You Did Everything Right and Still Got Breached
This week, careful people lost fortunes doing nothing wrong. Attackers drained tens of millions in Bitcoin from hardware wallets whose owners had followed every rule in the book: keys generated on a device that never touched the internet, seed phrases never shared, everything locked in safes. The flaw was not in their discipline. It was a firmware bug from 2021, baked into the tool before they bought it, that quietly weakened the secret keys the device created. It is a crypto story on the surface, but the lesson underneath belongs to every business that runs on software it did not write.
The risk that was never yours to control
Strip away the cryptocurrency and here is the shape of it: people did everything correctly and were still ruined by a weakness in code they had no way to see. That is inherited risk, and it is not exotic, it is the water every modern business swims in. You run on layers built by other people: your software, your vendors, the models behind your AI features, the platforms your operations sit on. You inherit their flaws along with their usefulness. "We followed best practices" feels like safety, but this incident makes the uncomfortable part vivid, some of the risk was never yours to manage in the first place.
Two kinds of protection, and most of us only do one
This is not an argument against best practices. They prevent the large majority of incidents, and you should keep every one of them. The argument is that prevention and resilience are different disciplines, and most businesses invest heavily in the first and barely think about the second.
| Prevention | Resilience |
|---|---|
| Lowers the chance of a failure | Limits the damage when one happens |
| Assumes you can keep threats out | Assumes something eventually gets in |
| Best practices, strong controls | Backups, redundancy, no single point of failure |
The wallet owners had prevention in abundance and resilience almost not at all, everything behind one mechanism, so when that one thing failed, it failed completely. That is the same reasoning behind asking whether you can undo what your AI just did: the goal is a system where one broken part is a setback, not a catastrophe.
Resilience, in plain terms
Concentration is the enemy. Resilience means not putting all of anything in one place: not all your data with a single vendor, not all your operations riding on one tool, not every critical process dependent on one system with no fallback. It means keeping backups you have actually tested rather than assumed, spreading your critical dependencies, and knowing your recovery steps before the day you need them. For the highest-stakes things, it means insisting on more than one safeguard, so that a single broken layer, a firmware bug, a vendor outage, a compromised account, is survivable rather than fatal.
Where this leaves you
Go through the critical parts of your business and ask one blunt question of each: if this tool, vendor, or system failed completely tomorrow, through no fault of ours, what would happen, and how fast could we recover? Wherever the honest answer is "we would be devastated," you have found a concentration risk worth reducing with a backup, a fallback, or a second layer. You cannot inspect every line of code your business depends on, and you never will. What you can do is make sure that no single hidden flaw in that code, whenever it surfaces, is powerful enough to take you down.
Frequently Asked Questions
What actually happened?
Attackers drained tens of millions of dollars in Bitcoin from hardware wallets whose owners had followed every best practice, keys generated on an offline device, never connected to the internet, seed phrases never shared, stored in safes. The cause was a firmware flaw dating to 2021 that quietly weakened how the device generated its secret recovery phrase, making those phrases far more predictable than intended. Attackers, reportedly aided by AI, then guessed the weakened keys offline and swept the funds. The victims did nothing wrong. The flaw was baked into the tool before they ever bought it.
Why is a crypto story relevant to my business?
Because the underlying lesson has nothing to do with crypto. It is about inherited risk: you can follow every rule and still be exposed by a flaw in code you did not write and could not have inspected. Every business now runs on layers of software and services built by other people, your tools, your vendors, the models behind your AI features. You inherit their weaknesses along with their capabilities. The uncomfortable truth this incident makes vivid is that "we followed best practices" is not the same as "we are safe," because some of the risk was never yours to control.
Does that mean best practices are pointless?
No, best practices still prevent the large majority of incidents and you should absolutely keep them. The point is subtler: prevention is necessary but not sufficient. Best practices reduce the odds of a failure; they do not eliminate the possibility of one arriving through a channel you never controlled. So the mature response is not to abandon prevention, it is to add a second layer of thinking, resilience, that assumes something will eventually get through and asks how badly that would hurt and how quickly you could recover. Doing everything right lowers the chance; resilience limits the damage.
What does resilience actually look like for a small business?
Concentration is the enemy. The wallet victims were devastated partly because everything sat behind a single point of failure. Resilience means not putting all of anything in one place: not all your data with one vendor, not all your operations dependent on one tool, not all your savings in one mechanism. It means keeping backups you have actually tested, spreading critical dependencies, and knowing your recovery steps before you need them. For higher-stakes things, it can mean requiring more than one safeguard so that one broken layer is not catastrophic on its own.
What should a Canadian business take from this?
Pair prevention with resilience deliberately. Keep doing the fundamentals, they matter. But also ask, for each critical part of your business: if this one tool, vendor, or system failed completely tomorrow through no fault of ours, what would happen, and how fast could we recover? Where the honest answer is "we would be devastated," that is a concentration risk to reduce, with a backup, a fallback, or a second layer of protection. You cannot audit every line of code you depend on. You can make sure no single failure in that code can take you down.
Build a business that survives a bad day
We help Canadian businesses pair strong prevention with real resilience, finding single points of failure and building the backups and fallbacks that contain them.
Related Articles
Investors Are Buying Firms to Run Them With AI
AI Agents and Your Next Software Renewal
AI Compliance Is Becoming a Sales Advantage
AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.