In 2022, an attacker who had obtained five private keys out of a nine-key threshold crossed the Ronin Bridge's validator set. Four of those keys were held by a single entity, deployed in one cloud environment. The attacker walked away with 173,600 ether and 25.5 million USDC. At the time of withdrawal, approximately $625 million. That one batch of transactions exceeded the aggregate reported crypto theft volume of every full year before 2017.
Now consider a second statement. Crypto hacks are at a nine-year low. Security measures have improved. Institutional confidence should follow.
Both statements cannot describe the same system without statistically careful boundaries. The first is a documented incident with block-by-block forensic evidence. The second is the conclusion of a Grayscale Investments research report: a claim that hacking events across the crypto ecosystem have fallen to their lowest level in nine years, that this decline reflects improved security measures, and that it should boost investor confidence and drive institutional adoption. Grayscale, the largest SEC-registered digital asset manager, built its business model on routing institutional capital into crypto through regulated trusts and exchange-traded products. Its research staff are macro strategists and equity analysts. They are not security engineers. That does not invalidate their work. It does mean that the report deserves to be read the way a security professional reads a vendor claim: as an untested assertion with specific load-bearing assumptions.
I have spent most of my career auditing consensus mechanisms, liquidation engines, and smart contract architectures. In early 2017, I spent six months auditing the early draft of the Ethereum 2.0 slasher protocol, before the mainnet existed. I identified a critical divergence in the finalized proof-of-work state transition function that could have caused permanent chain splits under high latency. I wrote a forty-page technical memo to Vitalik Buterin. It was initially rejected, then quietly validated during the DAO recovery discussions. That experience taught me a durable lesson: security narratives travel faster than verification. The only question worth asking is whether the claim survives contact with the ledger. The ledger remembers what the interface forgets. The interface here is a polished research summary. The ledger is the incident chronology, the statistical denominator, and the on-chain trace that follows every stolen asset.
So let me begin with the claim itself.
Grayscale published its security assessment at a specific moment in the institutional adoption cycle. January 2024 brought the conversion of the Grayscale Bitcoin Trust into a spot ETF, ending a years-long regulatory battle that culminated in a D.C. Circuit victory over the SEC. The conversion, however, did not end Grayscale's problems. It launched the firm into a fee war against asset management giants — BlackRock, Fidelity, and Franklin Templeton — whose competing bitcoin ETFs offered materially lower expense ratios. Grayscale's GBTC bled billions in assets under management in the weeks following the conversion. Outflows only stabilized after the firm introduced its own low-fee bitcoin mini-trust. In this competitive context, research output is not merely informational. It is brand maintenance. Every report Grayscale publishes reinforces its position as the authoritative voice of institutional crypto. A report that demonstrates the ecosystem is becoming safer supports the narrative that its products — which hold the underlying assets — are becoming less risky investments.
The report's core contentions are straightforward. First, the number of crypto hacking events has reached a nine-year low. Second, this decline is evidence of improved security measures across the industry. Third, improved security supports investor confidence and accelerates institutional adoption. The first is an empirical observation. The second is a causal attribution. The third is a forecast. Each step in that chain carries more conceptual weight than the previous one, and each is weaker than the framing implies.
Let me start with what the data actually shows, and specifically with the first major statistical problem: the denominator.
"Nine-year low" is a claim about a time series. A time series of what, exactly? The Grayscale report, as summarized publicly, does not clearly specify. There are at least three plausible metrics hiding behind the phrase. The first is event frequency: the raw count of successful hacking incidents per period. The second is theft value: the aggregate US-dollar loss, or possibly a bitcoin-denominated loss, across all incidents. The third is a relative measure: losses expressed as a percentage of total value secured, or as a percentage of trading volume, or per dollar of total market capitalization. These three metrics produce radically different trend lines, and a "nine-year low" under one metric can coexist with elevated readings under another.
