Trust is a vulnerability, not a virtue.
That axiom emerged from an audit I ran on 0x protocol v2 in 2018. Seven edge cases in the relayer logic. Each one a gap between the whitepaper's promise and the EVM's execution. I submitted them to GitHub, received no response, and learned a permanent lesson: in this industry, claims are cheap. The code — or the data — decides.
The claim I want to examine today is statistical, not contractual. Grayscale Research published a report: crypto hacking incidents are at a nine-year low. The decline, the report suggests, reflects improved security measures. The corollary: investor confidence should rise. Institutional adoption should follow.
It is a beautiful narrative chain. It is also, on inspection, a sequence of unsupported junctures.
Grayscale's public summary discloses no counting methodology, no data source, no time-window definition, and no denominator. What is at a nine-year low? Number of events? Dollar value of losses? Losses as a fraction of total value secured? These are not interchangeable. "9-year low" is a title, not a statistic.
Let me treat it as what it is: a hypothesis. Then test it.

Context: The Institution Behind the Statistic
Grayscale Investments, LLC is not a security research firm. It is a Delaware trust company and SEC-registered investment adviser managing billions in crypto assets. Its flagship product, GBTC, converted to a spot Bitcoin ETF in January 2024 — under competitive siege.
The post-ETF landscape: BlackRock's IBIT and Fidelity's FBTC entered with fee structures a fraction of Grayscale's. GBTC experienced persistent outflows throughout early 2024 as allocators rotated to lower-cost exposure. Grayscale's research division, historically a thought-leadership engine, now carries a heavier commercial load.
This backdrop colors any Grayscale pronouncement. The hacking-low report arrives during a market repair cycle — post-FTX, post-Genesis bankruptcy (its parent DCG's subsidiary), post-SAB 121 controversy. Institutional capital wants to re-enter crypto; custodians, regulators, and allocators need a reason. A well-placed statistical claim about security improvement is exactly that reason.
I have read enough of these reports to know what they contain: conclusions in search of supporting evidence. What they rarely contain is methodology. The genre is institutional marketing with the texture of academic research.
Here is the structural problem: an asset manager that profits from institutional inflows publishes a reassuring security statistic. The incentive vector points in one direction. The report may be accurate — or it may be an artifact of selection, timing, or counting. Both possibilities require the same response: audit the claim.
Core: Deconstructing the Claim
1. The Metric Problem
The first question is definitional. Grayscale's report does not specify whether it tracks incident frequency, absolute dollar losses, or loss ratios.
The distinction is material.
Look at the incident series. 2021 contained major attacks: Poly Network ($611M), Cream Finance, BadgerDAO. 2022 was the year of bridges: Ronin Bridge ($625M), Wormhole ($326M), Nomad Bridge ($190M). 2023, by contrast, saw a high number of smaller attacks targeting DeFi protocols — roughly 300 on-chain incidents per the major surveillance vendors, totaling approximately $1.7B. 2015-era exchange breaches like Bitfinex's $72M hack were enormous for their time but trivial in absolute terms compared to 2022's single events.
Which of these years represents the "high" against which today's "9-year low" is measured?
If the metric is frequency: 2024's rolling count may genuinely be low, because most attacks now fall into the "low-value, high-volume" category — permissionless wallet drainers, address-poisoning scripts, fake token approvals. Each counts as an incident. Each is economically minor. This inflates historical counts and makes the current period look better by comparison.
If the metric is dollar losses: the "9-year low" is almost certainly false. Inflation-adjusted stolen value in 2023 exceeded most historical years. The 2024 H1 data through Q2 showed around $900M in losses — annualizing to a figure far above 2015 levels.
If the metric is loss ratio — stolen value divided by total value secured — that is the only statistically sound approach. And Grayscale did not publish it.
Based on my experience reviewing vulnerability disclosures and audit reports, a security metric without a stated denominator is a number without a frame. The frame is the entire argument. Without it, the "9-year low" tells us less than the press release implies.
2. What Actually Improved: The Hardening of the Perimeter
To be clear: the ecosystem has genuinely hardened in several measurable ways. The difference between 2018 and 2024 is real.
Cold storage. The single largest factor. Post-Mt. Gox, post-Coincheck, post-Bitfinex, the industry learned. Major exchanges now keep 90-98% of user assets in offline wallets. The attack surface for assets-in-custody collapsed. This alone explains a substantial portion of any frequency decline.
Multisignature and MPC. In 2018, single-key control was common. I audited relayers and exchanges that used one EOA as the withdrawal signer. That pattern is extinct at any serious institution. Threshold signature schemes, multi-party computation wallets, and quorum-based governance now distribute key custody across independent entities. The compromise threshold rose from "one key" to "N-of-M keys plus hardware modules plus geographic distribution."
Insurance. Institutional custodians now bundle crime insurance. This shifts financial risk from users to underwriters. An attack becomes an insurance claim and a post-mortem, not a protocol-destroying event. Insurers impose security standards, creating a feedback loop: better security → insurability → more institutional assets → more investment in security.
On-chain surveillance. Chainalysis, TRM Labs, Elliptic. Post-hoc tracking is now effective enough that major thefts face a real liquidation bottleneck. This raises the expected cost of large attacks and discourages the highest-profile ones.
Audit standardization and formal verification. The 2020-era contracts I reviewed had trivial reentrancy and unchecked external-call bugs. By 2023, audited code with such basic flaws was rare. My own work on ZK-rollup standardization in 2024 involved polynomial commitment schemes where correctness proofs became standard practice, not a luxury.
