Private keys, not smart contracts, caused 40% of crypto’s $16 billion hack losses. Here’s whats being done.

Share This Post

“Most blockchain infrastructure was originally built for a single-user, single-key model, one private key controls everything, and if that key is lost or stolen, all the assets are gone instantly. This goes against the basic security principles that traditional finance has relied on for decades: more than one person approving, separation of duties, and several layers of defense,” Wu told CoinDesk.

In a way, the system built to revolutionize global finance has weaker security than a typical email account.

Wu added that the number of routes through which an attack can be launched has increased significantly. “Cloud systems, third-party tools, social media accounts, and the people operating them, all of these can become a way in.”

Both Wu and Fan pointed to the Bybit hack of February 2025 as an example of a widening attack surface. Attackers compromised the software supply chain of a third-party developer tool, allowing them to inject malicious code into the wallet’s web interface and trick executives into unknowingly signing away $1.5 billion in Ethereum.

The fix

The industry is now moving to address the private key vulnerability issue, though not evenly, according to Wu.

“There’s progress on many fronts: MPC [multi-party computation] wallets, account abstraction with social recovery, passkey-based login, hardware wallet enforcement, and proper key management SOPs,” he said. “The problem is that these are often added as optional extras, instead of being built in from the start at the protocol level. Most chains still treat security as a feature to bolt on, not as a core design principle.”

Related Posts

Pump.fun’s PUMP Buybacks Top $400M as Token Stays Flat

The Solana launchpad's repurchases since July now exceed $400M,...

Can AI drain DeFi? Separating Claude Mythos hype from reality

Claude Mythos and DeFi: Real threat or overblown fear?When...

White House to speak with law enforcement groups to push Crypto’s Clarity Act

White House officials — especially lead crypto adviser Patrick...

Bitget Blocks 150 Million Cyber Threats in Major Security Push

Bitget, the world’s largest Universal Exchange (UEX), has launched...

Wall Street’s BNY expands stablecoin ties with Circle, lets institutions mint and hold USDC

Unlike cryptocurrencies such as bitcoin, stablecoins are designed to...