Hi readers,
Welcome to our institutional newsletter, Crypto Long & Short. This week:
- Most of 2026’s stolen crypto is leaving through keys, signs and governance, not contract bugs, writes Mitchell Amador
- Top headlines institutions should pay attention to by Francisco Rodrigues
- “Long tail volume share on solana rebounds past 60% as PUMP recovers” in Chart of the Week
CoinDesk will be attending the Digital Asset Yield Summit in Singapore on October 6th. This is an invite only private capital conference focused on digital assets. Learn more if you are interested in joining us at the event!
Thanks for joining us!
What H1's crypto hack numbers actually tell us about security
by Mitchell Amador, founder and CEO of Immunefi
This month, an attacker spent about $4 million to drain roughly $20 million from BonkDAO's treasury. No smart contract failed. The attacker bought enough tokens to pass a governance proposal in a low-turnout vote, and the vote executed exactly as written. The rules themselves were the vulnerability.
This same story repeated in June but from a different angle: the month's largest loss, more than $30 million at Humanity Protocol, came from a private key compromised on a team member's machine, with the contract untouched, per the project's own account.
This is the shape of 2026's worst losses, with crypto losing roughly $972 million so far this year. The number of incidents keeps climbing, and the money increasingly leaves through something other than a contract bug: a stolen signing key, a misconfigured verifier, a treasury anyone can vote their way into. If you look at the sheer number of incidents, you would think the industry is losing ground. But if you look into how much has actually been stolen in total, a narrower, more uncomfortable pattern shows up.
We can be precise about it. Across the 425 hacks we studied from 2021 to 2025, a small share of operational failures carries most of the value lost. In the 2024 to 2025 window, 54.6% of all value lost, across 191 hacks, can be traced to centralized exchange compromises: the keys, custody and signing that sit above the contract.
However, none of this means the code layer is solved. Criticals are everywhere in live code. 93.9% of programs that run five years or more surface a confirmed critical, and roughly one in five confirmed reports is rated critical. The code is never finished either. Every upgrade ships fresh attack surface. What has changed is that continuous, incentivized review now keeps pace with attackers on that code, which is exactly why the same model has to reach further.
Engage: CoinDesk will be attending the Digital Asset Yield Summit in Singapore on October 6th. This is an invite only private capital conference focused on digital assets. Learn more if you are interested in joining us at the event!
Looking for more? Receive the latest crypto news from coindesk.com and market updates from coindesk.com/institutions.
CoinDesk IndicesCrypto Long & Short