• bitcoinBitcoin (BTC) $ 109,220.00
  • ethereumEthereum (ETH) $ 2,572.31
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.27
  • bnbBNB (BNB) $ 662.80
  • solanaSolana (SOL) $ 151.82
  • usd-coinUSDC (USDC) $ 0.999901
  • tronTRON (TRX) $ 0.287183
  • dogecoinDogecoin (DOGE) $ 0.171899
  • staked-etherLido Staked Ether (STETH) $ 2,571.98
  • cardanoCardano (ADA) $ 0.586237
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 109,268.00
  • hyperliquidHyperliquid (HYPE) $ 39.79
  • wrapped-stethWrapped stETH (WSTETH) $ 3,098.43
  • suiSui (SUI) $ 2.91
  • bitcoin-cashBitcoin Cash (BCH) $ 494.30
  • chainlinkChainlink (LINK) $ 13.51
  • leo-tokenLEO Token (LEO) $ 9.00
  • stellarStellar (XLM) $ 0.252024
  • avalanche-2Avalanche (AVAX) $ 18.33
  • usdsUSDS (USDS) $ 0.999884
  • the-open-networkToncoin (TON) $ 2.84
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • wrapped-eethWrapped eETH (WEETH) $ 2,754.78
  • hedera-hashgraphHedera (HBAR) $ 0.159525
  • wethWETH (WETH) $ 2,572.01
  • litecoinLitecoin (LTC) $ 87.43
  • whitebitWhiteBIT Coin (WBT) $ 45.06
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • moneroMonero (XMR) $ 319.23
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 109,216.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 4.47
  • polkadotPolkadot (DOT) $ 3.40
  • uniswapUniswap (UNI) $ 7.44
  • aaveAave (AAVE) $ 286.76
  • pepePepe (PEPE) $ 0.000010
  • daiDai (DAI) $ 0.999703
  • pi-networkPi Network (PI) $ 0.463712
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.18
  • bittensorBittensor (TAO) $ 326.75
  • okbOKB (OKB) $ 48.78
  • aptosAptos (APT) $ 4.47
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 184.43
  • nearNEAR Protocol (NEAR) $ 2.19
  • internet-computerInternet Computer (ICP) $ 4.85
  • ethereum-classicEthereum Classic (ETC) $ 16.67
  • crypto-com-chainCronos (CRO) $ 0.081283
  • ondo-financeOndo (ONDO) $ 0.795980
  • susdssUSDS (SUSDS) $ 1.06
  • usd1-wlfiUSD1 (USD1) $ 0.999459
  • kaspaKaspa (KAS) $ 0.077376
  • mantleMantle (MNT) $ 0.572168
  • fasttokenFasttoken (FTN) $ 4.43
  • cosmosCosmos Hub (ATOM) $ 4.08
  • gatechain-tokenGate (GT) $ 15.23
  • vechainVeChain (VET) $ 0.020851
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.681630
  • official-trumpOfficial Trump (TRUMP) $ 8.63
  • bonkBonk (BONK) $ 0.000022
  • skySky (SKY) $ 0.079528
  • render-tokenRender (RENDER) $ 3.23
  • ethenaEthena (ENA) $ 0.262426
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 109,176.00
  • arbitrumArbitrum (ARB) $ 0.334324
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.183632
  • quant-networkQuant (QNT) $ 108.69
  • filecoinFilecoin (FIL) $ 2.29
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,571.40
  • algorandAlgorand (ALGO) $ 0.177222
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.51
  • worldcoin-wldWorldcoin (WLD) $ 0.892758
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998027
  • sei-networkSei (SEI) $ 0.264729
  • usdtbUSDtb (USDTB) $ 0.999641
  • tokenize-xchangeTokenize Xchange (TKX) $ 18.09
  • binance-staked-solBinance Staked SOL (BNSOL) $ 161.04
  • kucoin-sharesKuCoin (KCS) $ 11.07
  • usdt0USDT0 (USDT0) $ 0.999369
  • jupiter-exchange-solanaJupiter (JUP) $ 0.445066
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,695.96
  • nexoNEXO (NEXO) $ 1.23
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,929.63
  • spx6900SPX6900 (SPX) $ 1.30
  • fartcoinFartcoin (FARTCOIN) $ 1.17
  • flare-networksFlare (FLR) $ 0.016541
  • celestiaCelestia (TIA) $ 1.62
  • polygon-bridged-usdt-polygonPolygon Bridged USDT (Polygon) (USDT) $ 1.00
  • injective-protocolInjective (INJ) $ 10.62
  • xdce-crowd-saleXDC Network (XDC) $ 0.063316
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.55
  • blockstackStacks (STX) $ 0.658824
  • sonic-3Sonic (S) $ 0.312490
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.015784
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999847
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,759.91
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,702.07
  • optimismOptimism (OP) $ 0.544131
  • syrupusdcSyrupUSDC (SYRUPUSDC) $ 1.11
  • pax-goldPAX Gold (PAXG) $ 3,333.09
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 109,097.00
