Crypto has lost roughly $972 million to hacks so far in 2026, but the more uncomfortable pattern is where that money is leaving from. Mitchell Amador, founder and CEO of Immunefi, argues in this week's Crypto Long & Short that the dominant exit vector is no longer the smart contract layer at all. It is the keys, the signers and the rules of governance that sit above it.
The BonkDAO exploit this month is the cleanest recent example. An attacker spent about $4 million to accumulate enough tokens to pass a governance proposal in a low-turnout vote, then drained roughly $20 million from the treasury. No contract failed. The rules themselves were the vulnerability. The same shape showed up in June at Humanity Protocol, where the month's largest loss, more than $30 million, came from a private key compromised on a team member's machine, with the contract untouched.
Why it matters
Immunefi's review of 425 hacks from 2021 to 2025 puts numbers to the pattern. In the 2024 to 2025 window, 54.6% of all value lost across 191 incidents traced back to centralized exchange compromises, the keys, custody and signing layers above the contract. The code layer is not solved either: 93.9% of programs that have run five years or more surface a confirmed critical, and roughly one in five confirmed bug reports is rated critical. One protocol was audited eleven times and still lost $128 million.
What has actually hardened contract code is continuous, incentivized review through live bug bounty programs. A roughly $20,000 median bounty routinely prevents a hack that would average around $25 million, making that payout the highest-ROI security spend a protocol can make. The model holds because it never stops and because incentives do not decay when the org chart changes or a signer leaves.
Market impact
That same discipline now has to extend to keys, signers and governance, or the catastrophic losses in this category will keep repeating. For institutions underwriting protocol risk, the read is that an audit report is necessary infrastructure but not a risk certificate. A protocol is secure only when its code, its keys, its people, its governance and its monitoring are all treated as a live attack surface, and tested continuously by researchers paid to break them first. The bear market backdrop, with Strategy repurchasing preferred stock while BitMEX and BitMart wind down, sharpens the urgency: thinner treasuries have less margin for the same governance or key-management mistakes.
Frequently asked questions
-
How much crypto has been lost to hacks in 2026?
Crypto has lost roughly $972 million to hacks so far in 2026, according to Immunefi's Mitchell Amador writing in CoinDesk's Crypto Long & Short. The number of incidents keeps climbing, and the value increasingly leaves through keys, signers and governance rather than contract bugs.
-
What share of recent crypto hack losses came from centralized exchanges?
In Immunefi's review of 425 hacks from 2021 to 2025, 54.6% of all value lost in the 2024 to 2025 window across 191 incidents traced back to centralized exchange compromises, the keys, custody and signing layers above the contract.
-
Why are audits not enough to secure a crypto protocol?
An audit verifies code at a moment in time and says nothing about who holds signing authority, how a key is stored, or what happens when a laptop is compromised. Amador cites one protocol that was audited eleven times and still lost $128 million.
-
What is the highest-ROI security spend a protocol can make?
Live bug bounty programs. Amador points to a roughly $20,000 median bounty that routinely prevents a hack averaging around $25 million, a payout he calls the highest-ROI security spend a protocol can make, because the pressure is continuous and incentives do not decay when signers or staff change.
-
What were the biggest governance and key-management losses in 2026?
BonkDAO lost roughly $20 million this month after an attacker spent about $4 million to pass a governance proposal in a low-turnout vote and drained the treasury without breaking any contract. Humanity Protocol lost more than $30 million in June after a private key was compromised on a team member's machine, with the…
CoinDesk