Back in late 2017, when the ICO mania was peaking, I spent my evenings in a crowded Mexico City coworking space, watching Status Network's Telegram group vibrate with anxiety. People weren't asking about smart contract bugs; they wanted to know if their vesting schedules would survive the first price shock. I had left a traditional economics background just a few years before, and I was trying to apply my training to this strange new world of tokens and whitepapers. Instead of scanning code, I found myself reading group chat dynamics, measuring the emotional temperature of a community that had thrown its savings into a concept. That experience stayed with me. It taught me that in crypto, security is as much about human trust as it is about code. So when Grayscale published its latest research note last week, declaring that bitcoin and crypto hacks have fallen to a nine-year low, I didn't celebrate. I pulled up the raw data, checked the definitions, and asked a question no one in the headlines was asking: What exactly is at this 'low'? History repeats, but liquidity decides the tempo. And this time, the tempo might be slower than the headline suggests.
Let's start with what we actually know. Grayscale's report, as summarized by crypto media, claims that the number of hacking incidents targeting bitcoin and the broader cryptocurrency ecosystem has reached its lowest point in nine years. The report attributes this decline to improved security practices: more assets in cold storage, wider adoption of multisignature wallets, more robust insurance products, and better chain surveillance tools from firms like Chainalysis and Elliptic. At first glance, this feels like welcome news. After the FTX collapse, the Terra/Luna fiasco, and a long list of bridge exploits, we could all use a positive security headline. But as a fund manager who has lived through multiple cycles, I've learned that aggregated statistics often hide more than they reveal. Culture is the code that compels human adoption, and our culture right now is built on narratives—sometimes comforting, sometimes convenient.
Grayscale is not a neutral observer. The firm manages billions in digital asset trust products, and its research arm functions as a bridge between institutional capital and the crypto market. A 'security is improving' report serves to reassure pension funds and family offices that the asset class is maturing. That doesn't make the data false, but it does mean we need to examine the construction of the statistic. What does 'nine-year low' actually measure? Is it the frequency of events? The total dollar value lost? Or the amount measured in bitcoin terms? The summary we're all reacting to doesn't specify. In my experience auditing ICO communities back in 2017, I learned that people anchor to the most emotionally satisfying version of a number. This is no exception.
To understand the current metric, we need to go back to 2015, the beginning of the nine-year window. That year, bitcoin was trading below $300. The 'hacker' events that made headlines were mostly exchange breaches: Bitstamp lost 19,000 BTC, and Bter lost about 7,000 BTC. In dollar terms, the total losses were in the tens of millions. Compare that to 2022, when decentralized finance protocols and bridges became the favored targets. The Ronin Bridge attack alone accounted for over $600 million, while Wormhole lost $325 million, and Nomad saw $190 million swept away. The dollar value of lost assets is now in the billions. So if we are using frequency as the metric, a 'nine-year low' is plausible: attack campaigns have become more concentrated and larger in scale, reducing the total number of incidents even as the damage from each incident grows. But for an allocator, the number of incidents is irrelevant; the amount of loss is what determines capital destruction.
Here's where the data opacity becomes a problem. In my work, I've seen how different on-chain security firms count incidents. Some include scam contracts, others only count network exploits. Some measure losses in dollar terms at the time of attack, others in current value. A 'nine-year low' could be the result of a specific set of definitions that are narrower than the public might assume. For example, a report might exclude any incident involving the Ethereum chain or any loss below a threshold. If Grayscale's statistic is based on a particular vendor's dataset, then the conclusion is only as good as that vendor's coverage. Without disclosure, we can't evaluate the claim.
Let's also talk about the shift in institutional practice. After the ETF approval, I advised several institutional clients on how to think about bitcoin in their portfolios. Their first question was never about price; it was about custody and insurance. They wanted to know who holds the private keys, what happens if a custodian is hacked, and whether the insurance covers the full value. This is why the Grayscale report is so strategically timed. It reassures these clients that the industry has solved the operational security problem, at least for the assets that flow through regulated vehicles. But the narrative masks a critical gap: the security of regulated custody is not the security of the open protocol. The ETF wrapper is a walled garden, and the walled garden's security doesn't make the wild field outside any safer.
