The nice thing is, security breaches in a decentralized network like bitcoin serve to make the entire network anti-fragile. There's a huge incentive for people with bitcoin to secure their own bitcoins against known exploits and hence make that exploit null while inevitably protecting against similar class exploits.
Keeping bitcoin online enough for convenient transactions carries the small but important risk of losing your entire wallet.
Much like early immigrants to North America who had leaving the stability and safety of UK/European banks for an emerging market and/or the Wild West.
Seems like the right kind of way to do a canary.
But why bitcoin is targeted?
Because bitcoin is an open protocol, they could target it's root, mining rigs because that's where the value is generated. In banking systems, to generate money you need to have internal access and secure credits .
These can be target vectors too.
If you manage to steal Bitcoin, you can transfer it all to your personal wallet in one transaction in broad daylight and, by design, no one can stop you or reverse the transaction once it's discovered to be fraudulent. Maybe run it through a darknet tumbler for good measure, but you're basically home free the second you get the private keys.
Stealing $100m worth of Bitcoin would be massively more valuable than stealing CC numbers with access to $500m in credit because you can actually cash out all of it. So much larger R&D budgets and more sophisticated attacks make financial sense.
With Bitcoin, every marginal theft adds 100% to the total Bitcoin thefts.
If your private key is compromised, the thief takes your entire balance, and there's nothing you can do about it. So you really want to keep it safe.
Lose your private key, lose everything it was protecting. So keeping the key in only one place, and one place where only you can access, is a big problem. There is nobody out there to give access to your money if you pass away. A hardware failure can be catastrophic.
The problem is that everything that makes the private key survive accidents makes it easier to hack. The way we treat something like this in a corporation is with things like shared secrets: Need 3 out of 5 people to use their issued keys so that the real private key protecting everything is revealed. And even with that level of effort, getting the key is still possible with enough effort.