Crypto has lost roughly $972 million to hacks so far this year, and the money is walking out the front door. Immunefi founder Mitchell Amador argues the industry's security budget has been aimed at the wrong layer: the largest losses in 2026 are not coming from broken smart contracts but from stolen signing keys, compromised laptops and governance proposals that executed exactly as written.
The numbers point to operations, not code
Amador's team studied 425 incidents from 2021 through 2025. In the 2024-to-2025 window, 54.6% of all value lost across 191 hacks traced back to centralized-exchange compromises, the keys, custody and signing infrastructure that sits above the contract. This year's pattern matches. In June, Humanity Protocol lost more than $30 million when a private key on a team member's machine was compromised; the contract was untouched. Earlier, an attacker spent about $4 million to buy enough tokens to pass a governance proposal draining roughly $20 million from BonkDAO's treasury in a low-turnout vote. The rules themselves were the vulnerability.
The code layer is not solved
None of this means smart contracts are safe. Amador notes that 93.9% of programs running five years or more surface a confirmed critical vulnerability, and roughly one in five confirmed reports is rated critical. Every upgrade ships fresh attack surface. The difference is that continuous, incentivized review now keeps pace with attackers on the code layer, which is exactly why the same model has to reach further.
Audits verify a moment, not a system
The standard playbook runs out at the audit. An audit verifies code at a point in time; it says nothing about who holds signing authority, how a key is stored or what happens when a laptop is compromised. "We were audited" was never the same as "we are safe," Amador writes. Audits are essential and every serious team should run them, but they cover only the layer where the industry has learned to defend. The money is leaving through the layers it hasn't.
