Here's Why Security Audits Alone Aren't Enough to Protect Your Crypto
Features

Here's Why Security Audits Alone Aren't Enough to Protect Your Crypto

6m
3 hours ago

Infrastructure and key compromises drove 76% of 2026's hack losses. Four breaches in three weeks show why audits alone can't protect your crypto funds.

Here's Why Security Audits Alone Aren't Enough to Protect Your Crypto

Tabla de contenidos

Infrastructure and key compromises account for about 15% of this year's hacking incidents but 76% of the dollars lost; meanwhile, smart-contract bugs—the flaw retail checks for—make up 60% of incidents and only a small share of the damage.

Source: TRM Labs

That split points somewhere more uncomfortable than "read the audit." Four separate failures landed within three weeks, and each one had been set up long before the month it happened.

Allbridge lost $1.65 million on July 20 to a flaw its own 2023 patch left open. AFX lost $24.15 million two days later over how its signing keys were held.
Triple-A's treasury breach reached near $11.8 million by July 27 over who held the keys. Coldcard wallets have lost as much as $130 million since July 30 due to a March 2021 firmware release.

Every question retail knows to ask is present tense: is it audited, is it big, has it been hacked before?

Yet every one of these losses was set up in the past, by someone else, in a decision no depositor was ever shown.

Join us in showcasing the cryptocurrency revolution, one newsletter at a time. Subscribe now to get daily news and market updates right to your inbox, along with our millions of other subscribers (that’s right, millions love us!) — what are you waiting for?

AFX Trade's Hack Was Made Possible Months Earlier at Setup

AFX Trade runs its own bridge on a validator quorum, a set of signers who must clear a threshold before a withdrawal executes. On July 22, an attacker gained control of enough keys to clear it, roughly two-thirds of the total, and the withdrawal executed exactly as the system was built to allow.

Offchain Labs co-founder Steven Goldfeder said Arbitrum's native bridge was never touched. The contract logic did its job. What failed was a decision made long before July, when someone chose how many signers to use and where their keys would live—whether on hardware split across separate people and locations or as software keys on one operator's machine.

A deposit screen shows a token symbol and a network name. The validator count, who holds the keys, and whether they're hardware-secured across separate custodians never appear on it, and AFX's bridge doesn't publish them anywhere else either.

The attacker bridged the funds to Ethereum and swapped them for roughly 12,467 ETH. AFX offered to let them keep 30% if the rest came back, but as of Aug. 9 there's been no response and no recovery.

Source:

When a stolen key is the failure, there's no patch to write, only a negotiation.

Allbridge’s Failure Was Decided in 2023, When "Fixed" Meant One Pool

Five days earlier, a different bridge failed through a decision made three years ago.

An attacker borrowed $1.12 million from Kamino with no collateral, used it to skew the price in Allbridge's Solana USDC/USDT pool, withdrew at the distorted rate, and repaid the loan in the same transaction.
The flash loan attack netted $1.65 million before the protocol could react.
Allbridge lost roughly $570,000 to an identical pattern on its BNB Chain pools in 2023, and subsequently patched it. The patch covered the pool that was hit. The Solana pool ran the same design, untouched, for three more years.

A user checking Allbridge's history in June 2026 would have found a 2023 incident marked resolved—a fact both true and useless. What they needed to see was the scope of the fix, which nobody publishes, because a patch closes the hole it names and leaves the class of attack behind it open.

That gap is structural in any bridge built on liquidity pools instead of a lock-and-mint design, where funds lock on one chain and mint on the other, leaving no pool balance to manipulate.

Allbridge said it will return affected funds and move away from pools, though nearly three weeks on, it hasn't reported either as finished.

Triple-A Shows the Same Invisible Decision Cutting Both Ways

Triple-A, a Singapore-based stablecoin payments processor, confirmed unauthorized access to its treasury wallets starting July 24. The drain ran roughly 31 hours across Ethereum (ETH), TRON (TRX), Polygon (POL), Arbitrum (ARB), Solana (SOL), TON (GRAM), and Bitcoin (BTC).

