Skip to content

The main battlefield of crypto security has changed: from vulnerability economy to permission economy.

Sep 30, 10:36·Original author: Fugui
The main battlefield of crypto security has changed: from vulnerability economy to permission economy.

Few days ago, on September 24, 2026, Bitget lost approximately $387.5 million from its hot and warm wallets. The attackers breached the backend system, injected fake transaction data, and triggered the exchange's own approval workflow. The CEO later stated in an announcement: "Our own system approved the transfer." Private keys were not compromised, and cold wallets remained untouched.

Five months earlier, on April 18, 2026, KelpDAO fraudulently minted approximately $290 million worth of rsETH due to tampered data on a single RPC node. Not a single line of contract code was erroneous. Attackers obtained the RPC list relied upon by the LayerZero DVN, breached two independent clusters, and swapped op-geth for a malicious version. The compromised nodes returned fake data only to the DVN's IP addresses while serving legitimate data to monitoring tools. They then used DDoS attacks to force fault migration onto the contaminated nodes. The DVN confirmed a transaction that never occurred, and the bridge released 116,500 rsETH without any actual burning.

Two weeks before that, on April 1, 2026, a member of the Drift protocol's security council pre-signed a blank transaction, allowing attackers to drain approximately $285 million within twelve minutes. Starting in autumn 2025, the attackers posed as quantitative trading firms, attended offline dinners with core contributors at international conferences, and even deposited over $1 million in genuine funds into the Ecosystem Vault. Once trust was established, they coerced the committee into signing what appeared to be a harmless governance transaction—hiding an ownership transfer inside it using Solana's durable nonce mechanism. Drift had just switched its multi-sig setup to zero latency and removed the timelock, leaving no room for withdrawal or reversal.

These three incidents totaled less than $1 billion, all occurring within the past year. Pushing back another year, on February 21, 2025, Bybit's cold wallet transferred out approximately $1.45 billion, marking the largest publicly acknowledged cryptocurrency theft to date. The attackers did not break Ethereum's cryptography, find a bug in the Safe multi-sig contract, or even directly touch private keys. Instead, they compromised the machines of Safe{Wallet} developers and injected JavaScript into the signing interface. The three signatories saw what looked like a routine operation on their screens—"cold wallet to hot wallet transfer"—and clicked confirm.

Totally, these four incidents add up to over $2.4 billion. None of these cases exploited undiscovered 0-days in contracts. Code audits were completed, formal verification was performed, multi-sigs were configured, and cold wallets were isolated, yet the funds were still stolen.

Some claim security has improved in 2026. Total industry losses in the first half reached $956 million to $1.39 billion, half of last year's figure. However, excluding the $1.45 billion outlier from 2025, the metric calculated by CertiK rose 28% year-over-year, and SlowMist recorded a 50% increase in incident volume. The median loss per incident surged 60.6% to $169,000. The numbers look better only because no record-breaking heists occurred this year—it doesn't mean thieves have stopped. They've multiplied, fragmented their operations, and each heist has become more expensive.

We've been upgrading our safe doors with thicker steel plates, while the thieves have already started climbing through the windows.

Beyond Signatures

Cryptography can ensure that no one can forge my signature, but it cannot guarantee why I chose to sign this transaction in the first place.

In the first half of 2026, 33 compromised wallets resulted in $445 million in losses. Another 1.52 billion USD was lost across 204 code vulnerability incidents. The numbers clearly show that compromising humans yields higher returns than exploiting code. Hacken's Q2 report states this even more bluntly: 88% of losses stemmed from operational compromises, while smart contract vulnerabilities accounted for only 11%. Out of 67 incidents, 44 involved contract vulnerabilities, yet they contributed less than 10% of the total financial damage.

The Drift case is the most typical. Attackers spent six months building trust, ultimately coaxing security council members into signing a seemingly benign governance transaction. This transaction utilized Solana's durable nonce mechanism—in essence, a signed blank check that could be cashed at any time. Within 12 minutes, across 31 withdrawals, over half of the locked assets vanished.

