Crypto Hacks Reveal Larger Pattern: Keys, Governance, Not Code Bugs
This year's crypto hacks have resulted in losses of roughly $972 million. However, an analysis by Immunefi's Mitchell Amador reveals that most of this money has not been stolen through contract bugs, but rather through compromised keys, governance votes, and misconfigured verifiers.
A recent example is the BonkDAO hack, where an attacker spent about $4 million to drain roughly $20 million from the treasury by buying enough tokens to pass a governance proposal in a low-turnout vote. The rules themselves were the vulnerability.
Across 425 hacks studied from 2021 to 2025, Amador found that a small share of operational failures carries most of the value lost. In the 2024-2025 window, 54.6% of all value lost can be traced to centralized exchange compromises.