Hacking analysts say many crypto companies are failing to meet even the baseline cryptocurrency security standard, leaving billions exposed to insider threats and credentials leaks.
In crypto, one silent smart contract update can undo months of security work. And yet, according to analysts at blockchain forensics firm Hacken, the industry still treats audits as branding tools, rather than the breath checkpoints they should be.
Audits “should not be treated like a checkbox or a logo on your homepage,” said Dyma Budorin, CEO of Hacken in an exclusive interview with crypto.news. According to him, too many projects rely on a static snapshot of their code and call it a day. But once that code changes – and it often does – the relevance of the audit can disappear. “Any audit becomes obsolete as soon as a contract is changed,” he warned.
The problem is not only the lack of audits, but also the lack of systems that monitor code after implementation. Hacking argues that without constant validation and reaudits, teams can fall into a false sense of security.
“One overlooked feature can open the door to disaster. The real problem is not just audit coverage, but audit relevance. We need systems that track every change, revalidate assumptions, and trigger new audits as necessary. Otherwise, all it takes is one silent update to break everything you thought was secure.”
Dyma Budorin
The team suggests a shift towards more standardized and automated controls. Things like symbolic execution, fuzzing, and formal verification should be part of the launch checklist – not optional extras. No smart contract, they say, should go live without first passing a basic set of automated tests.
But even that isn’t enough. Contract ecosystems are changing. Upgrades happen. And sometimes they don’t, even when they should. Hacking wants better controls around upgradability. Protocols should encourage patching or even deactivate outdated contracts when risks are discovered. As the Hacking team noted, “patching is too often left to chance – or worse, at the mercy of the hackers.”
Ultimately, the message is simple: if crypto is to evolve into an infrastructure layer – something fundamental, not just speculative – then security cannot be an afterthought.
Multisig is not enough
However, code isn’t always the problem. In some of the biggest crypto breaches, it’s the things off-chain that break first. Take Bybit for example. The exchange lost almost $1.5 billion due to a compromised multisig setup. Not because of a bug in the code, but because of what appears to be poor operational security.
“Many crypto platforms ignore fundamental off-chain security principles, secure operational practices, and specific requirements outlined in the Cryptocurrency Security Standard, leaving them vulnerable to similar threats.”
Dmytro Yasmanovych, head of compliance at Hacken
Yasmanovych said the team recommends crypto companies urgently implement or strengthen several practical security controls in accordance with the CCSS. These include, for example, deploying multi-factor authentication using secure, hardware-enabled methods – such as biometric solutions or physical tokens – for all critical off-chain operations to defend against credential-based attacks.
He also emphasized the need for a clear transaction authorization policy, with documented roles, approval thresholds and procedures to prevent unauthorized activity. In addition, Yasmanovych advised companies to define and enforce secure, encrypted communication channels for sensitive operations, including transaction requests and approvals.
Exit liquidity dressed up as innovation
But perhaps Hacking’s most controversial insight was reserved for the LIBRA token, a politically hyped memecoin that ended in a textbook carpet-pulling. According to the Hacken team, insiders may have made more than $300 million by selling into market hype.
The LIBRA token had claimed to introduce ‘concentrated liquidity’, but for Hacken’s CEO, that wasn’t what it was.
“To newcomers it sounds like they were strengthening the market or adding value to the token, but in reality it was just a sophisticated way to place large sell orders at specific price points. When the price spiked due to hype, those orders were tokenized into cash, allowing insiders to exit with huge profits. It’s not innovation, it’s exit liquidity. Never invest in something like that. This kills confidence in the space and turns the industry into a circus.”
Dyma Budorin
Hacken believes that crypto can – and should – adopt some ideas from the traditional financial world to prevent these kinds of things from happening. In regulated markets, insiders must disclose large holdings and planned sales. Perhaps crypto projects should start doing the same. Disclosure of tokenomics, vesting schedules, and team assignments should be the norm, not the exception.
And while full regulation is still a matter of debate, Hacken suggests that the space at least needs oversight mechanisms. Consider third-party monitoring platforms, public rating systems, or watchdogs that can flag strange token behavior or unusual liquidity events before it’s too late. Until then, trust will remain shaky. And every exit scam or stealth coin will only drag crypto further away from public legitimacy.