North Korea's Lazarus Group has industrialized this exact playbook. They craft fake resumes, set up shell companies, maintain authentic LinkedIn profiles, apply to target organizations, obtain SSO and VPN access, remain dormant for months, and gradually pivot toward machines used for signing. SlowMist estimates that North Korean-linked actors stole a combined $2.837 billion between January 2024 and September 2025, with $2.02 billion taken in 2025 alone, accounting for 76% of service-provider losses. Only 13.2% has been recovered. In the Bybit case, merely 3.54% was frozen after a year.

They don't hunt for code vulnerabilities; they hunt for individuals with signing authority. Finding humans is cheaper than finding bugs.

The Boundaries of Chains

The blockchain itself hasn't been hacked; everything surrounding the blockchain has been compromised.

Not a single line of code in the KelpDAO contract was flawed. This marks the first historical case where a compromised RPC node returning falsified data directly caused massive losses. It highlights a widely known but rarely acted-upon reality: so-called decentralized applications rely almost entirely on just two or three cloud providers and RPC services when reading data. MetaMask defaults to Infura, DApp backends use Alchemy and QuickNode, and L2 sequencers depend on these same nodes, which mostly run on AWS us-east-1. A chain may boast a thousand validators, yet everyone trusts data returned by merely two or three cloud providers. How is this decentralized?

TRM Labs' metrics are even sharper: infrastructure and operational incidents account for only about 15% of total incidents but drive roughly 76% of the losses. SlowMist's H1 data indicates that supply chain attacks rank third in incident frequency but first in financial damage, totaling approximately $298 million, with the KelpDAO breach alone accounting for $290 million.

Traditional hackers are also leveraging blockchains for similar purposes. A September 2026 Chainalysis report labels this practice as "Blockchain Dead Drops." Instead of hosting malware and C2 commands on servers, attackers embed them into BSC smart contracts and Bitcoin transactions. Domain seizures or server takedowns are useless. On-chain data cannot be deleted, and once infected, computers only need to sync blocks to retrieve new instructions. Over the past 12 months, such activity surged by 420%, with North Korean and Iranian-linked groups comprising two-thirds of the growth. Google Threat Intelligence has also tracked UNC5342 employing EtherHiding techniques since February 2025, targeting crypto developers via fake job postings, with payloads hidden inside TRON, Aptos, and BNB Chain smart contracts.

The blockchain's greatest strength—immutability—has become hackers' most reliable command-and-control server.

Permissions as Attack Surface

Web3 has shifted from a vulnerability economy to a permissions economy.

In the past, attackers did three things: find a bug, exploit it, and steal the funds. Today, they do the exact same three steps: find someone with signing authority, trick them into signing, and legally transfer the money.

Examining the Bybit and Bitget breaches side-by-side best illustrates this shift. Bybit lost $1.45 billion because signatories saw what looked like a routine liquidity replenishment to a hot wallet on their screens, while the actual signed transaction routed funds to hackers. Bitget lost $387.5 million without even modifying the frontend; attackers bypassed straight into the backend, injected fraudulent transaction data, and the exchange's own approval workflow recognized it as a standard internal transfer, automatically authorizing the movement.

Both heists were executed "legally." Multi-sig workflows were fully completed, signatures were valid, and contract execution strictly adhered to protocol rules. The issue isn't who can technically hack the system, but who holds the authorization to approve transfers. Signing interfaces can display manipulated prompts, and approval systems can process fabricated data. If multiple signatories all view the same contaminated RPC, rely on the same cloud provider, and use identical setups, then a 3-of-5 configuration is merely mathematical decentralization. In a real crisis, it remains a single point of failure. Many protocols achieve mathematically distributed multi-sigs at the smart contract level, but at the infrastructure layer, the entire stack runs on a single cloud provider, depends on one RPC endpoint, and is operated by one person managing a browser. This is "pseudo-decentralization," representing the most fatal single point of failure.