In a sideways market, reports like this become a form of positioning. We know that chop is for positioning: the goal is to identify undervalued projects with good security and community trust. A report that says 'hacks are down' might be interpreted as a signal to buy bitcoin and hold, but it should also prompt us to ask which teams are actually investing in audit and transparency. Over the past 7 days, I've been following a few protocols that have shown resilience despite the noise. Their common feature isn't a low hack metric; it's a commitment to open communication and gradual feature rollout. That's the kind of culture that compels adoption.
Let's examine the three possible interpretations of the 'nine-year low' claim. The first—and most likely—is that the metric refers to the count of separate hacking events. This is consistent with the observable industry trend: as security practices mature, the average exploit size has increased, but the number of small-scale attacks has declined. We see this in the shift from exchange hacks to DeFi protocol exploits. In 2018, we saw a wave of small exchange hacks, each losing a few million. By 2023, the surviving exchanges had hardened their custody, and the profitable targets moved to bridges and liquidity pools, which tend to be exploited in dramatic single events rather than in scattered attempts. This concentration effect can show up as a decline in event count even as total losses remain elevated. The problem is that a frequency-based statistic creates an overly rosy impression. A single black swan event can reset the denominator.
The second interpretation is dollar-denominated losses. Under this lens, the 'nine-year low' becomes less defensible. Consider the historical totals: even though 2023 saw a drop from 2022's peak, the total value stolen across crypto still exceeded $1.7 billion. That is far above the losses recorded in the 2015-2016 period. The only way to reconcile a dollar-loss low with public data is to restrict the measurement to Bitcoin's base layer, where actual thefts of protocol-level funds are rare. But the Grayscale report, as presented in the press, doesn't make that restriction clear. Without a precise definition, the 'low' remains an artifact of methodology.
The third possibility is that the report uses a rolling twelve-month window that ends at a particularly quiet quarter. This is common in institutional research; it smooths noise but also creates a lag. A rolling window tells you where the attack surface was, not where it's going. Just as a declining hurricane count over nine years doesn't predict next season, a nine-year low in hacks doesn't tell us whether we've solved the underlying vulnerabilities. We have, in fact, learned that the threat landscape is constantly shifting. The use of AI to generate phishing attacks and automated exploit schemes is one example. The emergence of Account Abstraction and intents-based protocols is creating new ephemeral security surfaces that are hard to audit. If we rely on a lagging indicator, we are essentially driving while looking in the rearview mirror.
Now let me bring in my own experience. During DeFi Summer in 2020, I directed a $2 million allocation into Aave and Compound pools. What struck me wasn't the yield; it was the friction. Non-technical users couldn't figure out how to manage collateral, understand liquidation thresholds, or assess smart contract risk. I worked with product teams to smooth those interfaces, because I knew that UX friction directly affects capital retention. That experience gave me a lasting appreciation for the 'user journey' as a security surface. Many hacks succeed not because cryptography fails, but because users are confused. The same principle applies to the current security narrative: if the community cannot understand the metrics behind 'nine-year low,' that confusion itself becomes a vulnerability.
Over the past 7 days, I've been looking at protocol data from DefiLlama and Layer 2 fee schedules. A pattern emerges: the security improvements that Grayscale points to are largely centralized in the custody and exchange layer, not in the code of decentralized protocols. Cold storage, multisig, and insurance protect institutional funds. They don't protect a retail user who provides liquidity to a new, unaudited farm. The decrease in headline hacks may reflect a shift in attacker behavior rather than an actual reduction in systemic risk. Hackers follow the money. Just as liquidity moves between chains, attacker attention moves between sectors. In 2022, bridges were the target because that's where funds were concentrated. In 2024, we're seeing more incidents around governance attacks, private key leaks in DeFi protocols, and even AI-driven social engineering.
