$972 Million Crypto Hacks Show Governance is the New Vulnerability
The $972 million worth of crypto lost this year might not be as alarming as it seems. According to Mitchell Amador, founder and CEO of Immunefi, a closer look at the data reveals that most of these losses come from vulnerabilities in governance, signing keys, and custody, rather than contract bugs. In fact, in 54.6% of hacks from 2024 to 2025, the value lost can be traced back to centralized exchange compromises.
One notable example is the BonkDAO hack, where an attacker spent $4 million to drain around $20 million from the treasury by buying enough tokens to pass a governance proposal. The rules themselves were the vulnerability in this case.
Another incident at Humanity Protocol saw a team member's compromised private key lead to losses of over $30 million. These hacks demonstrate that while contract bugs are not the primary cause of losses, they do highlight the importance of continuous review and security measures.