Among these major 2026 incidents: KelpDAO relied on a 1-of-1 DVN validation model; Drift used a zero-latency 2-of-5 multi-sig coupled with a blank-check transaction; Resolv Labs stored credentials in a single AWS KMS key; and Wasabi granted full admin rights to one external account. None of the four cases introduced new vulnerabilities—all stem from known misconfigurations and single points of failure. Data on Dune shows that 47% of applications in the LayerZero ecosystem still operate with 1-of-1 DVNs, 45% use two, and only 5% deploy three or more. Everyone knows single points are dangerous, but convenience often wins. Fifteen months before the KelpDAO breach, developers warned on the Aave governance forum to add more validators, but no changes were made. Now, both parties are litigating. Post-incident, LayerZero announced it will no longer sign transactions for any application configured with 1-of-1 setups.

The most dangerous transactions always appear the most compliant.

The Inversion of AI Attack Economics

AI hasn't made attacks smarter; it has simply enabled them to be executed at scale for the first time.

Previously, targeting a single individual or organization via social engineering took a month and carried high costs. Thus, phishing campaigns relied on broad net approaches—sending tens of thousands of emails to secure two or three successes. Today, AI automates identity fabrication, website cloning, phishing copywriting, automated vulnerability scanning, target identification, and attack execution.

North Korean-linked HexagonalRodent stole 26,584 wallets from 2,726 developer machines within three months. Its command dashboard features real-time infostealer views, VNC-style remote control, browser file managers, and team-member-based wallet "performance dashboards." Delivery methods involve configuring `runOn: "folderOpen"` in VS Code's `tasks.json`, executing immediately upon folder opening without requiring clicks. Attackers utilize ChatGPT and Cursor to write malware, generate fake corporate and executive profiles via AI, and even test whether backdoors evade antivirus solutions. TRM Labs' AI Crime Index nearly doubled from 28 in 2024 to 54 currently. From the start of 2026 through now, losses from deepfake scams have already reached 263% of the entire 2025 annual total.

Researchers from Anthropic and MATS developed SCONE-bench, a benchmark suite containing 405 historically attacked smart contracts. AI agents successfully simulated $4.6 million worth of attacks within this environment. When screening 2,849 newly deployed contracts with no known vulnerabilities, the AI discovered two 0-days valued at $3,694, against an API cost of $3,476, yielding an ROI of roughly 1.06. The return barely exceeds one, but these are preliminary results. A single generation improvement in model capability or an order-of-magnitude increase in contract scale would easily double this number. Once that threshold is crossed, "automated cross-chain scanning + automatic monetization" becomes a highly profitable enterprise.

The defense side is adopting AI as well. The day after Claude Opus 4.8's release, researchers leveraged it to uncover a four-year-old soundness flaw within the Zcash Orchard privacy pool's ZK circuit. Attackers could exploit this vulnerability to indefinitely forge ZEC tokens undetectably. Zcash emergency-activated a hard fork to isolate the risk. Zcash employs a mechanism called turnstile for cross-pool accounting checks. Even if issues arise internally within the Orchard pool, the total supply won't inflate infinitely. This serves as a runtime safeguard, catching failures precisely when cryptographic guarantees break down.

AI has flipped the cost burden onto defenders. Previously, attacking was expensive while defending was cheap; well-written audited code prevented most breaches. Today, crafting a highly targeted phishing email takes seconds, simulating a convincing video conference takes minutes, and batch-scanning thousands of legacy contracts for vulnerabilities requires minimal investment. Defenders must guard every entry point, while attackers only need to deceive one person. Four targeted social engineering attacks alone caused $310 million in losses, representing 85% of total phishing damages. Scammers have abandoned broad nets and are now specifically hunting whales.

Legacy code has become a prime target again. Q2 2026 saw code vulnerability incidents surge from 78 in Q1 to 126, as attackers systematically scan contracts deployed years ago that have never undergone re-auditing. BNB Chain experienced 33 legacy token attacks in the first half alone, ranging from tens of thousands to hundreds of thousands per incident—all uncovered through automated AI scanning. Audits capture a snapshot of code on deployment day, while attacks occur daily. Old code will always be revisited.

