Skip to main content
Trends & Strategy6 min read

You Did Everything Right and Still Got Breached

August 2, 2026By ChatGPT.ca Team

This week, careful people lost fortunes doing nothing wrong. Attackers drained tens of millions in Bitcoin from hardware wallets whose owners had followed every rule in the book: keys generated on a device that never touched the internet, seed phrases never shared, everything locked in safes. The flaw was not in their discipline. It was a firmware bug from 2021, baked into the tool before they bought it, that quietly weakened the secret keys the device created. It is a crypto story on the surface, but the lesson underneath belongs to every business that runs on software it did not write.

The risk that was never yours to control

Strip away the cryptocurrency and here is the shape of it: people did everything correctly and were still ruined by a weakness in code they had no way to see. That is inherited risk, and it is not exotic, it is the water every modern business swims in. You run on layers built by other people: your software, your vendors, the models behind your AI features, the platforms your operations sit on. You inherit their flaws along with their usefulness. "We followed best practices" feels like safety, but this incident makes the uncomfortable part vivid, some of the risk was never yours to manage in the first place.

Two kinds of protection, and most of us only do one

This is not an argument against best practices. They prevent the large majority of incidents, and you should keep every one of them. The argument is that prevention and resilience are different disciplines, and most businesses invest heavily in the first and barely think about the second.

PreventionResilience
Lowers the chance of a failureLimits the damage when one happens
Assumes you can keep threats outAssumes something eventually gets in
Best practices, strong controlsBackups, redundancy, no single point of failure

The wallet owners had prevention in abundance and resilience almost not at all, everything behind one mechanism, so when that one thing failed, it failed completely. That is the same reasoning behind asking whether you can undo what your AI just did: the goal is a system where one broken part is a setback, not a catastrophe.

Resilience, in plain terms

Concentration is the enemy. Resilience means not putting all of anything in one place: not all your data with a single vendor, not all your operations riding on one tool, not every critical process dependent on one system with no fallback. It means keeping backups you have actually tested rather than assumed, spreading your critical dependencies, and knowing your recovery steps before the day you need them. For the highest-stakes things, it means insisting on more than one safeguard, so that a single broken layer, a firmware bug, a vendor outage, a compromised account, is survivable rather than fatal.

Where this leaves you

Go through the critical parts of your business and ask one blunt question of each: if this tool, vendor, or system failed completely tomorrow, through no fault of ours, what would happen, and how fast could we recover? Wherever the honest answer is "we would be devastated," you have found a concentration risk worth reducing with a backup, a fallback, or a second layer. You cannot inspect every line of code your business depends on, and you never will. What you can do is make sure that no single hidden flaw in that code, whenever it surfaces, is powerful enough to take you down.

Frequently Asked Questions

What actually happened?

Attackers drained tens of millions of dollars in Bitcoin from hardware wallets whose owners had followed every best practice, keys generated on an offline device, never connected to the internet, seed phrases never shared, stored in safes. The cause was a firmware flaw dating to 2021 that quietly weakened how the device generated its secret recovery phrase, making those phrases far more predictable than intended. Attackers, reportedly aided by AI, then guessed the weakened keys offline and swept the funds. The victims did nothing wrong. The flaw was baked into the tool before they ever bought it.

Why is a crypto story relevant to my business?

Because the underlying lesson has nothing to do with crypto. It is about inherited risk: you can follow every rule and still be exposed by a flaw in code you did not write and could not have inspected. Every business now runs on layers of software and services built by other people, your tools, your vendors, the models behind your AI features. You inherit their weaknesses along with their capabilities. The uncomfortable truth this incident makes vivid is that "we followed best practices" is not the same as "we are safe," because some of the risk was never yours to control.

Does that mean best practices are pointless?

No, best practices still prevent the large majority of incidents and you should absolutely keep them. The point is subtler: prevention is necessary but not sufficient. Best practices reduce the odds of a failure; they do not eliminate the possibility of one arriving through a channel you never controlled. So the mature response is not to abandon prevention, it is to add a second layer of thinking, resilience, that assumes something will eventually get through and asks how badly that would hurt and how quickly you could recover. Doing everything right lowers the chance; resilience limits the damage.

What does resilience actually look like for a small business?

Concentration is the enemy. The wallet victims were devastated partly because everything sat behind a single point of failure. Resilience means not putting all of anything in one place: not all your data with one vendor, not all your operations dependent on one tool, not all your savings in one mechanism. It means keeping backups you have actually tested, spreading critical dependencies, and knowing your recovery steps before you need them. For higher-stakes things, it can mean requiring more than one safeguard so that one broken layer is not catastrophic on its own.

What should a Canadian business take from this?

Pair prevention with resilience deliberately. Keep doing the fundamentals, they matter. But also ask, for each critical part of your business: if this one tool, vendor, or system failed completely tomorrow through no fault of ours, what would happen, and how fast could we recover? Where the honest answer is "we would be devastated," that is a concentration risk to reduce, with a backup, a fallback, or a second layer of protection. You cannot audit every line of code you depend on. You can make sure no single failure in that code can take you down.

Build a business that survives a bad day

We help Canadian businesses pair strong prevention with real resilience, finding single points of failure and building the backups and fallbacks that contain them.

Related Articles

Trends & Strategy

Investors Are Buying Firms to Run Them With AI

August 1, 2026Read more →
Trends & Strategy

AI Agents and Your Next Software Renewal

July 30, 2026Read more →
Trends & Strategy

AI Compliance Is Becoming a Sales Advantage

July 29, 2026Read more →
AI
ChatGPT.ca Team

AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.