Attackers Shift Beyond Smart Contracts
Code audits have become far more sophisticated, helping developers catch vulnerabilities before projects go live and reducing the number of flaws found in smart contracts. But as the technology has improved, hackers have changed their approach.
Attackers are trying to exploit humans and systems inside an organization rather than bugs in coding. Such types of attacks include phishing attacks, stealing private keys, exploitation of system updates, and internal threats. Many large-scale thefts in recent times have been due to such attacks, not flaws in the coding of applications.
Researchers said audits are still working as intended, identifying security issues before deployment. The problem is that audits can only assess code. They cannot prevent an employee from handing over credentials, approving a fraudulent transaction, or falling victim to a phishing attack. As a result, strong code is no longer enough to protect a crypto platform on its own.
Related: Binance at Risk of Losing EU Access as Greece Rejects MiCA Licence
False Confidence Creates New Risks
Crypto projects often point to security audits as evidence that their platforms are safe, highlighting completed reviews and reports from auditing firms. For many users, those audits can create the impression that a project is protected from major security failures.
Researchers say that assumption can be misleading. An audit only evaluates a project’s code at a specific point in time. New risks can emerge as platforms update their infrastructure, change governance structures, or expand operations.
The recent KelpDAO hack underscores that challenge. While the attack was not linked to a flaw in audited smart contract code, users still saw another crypto platform lose funds. Security experts say most investors do not distinguish between a coding failure and an operational failure when money is lost.
According to the report, reducing those risks will require more than code reviews. Researchers said projects should strengthen private key security, improve monitoring systems, expand employee security training, and add safeguards that can detect suspicious activity before losses escalate.
Related: SBF Says He Could Launch a New Coin After Prison as Lost Investments Reach Billions