Crypto’s security nightmare won’t be solved by ordinary audits

Traditional smart contract audits are failing to prevent crypto losses because they focus on code rather than human and operational vulnerabilities. The industry must expand security measures to address phishing, private key management, and insider threats to effectively reduce financial exploits.
Why it matters
As crypto adoption grows, the disconnect between technical audits and real-world operational risks poses a systemic threat to investor funds and platform stability.
But more audits have not translated into fewer losses. Neither the total number of incidents nor the amount of money stolen is significantly declining. Our research at Oak Security explains this: the majority of successful attacks target human vectors. In fact, when we look at the top causes of exploits, most completely bypass the attack surface protected by audits.
The article provides a technical critique of industry practices without taking a political stance.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in