An exploit drained thousands of Coldcard addresses by targeting a flaw in seed phrase generation, causing losses estimated at over $130 million according to Galaxy Research, which recorded more than 7,000 targeted addresses exploited by multiple distinct malicious actors. The head of security firm Blockaid, Ido Ben-Natan, called private keys the « original sin » of crypto, arguing that relying on a single secret creates a single point of failure by design. Nearly 75 % of funds lost to crypto exploits in the first half of 2026 came from private key compromises, out of a total exceeding one billion dollars, making it the most attacked semester on record. Holders who added an extra passphrase (BIP-39 passphrase) to their seed were largely spared, highlighting the need for proactive security hygiene beyond blind trust in hardware.
Source: Read the original article

