Private Key Compromises Account for Over 40% of Crypto Hack Losses

Private Key Compromises Account for Over 40% of Crypto Hack Losses

N
News Editor 01
2026-07-24 02:15:16
DeFiLlama data shows crypto projects have lost $16.69 billion to hacks, with about 40% tied to compromised private keys. Security firms say the main weakness is no longer smart contract code, but key management and operational security.

Compromised private keys, not smart contract bugs, are behind a large share of crypto losses. Data from DeFiLlama shows blockchain projects have lost a total of $16.69 billion to hacks, DeFi exploits, and bridge attacks, and roughly 40% of that amount is linked to attackers obtaining private keys rather than breaking blockchain infrastructure or finding flaws in smart contracts.

The distinction matters. The article argues that the core cryptographic systems have generally held up, while the weak point has often been how keys are handled in practice. CertiK told CoinDesk that operational security incidents are rising as smart contract exploits decline, a shift that suggests attackers are moving toward the weakest available targets. As more projects concentrated security spending on contract audits, other sensitive areas were left exposed.

Why private keys keep becoming the point of failure

Every crypto wallet relies on two pieces of information: a public key, which works like an account number for receiving funds, and a private key, which proves ownership and authorizes spending. Unlike a bank password, though, a private key cannot simply be reset through a support desk or fraud department. If that key is lost or stolen, control of the funds goes with it.

The source breaks private key incidents into two broad groups. One is brute-force attacks, where attackers guess their way to a key. The other is an unknown method, where the key was clearly leaked but the exact path of compromise is unclear. Together, those two categories account for about 40% of all crypto hack losses so far. That points away from blockchain design itself and toward failures in systems surrounding it.

The real exposure sits in day-to-day key management

Leo Fan, founder and CEO of ZK Proof Layer Cysic, said private key hacks are not failures of cryptography but failures of key management that the industry keeps mislabeling. In his words, the elliptic curve math is unbreakable. The problem starts when an operational key has to remain active to sign blockchain transactions. At that point, it lives inside a running service, next to secret stores, cloud credentials, software dependencies, and the people managing the setup.

That environment creates risk. The source compares private keys to passwords: a password that is never used and never written down is extremely hard to steal, but once it is entered on devices, stored somewhere, or shared across systems, the chances of leakage rise. The same logic applies to private keys. Use them, store them, or pass them around, and the attack surface expands.

The piece also cites Pharos co-founder and CEO Wish Wu, who traces the issue back to the way blockchain systems were originally designed. Based on the figures cited, the security discussion in crypto is no longer centered only on smart contract code. It is also about protecting private keys from the operational environments where breaches keep happening.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.