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 109,065.00
  • kaiaKaia (KAIA) $ 0.155632
  • story-2Story (IP) $ 3.13
  • wbnbWrapped BNB (WBNB) $ 662.76
  • dogwifcoindogwifhat (WIF) $ 0.877095
  • paypal-usdPayPal USD (PYUSD) $ 0.999482
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,701.33
  • clbtcclBTC (CLBTC) $ 110,087.00
  • the-graphThe Graph (GRT) $ 0.084672
  • flokiFLOKI (FLOKI) $ 0.000086
  • tether-goldTether Gold (XAUT) $ 3,323.95
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 170.38
  • immutable-xImmutable (IMX) $ 0.424263
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.28
  • vaultaVaulta (A) $ 0.483002
  • msolMarinade Staked SOL (MSOL) $ 198.36
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,778.95
  • ousgOUSG (OUSG) $ 111.69
  • theta-tokenTheta Network (THETA) $ 0.701579
  • curve-dao-tokenCurve DAO (CRV) $ 0.501502
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.73
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998044
  • jito-governance-tokenJito (JTO) $ 1.93
  • lido-daoLido DAO (LDO) $ 0.742959
  • galaGALA (GALA) $ 0.014286
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.09
  • zcashZcash (ZEC) $ 39.29
  • ethereum-name-serviceEthereum Name Service (ENS) $ 18.75
  • wrapped-hypeWrapped HYPE (WHYPE) $ 39.72
  • iotaIOTA (IOTA) $ 0.159794
  • bittorrentBitTorrent (BTT) $ 0.00000061
  • the-sandboxThe Sandbox (SAND) $ 0.246248
  • aerodrome-financeAerodrome Finance (AERO) $ 0.703386
  • syrupMaple Finance (SYRUP) $ 0.556111
  • solv-protocol-solvbtc-bbnSolv Protocol Staked BTC (XSOLVBTC) $ 108,799.00
  • saros-financeSaros (SAROS) $ 0.225986
  • jasmycoinJasmyCoin (JASMY) $ 0.012250
  • usual-usdUsual USD (USD0) $ 0.997870
  • raydiumRaydium (RAY) $ 2.17
  • super-oethSuper OETH (SUPEROETH) $ 2,571.85
  • tbtctBTC (TBTC) $ 108,961.00
  • pyth-networkPyth Network (PYTH) $ 0.099005
  • walrus-2Walrus (WAL) $ 0.410163
  • pendlePendle (PENDLE) $ 3.42
  • tezosTezos (XTZ) $ 0.530223
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 2,754.24
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,572.27
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 2,713.41
  • falcon-financeFalcon USD (USDF) $ 0.999773
  • newton-projectAB (AB) $ 0.008116
  • flowFlow (FLOW) $ 0.326842
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 109,219.00
  • decentralandDecentraland (MANA) $ 0.266655
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,572.60
  • coredaoorgCore (CORE) $ 0.501922
  • staked-hypeStaked HYPE (STHYPE) $ 39.71
  • true-usdTrueUSD (TUSD) $ 0.998653
  • apecoinApeCoin (APE) $ 0.611335
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • bitcoin-svBitcoin SV (BSV) $ 24.34
  • venomVenom (VENOM) $ 0.230917
  • chain-2Onyxcoin (XCN) $ 0.014009
  • dog-go-to-the-moon-runeDog (Bitcoin) (DOG) $ 0.004690
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999901
  • thorchainTHORChain (RUNE) $ 1.34
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.172094
  • based-brettBrett (BRETT) $ 0.044122
  • apenftAPENFT (NFT) $ 0.00000044
  • morphoMorpho (MORPHO) $ 1.40
  • dexeDeXe (DEXE) $ 7.54
  • beldexBeldex (BDX) $ 0.060380
  • kavaKava (KAVA) $ 0.395157
  • heliumHelium (HNT) $ 2.31
  • usddUSDD (USDD) $ 0.999591
  • reserve-rights-tokenReserve Rights (RSR) $ 0.007196
  • hashnote-usycCircle USYC (USYC) $ 1.09
  • starknetStarknet (STRK) $ 0.113661
  • movementMovement (MOVE) $ 0.155498
  • usdbUSDB (USDB) $ 0.996277
  • stader-ethxStader ETHx (ETHX) $ 2,736.04
  • mog-coinMog Coin (MOG) $ 0.000001
  • dydx-chaindYdX (DYDX) $ 0.525413
  • build-onBUILDon (B) $ 0.395483
  • compound-governance-tokenCompound (COMP) $ 41.40
  • neoNEO (NEO) $ 5.46
  • elrond-erd-2MultiversX (EGLD) $ 13.38
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • conflux-tokenConflux (CFX) $ 0.074223
  • kaitoKAITO (KAITO) $ 1.56
  • aioz-networkAIOZ Network (AIOZ) $ 0.313948
  • ecasheCash (XEC) $ 0.000019
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,568.80
  • deepDeepBook (DEEP) $ 0.146738
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 109,116.00
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.15
  • axie-infinityAxie Infinity (AXS) $ 2.18
  • telcoinTelcoin (TEL) $ 0.003902
  • ether-fiEther.fi (ETHFI) $ 0.954213