AI Agents have become new targets. Agents can read context, invoke tools, and sign transactions; a single malicious instruction hidden within normal input can instantly translate to tangible financial loss. Following the rollout of EIP-7702, USENIX 2026 research revealed that 63% of malicious delegated calls target compromised contracts. Account abstraction grants users convenience, but also expands attack surfaces. Historically, defenses targeted malicious actors; going forward, protections must guard against Agents that, upon receiving poisoned prompts, efficiently and legitimately transfer funds to attackers.

The Boundaries of Audits

According to CoinGecko's "2026 Crypto Security Report", among 245 incidents totaling $3.63 billion in losses, 147 protocols had already undergone independent audits, accounting for 88.44%. Only 11% of attacks targeted contract flaws actually covered by those audits. Supply chain and infrastructure vulnerabilities caused over $1.8 billion in damages.

Audits aren't useless; rather, the areas they cover increasingly diverge from where attackers strike. Audits examine smart contract code at deployment, whereas 2026 attacks target deployment keys, RPC endpoints, multi-sig workflows, supply chains, and post-audit integrations. Just because a thief enters through a window doesn't mean the door lock was poorly constructed.

Supply chain attacks ranked as the highest-loss vector in 2026, clocking in at $298 million per SlowMist metrics. A single malicious package on npm generates billions of weekly downloads; once integrated into frontends, SDKs, or wallets, it forces users to inadvertently sign fraudulent transactions. System breaches are unnecessary when you can get users to install it themselves. North Korean actors established a shell company named Veltrix Capital, extended offers to open-source maintainers, planted 24 malicious packages in npm, and 12 in PyPI. The most effective backdoor is always the one the user installs themselves.

Past security logic was straightforward: write code, audit, launch bug bounties, deploy, and pause contracts if incidents occur. This framework assumed the primary risk lay within the codebase itself. Since today's greatest threats originate outside the code, this traditional logic naturally fails to contain them.

Defense Must Follow the Attack Surface

If thieves stop using the front door, defensive lines cannot simply guard only the entrance.

Currently, the first diagram security teams should draft shouldn't be an architecture overview of smart contracts, but rather a complete end-to-end flowchart tracking fund movement from ingress to egress. Mapping the path from user wallets to treasuries reveals which signing nodes, administrators, oracles, and bridges are traversed. For every node, ask: If this point is compromised, what is the maximum fund exposure? How many signatures are required? Can execution be automated? Is there a timelock? Is there a secondary verification checkpoint? Can operations halt immediately upon incident detection? These questions yield far greater security dividends than repeating contract audits.

Next, avoid placing eggs in a single failure domain. It's not about how many signatories exist, but whether they rely on identical trust sources. If five signatories use the same cloud provider, same browser, same hardware wallet, and monitor the same RPC responses, a 3-of-5 arrangement remains purely mathematical decentralization—a single compromise ruins everything. True multi-sig implementation requires cross-vendor signing hardware, diverse network operators, jurisdictional separation of keys, and strict isolation between online and offline signing environments.

In July 2026, TeraSwitch published a defective interconnection route that propagated via Amsterdam's route reflectors. Consequently, 28.83% of staked SOL on Solana went offline simultaneously, falling just short of the 33.34% finality threshold by roughly 4.5 percentage points. Ninety validators were impacted, recovering after approximately 40 minutes. While the chain hosts 699 staking validators, the autonomous system AS20326 alone handled roughly 27.34% of staked SOL. Validators themselves may be decentralized, but their underlying custodians and upstream routing infrastructure are not. Validator decentralization does not equate to infrastructure decentralization.

Thus, "re-decentralization" is migrating from the consensus layer to the dependency layer. Shared sequencers, multi-DVN architectures, and independent failure domains are the true mechanisms for dismantling single points of failure.

RPC endpoints cannot be trusted by default. Systems handling substantial capital—such as oracles, bridges, liquidators, governance modules, and treasuries—must not base decisions solely on a single RPC response. Cross-validation across at least three distinct providers is mandatory; inconsistent responses should be treated as active attacks rather than transient network hiccups. High-value operations should run independent full nodes instead of relying on third parties. Post-KelpDAO, cryptographically verifiable RPCs capable of returning proofs will transition from optional selling points into institutional requirements.