Seven chains, one breach, because one operator held every key. Spreading funds across chains only helps when a different party controls each chain's keys, and that architecture was set long before the attacker arrived.

But the same kind of buried decision saved the customers. Triple-A's client funds were untouched because they sit in segregated trust accounts at separate institutions the company never custodies, so the company was able to absorb the loss from its own reserves.

Nothing visible to a client would distinguish the arrangement that lost $11.8 million from the one that lost nothing. Both were choices made years earlier, in the same invisible layer. Two weeks on, Triple-A has yet to disclose how the wallets were accessed.

Coldcard’s Fate Was Decided in March 2021, Five Years Before Anyone Lost a Coin

The purest version of this sort of predetermined failure arrived last. A March 2021 Coldcard firmware release routed seed generation through software randomization, bypassing the hardware generator and collapsing the randomness behind a seed phrase to as little as 40 bits on older models.

Anyone who set up a wallet on that firmware received a seed that an attacker could rebuild without ever touching the device.

The theft happened in 2026. The compromise happened in 2021, in a code path no owner could inspect, on hardware bought specifically to avoid trusting anyone.

Nobody caught it for five years. Starting July 30, attackers swept roughly 1,816 BTC from more than 5,200 addresses across four waves, the first draining 594 BTC in 25 minutes. By Aug. 7, a linked wallet moved about $1.94 million, with roughly 90% still sitting untouched.

Source:

Coinkite has shipped patched firmware for every affected model. It generates safe seeds going forward but cannot repair existing ones, so affected owners must move funds to a freshly generated seed themselves.

Disclosure Is the Only Thing You Can Verify

Most people think a bigger bridge is a safer bridge. That assumption is incorrect too.

LayerZero V2 carries one of the largest totals of any bridge on DeFiLlama, at $6.60 billion. It's also the network behind 2026's biggest DeFi hack.
In April, attackers drained $292 million from the Kelp DAO bridge by tricking its one verifier into reading fake data. Someone had chosen to rely on just that one verifier when they built the system. You couldn't see that choice on any deposit screen. And it had nothing to do with how much money the bridge held.

You can't check any of this the way you can check code with an audit. An audit tells you the contract logic works. It doesn't tell you who holds the keys, how many people have to agree before funds move, or what an old fix actually covered.

What you can check is simpler: does the operator tell you any of this at all? How many validators or verifiers does the bridge use, and how many of them must agree before money moves? How much of an old exploit did the last fix actually cover? Are customer funds kept separate from the company's own money, or mixed together in one pot?

Answering those questions doesn't make a bridge safe, but it's still the only part of this hidden decision layer that an outsider ever gets to see. When a bridge won't answer them, that silence is the clearest warning sign you can have.

Now put that risk next to what you're actually getting paid for taking it. Currently, Aave USDC is paying around 3.31%. Lido stETH is paying around 2.17%. A brokerage cash account, with none of this hidden risk, is paying roughly 3.13%. Ultimately, you are taking on invisible risk that no audit can catch, for a return that is barely more than a plain bank account.
This article contains links to third-party websites or other content for information purposes only (“Third-Party Sites”). The Third-Party Sites are not under the control of Vortex, and Vortex is not responsible for the content of any Third-Party Site, including without limitation any link contained in a Third-Party Site, or any changes or updates to a Third-Party Site. Vortex is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement, approval or recommendation by Vortex of the site or any association with its operators. This article is intended to be used and must be used for informational purposes only. It is important to do your own research and analysis before making any material decisions related to any of the products or services described. This article is not intended as, and shall not be construed as, financial advice. The views and opinions expressed in this article are the author’s [company’s] own and do not necessarily reflect those of Vortex.
0 people liked this article