CoinDesk IndicesCrypto Long & Short: Insights from $972 Million in Crypto Hacks
This week, Mitchell Amador from Immunefi discusses how the majority of crypto theft in 2026 has occurred through compromised keys and governance, rather than contract vulnerabilities, emphasizing that being audited does not equate to being secure.
By Mitchell Amador Jul 29, 2026, 3:13 p.m. 5 min read
Welcome to this week’s edition of Crypto Long & Short. In this issue:
- Mitchell Amador highlights that the bulk of crypto theft in 2026 is attributed to key and governance issues rather than contract flaws.
- Key news updates relevant for institutions by Francisco Rodrigues
- This week's chart showcases that Solana's long tail volume share has surged past 60% as PUMP recovers.
CoinDesk will be present at the Digital Asset Yield Summit in Singapore on October 6th, an exclusive event focused on digital assets. Discover more if you're interested in attending!
Thank you for joining us!
Examining H1's Crypto Hack Statistics
by Mitchell Amador, founder and CEO of Immunefi
Recently, an attacker utilized about $4 million to drain approximately $20 million from BonkDAO’s treasury without any smart contract failure. The attacker acquired enough tokens to pass a governance proposal during a poorly attended vote, resulting in the execution of the vote as intended. The underlying rules presented the vulnerability.
A similar incident occurred in June, where the largest loss of over $30 million at Humanity Protocol stemmed from a compromised private key on a team member’s device, with the contract remaining intact, according to the project's report.
In total, the crypto sector has incurred losses nearing $972 million in 2026 thus far. Although the frequency of incidents is rising, the funds are increasingly exiting through means other than contract flaws, such as stolen signing keys or misconfigured verifiers. While the number of incidents suggests a decline in security, a closer examination reveals a more nuanced and troubling trend regarding the total amount stolen.
To provide clarity, our analysis of 425 hacks from 2021 to 2025 indicates that a small fraction of operational failures is responsible for the majority of the value lost. Between 2024 and 2025, 54.6% of all lost value across 191 hacks can be attributed to centralized exchange breaches, which involve the keys and custody above the contract layer.
However, this does not imply that the code layer issues are resolved. Critical vulnerabilities are prevalent in active code. An alarming 93.9% of programs that have been operational for five years or more reveal at least one confirmed critical vulnerability, with about 20% of confirmed reports classified as critical. The code is continually evolving, and every upgrade introduces new potential attack vectors. What has improved is the ongoing, incentivized review process that keeps pace with attackers, highlighting the need for a more comprehensive approach.
This is where the conventional audit strategy falls short. An audit only verifies the code at a specific point in time and does not account for who has signing authority, how keys are stored, or what occurs if a device is compromised. Audits are crucial and should be conducted by any serious team, but simply stating “we were audited” does not guarantee safety. One protocol that underwent 11 audits still experienced a loss of $128 million.
What has effectively strengthened contract code is the continuous incentivization of security through live bug bounty programs and enhanced monitoring and rapid response systems. Security researchers are financially motivated to identify vulnerabilities before they can be exploited, with an average bounty of around $20,000 often preventing hacks that could cost around $25 million, making this expenditure the most efficient security investment a protocol can make. This model thrives because it is perpetual, and the incentives remain intact despite personnel changes.
To prevent further catastrophic losses, the same rigorous approach must be applied to keys, signers, and governance rules.
So, does having an audit ensure a protocol’s security? The answer is no, not in isolation. A protocol achieves security when its code, keys, personnel, governance, and monitoring are all regarded as an active attack surface, continuously tested by researchers incentivized to identify weaknesses.
Weekly Headlines
This week’s news reflects how the downturn in crypto is reshaping balance sheets and market structures. Strategy has increased its cash reserves and begun repurchasing preferred stock, while BitMEX and BitMart have announced their closures as the bear market impacts them.
