Crypto Hacks: Beyond Code Bugs
According to recent data, crypto hacks have resulted in losses of $972 million so far this year. However, a closer look at these incidents reveals that most of the stolen funds are not due to contract bugs, but rather from compromised private keys, misconfigured verifiers, and treasury access through governance votes.
The CEO of Immunefi, Mitchell Amador, points out that in many cases, smart contracts have not failed. Instead, attackers have exploited vulnerabilities in the rules themselves or gained unauthorized access to sensitive information.
Research by Immunefi shows that a significant portion of value lost can be attributed to centralized exchange compromises, with 54.6% of all losses from 2024 to 2025 coming from this source. However, Amador emphasizes that code layer vulnerabilities are still prevalent, with 93.9% of programs running for five years or more surfacing confirmed critical issues.
The article concludes that while the security landscape is complex and multifaceted, continuous review and incentivized testing can help mitigate these risks. This shift in focus may be why hacks are increasingly targeting areas beyond contract bugs.