$972M Crypto Hacks Shift to Keys and Governance Over Code Bugs
In brief
- Crypto lost $972 million to hacks in 2026; most theft bypasses contract audits
- BonkDAO drained $20 million via governance vote; Humanity Protocol lost $30 million from compromised key
- 93.9% of five-year-old protocols surface critical vulnerabilities despite audits
- Bug bounties averaging $20,000 prevent hacks worth ~$25 million each
The New Attack Surface
Crypto is losing roughly $972 million so far this year, but the threat model has evolved. Two recent cases illustrate the shift. An attacker spent about $4 million to drain roughly $20 million from BonkDAO's treasury by purchasing enough tokens to pass a governance proposal in a low-turnout vote. No smart contract failed. The rules themselves were the vulnerability.
In June, Humanity Protocol lost more than $30 million from a private key compromised on a team member's machine. Again, no code exploit. The money left through operational failure—a stolen signing key.
Most of 2026's stolen crypto is leaving through something other than a contract bug: a stolen signing key, a misconfigured verifier, or a governance trap. Mitchell Amador, founder and CEO of Immunefi, calls this the new reality.
Why Audits Miss the Real Risk
An audit is a point-in-time review. An audit verifies code at a moment in time and says nothing about who holds signing authority or how a key is stored. The distinction matters. One protocol was audited 11 times and still lost $128 million.
Across 425 hacks studied from 2021 to 2025, 54.6% of all value lost in the 2024 to 2025 window can be traced to centralized exchange compromises. The data is unforgiving. 93.9% of programs that run five years or more surface a confirmed critical vulnerability, whether audited or not.
The Case for Continuous Defense
Bug bounties tell a different story. A roughly $20,000 median bounty through bug bounty programs routinely prevents a hack that would average around $25 million. The math is stark: a small investment in continuous research catches threats that audits miss.
The distinction is live. A protocol is secure when its code, its keys, its people, its governance and its monitoring are all treated as a live attack surface, and tested continuously by researchers paid to break them first. Not once. Continuously.
Frequently asked questions
Why is an audit not the same as security?
An audit verifies code at a single moment in time. It says nothing about who holds signing authority, how keys are stored, or how governance is configured. One protocol audited 11 times still lost $128 million to a key compromise, not a code bug.
Where is most of the stolen crypto going now?
Most of 2026's stolen crypto is leaving through compromised signing keys, misconfigured verifiers, and governance exploits—not smart contract bugs. BonkDAO was drained via a low-turnout governance vote; Humanity Protocol lost $30 million to a compromised private key.
Do bug bounties actually work?
Yes. A median $20,000 bug bounty routinely prevents a hack averaging $25 million. Continuous researcher-led testing catches threats that point-in-time audits miss.


