What this year’s $972 million cryptocurrency hacks really tell us about security

This same story was repeated in June, but from a different angle: the biggest loss of the month, more than $30 million at Humanity Protocol, came from a compromised private key on a team member’s machine, with the contract intact, according to the project’s own account.

This is the shape of the worst losses of 2026: Cryptocurrencies have lost approximately $972 million so far this year. The number of incidents continues to rise, and more and more money is leaving through more than just a contract error: a stolen signature key, a misconfigured verifier, a treasury that anyone can vote into. If you look at the large number of incidents, you might think that the industry is losing ground. But if we look at how much has actually been stolen in total, a more limited and uncomfortable pattern emerges.

We can be precise about it. In the 425 hacks we studied between 2021 and 2025, a small proportion of operational failures carry the majority of the lost value. In the period from 2024 to 2025, 54.6% of all value lost, in 191 hacks, can be attributed to centralized exchange commitments: the keys, escrow and signature that sit on top of the contract.

However, none of this means that the code layer is solved. Critics are everywhere in live code. 93.9% of programs running for five years or more have confirmed critical results, and approximately one in five confirmed reports is rated as critical. The code is never finished either. Each update provides a new attack surface. What’s changed is that continuous, incentivized review now keeps pace with attackers on that code, which is exactly why the same model needs to go further.

Leave a Comment

Your email address will not be published. Required fields are marked *