S&P 5007,428.78▲0.2% Nasdaq24,876.91▼0.2% Dow52,747.32▲1.0% Russell 2K2,953.80▲0.2% 10-Yr4.60%−4bp VIX18.21−0.46 WTI$81.23▼1.7% Gold$4,023.80▼1.2% EUR/USD1.139▼0.1% BTC$63,912▲0.1% Nikkei64,931▲0.5%
At close · Tue, Jul 28, 2026
Daily Market Updates.

Crypto

HomeCryptoRegulation2026 crypto hacks show stolen keys and governance flaw…

2026 crypto hacks show stolen keys and governance flaws drive losses

Analysis of prior hacks finds a large share of value lost traced to centralized exchange compromises and other key or custody weaknesses rather than contract bugs.

CoinDesk reports that 2026 crypto losses continue to mount, with about $972 million stolen so far this year as incidents increase. The outlet points to cases where attackers were able to drain funds without any smart contract failing, including an attacker spending about $4 million to drain roughly $20 million from BonkDAO's treasury by buying enough tokens to pass a governance proposal in a low-turnout vote.

The coverage also highlights a pattern that money increasingly leaves through non-contract issues, including compromised private keys and governance or verification settings. It cites Humanity Protocol's loss of more than $30 million in June, where a private key was reportedly compromised on a team member's machine while the contract itself was untouched, according to the project's account.

CoinDesk further argues that audits alone do not equal safety because they assess code at a point in time, not whether key and signing authorities are properly secured. Using a sample of 425 hacks from 2021 to 2025, it says the 2024 to 2025 window saw 54.6% of value lost across 191 hacks linked to centralized exchange compromises, such as keys, custody, and signing above the contract.

The outlet also notes that critical security issues remain common in live code, with 93.9% of programs running five years or more showing a confirmed critical and about one in five confirmed reports rated critical. It concludes that while continuous, incentivized review can help keep pace with attackers, security needs to extend beyond the code layer to cover signing authority and key management.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.