Wednesday, 29 July 2026 · World
USD/EUR 0.8787 USD/GBP 0.7525 USD/JPY 163.8 USD/CNY 6.778 All rates →
RSS
EUROS The World Financial Report
Nº 18 Wednesday, 29 July 2026 · World Edition
LATEST
Crypto

Crypto loses $972M to key hacks as bear market shuts BitMEX, BitMart

EUROS Newsroom · 48m ago · 2 min read
Crypto loses $972M to key hacks as bear market shuts BitMEX, BitMart

A brutal bear market is shutting down major exchanges while operational security failures, rather than code bugs, drive nearly $1 billion in thefts this year, exposing the limits of standard audits for institutional investors.

Cryptocurrency thefts have reached $972 million so far in 2026, but the primary attack vector has fundamentally shifted. Instead of exploiting smart contract code, hackers are targeting private keys, signers and governance frameworks. This operational failure is unfolding alongside a broader market contraction that is forcing high-profile exchanges out of business.

BitMEX, the derivatives exchange that invented perpetual swaps, will close on Sept. 23 after 11 years. It lost its pioneering market to larger centralized rivals and decentralized platforms. BitMart is also shutting down, halting trading on Aug. 26 before ceasing operations entirely on Jan. 31, 2027.

For institutional capital still active in the sector, the changing nature of security vulnerabilities demands attention. Immunefi founder and CEO Mitchell Amador notes that attackers are increasingly exploiting the rules and access points around protocols rather than the code itself. An attacker recently spent $4 million to drain $20 million from BonkDAO by buying enough tokens to pass a governance proposal in a low-turnout vote. Similarly, Humanity Protocol lost over $30 million in June from a compromised private key on a team member's machine.

Operational flaws eclipse code bugs

Historical data confirms this shift. Across 191 hacks between 2024 and 2025, centralized exchange compromises involving keys, custody and signing accounted for 54.6% of all value lost. This undermines a common institutional assumption, as Amador points out that “we were audited” was never the same as “we are safe.” One protocol was audited 11 times and still lost $128 million.

The code layer remains deeply flawed, with 93.9% of programs running five years or more harboring a confirmed critical vulnerability. However, continuous, incentivized bug bounty programs have proven highly effective at mitigating these specific risks. Paying a median bounty of roughly $20,000 routinely prevents an average $25 million hack.

Survivors shore up balance sheets

While some firms collapse, others are aggressively fortifying their positions. Strategy raised $544.5 million through common-stock sales, boosting its cash reserve to $3.75 billion. The firm used a portion of those funds to repurchase $25 million of its STRC preferred stock while keeping its 843,775 Bitcoin unchanged.

Revolut, the crypto-friendly digital bank, reached a $115 billion valuation in a recent employee share sale. The 53% valuation increase makes it Europe’s most valuable private company. On the regulatory front, the Clarity Act is expected to miss its window before Congress’ summer break. Senate Majority Leader John Thune noted that lawmakers remain divided over ethics and stablecoin yield, reducing the bill's chances of becoming law in 2026.

Meanwhile, high-risk trading persists on Solana, where memecoins and other long-tail tokens now account for over 60% of volume, up from the high 30s in late June.