Consider the event-frequency metric honestly. Public incident trackers maintained by Rekt News, Immunefi, and independent researchers show that the 2021 and 2022 windows were abnormal outliers. The first quarter of 2022 alone contained the Wormhole attack ($326 million), the Ronin Bridge compromise ($625 million), and the Nomad Bridge collapse (roughly $190 million). Those two years were defined by a specific phenomenon: the bridge mania of the DeFi bull run. An extraordinary volume of new code shipped into production to serve cross-chain liquidity, and an equally extraordinary share of it was exploited within months. By this count, the trailing period relative to 2022 looks dramatically better. But nine years ago is not 2022. Nine years ago is 2015, when the total reported theft volume across the entire industry was a fraction of a single 2022 bridge exploit. In 2015, the largest incident was the Bitstamp hot wallet breach, which cost roughly $5 million. The event count for any classification of "significant" hack in 2015 was in the single digits. A 2015 baseline is a low bar. Any claim that recent event counts are at a nine-year low must contend with the fact that 2015 and 2016 were, by global incident count, the calmest years in the asset class's public history. If 2015 produced perhaps 20 publicly reported incidents, then to beat that record, the trailing period must have produced fewer than 20 incidents that meet the same inclusion criteria. I have not seen the Grayscale inclusion criteria. I do know, from monitoring the incident landscape professionally, that the first half of 2024 alone produced dozens of reported smart contract exploits across Ethereum, BNB Chain, and the L2 ecosystem. The claim strains credibility under the simplest count metric.
The dollar-value metric is cleaner, but no less ambiguous. The 2015 baseline is, in absolute dollar terms, small: total annual losses in 2015 across all reported incidents likely fell below $100 million. If the recent period's losses are at nine-year lows, they must be below that figure. Public data runs directly counter to this. TRM Labs and Immunefi both published loss figures for the relevant comparable periods showing hundreds of millions of dollars per quarter. The year of 2023 saw roughly $1.7 billion in stolen funds, a figure that dwarfs the entirety of 2015. Even accounting for exclusions — removing bridge-related attacks, removing the FTX estate drain event, removing incidents of unclear attribution — the dollar-loss figure does not reach the nine-year-low bar. The one metric under which the claim begins to make sense is the bitcoin-denominated metric. In 2015, bitcoin traded between $200 and $500. A theft of $50 million in 2015 represented between 100,000 and 250,000 BTC. A theft of $300 million in 2024, when bitcoin trades above $50,000, represents only 5,000 to 6,000 BTC. If one measures losses in units of the network's native asset, the decline is real and significant. But that is a different statement, with a different investment implication, and it is not the statement being made.
This is not an academic nitpick. The choice of denominator changes the investment conclusion. A dollar-denominated decline matters to a fund manager whose liabilities are denominated in dollars. A bitcoin-denominated decline matters to a bitcoin maximalist who views the network as a store of value. If the true statistic is the latter, the report's framing — "hacking events at nine-year low" — is doing silent work that its data may not support. Read the diffs. Believe nothing. That phrase has kept me safe through a decade of security reviews. It applies equally to research summaries as to smart contracts. The difference between "X is at a nine-year low" and "X-denominated losses, measured against Y baseline, are at a nine-year low" is the difference between a headline and a finding.
There is a second classification problem hidden inside the incident data. The FTX estate drain of November 2022, approximately $600 million, was initially reported by multiple services as a hack. We now know the attribution was murky at best. The event may have involved insider access, private key holders who were never identified, or a complicated mix of compromised systems. It was not a classic external network intrusion, and it never produced a standard exploit disclosure. If a data source classifies FTX's outflow as a hack, the 2022 numbers surge. If it classifies FTX as a misappropriation or an internal control failure, the 2022 numbers drop materially. Neither classification is wrong per se; they are choices, and the choices change the timeseries. The same issue affects the Poly Network incident of 2021, where the attacker purported to return funds and referred to themselves as a security researcher. Whether a $611 million event in which funds are ultimately returned counts as a "successful hack" under Grayscale's methodology is a judgment call. That call determines whether 2021 appears as a peak of chaos or as a hiccup.
The point is not that Grayscale fabricates data. It is that the data infrastructure supporting claims like "nine-year low" is loose, fragmented, and gated behind unpublished methodology. Two reputable research firms can quote different numbers for the same quarter and both be accurate under their own definitions. A nine-year-low claim built on one private slice of that fragmented data is a claim that cannot be independently falsified without the source code, the data set, and the inclusion rules. For a research product whose stated purpose is to guide institutional conviction, that opacity is an unforced error. The report would be stronger — and more genuinely useful to the institutions it wants to attract — if it disclosed whether it counted events or dollars, whether losses were measured in USD or BTC, whether bridge attacks and insider thefts were included, and which external data provider supplied the raw series.
