
Operational failures, stolen keys, governance attacks, now drive the biggest crypto losses. Immunefi CEO says audits alone aren't enough.
Crypto protocols and exchanges lost roughly $972 million to hacks in 2026, but the money is leaving through a different door. The biggest losses no longer come from smart contract bugs. They come from stolen signing keys, compromised governance votes and misconfigured verifiers – failures in the operational layer that audits do not catch.
Mitchell Amador, founder and CEO of security firm Immunefi, said the data tells a narrow and uncomfortable story. “If you look at the sheer number of incidents, you would think the industry is losing ground. But if you look into how much has actually been stolen, a narrower, more uncomfortable pattern shows up.”
Two recent cases illustrate the shift. This month an attacker spent roughly $4 million to drain about $20 million from BonkDAO’s treasury. No contract code failed. The attacker bought enough tokens to pass a governance proposal in a low-turnout vote, and the vote executed exactly as written. “The rules themselves were the vulnerability,” Amador said.
In June the month’s largest loss, more than $30 million at Humanity Protocol, came from a private key compromised on a team member’s machine, with the contract untouched, the project said.
Across 425 hacks studied from 2021 to 2025, a small share of operational failures carried most of the value lost. In the 2024–2025 window, 54.6% of all value lost, across 191 hacks, traced to centralized exchange compromises: key management, custody and signing processes above the contract layer, Amador said.
None of this means code vulnerabilities are solved. 93.9% of programs running five years or more surface a confirmed critical bug, and roughly one in five confirmed reports is rated critical, per Immunefi data. Every protocol upgrade ships fresh attack surface. What has changed is that continuous, incentivized review now keeps pace with attackers on the code layer itself.
“That same discipline now has to cover the keys, the signers and the rules of governance, or we will continue to see catastrophic losses,” Amador said.
A standard audit verifies code at a single point in time. It says nothing about who holds signing authority, how a key is stored or what happens when a laptop is compromised. One protocol was audited 11 times and still lost $128 million, Amador noted.
What has hardened contract code is continuous, incentivized pressure: live bug bounty programs, monitoring and rapid response. Security researchers are paid to find vulnerabilities before an attacker does. A roughly $20,000 median bounty routinely prevents a hack that would average around $25 million, making that payout the highest-ROI security spend a protocol can make, Amador said. The model works because it never stops and incentives do not decay when the org chart changes or a signer leaves.
“So does an audit make a protocol secure? On its own, no,” Amador said. “A protocol is secure when its code, its keys, its people, its governance and its monitoring are all treated as a live attack surface, and tested continuously by researchers paid to break them first.”
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.