This newsroom compiled three years of publicly confirmed exploits above one million dollars and classified each by root cause, using post-mortems and independent researcher accounts.
The largest category by value is no longer contract logic. Compromised keys, misconfigured multisignature thresholds and privileged upgrade functions account for the majority of losses.
That shift matters for where money is spent. Audits examine code, but most of these failures happened in operational procedure around the code.
Median time from deployment to compromise has fallen, driven by automated scanners that find newly deployed contracts within minutes.
Protocols that publish signer identities and require timelocks on upgrades appear in the dataset far less often, though the sample is too small to treat as proof.