This perimeter hardening is real. But "perimeter" is not "protocol."
3. Attribution and Its Alternatives
The report attributes the decline to "security measures." This is an interpretation — not a finding. Several competing explanations exist, and a robust analysis must weight them.
Bear market incentives. The 2022-2023 bear market reduced the expected profitability of attacks. Liquidity dried up. Exit liquidity — the ability to convert stolen assets into fiat without freezing — contracted. Exchanges implemented velocity checks and withdrawal limits. Professional attackers respond to incentives. A tree falling in a forest with no buyers makes less noise.
Attacker migration. The professional cybercrime labor market reallocates. During crypto downturns, traditional ransomware, corporate network intrusion, and nation-state espionage offer better risk-adjusted returns. The decline in crypto attacks may be partially explained by attackers choosing other targets — not by better defenses.
Reporting bias. In bear markets, media attention evaporates. A $100K exploit in a bull market is front-page news; in a bear market, it is a Telegram message in a niche channel. Surveillance companies also expanded coverage over time, creating non-comparable time series. An apparent decline could be an artifact of what got reported and what got aggregated.

Attack surface contraction. The 2022 bridge attack wave was concentrated on a handful of high-TVL cross-chain bridges. Post-winter, many of those bridges shut down or saw TVL collapse to near zero. The attack surface did not harden; it shrank. Fewer bridges exist, so fewer bridge hacks occur.
None of these explanations are mutually exclusive. The correct answer is likely: real security improvements plus bear-market incentive shifts plus reporting artifacts plus attack-surface contraction. The report's simplification to "security measures improved" is convenient but incomplete.
4. The Publisher's Incentive Function
Grayscale's motives deserve explicit modeling.
Competitive positioning. Post-ETF conversion, Grayscale competes directly with BlackRock and Fidelity on fees — a race it cannot win on price. Its differentiation strategy is authority. Research reports that position Grayscale as the institutional-grade intelligence source reinforce brand loyalty among allocators rotating out of GBTC.
AUM stabilization. Security narratives reduce friction in the institutional sales cycle. A "safe asset class" narrative supports sustained inflows. The timing — active outflows in early 2024 — is not coincidental. The report is, in part, a capital-markets communication exercise.
Regulatory signaling. SAB 121 made custody safety a regulatory flashpoint. The SEC's accounting staff required custodians to book digital assets as liabilities, implying a risk profile. A high-profile report claiming "hacking at 9-year lows" provides political cover for any future softening of that rule. It frames the industry as having matured past its reckless phase.
Data opacity. Grayscale's public summary does not name its data provider. The probable sources — Chainalysis, TRM Labs, Rekt.news — have their own measurement quirks. Without the methodology, the data cannot be replicated or falsified. A non-falsifiable statistic has rhetorical value, not evidentiary value.
Contrarian: The Blind Spot the Market Will Miss
Here is what the market's reaction will overlook.
First, this is a trailing indicator — and a boundary condition. The "9-year low" describes the past 12 months of a specific custody-and-exchange segment. It says nothing about the attack surface expanding right now: DeFi protocols, cross-chain messaging layers, stablecoin issuers' operational security, and the emerging frontier of AI-agent-controlled wallets. Each has its own vulnerability lifecycle. None are captured in Grayscale's frequency aggregate.
Second, the trend line will break — probably in a bull market. The structural game dictates it. A new bull market attracts fresh capital into unaudited applications, experimental restaking mechanics, and fast-shipping L2s. Audit capacity is finite. Attackers return when liquidity returns. The record will reset. The "9-year low" becomes the "post-hack correction," and the narrative flips exactly as quickly as it flipped up.
Third, frequency statistics are blind to rare-event risk. A single critical zero-day in a widely deployed library — or a compromised key ceremony at a major custodian — can produce losses exceeding the cumulative sum of an entire year's smaller incidents. The security industry historically fails at precisely the moment when frequency data indicates safety. That is when vigilance drops. The 9-year low is, from a game-theoretic perspective, the peak-risk window: confidence is highest, defenses are loosest.
Fourth, there is a category error hiding in the report's implication. Bitcoin's attack surface is narrow because Bitcoin has few applications. The same security record does not extend to a DeFi ecosystem whose composability means every contract is one misbehaving dependency away from exploit. The report's framing — "crypto is safe" — erases the difference between a low-attack-surface base layer and a high-attack-surface application economy.
I have lived this pattern before. In 2022, after the Terra/Luna collapse, I spent six months studying the game-theoretic flaws of algorithmic stablecoins. The market's reaction back then: "failures are isolated, the infrastructure is fine." The follow-on year produced the largest bridge hack in history. The lesson: the narrative that security is solved is the precursor to the next exploit.
Takeaway
Math doesn't care about your marketing calendar. A nine-year low is a data point, not a proof. Privacy is a protocol, not a policy — and so is security. It is a property of verified code, audited custody, and formalized processes. It is not a property of press releases.
Before allocating a single institutional dollar on the basis of this report, ask three questions. What is the denominator? Who collected the data, and under what counting rules? And what was the publisher's outflow trajectory at the moment of publication?
The answer to the last question will tell you more than the headline. The compromises that will matter are still in development — and the narrative that "hacking is at a nine-year low" is precisely the confidence signal that makes the next attack profitable.