Private Key Leaks Cause 40% of $16.69B in Crypto Hack Losses, Experts Say
Roughly $16.69 billion has been lost to crypto hacks, with about 40% tied to stolen private keys rather than flaws in blockchains or smart contracts, according to data from DeFiLlama. Security experts attribute most losses to key-management and operational failures in systems, people, and third-party tools, not broken cryptography. The industry is turning to multi-party computation (MPC), account abstraction, and built-in security practices to reduce reliance on single private keys. The Bybit hack of February 2025, where attackers compromised a third-party tool to steal $1.5 billion in Ethereum, exemplifies the widening attack surface. Wish Wu, CEO of Pharos, notes that while progress is being made on MPC wallets and account abstraction, these solutions are often optional rather than integrated at the protocol level. Leo Fan, CEO of Cysic, emphasizes that private key hacks are a key-management failure, not a cryptography failure, and that the full key should never exist in a single place.
Key facts
- $16.69B lost to crypto hacks; 40% from private key theft.
- Private key hacks blamed on key-management, not cryptography failures.
- Industry adopting MPC and account abstraction to reduce single-key reliance.
- Bybit hack: $1.5B stolen via compromised third-party developer tool.
- Security measures often optional, not built into protocol design.
KeyAudit data perspective
🔧 Check your seed against KeyAudit leak DB