Crypto projects losing millions due to exploits and hacks are becoming almost daily headlines. So much so that some of this news had almost become background noise.
While hacks are a big deal in the tech industry, the problem leading to these exploits in crypto isn't the technology itself; rather, it's the compromised "private key."
Blockchain projects have lost a total of $16.69 billion to hacks, DeFi exploits, and bridge attacks, according to data source DeFiLlama. About 40% of that amount is tied to someone obtaining a private key, rather than to a flaw in blockchain technology or a smart contract vulnerability.
In simple terms, private keys are like passwords. Think of online banking. The core infrastructure and systems that actually move and store users' money in traditional banks rarely get breached directly. But passwords get leaked or hacked, and malicious actors can gain access to millions of dollars online. That's the equivalent of the blockchain and smart contract code, and it's generally been solid. What's been compromised, again and again, is the private key or the equivalent of a password.
"We are observing that operational security incidents are rising while smart contract exploits are declining, reflecting that attackers typically target the weakest points. As projects have focused their security investments on smart contracts, other critical areas have been left exposed," CertiK, one of the leading blockchain and Web3 security firms, told CoinDesk.

How the hacks happen
Every crypto wallet has two key numbers. One is public, like a bank account number, which users share to receive money. The other is private, a string of characters like a user's bank password, that proves ownership of funds in their wallet and lets them spend them.
But here is where it gets more complicated. If a user loses this private key, there is no bank-like option to reset it, no private banker to help access funds, and no fraud department to file a claim. Whoever holds that key holds the funds, regardless of the tech or code behind that protocol.
Private key hacks fall into two categories: brute-force attacks, where attackers guess or brute-force their way to a user's private key. The second is the unknown method, in which the private key is leaked, but nobody is entirely sure how it happened.
These two methods account for roughly 40% of all crypto hack losses to date, underscoring that the majority of these exploits are not due to blockchain infrastructure but to vulnerabilities outside it.

-
1White House to speak with law enforcement groups to push Crypto's Clarity Act32 minutes ago
-
2J.P. Morgan broadens blockchain settlement network as banks modernize cross-border payments32 minutes ago
-
3Crypto analytics firm Chainalysis proposes standards for blockchain tracing48 minutes ago
-
4MiCA's looming deadline could leave 10 million crypto users without a platform in the EU52 minutes ago
-
5Ripple wants institutions to borrow against tokenized assets on XRPL56 minutes ago
-
6Wall Street's BNY expands stablecoin services for institutions, starting with Circle's USDC1 hour ago
-
7Strategy opens door to selling billions of bitcoin under new capital plan. Here's what it means1 hour ago
-
8Ukraine transfers $8.3 million in seized crypto amid potential plans for strategic reserve1 hour ago
-
9BlackRock pushes deeper into DeFi with Ethena integration, sending ENA up 8%1 hour ago
-
10Kalshi and Polymarket could become M&A targets as prediction markets consolidate: Bernstein2 hours ago

The Evolution of the Crypto CEX Landscape: A Case Study on Binance

The Evolution of the Crypto CEX Landscape: A Case Study on Binance
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Why it matters:
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.

Ripple wants institutions to borrow against tokenized assets on XRPL

Vitalik Buterin says crypto’s most powerful idea isn't nearly ready for use

coindesk.com