Crypto Long & Short: What this year's $972 million crypto hacks actually tell us about security

Crypto Long & Short: What this year's $972 million crypto hacks actually tell us about security

In this week's Crypto Long & Short, Immunefi's Mitchell Amador writes that most of 2026's stolen crypto is leaving through keys, signers and governance, not contract bugs, and explains why “we were audited” was never the same as “we are safe.” Hi readers,Welcome to our institutional newsletter, Crypto Long & Short. This week:Most of 2026’s stolen crypto is leaving through keys, signs and governance, not contract bugs, writes Mitchell AmadorTop headlines institutions should pay attention to by Francisco Rodrigues“Long tail volume share on solana rebounds past 60% as PUMP recovers” in Chart of the WeekCoinDesk will be attending the Digital Asset Yield Summit in Singapore on October 6th. This is an invite only private capital conference focused on digital assets. Learn more if you are interested in joining us at the event!Thanks for joining us!Hi readers,Welcome to our institutional newsletter, Crypto Long & Short. This week:Most of 2026’s stolen crypto is leaving through keys, signs and governance, not contract bugs, writes Mitchell AmadorTop headlines institutions should pay attention to by Francisco Rodrigues“Long tail volume share on solana rebounds past 60% as PUMP recovers” in Chart of the WeekCoinDesk will be attending the Digital Asset Yield Summit in Singapore on October 6th. This is an invite only private capital conference focused on digital assets. Learn more if you are interested in joining us at the event!Thanks for joining us!What H1's crypto hack numbers actually tell us about securityby Mitchell Amador, founder and CEO of ImmunefiThis month, an attacker spent about $4 million to drain roughly $20 million from BonkDAO's treasury. No smart contract failed. The attacker bought enough tokens to pass a governance proposal in a low-turnout vote, and the vote executed exactly as written. The rules themselves were the vulnerability.This same story repeated in June but from a different angle: the month's largest loss, more than $30 million at Humanity Protocol, came from a private key compromised on a team member's machine, with the contract untouched, per the project's own account.This is the shape of 2026's worst losses, with crypto losing roughly $972 million so far this year. The number of incidents keeps climbing, and the money increasingly leaves through something other than a contract bug: a stolen signing key, a misconfigured verifier, a treasury anyone can vote their way into. If you look at the sheer number of incidents, you would think the industry is losing ground. But if you look into how much has actually been stolen in total, a narrower, more uncomfortable pattern shows up.We can be precise about it. Across the 425 hacks we studied from 2021 to 2025, a small share of operational failures carries most of the value lost. In the 2024 to 2025 window, 54.6% of all value lost, across 191 hacks, can be traced to centralized exchange compromises: the keys, custody and signing that sit above the contract.However, none of this means the code layer is solved. Criticals are everywhere in live code. 93.9% of programs that run five years or more surface a confirmed critical, and roughly one in five confirmed reports is rated critical. The code is never finished either. Every upgrade ships fresh attack surface. What has changed is that continuous, incentivized review now keeps pace with attackers on that code, which is exactly why the same model has to reach further.This is where the standard playbook runs out. An audit verifies code at a moment in time. It says nothing about who holds signing authority, how a key is stored or what happens when a laptop is compromised. Audits are essential and every serious team should run them, but “we were audited” was never the same as “we are safe.” One protocol was audited 11 times and still lost $128 million.What actually has hardened contract code is continuous, incentivized pressure. Through live bug bounty programs and a wider stack of monitoring and rapid response, security researchers are paid to find the vulnerability before an attacker does. A roughly $20,000 median bounty routinely prevents a hack that would average around $25 million, making that payout the highest ROI security spend a protocol can make. The model holds because it never stops, and because incentives do not decay when the org chart changes or a signer leaves.That same discipline now has to cover the keys, the signers and the rules of governance, or we will continue to see catastrophic losses in this area.So does an audit make a protocol secure? On its own, no. A protocol is secure when its code, its keys, its people, its governance and its monitoring are all treated as a live attack surface, and tested continuously by researchers paid to break them first.Headlines of the WeekBy Francisco RodriguesThis week’s headlines show the crypto downturn reshaping balance sheets and market infrastructure. Strategy raised cash and began repurchasing preferred stock, while BitMEX and BitMart announced plans to close as the bear market takes its toll.Strategy boosts cash reserve to $3.75 billion, repurchases $25 million of STRC: The firm raised $544.5 million through common-stock sales and used a portion to buy back 288,930 STRC shares, while leaving its 843,775 BTC unchanged.BitMEX, the exchange that invented perpetual swaps, is shutting down: The derivatives exchange will close on Sept. 23 after 11 years, having lost the market it pioneered to larger centralized rivals and decentralized trading platforms.BitMart to shut down after nine years as BMX token crashes: The exchange will halt trading on Aug. 26 and cease operations on Jan. 31, 2027, without giving a specific reason for the closure.Revolut hits $115 billion valuation in employee share sale: The secondary transaction lifted the crypto-friendly digital bank’s valuation by 53% in less than a year, making it Europe’s most valuable private company.Clarity Act expected to miss its window before Congress’ summer break: Senate Majority Leader John Thune said the bill was unlikely to pass before the recess, reducing its chances of becoming law in 2026 as lawmakers remained divided over ethics and stablecoin yield.Chart of the WeekLong tail volume share on solana rebounds past 60% as PUMP recoversMemecoins and other long tail tokens now account for over 60% of Solana volume, up from the high 30s at the end of June. PUMP has tracked the recovery closely, rising 42% month to date.Listen. Read. Watch. Engage.Listen: Did you know all of CoinDesk’s research can be found in one spot? Don’t miss the latest reports like Exchange Review, Stablecoins & Tokenized Assets, Quarterly Review & Outlook and more. View our award-winning digital asset research today.Read: In Crypto for Advisors, Jason Barraza explores why the conversation at TokenizeThis shifted from "if" to "how" as asset managers prioritize real-world utility over hype. Then, in “Ask an Expert,” Joshua de Vos from CoinDesk Research answers questions about tokenized investment products and current market trends.Watch: For pertinent topics dominating headlines don’t miss CoinDesk’s Public Keys from the floor of the NYSE. Last week, Jennifer Sanasie was joined by Ben Emons, Founder and Chief Investment Officer of FedWatch Advisors LLC, Nadine Chakar, Managing Director and Global Head of Digital Assets at DTCC, and Bilal Little, Global ETF Strategist at Direxion. New episodes launch Monday afternoon.12345678910Anvil: The Missing Collateral LayerAnvil: The Missing Collateral LayerAnvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.Why it matters:Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.View Full Report

Original Source

Read the full article at Coindesk →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.