Crypto hacks reveal $972M losses mainly from keys, signers and governance—not smart contracts

CoinDesk’s Crypto Long & Short argues that this year’s crypto hacks (about $972 million stolen so far) are increasingly driven by operational and governance failures rather than contract bugs. The analysis of 425 hacks from 2021–2025 finds that a small fraction of incidents accounts for most of the value lost. In 2024–2025, 54.6% of total value lost across 191 hacks traced back to centralized exchange compromises—custody, keys and signing above the contract layer. Several examples highlight the pattern. An attacker drained roughly $20 million from BonkDAO by buying enough tokens to pass a governance proposal; the vote executed as written. In June, Humanity Protocol’s biggest loss (over $30 million) stemmed from a compromised private key on a team member’s machine, with the contract itself untouched. While code quality is still a concern—93.9% of programs running five years or more show at least one confirmed critical—the article stresses that audits alone don’t address who holds signing authority, how keys are stored, or what happens after endpoint compromise. Instead, continuous, incentivized security pressure matters: live bug bounty programs and monitoring/rapid response. It cites a median bounty of about $20,000 preventing hacks averaging around $25 million. For traders, the takeaway is that crypto hacks risk is shifting toward governance and key management. That can amplify tail-risk events and liquidity shocks if large treasuries or signing setups are compromised.
Neutral
This is largely a security/operational thesis rather than a single market-moving incident. It suggests crypto hacks are increasingly driven by governance takeovers and key/signing compromise—factors that can create sudden, high-impact losses and tail-risk. That is mildly negative for risk appetite, but the article also points to mitigation (continuous bug bounties, monitoring, rapid response), which can reduce frequency over time. In the short term, traders may rotate toward projects with stronger governance controls and key-management practices, pricing in higher risk premiums for DAOs/treasuries with weak signer/key custody or low-voter governance. In the long term, the repeated finding that “audited” is not “safe” could shift market attention from one-off audits to continuous, incentivized verification—potentially improving risk outcomes but also raising costs, affecting token valuations of lower-security teams. Compared with past events where large treasury drains occurred via compromised access (rather than pure contract bugs), markets typically see sharp, event-driven volatility followed by gradual repricing. Without a specific new hack in the report, the net effect is best described as neutral: the information may influence positioning, but it doesn’t directly signal immediate systemic failure.