By Interestana AI Editorial — AI-drafted, human-overseen. How we report
2026 Crypto Hacks Reveal Key, Signer, Governance Vulnerabilities

In 2026, cryptocurrency hacks have resulted in the loss of $972 million, with a significant portion of these funds being exploited through vulnerabilities related to private keys, multi-signature signers, and governance mechanisms, rather than solely through smart contract bugs. This analysis, presented by Mitchell Amador of Immunefi, a prominent bug bounty and security services platform for smart contracts, highlights a critical shift in the landscape of cryptocurrency security threats. Amador's insights, shared in this week's "Crypto Long & Short" commentary, emphasize that the common assurance "we were audited" does not equate to a guarantee of complete safety.
The data indicates that the primary vectors for these substantial losses are not flaws within the code of smart contracts themselves, which are often subjected to rigorous auditing processes. Instead, the exploits are targeting the broader ecosystem that manages and controls digital assets. This includes the compromise of private keys, which grant direct access to wallets and funds, and the manipulation of multi-signature (multi-sig) wallets, where multiple approvals are required to authorize transactions. Exploits targeting signers, the entities or individuals responsible for providing these approvals, have become a significant concern. Furthermore, governance attacks, where malicious actors gain control of decentralized autonomous organizations (DAOs) or other governance structures, have been used to approve fraudulent transactions or drain treasuries.
Immunefi's findings suggest that while smart contract audits are a crucial step in identifying and mitigating code-level vulnerabilities, they are insufficient on their own to protect against all forms of attack. The security of a decentralized application or protocol extends beyond its on-chain code to encompass the management of administrative keys, the security practices of multisig signers, and the robustness of its governance framework. This broader perspective is essential for understanding the true security posture of any crypto project. The $972 million figure represents a stark reminder of the ongoing risks within the digital asset space and the need for comprehensive security strategies that address all potential points of failure.
Amador's commentary underscores a growing realization within the industry: security is a multifaceted challenge. The focus must expand from purely technical code audits to include operational security, key management best practices, and secure governance design. Projects that have undergone audits may still be vulnerable if their administrative access or governance processes are compromised. This distinction is vital for investors, developers, and users to accurately assess risk and for security professionals to develop more effective defense mechanisms against the evolving threat landscape in the cryptocurrency domain.
Original source — read the full reporting at the publisher:
Read on CoinDeskGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.