led by Coefficient Backed by the Sawiris Family

Controversial Influencer Launches Meme Coin, Hype Fades Quickly

Ethereum Trader Returns: Buys $5.33 Million After $12 Million Loss

AI is in a Credit Expansion Phase: The Stronger AI Becomes, the More the Federal Reserve Needs to Cut Rates

Chinese Naval Activity Near Taiwan Sets Record for Third Consecutive Month

Hawk Fire Forces Evacuation of 90,000 People Near Reno

Institutional Cryptocurrency Trading Reaches Record 72%: Major Players Smooth Market Volatility

Solana Burn Surges to 87,000 SOL: Does This Change Token Scarcity?

Cryptocurrency Exchange in Russia: Top 3 Services for 2026

Top 20 Cryptocurrencies: New Market Leaders and the Battle for Infrastructure

The US approved high-leverage Bitcoin trading while crypto founders remain legally blocked from raising funds

Central Bank Explains Cryptocurrency Exchange for Russian Securities

Hacker Who Leaked GTA 6 Created a Coin, Soared 20 Times in a Day

CVM Brings Tokenization Agenda to NYSE, Nasdaq, and SEC

Russia Strikes 'Aurora' Distribution Center Twice

Ethereum Accelerates Work on zkEVM Security Ahead of December Deadline

How Big is Iran's Cryptocurrency Market Really? Tracing Billions of Dollars of Iranian Money on the Blockchain

Houthi Claims Drone Attacks on Najran Airport and Aramco

If an Iranian Exchange Goes Bankrupt, Is the User the Owner of the Assets or a Creditor?

Evergrande Founder Sentenced to Life in Prison in China

Why Moderna (MRNA) Stock More Than Doubled: The INTerpath-001 Cancer Vaccine Result, Explained
Moderna shares more than doubled on 19 August 2026 after Merck and Moderna said the Phase 3 INTerpath-001 trial of intismeran autogene plus KEYTRUDA met its recurrence-free survival endpoint in resected melanoma. This page explains what the result is, why the stock reacted this hard, what is still unknown, which dates come next (presentation and earnings, both unconfirmed), and what a trader can actually do on WEEX — which does not list Moderna; the nearest instrument is the XBI-USDT biotech ETF perpetual. No price targets, no forecasts.

Who is Certifying the Crypto Industry Amid the Regulatory 'Vacuum' in the U.S.?

Moscow Exchange Launches Perpetual Futures for Bitcoin and Ethereum

Pressure for Redemptions Grows in $2 Trillion Private Lending Market










