In one week of September 2026, the crypto industry was rocked by three major incidents: the hack of the Liquid sidechain, an attack on cross-chain protocol Symbiosis, and data breaches at Revolut and Coldcard. Total losses exceeded $322 million. For those who buy Bitcoin and hold it on exchanges or wallets, this isn't just news — it's a reason to rethink your security model.
What Happened: A Seven-Day Timeline
First, the Liquid sidechain fell — attackers drained $320 million. This isn't just "another hack": Liquid is used for fast and cheap transactions, and compromising such a bridge undermines trust in cross-chain solutions as a whole. Next, cross-chain protocol Symbiosis lost $2.2 million — a smaller sum, but the fact that infrastructure for exchanging between networks was attacked shows: vulnerabilities exist wherever there are bridges.
Separately, Revolut and Coldcard deserve mention. Here, it's not about direct thefts, but about what the companies "got wrong" in terms of security — details aren't disclosed in the source, but the fact that they're grouped with major hacks points to systemic issues. For users, this is a signal: even familiar services can become an attack vector.
Why This Matters for Those Paying by Card or Crypto
If you buy Bitcoin through an exchange or P2P, then pay for foreign services with a virtual card, your security chain looks like this: exchange → wallet → card → merchant. A break at any stage means lost funds. Sidechain and bridge hacks attack the first and second stages. Breaches at Revolut and Coldcard affect the storage and conversion stage.
In practice, this means several things:
- Don't keep large sums on an exchange longer than needed for a purchase. Move to a non-custodial wallet immediately.
- Check how the service stores keys. If it's a custodial wallet or a sidechain bridge — risk is higher.
- Use virtual cards with limited limits for online payments. Even if card details leak, an attacker can't drain everything at once.
- Enable 3DS and notifications. Most virtual cards support 3-D Secure — an extra barrier against fraudulent charges.
Common Mistakes When Buying Bitcoin After Hacks
After high-profile incidents, people often act impulsively: move everything to the "safest" wallet, switch exchanges, buy a new card. But the mistakes remain the same:
- Ignoring regional restrictions. Some virtual cards don't work with crypto exchanges or in certain jurisdictions. Check this before buying.
- Lack of 3DS. If the card doesn't support 3-D Secure confirmation, the risk of declines and fraud is higher.
- Exceeding limits. Virtual cards often have daily and monthly limits. For a large crypto purchase, the transaction may fail.
- Trying to pay for crypto by card where it's prohibited. Many banks and payment systems block such operations — a typical reason for decline.
What to Do Practically: A Checklist for Safe Buying
Here's a minimal set of steps that reduces risks:
- Buy Bitcoin on exchanges with a proven reputation and two-factor authentication.
- Immediately withdraw your purchase to a hardware or non-custodial wallet.
- For paying foreign services, use virtual cards with 3DS support and adjustable limits.
- Don't store card details in your browser and don't link it to dubious services.
- Regularly check transaction history and react to any suspicious charges.
Conclusion
The hacks of Liquid, Symbiosis, Revolut and Coldcard are not a series of coincidences but a reminder: security in crypto and online payments is a process, not a one-time action. The fewer links in the chain and the stricter the control at each, the lower the risk of losing money. Virtual cards with limits and 3DS are one tool that helps reduce damage if something goes wrong.
Disclaimer: This material is for informational purposes only and is not investment advice. Cryptocurrencies are volatile and risky assets.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.