Finst

Crypto Hacks in 2026 Shift Toward Keys and Governance

Immunefi says attacks are increasingly moving through signing keys, governance, and infrastructure. BonkDAO and Humanity Protocol show how big the damage can be without a smart contract bug.

Crypto Hacks in 2026 Shift Toward Keys and Governance

Key Takeaways

  • In 2026, crypto attacks are shifting mostly toward keys, governance, and operational security, not just smart contract bugs.
  • Immunefi says about $972 million has already been stolen this year, with examples like BonkDAO and Humanity Protocol.
  • Audits alone are not enough, because key management, custody, and signing can also lead to major losses.

Crypto losses in 2026 are being driven less by smart contract bugs and more by weak points in keys, governance, and operational security. According to Immunefi, roughly $972 million (€854 million) has already been stolen this year, and more of those attacks are now flowing through signing keys, votes, and infrastructure than through coding errors.

Keys Are Becoming the Weak Spot

The BonkDAO incident shows how a treasury can be emptied even when the smart contract itself never breaks. In that case, an attacker spent about $4 million (€3.5 million) to buy enough tokens during low turnout to force a governance proposal through, and the proposal was then executed exactly as written. The weakness was not the code. It was the rules.

Humanity Protocol followed a similar pattern. In June, more than $30 million (€26.4 million) was lost after a private key on a team member's machine was compromised, while the contract itself remained untouched. The case reflects a broader shift that became clear in the first half of 2026: wallet compromises and other operational mistakes caused more damage than classic smart contract exploits. That also fits the wider trend showing that private keys account for a large share of hacks, rather than flaws in the code itself.

Audits Are Not Enough

Mitchell Amador, founder and CEO of Immunefi, says an audit only shows what the code looked like at a specific moment. It does not reveal who can sign transactions, how a key is stored, or what happens if a laptop is compromised. That means a protocol can clear several audits and still lose a huge amount of money; according to the text, one project even lost $128 million (€112 million) despite 11 audits.

The data supports that point. In an analysis of 425 hacks between 2021 and 2025, a small number of operational mistakes were responsible for most of the losses. During the 2024 to 2025 period, 54.6% of all stolen value across 191 hacks came from compromises of centralized exchanges, which points to keys, custody, and signing risks above the contract layer.

Why This Matters for Investors

For European crypto investors, the takeaway is that the biggest risks are becoming harder to spot in the code itself. Security work around infrastructure, key management, and governance is now just as important as audits or formal code reviews. That makes security more than a technical issue. It also affects investment products, custody, and the internal controls crypto companies put in place.

Immunefi says ongoing, incentive-based security programs can help a lot because researchers are paid to find vulnerabilities before attackers do. But that approach also has to extend beyond smart contracts and cover the people, systems, and rules that keep a protocol running.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.