Wallets must do more than verify signature validity; they must validate whether the transaction aligns with user intent. If a user requests "swap 1000 USDC for ETH with a maximum slippage of 0.5%," the wallet should first simulate the transaction, pass it through risk engines, and confirm legitimacy before prompting for authorization. Malicious calldata, unlimited approvals, address swaps, and frontend modifications can largely be intercepted at this layer.

Effective defense requires a four-layer architecture.

Layer One focuses on permissions governance. Eliminate 1-of-1 configurations across DVNs, multi-sigs, and ADMIN_ROLES. Mandate timelocks for all high-authority operations. Separate deployment keys from runtime keys, transferring deployer EOAs immediately post-deployment to prevent long-term admin retention.

Layer Two covers infrastructure hardening. Production environments must integrate RPC endpoints from at least two distinct cloud providers for failover redundancy. Critical decisions—withdrawals, minting, oracle price feeds—must undergo header or Merkle proof verification, refusing direct reliance on eth_call return values.

Layer Three implements runtime protection. Circuit breakers, rate limiting, and anomaly alerts are essential. Redefine "maximum potential loss" from Total Value Locked (TVL) to a formula of "time window × cap". THORChain's Solvency Checker paired with its Outbound Delay mechanism serves as an exemplary model: observer nodes continuously reconcile live native chain balances against internal state machine calculations. Even if on-chain logic or RPC nodes are compromised and hackers artificially inflate assets within the state machine, real-time reconciliation detects discrepancies immediately, suspending large withdrawal queues and using physical latency to block illicit arbitrage. This dual economic-time circuit breaker maintains a bottom-line safeguard at the treasury gates even when frontend and computational layers fail.

Layer Four replaces one-off audits with continuous review. Attack methodologies evolve faster than pre-launch audits can accommodate. The true value of monitoring tools lies in observing real-time system activity rather than assessing static code snapshots from months prior.

Finally, accept that breaches are inevitable. Abandon hopes of perfect defense; instead, design protocols to prevent catastrophic one-shot drains. Treasuries must never permit single transactions moving $100 million. Automate small transfers, trigger timelocks for medium sums, and mandate manual review for large amounts. Auditing ends at deployment, but on-chain monitoring must run perpetually, tracking transaction patterns, privilege alterations, oracle pricing deviations, RPC consistency, and gas anomalies. Security isn't solely about preventing attacks; it's the simultaneous execution of prevention, testing, containment, and recovery.

Risk sharing is equally critical. Hours after the KelpDAO incident, Aave froze rsETH markets while multiple protocols jointly absorbed bad debt. Decentralized insurance transcends simple payout mechanics; it distributes risk across network participants, incentivizing every token holder to actively monitor protocol security. Nexus Mutual is developing OpSec Failure Cover, while OpenCover launched Covered Vaults to embed risk transfer directly into vault products. More intriguing is cross-capital structuring: identical restaked capital secures network safety while underwriting DeFi vault risks. Upon incident activation, paired capital automatically triggers slashing mechanisms to compensate depositors.

Insurance premiums will eventually serve as market-priced valuations for security architectures. Underwriters assessing a protocol will demand answers: How many multi-sig signatories do you have? Is there a timelock? Are RPCs centralized? How many independent oracle data sources feed your system? What is the Treasury's maximum transfer threshold? Do circuit breakers exist? This isn't a security team prescribing compliance steps; it's capital markets quantifying the actual worth of your security posture.

Code is written by humans, humans make mistakes, configurations get forgotten, and single points inevitably slip through. Funds belong collectively, so collective vigilance drives mutual care.

Seek Trust, Not Vulnerabilities

Looking back over the past three years, the trajectory is clear.

