‹ BackNewsPermissions

Permissions

Crypto Securi
2026-09-30 03:00:58

Crypto security’s center of gravity is shifting from code bugs to permissions and trust chains

A TechFlowPost article argues that the biggest security failures in crypto are no longer centered on undiscovered smart contract bugs. Instead, recent losses have clustered around permissions, signing flows, RPC dependencies, supply chains, backend approval systems, and the people trusted to operate them. The piece points to four major incidents — Bybit, Bitget, KelpDAO, and Drift — as evidence that attackers are increasingly bypassing code and going after the trust assumptions wrapped around it. In the article’s framing, the industry has spent years hardening contracts, adding multisigs, separating cold wallets, and expanding audits, yet funds still disappeared because the systems approving transactions were fed false data or because authorized signers were manipulated into approving malicious actions. It also argues that AI is changing the economics of attacks by making social engineering, malware delivery, identity fabrication, and large-scale contract scanning cheaper and easier to automate. The article does not say audits are useless. Its point is narrower: audits cover a shrinking share of the places where money is actually lost. As attack surfaces move outward, the proposed response shifts as well — toward permission governance, infrastructure diversity, runtime controls, continuous monitoring, and insurance structures that price security architecture directly.

140
Crypto security’s center of gravity is shifting from code bugs to permissions and trust chains
Meta’s Muse faces another permissions dispute after arranging a Marketplace pickup without confirmation