CoinDesk’s Crypto Long & Short this week features a piece by Immunefi’s Mitchell Amador arguing that the biggest lesson from 2026’s $972 million in crypto hacks is not simply about flawed code. According to the article, most of the stolen funds this year have left projects through compromised keys, signers, and governance mechanisms rather than smart contract bugs alone. Amador’s core point is that security failures are showing up in operational control layers that audits do not fully cover. He also stresses that the phrase “we were audited” was never the same as saying “we are safe,” drawing a line between code review and actual end-to-end security. The article was published by CoinDesk on July 29, 2026, under the Crypto Long & Short column.
CoinDesk published a new Crypto Long & Short column on July 29 saying that the main lesson from this year’s $972 million in crypto hacks may lie outside smart contract code.
In the piece, Immunefi’s Mitchell Amador writes that most of 2026’s stolen crypto is leaving through keys, signers, and governance, rather than contract bugs. The argument shifts attention away from code exploits alone and toward the people, permissions, and control structures around a protocol.
Audits are not the same as safety
Amador also writes that “we were audited” was never the same as “we are safe.” His point is that an audit does not cover every path through which funds can be lost, especially when major failures are showing up in key management, signer access, and governance processes.
The article appeared in CoinDesk Indices under the Crypto Long & Short banner and was written by Mitchell Amador.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.