Total 2024 losses reached $2.36 billion, marking the first year phishing surpassed private key leaks as the dominant threat, forcing awareness of human-factor vulnerabilities. In February 2025, Bybit's $1.45 billion drain pushed the annual total to $3.35 billion, exposing front-end supply chains and signing interfaces as lethal choke points. In 2026, breaches at KelpDAO, Drift, and Bitget cumulatively exceeded $900 million, establishing RPC endpoints and permission configurations as primary battlegrounds. AI transformed attacks into assembly-line processes, while even traditional hackers began leveraging blockchains as foundational infrastructure.

Over this three-year span, attacker strategy crystallizes: shifting focus from code exploitation to human manipulation, from on-chain targets to off-chain infrastructure, from discovering vulnerabilities to exploiting trust relationships. Direct losses at the consensus and execution layers of seven leading public chains approached zero over this period. Chains themselves have grown remarkably resilient, but massive capital continues draining through people, workflows, configurations, and surrounding infrastructure.

Web3 hasn't inherently become less secure; its highest-value attack surface has merely migrated from inside the code to outside it.

Cryptography guarantees signature authenticity, prevents transaction alteration, and ensures immutable on-chain records. Yet it cannot verify whether signatories were deceived, whether displayed data is accurate, whether approval requests are forged, or whether RPC-reported balances truly reflect on-chain reality. These are fundamentally trust issues, not cryptographic ones.

Future security demands holistic system management extending beyond code to encompass the entire trust chain. Security is no longer a static audit checkbox completed post-deployment; it must be a continuously operating framework spanning personnel, permissions, infrastructure, supply chains, and AI components. Each segment requires independent validation, and compartmentalization must prevent localized failures from cascading into systemic collapse.

Tomorrow's Web3 security won't rely on thicker walls, but finer-grained permission architectures. Design objectives shift from "we will never be breached" to "even if an operator is compromised, an RPC is poisoned, a dependency is corrupted, a signatory is duped, or an Agent makes faulty decisions, the system must prevent immediate total liquidation."

The measure of success is whether remaining system components stay upright after one element falls.

Where we once constantly asked "does this contract contain vulnerabilities?", we must now interrogate: Who holds transfer authority? What data dictates their decisions? How reliable are their trust assumptions? Who absorbs losses when breaches occur?

Only by asking the right questions can defense perimeters be positioned correctly.

Join the official Coincamps community:

X: https://x.com/coincamps

Telegram: https://t.me/coin_camps

Recommended

Hyperliquid will use $15 million USDC revenue for HYPE buybacks; buybacks will no longer rely solely on trading fees.

Oct 3, 18:27
Hyperliquid will use $15 million USDC revenue for HYPE buybacks; buybacks will no longer rely solely on trading fees.

Grayscale Zcash Spot ETF Sees $93.56M in Single-Week Redemptions: Honeymoon Period Turns Sharp, Once Held Nearly 3.5% of Supply

Oct 3, 16:41
Grayscale Zcash Spot ETF Sees $93.56M in Single-Week Redemptions: Honeymoon Period Turns Sharp, Once Held Nearly 3.5% of Supply

After resuming withdrawals, funds did not fall but rose instead. How did Bitget turn the situation around in five days?

Oct 3, 16:32
After resuming withdrawals, funds did not fall but rose instead. How did Bitget turn the situation around in five days?

SEC Clears 3x Leveraged Bitcoin and Ethereum ETPs: Listing Rules Approved, Trading Still Pending Activation

Oct 3, 16:22
SEC Clears 3x Leveraged Bitcoin and Ethereum ETPs: Listing Rules Approved, Trading Still Pending Activation

Funds Rose Instead of Fell After Withdrawals Were Resumed: How Did Bitget Turn Things Around in Five Days?

Oct 3, 16:11
Funds Rose Instead of Fell After Withdrawals Were Resumed: How Did Bitget Turn Things Around in Five Days?

CryptoPunks Trading Volume Surges Nearly 12X in a Week: Rare Variants Sell for Millions Again, Market Rally Decoupled from ETH

Oct 3, 13:36
CryptoPunks Trading Volume Surges Nearly 12X in a Week: Rare Variants Sell for Millions Again, Market Rally Decoupled from ETH