How to Buy Bitcoin Safely After a Week of Hacks: What Liquid, Symbiosis, Revolut and Coldcard Got Wrong
Three separate Bitcoin failures hit in seven days, and each one broke at a completely different point in the chain between buyer and coin. Which layer you trust determines whether you were safe or wiped out.
This post may contain links from our sponsors and affiliates, and Flywheel Publishing may receive compensation for actions taken through them.
Three separate failures hit Bitcoin (CRYPTO: BTC) in seven days. Attackers drained $320 million from a sidechain, minted 46.1 billion fake tokens on a cross-chain bridge, and tricked a bank into handing over customer passports and full Bitcoin transaction histories.
One came from broken code, one from a broken contract, and one from a bank that fell for a fake email. So how to buy Bitcoin safely depends on who you let hold the coins.
Each of the Three Failures Broke at a Different Point

Attackers drained Blockstream’s Liquid sidechain on September 6. A bug in the Elements range-proof cache let them create L-BTC with no Bitcoin behind it and swap it for real Bitcoin. Close to 4,000 BTC, worth about $320 million, left the federation wallet in a single transaction.
The attackers sent 3,400 BTC back the next day once Blockstream patched the bridge nodes, then demanded a 10% bounty on the remaining 598.5 BTC and threatened Liquid users with a 15% loss. Blockstream refused, so roughly $47 million is still gone. However, the fix for that bug had been public on GitHub since September 1, five days before anyone used it, and no software update ever carried it to the computers running Liquid.
Symbiosis broke three days later, and it broke for a different reason. At 04:28 UTC on September 11, an attacker exploited its BridgeV2 contract and minted roughly 46.1 billion fake syBTC, more than 2,000 times every Bitcoin that will ever exist. However, only 4.39 WBTC sold through Uniswap before the market worked out what the tokens were, netting about $336,000. Symbiosis recovered 15 BTC, offered a 20% bounty, and left its Bitcoin bridge paused.
Revolut disclosed on September 12 that attackers had built a domain to look like an official law-enforcement portal and used it to request customer files. The bank handed over passports, selfies, IBANs, and full Bitcoin transaction histories on high-net-worth accounts. Every Revolut customer kept the coins they held. However, a transaction history tells a phisher how much a customer holds and which addresses to hit, which makes the next attempt the dangerous one.
The Three Ways to Buy Bitcoin Carry Three Different Risks

A spot Bitcoin ETF gives a buyer shares in a fund that holds the coins for them. iShares Bitcoin Trust (NASDAQ:IBIT) held 99.93% of its assets in Bitcoin through a custodian as of March 14, 2026, on a 0.33% expense ratio, and sponsor fees across the category start at 0.25%.
Only one failure from those seven days could reach a shareholder, and that is a breach at the custodian. Coinbase custodies most of the U.S. spot ETF market, so a breach there would hit almost every fund at once.
A regulated exchange holds the coins on its own balance sheet, so a collapse there takes customer coins down with it. Two-factor authentication through an app beats a text message, because a SIM swap defeats SMS in an afternoon. An exchange works for buying, and makes a poor vault for a balance worth stealing
Self-custody cuts every other party out, and the holder carries every mistake alone. The seed phrase belongs on metal, never on paper and never on a screen. The holder never types it into a device that has touched the internet, and tests the recovery before the wallet holds anything worth losing. Hardware wallets fail too, as Coldcard owners found out in August when a firmware flaw cost them $70 million.
Every Safe Buy in 2026 Starts With Checking the Address Bar

Revolut’s attackers won because they owned a domain that looked like Revolut’s. The same trick works against every exchange and wallet vendor a customer might expect to hear from, which makes the browser address bar the only link worth trusting. A small test transaction on every new setup costs a few cents and catches the rest.
Any service paying yield on Bitcoin is lending that Bitcoin to somebody, which is how Liquid’s users lost their money. The CFPB’s 2025 consumer complaint report found that companies routinely deny fraud claims where the customer authenticated the transaction, so a scam the holder helped complete rarely gets refunded.
The ETF Avoids Everything That Broke Except the Custodian
For most people asking how to buy Bitcoin safely, the spot Bitcoin ETF is the answer, because none of the three failures between September 6 and September 12 reached a shareholder. In return, a buyer trusts Coinbase to keep the coins safe and gives up the ability to spend them. That works for anyone who wants the price appreciation and not the Bitcoin.
Anyone who wants the coins themselves gets the same answer from all three failures. Fewer parties between a buyer and their Bitcoin means fewer ways to lose it, and every extra layer adds a way back. A bridge, a wrapper, a yield product, or a support line somebody can fake all count. A breach at a custodian would put the ETF last instead of first, and until that happens, the order above stands.
Contact [email protected] for any questions or corrections.