Now let me take the second claim seriously, on its own terms. Suppose the nine-year low is real under a defensible metric. Improved security measures — is that the correct causal story? Here, I need to separate what the security industry actually did improve from what the macro environment achieved for us. Genuine improvements exist, and I have audited plenty of them. Custody moved decisively toward cold storage, multi-party computation, and quorum signing schemes. In 2015, a substantial share of exchange balances lived in single hot wallets protected by one private key. Today, the institutional standard is threshold signing with geographically distributed share holders, hardware security modules, and air-gapped signing ceremonies. This is a real advance. I have reviewed custody architectures in 2024 that would have been unthinkable in 2017. Multisig also went mainstream in protocol design: what was once a novel pattern deployed by a handful of advanced teams is now the default treasury and admin standard across the ecosystem, institutionalized by Gnosis Safe and its clones. Formal verification and standardized audit practices improved. Trail of Bits, OpenZeppelin, and a handful of reputable shops publish their methodologies; bug bounty programs administered by Immunefi created financial incentives for researchers to disclose rather than exploit. On-chain monitoring and forensics matured, with Chainalysis, TRM Labs, and Elliptic building the investigative infrastructure that makes it harder for large thefts to be laundered without detection.
These are not illusory gains. They are real, measurable in the daily practice of security engineering, and I would defend them against any claim that the industry has not matured. But they do not, by themselves, explain a nine-year low in the observed data. The bear market deserves co-authorship of any claimed security improvement. Exploitation is an economic activity. Attackers deploy capital, acquire infrastructure, and take on risk. The 2022-2023 bear market changed that calculus. The number of new, poorly audited, high-value bridge contracts deployed to mainnet collapsed as venture funding dried up. Exploitable attack surface is a function of new code velocity. When the bull market stopped shipping, the vulnerability pipeline constricted. Asset prices fell as well. A protocol that held $50 million in a bull market held $5 million in the bear market, and attackers rationally redirected their attention to targets with higher expected value — or to entirely different crime categories. Pig butchering scams, romance scams, and ransomware campaigns targeting traditional enterprises all absorbed capacity that previously flowed into smart contract exploits. The decline in hack events may be that simple: the criminals went elsewhere. The "security improvements" narrative attributes to engineering what may belong to economics.
There is an even more uncomfortable version of this objection. If attacker attention moved away from on-chain exploitation because the risk-to-reward ratio worsened, what made it worsen? The same monitoring and forensics infrastructure that I credited above. But there was also a change in the cost of liquidation. The 2022 sanctions on Tornado Cash and the subsequent aggressive enforcement against mixing services raised the friction of converting stolen assets into fiat. Stablecoin issuers froze assets associated with attack addresses. Coinbase, Binance, and other major venues collaborated with investigators to freeze tainted funds. Catching attackers became measurably easier. Hacking became more dangerous and less profitable. That is a security improvement in the most concrete sense. But it is not a software security improvement. It is a law-enforcement-improvement, a sanctions-improvement, and a market-infrastructure improvement. The distinction matters because the investment implication differs. Software security improvements compound and endure. Enforcement improvements can be reversed by a single court ruling or a change in administration.
Now I want to address a decoupling that I believe the report, if it follows the standard Grayscale architecture, likely understates. There is a defensible sense in which bitcoin-related hacks are at a multi-year low: not because bitcoin security improved, but because bitcoin's on-chain application layer is minimal. The bitcoin network runs a UTXO script engine with a deliberately small instruction set. There are few contracts to exploit, few composable plumbing models, and no bridge ecosystem of any consequence. Its attack surface is the custody periphery — exchanges, custodian systems, and manager keys — and that periphery genuinely hardened. The consensus layer itself, however, has not changed in any meaningful security-relevant way since 2015. Proof-of-work and the UTXO model are structurally the same. The ninth year of "low hacks" is largely the ninth year of bitcoin's architectural discipline, not a year of new cryptographic invention.
