A year that has already seen $972 million in crypto stolen is offering a blunt reminder about where digital asset security is still breaking down. In a CoinDesk Crypto Long & Short column, Immunefi co-founder Mitchell Amador argues that the biggest losses in 2026 have come less from smart contract flaws than from failures around keys, signers and governance.
That distinction matters. For years, many projects have treated a security audit as a benchmark for safety. But as Amador notes, being audited is not the same as being secure. Audits can help surface code issues, yet they do not eliminate the operational and organizational risks that often sit outside the contract itself.
The takeaway from this year’s losses, as described in the piece, is that attackers do not need to find the weakest line of code if they can instead compromise the people, systems or processes that control access. Private keys remain a critical point of failure. So do signer workflows and governance structures that determine how funds move or how permissions are changed.
That shift is important for market participants because it broadens the definition of security. It is no longer enough to ask whether a protocol’s code has been reviewed. A fuller assessment has to include how keys are stored, who can approve transactions, how signers are managed and whether governance controls are robust enough to resist abuse or compromise.
The column does not suggest that audits are useless. Rather, it frames them as one layer in a wider defense model. In practice, that means the industry’s conversation is moving away from a narrow focus on code quality and toward a more operational view of risk.
For investors and users, the message is straightforward: losses can arise from vulnerabilities that are not visible in a code review. For builders, the implication is that security posture needs to extend beyond the contract to the full stack of permissions and controls surrounding it.
The article points to a familiar but still uncomfortable truth in crypto markets. Security is not a single event or a certification stamp. It is a continuing process, and this year’s hacks suggest that the most costly failures are often the ones that sit outside the codebase altogether.
Source: CoinDesk, citing Immunefi's Mitchell Amador.