- Strategy raises cash reserve to $3.75 billion, repurchases $25 million of STRC: The firm raised $544.5 million through common-stock sales and used a portion to buy back 288,930 STRC shares, while maintaining its 843,775 BTC.
- BitMEX, the pioneer of perpetual swaps, is shutting down: The derivatives exchange will cease operations on September 23 after 11 years, having lost its market leadership to larger centralized and decentralized trading platforms.
- BitMart will close after nine years as BMX token plunges: The exchange will stop trading on August 26 and end operations on January 31, 2027, without providing a specific reason for its closure.
- Revolut achieves $115 billion valuation in employee share sale: This secondary transaction boosted the valuation of the crypto-friendly digital bank by 53% in less than a year, establishing it as Europe’s most valuable private company.
- Clarity Act likely to miss its chance before Congress’ summer break: Senate Majority Leader John Thune indicated that the bill is unlikely to pass before the recess, diminishing its odds of becoming law in 2026 as lawmakers remain divided on ethics and stablecoin yields.
Chart of the Week
Long tail volume share on Solana exceeds 60% as PUMP recovers
Long tail tokens and memecoins now represent over 60% of Solana's trading volume, a significant increase from the high 30s at the end of June. PUMP has closely followed this recovery, rising by 42% month-to-date.
Engagement Opportunities
Listen: You can find all of CoinDesk’s research consolidated in one place. Don’t miss recent reports like Exchange Review, Stablecoins & Tokenized Assets, Quarterly Review & Outlook, and more. Check out our award-winning digital asset research now.
Read: In Crypto for Advisors, Jason Barraza discusses how the dialogue at TokenizeThis has shifted from "if" to "how" as asset managers focus on practical utility over mere hype. Additionally, in “Ask an Expert,” Joshua de Vos from CoinDesk Research addresses queries about tokenized investment products and current market dynamics.
Watch: For key topics making headlines, tune into CoinDesk’s Public Keys from the NYSE floor. Last week, Jennifer Sanasie was joined by Ben Emons, Founder and Chief Investment Officer of FedWatch Advisors LLC, Nadine Chakar, Managing Director and Global Head of Digital Assets at DTCC, and Bilal Little, Global ETF Strategist at Direxion. New episodes release on Monday afternoons.
Engage: CoinDesk will attend the Digital Asset Yield Summit in Singapore on October 6th. This invitation-only conference is dedicated to digital assets. Learn more if you wish to participate!
For more updates, follow coindesk.com for the latest crypto news and market insights from coindesk.com/institutions.
CoinDesk IndicesCrypto Long & ShortLatest Crypto News- 1Stablecoin firm Brale claims new protocol can eliminate significant barriers to scaling custom tokens39 minutes ago
- 2Coinbase faces a slump in spot trading as Wall Street lowers earnings expectations52 minutes ago
- 3Ethereum Foundation appoints pcaversaccio to board amidst leadership transitions1 hour ago
- 4The inside story of a Hong Kong hike that altered crypto trading dramatically2 hours ago
- 5Approximately $80 million ZEC enters Zcash's new Ironwood pool on its first day2 hours ago
- 6The systemic risk conversation about perpetual futures is misdirected3 hours ago
- 7BNY aims at the $8.6 trillion transfer agency market with blockchain solutions3 hours ago
- 8Three reasons why Wednesday's Fed meeting is crucial for BTC4 hours ago
- 9Bitcoin stabilizes above $64,000 as the crypto market awaits the Fed's interest rate decision5 hours ago
- 10Binance introduces gold and silver options following a surge in commodity futures trading volume6 hours ago
Anvil: The Missing Collateral Layer
Anvil: The Missing Collateral Layer
Anvil represents a shared on-chain collateral framework based on a programmable letter of credit: reserve assets serve as guarantees, eliminating loans and interest while maintaining custody and yield.
Why it matters:
Anvil is a shared on-chain collateral layer built on a programmable letter of credit: reserve assets as a guarantee -no loan, no interest, keep custody & yield.
View Full ReportMore From CoinDesk Indices