The broader crypto ecosystem — the "crypto" that includes DeFi, cross-chain infrastructure, and the L2 landscape — is a different story. The 9-year-old baseline is irrelevant here because most of this ecosystem is younger than nine years. DeFi did not meaningfully exist in 2015. You cannot establish a nine-year trend for an asset class that was born in 2020. If the report's security claim is about crypto broadly, it is mixing apples with oranges, comparing 2015's quiet proto-ecosystem with today's industrialized DeFi. If the claim is about bitcoin specifically, it should say so, and it should acknowledge that bitcoin's low hack rate is a property of its design limitation, not of recent improvements in its software supply chain.
My own audit history illustrates the point. In 2020, during the DeFi summer, I dissected MakerDAO's vault liquidation logic when a rapid ETH price crash threatened the DAI peg. The system weathered the storm. The reason, as I documented in a 15,000-word breakdown, was not that the protocol had exceptional security engineering in some novel sense. It was that conservative collateralization ratios absorbed the impact. Over-collateralization served as a redundancy mechanism. The security was a property of the design, not a property of the code lines. Contrast that with 2021, when I audited the OpenSea migration path toward Seaport and identified twelve distinct edge cases in the consideration fulfillment logic, including a race condition that could allow front-running on rare asset sales. The NFT ecosystem was new, moving fast, and carried a fundamentally different risk profile. Both experiences taught me the same lesson: security claims are only meaningful relative to the architecture they describe. A low hack rate in a system that allows few attacks is not comparable to a low hack rate in a system that permits many. The maker system is safe because it was designed boring. The bitcoin network is safe because it refuses to be interesting. Neither safety profile justifies a blanket narrative about "crypto security improving" as a single phenomenon.
Now let me turn to the contrarian angle, and it is here that I want to be most direct. Grayscale is a stakeholder with a product pipeline. That does not make its reports false. It does make them something to be evaluated with the same skepticism I apply to a protocol that publishes its own audit without disclosing the auditing firm. Consider what the "security has improved" narrative accomplishes for Grayscale's franchise. It lowers the perceived risk premium of the asset class at the exact moment when institutional allocators are making first-in-kind decisions about allocating to spot bitcoin ETFs. It also implicitly endorses the custody and compliance infrastructure that Grayscale itself uses. It provides a counter-narrative to the 2022-era scandals — FTX, Celsius, Genesis, the DCG complex itself — that gave institutional committees a clean excuse to decline crypto mandates. Telling those committees that hacking events are at a nine-year low is a form of permission structure. It is what we, in the industry, sometimes politely call "narrative infrastructure." The ledger remembers what the interface forgets: Grayscale's parent company, Digital Currency Group, endured the Genesis bankruptcy and a cascade of liabilities that eroded confidence across the group. The research arm is not operationally responsible for the balance sheet problems of its affiliates. But a casual observer might notice that a report emphasizing industry maturity and safety arrives at a moment when the parent group's credibility could use a tailwind. This is not an accusation. It is a structural observation: when the party that benefits from a narrative is the party publishing the data, the data becomes a product, and products are subject to selection bias.
The deeper issue is what I would call "strawman security." By pinning the decline in hack events to improved security measures, the report invites investors to believe that the two are causally linked and that the trend will persist as long as security spending continues. But if the actual drivers include the bear market, the shifting attention of criminals, and the deterrent effect of sanctions against mixers, then the causal chain is much looser. Security spending will not prevent the next large-scale attack if the next attack comes from a novel primitive deployed in a bull-market code rush. The heavy-tailed nature of security risk means that long quiet periods and sudden catastrophic events are entirely compatible. The period from 2015 through 2019 was, by dollar-loss standards, tranquil. Then 2021 and 2022 produced a run of nine-figure exploits. The tranquility itself contributed to the complacency that produced the bridge boom. A report claiming a nine-year low is, in a subtle sense, a pro-cyclical document: it encourages confidence precisely when the conditions that produced the low may be at risk of reversing.
This matters for the institutional decision-maker more than any single statistic. The question is not whether the last twelve months were calm. Every security professional I know would agree that they were calmer than 2022. The question is whether the claim of a nine-year low is robust to definitional changes, to the next bull market, and to the inevitable next large-scale attack. Consider the fragility of the narrative. If a single Ronin-sized event happens next quarter, the "nine-year low" claim collapses overnight. The entire "security improving" narrative was never meant to survive contact with a single $600 million exploit, and yet such exploits remain entirely plausible — not because security engineering has failed, but because the tail is long. A distribution can have a median outcome of quiet quarters and a mean poisoned by rare catastrophes. Institutional investors are, in theory, trained to think in terms of tail risk. Crypto has historically been taught the same lesson every few years: long periods of apparent maturity, followed by a black swan that resets expectations.
