What the record actually shows
Across the 25 incidents in our tracker, key compromise is the largest single attack class, appearing in 13 records. Bridge exploits follow at 7 — and every one of those also failed on key management or message validation rather than on cryptography.
Reentrancy, the vulnerability class that defined smart contract security discourse for a decade, appears twice.
Where the attention goes instead
Audits are visible, marketable and countable. “Audited by three firms” fits on a landing page. “Our signers verify raw payloads on separate infrastructure and we rotate access when contractors leave” does not.
Yet the incidents that produced the largest losses in our record — Bybit, Radiant Capital, and now the Coldcard entropy failure — involved no contract defect at all. In two of them, hardware wallets and multi-signature schemes were both in use and both behaved exactly as designed.
The uncomfortable version
An audit tells you a reviewer read the code. It cannot tell you who holds the keys, whether access was revoked when someone left, whether the machine constructing a transaction is the machine displaying it, or whether the entropy behind a seed was real.
Those are the questions the loss data keeps pointing at, and they are considerably harder to put in a marketing page.
Sources
- QuillAudits, July 2026 Crypto Hacks — monthly breakdown (1 Aug 2026)
- MetaMask, Crypto Security Report: July 2026 (1 Aug 2026)
Not advice. Conisec reports for information only. Nothing in this article is financial, legal, tax or security advice. Verify against the primary sources linked above before acting on anything.