Mitchell Amador, founder and CEO of blockchain security firm Immunefi, stated that so far in 2026, the crypto industry has lost approximately $972 million due to hacking attacks. He pointed out that most of the stolen assets were not lost through smart contract vulnerabilities, but rather through stolen keys, signer permissions, and issues with governance mechanisms. Amador emphasized that audits only verify the security of the code at a specific point in time and cannot guarantee security in the event of compromised key storage, signing permissions, or team members’ devices; therefore, “we have passed an audit” does not equate to “we are secure.” He believes that continuous, incentive-driven security reviews—such as bug bounty programs—are crucial for protecting code, and that this model of review must now be extended to the levels of keys, signers, and governance rules.