I want to be precise about what would change my mind about this report. First, disclosure. A reputable research product should disclose its data sources, its definition of "hack," its inclusion criteria for events, and its currency of measurement. If Grayscale publishes that methodology and the data survives independent reconstruction, the "nine-year low" claim becomes falsifiable and therefore meaningful. Second, decomposition. The report should separate bitcoin-related incidents from the broader DeFi ecosystem, and separate custody losses from smart contract exploits, and separate thefts from regulatory seizures. A single aggregated number hides the heterogeneity that determines whether the trend is structural or incidental. Third, historical context. The report should explain why the metric was at a peak in 2021-2022 and what specific security practice changes reduced it. If the answer is "more multisig and formal verification," that is constructive. If the answer is "the bear market," that is honest but admits the trend is fragile. I have read enough protocol documentation to know which of these answers is more likely to be defensible.
There is also a read-the-diffs discipline that I apply here as naturally as I would to a smart contract upgrade. When a protocol upgrades, we diff the code to see what actually changed. The equivalent for Grayscale's report is: what changed in the ecosystem that would explain a nine-year low? The honest list includes: custody consolidation among fewer, more professional players; the institutionalization of multisig as a default; the maturation of security audits and the bug bounty ecosystem; the contraction of the attack surface as the market shrank; the migration of attackers toward on-ramp fraud rather than protocol exploits; the sanctions and enforcement infrastructure that made liquidation more expensive; and the growth of legitimate, regulated buying channels that reduced the premium on stolen assets. Each of these contributes a share. I would estimate, based on my experience as an auditor who has seen the operational reality inside projects, that perhaps half of the decline is attributable to genuine security practice improvements and half to the economic and regulatory environment. The report's framing, as summarized, attributes essentially the whole decline to the former. That is the kind of attribution error that a forensic reader should flag.
The final risk is one that Grayscale's own institutional audience should recognize, because it is the mirror image of the 2022 collapse. Institutional adoption was stalled after FTX not because the technology was vulnerable, but because confidence was shattered by a custodial failure. The same can happen in reverse. A security narrative that proves over-optimistic — whether because the denominator shifts or because the next bull market ships another generation of unaudited bridges — will produce a confidence shock that disproportionately affects the institutions that entered on the strength of the claim. The institutions that bought the "security improved" thesis will not distinguish between a bear-market tailwind and a real structural advance when the next exploit lands. They will simply mark down the asset class. The ironic result is that the narrative of security maturity could increase the volatility of institutional capital flows: it attracts investors who otherwise would not have entered, and those investors prove the most fragile when the narrative breaks.
What should the security researcher take from this? The same thing I take from every report I review. The claim of a nine-year low is, in its current published form, a hypothesis. It needs a data appendix, a methodology section, and an acknowledgment of the heavy-tailed nature of the risk it measures. Without those, it is marketing dressed as research. With them, it is a contribution to a genuinely important question: whether the crypto industry has actually built the infrastructure of safety that institutional adoption requires. I have spent years inside that infrastructure, and I believe substantial parts of it are real. Multi-signature custody, hardware-backed key management, formal verification, and mature audit practice are not theater. They have reduced the attack surface in measurable ways. But the security industry itself would be the first to warn you: there is no such thing as a nine-year low in a system that is undergoing active, rapid transformation. There is only a long quiet period that feels permanent until it is not. Static analysis. Zero mercy. The ledgers of the future will record not whether Grayscale's claim was made, but whether it was tested.
The market will eventually decide which framing was accurate. In the meantime, I would advise institutional readers to ask one question of the firm's research department that Gatekeepers should also ask: show me the data, the definitions, and the outlier events. If the answer is transparent, the report is a signal. If the answer is a marketing summary, the report is noise. The difference between signal and noise here is the difference between an asset manager that wants to inform its market and one that wants to encourage it. Security improvements deserve celebration only when they are real, and reality has a habit of demanding evidence. The ledger remembers what the interface forgets. Trust but verify. In this industry, there is no substitute for the second half of that sentence.


