Hacken reports that of the roughly $764 million stolen from crypto projects last quarter, 88.3% came from compromised keys, signers, and infrastructure — not the smart contracts the audits examined. Fourteen exploited projects had been audited. An audit reads the code. But the losses came in through the admin keys and the signers, which is to say through the people trusted to hold them. So the trusted third party was never removed. It was just moved to where nobody was auditing. I think that's the whole finding.
0 replies
No replies yet.