The Good Tech Companies - Admin Keys, Phishing, and DNS: The New Front Line of Crypto Security
Episode Date: August 21, 2026This story was originally published on HackerNoon at: https://hackernoon.com/admin-keys-phishing-and-dns-the-new-front-line-of-crypto-security. Crypto losses fell in H1 ...2026, but attacks reached a record. Learn why admin keys, phishing, DNS, credentials, & governance are becoming critical security risks Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #crypto-security-2026, #crypto-security-threats, #crypto-phishing-attacks, #crypto-dns-attacks, #defi-security, #smart-contract-security, #crypto-infrastructure-security, #good-company, and more. This story was written by: @jonstojanjournalist. Learn more about this writer by checking @jonstojanjournalist's about page, and for more stories, please visit hackernoon.com. Crypto losses fell to roughly $972 million across 207 incidents in the first half of 2026, but the record incident count shows attackers have not slowed down. As smart contract security improves, attackers are increasingly targeting admin keys, credentials, governance systems, phishing, DNS, and operational infrastructure. The result is a broader crypto security problem that traditional smart contract audits alone cannot address.
Transcript
Discussion (0)
This audio is presented by Hacker Noon, where anyone can learn anything about any technology.
Admin keys, fishing, and DNS. The new front line of crypto security by John Stoy and journalist.
Roughly $972 million was lost across 207 incidents in the first half of 2026, less than half the
total of the same period a year earlier, while the incident count more than doubled from 83 and set a record.
Attacks became more frequent and less profitable at the same time. That is a chance.
change in where the money leaves, not in whether protocols get attacked. Losses fell.
Attacks did not. For most of the past five years, the industry's working model of crypto-risk
begin and ended with a contract bug. The apparatus built around that model changed the economics
of attacking the code well enough that breaking a contract is no longer the only route to a major
loss. Verification got formal, audits go repeated, bounty programs became standing rather than
occasional. None of it reduced the capital sitting inside those protocols. Immune Fee, which
operates bug bounty infrastructure for the sector and has an interest in the answer, puts Defy Exploid
Losses 74% below their 2022 peak of $2.62 billion at $680, $3 million across full year 2025,
with the median loss per exploit falling 75% over the same stretch. TRM Labs, measuring the same period
on a different taxes, found that infrastructure and operational compromises made up roughly 15% of
incidents but about 76% of the value stolen. Code is no longer necessarily the weakest link in Web 3,
says Jimmy Sue, chief security officer at Binance. As smart contract security improves,
attackers are shifting their attention to the people, credentials and governance systems
surrounding protocols. We saw this firsthand when Binance security helped prevent a $1.2 million
governance attack on brain trust. Protecting a protocol today means securing not just its code,
but also who can control it, how that control is exercised, and the infrastructure and people behind it.
A distribution where a sixth of the incidents carry three quarters of the damages not one a code
review reaches. What separates a routine theft from a protocol ending one now sits in operational
control rather than in audited logic, and the arithmetic shows it. TRM put the median hack at roughly
$219,000 against a mean of $4.7 million. What an audit cannot see. An audit is a snapshot.
It measures the code as it stood on a particular date and says nothing about who holds the keys
to it afterward, which is why, we wear audited, has never been the same statement as,
we are safe. The loss record supports the distinction, though the firm making the case sells
the alternative. Immune fees analysis of 425 hacks between 2021 and 2025 traced 54.
6% of the value lost across 2024 and 2025 to centralized exchange compromises rather than to contract exploits.
Continuous review keeps surfacing what a point in time pass closed the book on, and Immune fee's own numbers are the argument for its product.
93.
9% of bounty programs running five years or longer eventually produce a confirmed critical vulnerability.
A protocol can pass a flawless code audit and still lose millions because of a compromised admin key, says Rungwee G.U.
co-founder of Sur Decay. The economics on the defensive side are lopsided in a way that rarely
gets stated plainly. Around 20% of confirmed vulnerability reports are rated critical and
immune fee paid researchers $13.45 million for 837 valid bugs in the first half of 2026 alone.
Set a median bounty of $20,000 against an average hack of roughly $25 million, and the incentive
to disclose rather than exploit starts to look thin. The harder-listing,
limit remains even where the incentive works. One protocol was audited 11 times and still lost
$128 million. Five firms, four totals, one definitional argument. Five security firms measured the same
six months and published four different answers. Immune Fee and TRM Labs both landed at roughly
$972 million across 207 incidents. Slow MIST counted 182 incidents and about $956 million.
PEC Shield put the damage near $750 million.
Serta K reported $1,315 billion across 344 incidents on a scope that explicitly counts
fishing and wallet compromise alongside exploits.
Read that way, wallet compromise becomes the costliest category at more than $44 million,
with a $13 million average per event.
Code bugs are the most frequent category at 204 incidents and among the cheapest at $1,504.
$51.6 million. None of the five is counting badly. They are counting different things, and none
publishes a reconciliation against the others. The spread is an unresolved argument about whether
a stolen seed phrase is a hack, and the answer decides what the industry believes it is defending.
Budgets follow the definition, which is why the narrow one is expensive. It undercounts precisely
the category that is growing. What the half actually measured, a falling loss total alongside
a record incident count reads less like a safer market than a relocated one. Hardening the
contracts worked and the effect was to move attacker attention onto credentials, operations and
the infrastructure sitting around the code. That residual risk now sits where most security
budgets were never built to look. This suggests resilience through the rest of 2026 may
increasingly depend on how well protocols defend the access layer rather than the contract itself.
This story was distributed as a release by John Stoyen under Hackernoon Business Blogging Program.
Thank you for listening to this Hackernoon story, read by artificial intelligence.
Visit hackernoon.com to read, write, learn and publish.
