Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Onchain Data, The Market's Most Honest Signal
onchain-bible.com
LATEST
Your LRT Yield Is Visible, Your Slashing Risk Isn't: The Hidden Break Point in EigenLayer Restaking  ·  Crypto's Biggest Losses Don't Come From Code Bugs — 2026 Data Breaks the Intuition  ·  The Contract "Self-Destructed," But Never Actually Disappeared: After EIP-6780, Onchain "Death" Is an Illusion  ·  You Only See the Outcome Onchain, Never the Process: How Intent-Based Trading Makes Solver Decisions Invisible  ·  Is This Address a Person or a Contract? EIP-7702 Breaks On-Chain's Most Basic Classification  ·  Whale Balances Rose 47%, But They Were Net Sellers of $130K — Three Tokens That Debunk 'Rising Holdings = Bullish'
fundamentals

Crypto's Biggest Losses Don't Come From Code Bugs — 2026 Data Breaks the Intuition

30-Second Version · For the impatient
What actually moved the money out in 2025 wasn't smart contract bugs — it was private key management and signing workflows. Infrastructure attacks made up 76% of total losses.

Full Explanation +
01 · Why did this happen?

Infrastructure attacks and code exploits are two distinct categories of security risk: the former targets Private Key management, multisig signing workflows, and frontend domains — the support systems outside the contract itself — while the latter is a flaw in the Smart Contract logic. Their attack surfaces, defense tools, and traceable signals are entirely different.

02 · What is the mechanism?

This distinction matters because the industry has spent the past decade pouring security resources heavily into code audits, yet TRM Labs' data shows the true source of massive losses is the infrastructure layer — revealing a clear mismatch between where resources go and where the real risk actually comes from, one that needs to be named before it can be corrected.

03 · How does it affect me?

Breaking down the actual numbers: in 2025, infrastructure attacks totaled 45 incidents and $2.2 billion in losses (76% of the total, averaging $48.5 million per incident); code exploits totaled 52 incidents and $350 million (12.1%, averaging $6.7 million per incident); protocol attacks totaled 25 incidents and $277 million (9.6%, averaging $11.1 million per incident). The most frequent category is not the most costly category — that inversion is the point.

04 · What should I do?

The practical takeaway is this: when assessing a protocol or exchange's security, don't stop at "has it been audited" — also ask how private keys are managed, what the multisig threshold is, who the signers are, and whether the frontend has ever been hijacked. None of these appear in an audit report, but they're exactly where the massive 2025 losses actually came from, and they deserve equal attention.

Full Content +

Ask anyone familiar with crypto what the biggest security risk is, and most answers will circle around smart contracts: reentrancy attacks, Flash Loan manipulation, edge cases that audits missed. That instinct isn't baseless — there have been plenty of high-profile contract exploits over the years. But TRM Labs' 2026 Crypto Crime Report lays out a different ranking once you look at the actual numbers.

Across all of 2025, infrastructure attacks caused $2.2 billion in losses — 76% of total losses for the year — across 45 incidents, averaging $48.5 million per incident. Code exploits, by contrast, were the most frequent category at 52 incidents, but caused only $350 million in losses, just 12.1% of the total, averaging $6.7 million per incident. Protocol attacks accounted for 25 incidents and $277 million, or 9.6%, averaging $11.1 million per incident. In other words: code exploits happen most often, but infrastructure attacks are what's actually moving the bulk of the money out — with more than seven times the damage per incident compared to code exploits.

What "Infrastructure Attack" Means, and How It Differs From a Code Exploit

A code exploit is a flaw in the Smart Contract logic itself — exactly what audits, Formal Verification, and bug bounties are built to catch, and what the industry has spent the most resources defending over the past decade. An infrastructure attack is something else entirely: it doesn't target contract logic, it targets the layer outside the contract that keeps the whole system running — Private Key management, multisig signing workflows, frontend domains and DNS, cloud service accounts, employee devices and permissions, signing servers. These pieces are rarely written into smart contract code, audit reports almost never cover them, yet they're the entry point attackers have most frequently and most successfully targeted in recent years.

Why This Gap Gets Overlooked

This gap persists partly because "audited" has become shorthand for "safe." A protocol announcing it passed three separate audit firms sounds reassuring, but audit scope almost never extends to how private keys are stored, how secure employee devices are, or who has access to frontend servers. That creates a resource-allocation mismatch: protocols pour most of their security budget into audits and code review, while relatively little goes into signing-process hygiene and internal access management — precisely the area attackers have actually been exploiting.

What This Means for Your Money

For anyone using onchain data to assess risk, this means "is this protocol safe" can't be answered by checking whether it has an audit report alone. A few infrastructure-layer signals matter too: whether multisig signers are overly concentrated among a small group, whether the multisig threshold is reasonably set, whether the team has publicly documented its internal security processes (how signing servers are isolated, for example), and whether the frontend domain has any history of hijacking or phishing incidents. None of these show up in a code audit report, but onchain multisig transaction history, domain registration records, and historical incident disclosures can offer indirect clues. Treating "passed audit" as synonymous with "secure" is precisely the misconception this data set out to correct.

Sources: TRM Labs — 2026 Crypto Crime Report, TRM Labs — H1 2026 crypto hacks reach record high as losses fall below USD 1 billion
Diagram
2025 年損失結構:基礎設施攻擊 vs 程式碼漏洞TRM Labs 2026 報告:基礎設施攻擊 45 起、損失 22 億美元(76%);程式碼漏洞 52 起、損失 3.5 億美元(12.1%)2025 Crypto Losses by Attack Category (TRM Labs)Infrastructure Attacks$2.2B (76%)Code Exploits$350M (12.1%)Protocol Attacks$277M (9.6%)Incident count:Infra 45 | Code 52 | Protocol 25Avg loss/incident:Infra $48.5M | Code $6.7M | Protocol $11.1MMost frequent category (Code) is NOT the most costly category (Infrastructure)onchain-bible.com · Source: TRM Labs 2026 Crypto Crime ReportOnchain Bible · onchain-bible.com
Feel free to share. Please credit the source.
Ask a Question
Please enter at least 10 characters
Related Articles
The Longest Miner Capitulation on Record Just Ended: What Is the Hash Ribbon Indicator Actually Measuring?
fundamentals · Aug 31
How Do You Actually Verify "Network Effect" On-Chain? The Gap Between Active Addresses and Genuine Usage
fundamentals · Aug 19
Are Miners Selling? The Other Half of the Story Hashrate Distribution Doesn't Show You
fundamentals · Aug 19
"Whose Wallet Is This?" How the On-Chain World Figures Out Who's Behind an Address
fundamentals · Aug 17
More Related Topics