The article creates a study on audit findings vs. the impacts of real world exploits. They aggregated data from 24K findings from audit reports from 22 firms. In comparison, the hacks were 218 events that mostly came from rekt.news. This was a four year study.
In the audit reports, they show the percentage of bugs with classification. Critical (6%) and high (11.2%) are the bugs that probably lead to exploits. Medium (22.4%), low (37.5%), and informational (22.9%) are the other ones.
From the vulnerabilities reported, 14.6% were logic errors, 13% code quality, 10% input validation, 9.8% authorization, and a large number of other vulnerabilities like reentrancy, and oracle manipulation. EVM compatiable chains make up about 80% of findings per year. Rust/Solana is around 4%, TON is around 4%, CosmWasm/Cosmos SDK 6%, and Move-based ecosystems are around 4%.
On the hacks side, the numbers are pretty startling but don't include bloody April from 2026. Each year averages about 50 incidents. Of these, there has been a total of $7.7B in losses, with $4.3B of that being audited. Of the 218 incidents, about half of them (105) were in audited code. The worst exploits tend to make up most of the funds, such as the Bybit hack. The eight largest hacks make up 50% of the funds stolen.
What classifications of bugs have the largest losses? 45 of the incidents, for a total loss of 1.8B are private key compromises, and phishing making up $1.5B; these losses make up over 43% of total losses. Access control at 12.8% losses, and oracle manipulation at 8.6% make it up. There's a lot of other items ranging from 7.6% to 2.7%.
The main notice is that 46% of exploit losses come from private key compromises, social engineering, and dependency issues. However, this makes up a small number of audit findings. Literally all audit findings are associated with application-level issues. There's a major divide between where the money is going, and where the hacks are happening. Clearly, traditional security is just as important as the application-level.
In the event that code was audited and exploited, much of the time it feel outside the scope of the audit. It was either a post-audit upgrade, a deployment issue, or a bug in code that the audit team was not tasked with reviewing.
Overall, a great look into the hacks and auditing dynamic of web3. More money needs to be put into more traditional security.