HomeBlockchainBlockchain NewsPrivate Keys, Not Blockchains, Behind 40% of Crypto's $16.69 Billion in Hack...

Private Keys, Not Blockchains, Behind 40% of Crypto’s $16.69 Billion in Hack Losses

Stolen private keys — not flaws in blockchain code or smart contracts — are responsible for roughly 40% of the $16.69 billion lost to crypto hacks in total, according to data from DeFiLlama, raising urgent questions about whether the industry’s foundational security architecture is fit for an asset class now competing with institutional finance.

$6.7 billion in crypto has been taken not by breaking the math behind blockchains — but by stealing the equivalent of a password. The cryptography held. The humans and systems around it didn’t.

The figures come from DeFiLlama’s hack tracker, which aggregates losses across DeFi exploits, bridge attacks, and direct theft events. Of the $16.69 billion total recorded, approximately $6.7 billion traces back to private key compromises — either through brute-force attacks or through so-called “unknown method” leaks where the key was obtained but the exact vector remains unconfirmed. The remaining losses stem from smart contract vulnerabilities and protocol-level exploits, categories that, according to security firm CertiK, are actually declining in relative frequency as projects pour resources into on-chain code audits.

“We are observing that operational security incidents are rising while smart contract exploits are declining, reflecting that attackers typically target the weakest points. As projects have focused their security investments on smart contracts, other critical areas have been left exposed,” CertiK, one of the leading blockchain and Web3 security firms, told CoinDesk.

In plain terms, a private key is the cryptographic equivalent of a bank password — a unique string of characters that proves ownership of funds and authorizes transactions. Unlike a forgotten bank password, however, there is no reset mechanism. No fraud department. No recourse. Whoever holds the key holds the money, irrespective of the underlying protocol’s quality.

Who’s Affected?

The exposure is industry-wide, but the heaviest losses have concentrated at the custodial and institutional layer — exchanges, bridges, and multi-signature wallet operators that must keep keys “hot,” meaning actively available to sign transactions. Leo Fan, founder and CEO of ZK Proof Layer Cysic, framed the structural contradiction clearly: “Private key hacks aren’t a cryptography failure — they’re a key-management failure the industry keeps mislabeling. The curve math is unbreakable.” The moment a key is used to authorize a transaction, it must reside somewhere — a server, a cloud environment, a hardware device managed by humans — and that surrounding operational surface is precisely where breaches occur.

The February 2025 Bybit incident, cited by both Fan and Wish Wu, co-founder and CEO of Pharos, illustrates how far the attack surface has expanded beyond the key itself. Attackers compromised the software supply chain of a third-party developer tool, injecting malicious code into the exchange’s wallet web interface. Executives unknowingly signed away $1.5 billion in Ethereum — not because the blockchain failed, but because the operational stack around the signing process was infiltrated. Wu noted that attack vectors now include “cloud systems, third-party tools, social media accounts, and the people operating them.” This widening of the perimeter means that a project with pristine smart contract code can still be financially devastated through its human and operational layer.

What Comes Next?

The industry is moving toward structural fixes, though adoption remains uneven, according to Wu. The leading technical approaches are multi-party computation (MPC) wallets and account abstraction. MPC splits the signing process across multiple parties so the complete private key never exists in a single location at any moment — eliminating the single point of failure that attackers currently exploit. Account abstraction, which allows smart contracts to function as user accounts with programmable rules, adds spending limits, approved address whitelists, and backup guardian designations directly into the wallet logic, so a compromised signer cannot unilaterally drain funds.

Wu’s broader critique is architectural: “Most blockchain infrastructure was originally built for a single-user, single-key model — one private key controls everything, and if that key is lost or stolen, all the assets are gone instantly. This goes against the basic security principles that traditional finance has relied on for decades: more than one person approving, separation of duties, and several layers of defense.” The implication is that crypto, built to replace legacy finance, replicated none of legacy finance’s hard-won operational controls. As the regulatory environment tightening around crypto capital markets intensifies scrutiny on institutional-grade custody standards, that gap is becoming a liability as much as a technical problem.

There is a compounding dynamic at work that neither DeFiLlama’s raw figures nor individual executive quotes fully surface: the industry’s security investment has been systematically misallocated. As smart contract auditing became commoditized and mandatory — driven by DeFi’s explosive growth between 2020 and 2022 — attackers rationally shifted focus to the softer operational layer. The result is a security arms race in which on-chain code quality has materially improved even as off-chain key management, supply chain integrity, and human operational discipline have lagged. That mismatch, and not any single exploit, is what the $6.7 billion private-key loss figure actually measures. Investors evaluating crypto infrastructure projects should treat key-management architecture as a first-order diligence question, on par with smart contract audit history — a standard that currently almost no public due-diligence framework enforces.

Why Crypto’s Key-Management Problem Is Becoming a Market, Security, and Regulatory Risk

At the same time, AI-orchestrated attack tooling is making brute-force, phishing, and supply-chain attacks cheaper and faster to deploy, raising the probability of a high-profile private-key incident. Regulatory pressure is also building, with congressional crypto regulation efforts and expected SEC custody-related rules likely to focus more closely on institutional key management. Overall, MPC offers a practical near-term improvement, while account abstraction provides the more flexible long-term security model for institutional-grade crypto controls — but the gap between current industry practice and future compliance expectations may be larger than many projects have priced in.
How Serious Players Should Respond

Institutional investors conducting due diligence on crypto infrastructure projects, exchanges, or custodians should treat key-management architecture as a non-negotiable audit category — not a secondary technical footnote. The data from DeFiLlama makes clear that operational security failures, not protocol-level weaknesses, are the dominant loss driver. That means asking specific questions: Does the entity use MPC or threshold signing for operational wallets? Has a formal software supply chain audit been conducted, covering third-party dependencies? Are there documented separation-of-duties controls for transaction signing, analogous to dual-control standards in traditional banking? The absence of credible answers to any of these should weigh materially on risk assessments.

For crypto projects and protocol teams, Wu’s prescription is direct: security must be designed in at the protocol level, not bolted on after launch. That means adopting MPC wallet infrastructure, implementing account abstraction with programmable spending controls, and treating the human operational layer — key handling procedures, insider threat protocols, security culture training — as a continuous operational discipline rather than a one-time audit checkbox. The Bybit incident demonstrated that a single compromised third-party tool in the development stack is sufficient to bypass every on-chain safeguard.

For regulators and standards bodies, the findings point toward a specific gap in existing frameworks: current crypto security guidance focuses disproportionately on smart contract audits and on-chain transparency, while the operational key-management layer — where roughly 40% of total losses actually originate — remains largely ungoverned. Establishing minimum standards for key custody, supply chain integrity, and multi-party authorization for high-value transaction signing would address the sector’s documented failure mode more directly than any amount of additional on-chain disclosure.

Most Popular