Crypto’s obsession with on-chain security lets off-chain mistakes cost billions, analysts warn

0 15

Crypto’s obsession with on-chain security lets off-chain mistakes cost billions, analysts warn

Hacken analysts say many crypto firms fail to meet even the baseline of the cryptocurrency security standard, leaving billions exposed to insider threats and credential leaks.

In crypto, one quiet smart contract update can undo months of security work. And yet, according to analysts at blockchain forensic firm Hacken, the industry still treats audits like branding tools, not like the breathing checkpoints they ought to be.

Audits “shouldn’t be treated as a checkbox or a logo on your homepage,” Dyma Budorin, CEO of Hacken in said in an exclusive interview with crypto.news. In his view, too many projects rely on a static snapshot of their code and call it a day. But once that code changes — and it often does — the audit’s relevance can evaporate. “Every audit becomes outdated the moment a contract is changed,” he warned.

The issue isn’t just the lack of audits, but the lack of systems that monitor code after deployment. Hacken argues that without continuous validation and re-audits, teams might be lulled into a false sense of security.

“A single overlooked function can open the door to disaster. The real issue isn’t just audit coverage, it’s audit relevance. We need systems that track every change, revalidate assumptions, and trigger re-audits when needed. Otherwise, all it takes is one silent update to break everything you thought was secure.”

Dyma Budorin

The team suggests a shift toward more standardized and automated checks. Things like symbolic execution, fuzzing, and formal verification should be part of the launch checklist — not optional extras. No smart contract, they say, should go live without first passing a baseline set of automated tests.

But even that isn’t enough. Contract ecosystems change. Upgrades happen. And sometimes, they don’t — even when they should. Hacken wants to see better controls around upgradability. Protocols should encourage patching or even deactivate legacy contracts when risks are discovered. As the Hacken team noted, “too often, patching is left to chance — or worse, to the hackers’ mercy.”

In the end, the message is simple: if crypto wants to grow up into an infrastructure layer — something foundational, not just speculative — then security can’t be an afterthought.

You might also like: Bybit CEO: 27.6% of Bybit hack funds remain untraceable

Multisig is not enough

Code isn’t always the problem though. In some of the biggest crypto breaches, it’s the off-chain stuff that breaks first. Take Bybit, for example. The exchange lost nearly $1.5 billion due to a compromised multisig setup. Not because of a bug in the code, but because of what looks like poor operational security.

“Many crypto platforms neglect fundamental off-chain security principles, secure operational practices, and specific requirements outlined in the Cryptocurrency Security Standard, leaving themselves vulnerable to similar threats.”

Dmytro Yasmanovych, head of compliance at Hacken

Yasmanovych said the team recommends crypto firms urgently implement or strengthen several practical security controls in line with the CCSS. For instance, these include deploying multi-factor authentication using secure, hardware-backed methods — such as biometric solutions or physical tokens — across all critical off-chain operations to defend against credential-based attacks.

He also emphasized the need for clear transaction authorization policies, with documented roles, approval thresholds, and procedures to prevent unauthorized activity. In addition, Yasmanovych advised firms to define and enforce secure, encrypted communication channels for sensitive operations, including transaction requests and approvals.

Exit liquidity dressed as innovation

But perhaps the most controversial insight from Hacken was reserved for the LIBRA token, a politically hyped memecoin that ended in a textbook rug pull. According to the Hacken team, insiders might have walked away with over $300 million by selling into market hype.

The LIBRA token had claimed to introduce “concentrated liquidity,” but to Hacken’s CEO, that’s not what it was.

“For newcomers, it sounds like they were strengthening the market or adding value to the token, but in reality, it was just a sophisticated way to place large sell orders at specific price points. When the price spiked due to hype, those orders converted tokens into cash instantly letting insiders exit with massive profits. It’s not innovation, it’s exit liquidity. Never invest in anything like that. This kills trust in the space and turns the industry into a circus.”

Dyma Budorin

Hacken believes that crypto can — and should — borrow some ideas from traditional finance to avoid this kind of thing. In regulated markets, insiders must disclose major holdings and planned sales. Maybe crypto projects should start doing the same. Disclosure of tokenomics, vesting schedules, and team allocations should be the norm, not the exception.

And while full-on regulation is still a matter of debate, Hacken suggests the space at least needs oversight mechanisms. Think third-party monitoring platforms, public rating systems, or watchdogs that can flag strange token behavior or unusual liquidity events before it’s too late. Until then, trust will remain shaky. And every exit scam or stealth mint will only drag crypto further away from public legitimacy.

Read more: The Coinbase hack that shadowed its S&P rise — and the investigators who saw it coming

Source

Leave A Reply

Your email address will not be published.

Verified by MonsterInsights