At first I assumed most Bitcoin-in-DeFi talk focuses on the holder. What about the chains that need security?
That's the side of Babylon I find more interesting. New proof-of-stake networks have a hard cold-start problem: their security is only as strong as the value staked, and early on there just isn't much. So they inflate their own token to bribe validators, which dilutes everyone and rarely lasts.
Babylon's pitch to a builder is different tap into Bitcoin's idle capital for economic security, instead of printing your own. If that works, a new chain could borrow real weight from day one.
Big "if," though. It only holds if slashing is actually enforceable and if enough BTC shows up to matter. Unproven demand is still just a whiteboard.
Still, for builders, the problem it targets is very real.
Are the chains you follow secured by native tokens, or would borrowed BTC security change how you trust them?
"I Did Everything Right": The Coldcard Hack and the Limits of Cold Storage
A hardware wallet exists to make one promise. Keep your Bitcoin keys on a device that never touches the internet, and no attacker on the far side of the world can reach them. For most of the last decade, that promise held. Over the past week, for thousands of Bitcoin holders, it broke. Beginning July 30, an attacker started sweeping $BTC out of wallets secured by Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. There was no phishing email. No malware. No stolen device. The keys were guessed from the outside, and the funds were gone before most victims knew anything was wrong. By the latest count from Galaxy Research, roughly 1,816 BTC, worth around $116 million, has been drained from more than 5,200 addresses. Some blockchain analysts put the running total closer to $130 million. This is now widely described as the worst self-custody failure in Bitcoin's history, and that framing is the real story here, bigger than the dollar figure. What actually happened The mechanics matter, so let me walk through them plainly. The flaw did not live in Bitcoin. It lived in a single firmware release Coldcard shipped back in March 2021. A build configuration error caused the device to generate wallet seeds using a predictable software random number generator instead of the dedicated hardware chip that was supposed to supply true randomness. In plain terms, the part of the process that is meant to be impossible to guess became, for affected devices, guessable. The consequence was brutal. A properly generated seed carries around 128 bits of strength, a number so large that brute-forcing it is effectively impossible with any computer that exists. On the affected Coldcard devices, that strength collapsed to as little as 40 bits on older models. Forty bits is not impossible. Forty bits is a weekend for modern computing power. An attacker who could narrow down a few device details could reproduce the "random" seed offline, reconstruct the private key, and sweep the wallet, all without ever touching the physical device sitting in someone's safe. The theft came in waves. The first sweep on July 30 moved hundreds of Bitcoin out of roughly 500 wallets in about twenty-five minutes. The largest single sweep, according to Galaxy Research, took 1,082 BTC from 1,196 addresses inside a 41-minute window. At least four waves followed over the days after, each one draining hundreds more addresses, with fresh sweeps still moving through the network as researchers were writing up their assessments. This was not a smash-and-grab. It was methodical, and it was patient. Who is exposed, and who is safe If you hold Bitcoin on a Coldcard, the details are worth knowing exactly, because the risk is not uniform. The vulnerability affects certain Mk3 devices set up on firmware version 4.0.1 or later, and Mk4, Mk5, and Q devices running older firmware. Crucially, wallets created using the manual dice-roll option, where the user supplies their own entropy by physically rolling dice, are considered safe. That detail is almost poetic. The people who trusted the machine least were the ones the machine could not betray. Two hard truths for affected users. First, simply updating the firmware does not fix a seed that was already generated with weak randomness. The patch protects future seeds, not existing ones. Anyone on an affected setup has to update the device, generate an entirely new seed, and move every coin to fresh addresses derived from it. Second, this is a #Coldcard-specific problem. Ledger, Trezor, and Block, the maker of Bitkey, have all confirmed their devices use different entropy methods and are not affected by this particular flaw. #SelfCustody is not the thing that failed here. One implementation of it did. The human cost behind the numbers Numbers this large go abstract fast, so hold onto one person. A Canadian entrepreneur named Jonathan Goodman posted that roughly $1.6 million in Bitcoin left his wallet on the night of July 29. He kept his Coldcard in a safety deposit box. It had never connected to the internet. He never shared his seed phrase. By every checklist the community has ever published, he was a model of good practice. His summary was four words: "I did everything right." The post was viewed millions of times, and it landed so hard because so many people recognized themselves in it. That is why this incident cut deeper than its dollar value suggests. Coldcard's user base skews toward exactly the people who went out of their way to learn Bitcoin security properly, not casual holders. When a five-year-old bug can sit undetected inside a well-regarded device and defeat someone who followed every rule, it forces an uncomfortable question that no amount of best-practice advice fully answers: what can self-custody actually promise? #CryptoSecurity as a field just got a very expensive reminder that the threat model has to include the tool itself. The response, and the friction Coinkite moved quickly on the messaging. Its CEO, Rodolfo Novak, told users on July 31 to move their funds immediately using updated best practices, before reading anything else. The company released patched firmware and says it is assisting victims. As of the latest reporting, it has not offered compensation. Novak also floated a theory that drew pushback, suggesting artificial intelligence might now be capable of surfacing dormant bugs like this one. Security researchers largely pointed the finger elsewhere, at ordinary human engineering error in a 2021 build. Whichever explanation you find more convincing, the practical lesson is the same. A dependency you cannot see, buried in a firmware release half a decade old, was load-bearing for real money the entire time. Why the market barely blinked Here is the part that tells you something about where crypto is in 2026. Through all of this, Bitcoin's price hardly moved, holding around $64,000 the entire week. A nine-figure theft from a trusted wallet in years past might have rattled the whole market. This time, #Bitcoin absorbed it and kept trading flat. That calm is double-edged. On one hand, it shows a maturing market that no longer panics at every security headline, one that correctly understood this was a vendor-specific flaw and not a crack in Bitcoin itself. On the other, social sentiment readings fell to some of their most negative levels on record even as the price held. The fear did not show up on the chart. It showed up in the confidence of the people who hold the asset, which is a harder thing to measure and a slower thing to rebuild. The takeaway I am not going to turn this into a sales pitch for one product over another, and I would be skeptical of anyone who does. The honest lessons are less dramatic and more durable. Randomness is the foundation everything else in a wallet rests on, and most users never think about it because they are never supposed to have to. Where it is offered, supplying your own entropy through dice rolls removes a layer of blind trust. For larger holdings, a multisignature setup that spreads keys across different devices and vendors means no single firmware bug can drain everything at once. And "set it and forget it" is quietly dangerous in an asset that settles with finality, because there is no chargeback and no support line that reverses an on-chain sweep. The Coldcard hack did not break Bitcoin. It broke an assumption, the quiet belief that once your coins are in cold storage, the thinking is done. That is the piece of this #CryptoNews worth sitting with. Self-custody remains the right goal for a lot of people. This week was a reminder that it is a practice, not a purchase. Did this change how you think about hardware wallets, or is it a one-vendor problem to you? Tell me below.