Let's talk about the Bitcoin network itself, because that's the centerpiece of Grayscale's product. The base layer has not changed fundamentally in the last nine years. The Proof-of-Work consensus and the UTXO model are the same as they were in 2015. The reduction in hacking incidents is not due to an upgrade of the Bitcoin protocol; it's due to the ecosystem around it building better custody, better monitoring, and better insurance. This is a peripheral improvement, not a core one. It's as if a city reported a decline in home burglaries because more people installed alarms and bought insurance policies, while the locks and doors remained identical. Good, certainly. But it doesn't mean the security landscape is transformed.
This distinction matters because of the shift in bitcoin's role after the ETF approvals. In January 2024, the SEC approved spot bitcoin ETFs, including one converted from the Grayscale Bitcoin Trust. That event changed bitcoin's character in ways that few people fully appreciate. Bitcoin is no longer a counterculture money experiment; it's a Wall Street toy. The 'peer-to-peer electronic cash' that Satoshi described has been repackaged as a digital gold narrative that fits neatly into pension fund portfolios and risk models. That's not necessarily bad for prices, but it changes what we mean by 'security.' For a Wall Street toy, security is about custody, insurance, and regulatory compliance. For a peer-to-peer cash system, security is about censorship resistance, self-sovereignty, and decentralization. The Grayscale report speaks to the former, not the latter. When the firm highlights 'nine-year low hacks,' it is reassuring institutions that their assets are safe in custody. It is not reassuring a Bitcoin user in Mexico that she can transact without interference.
The Layer 2 landscape makes this contrast even sharper. We're now building a universe of rollups, with Dencun's blob architecture creating cheaper data space. But that data space is finite, and my modeling suggests it will be saturated within two years. When that happens, rollup gas fees will double again, as users compete for the same blob capacity. In the meantime, we're adding complexity with hooks, restaking mechanisms, and cross-chain applications—complexity that increases the attack surface. Uniswap V4's hooks, for example, turn the DEX into programmable Lego, but the flexibility will scare off 90% of developers who aren't prepared for the security implications. Every new feature is another place where a bug can hide. We celebrate security improvements after the fact, while simultaneously building the next generation of vulnerabilities. The Grayscale report, by focusing on past incidents, does not account for the fragility of new construction.
Let me return to the Grayscale economic model. As a fund manager, I see that the report has a commercial function. Grayscale faces intense competition from low-fee ETF providers like BlackRock and Fidelity. To maintain its market share, it needs to position itself as the trustworthy custodian and research leader in the space. Publishing a report that says 'hacks are at a nine-year low' is an effective way to reinforce the brand narrative. It also aligns with the changing regulatory environment: the SEC has been concerned about crypto custody risks, and the industry has been lobbying for clearer rules. If institutions believe the security problem has largely been solved, they are more likely to support proposals that lighten regulatory burdens. In that sense, the report is not just an observation; it is an instrument of policy advocacy.
Another point that gives me pause is the lack of disclosed data sources in the summary. Grayscale is a credible institution, but it has not published the full methodology behind the 'nine-year low' claim. In institutional research, such a dramatic decline would normally be accompanied by a breakdown by attack vector, a table of losses over time, and a clear definition of what constitutes a hack. Without that, we are left with a press release that functions as a narrative synecdoche—a part standing in for the whole. This is a common problem in crypto research, where the desire for a clean headline often overrides statistical rigor. I would love to see Grayscale release its supporting data, but I'm not holding my breath.
The parent company, Digital Currency Group, has its own complications. DCG's subsidiary Genesis filed for bankruptcy in early 2023, and the group's financial structure has been the subject of intense scrutiny. This isn't directly a comment on the research quality of Grayscale's analysts, but it does create a potential conflict-of-interest question. If the parent company is under financial stress, there is pressure on the research arm to produce messages that support asset flows into the group's products. I'm not saying that happened here; I'm saying that as an experienced allocator, I need to be aware of the institutional context. Trust can be blind, but it leads to mistakes.
Let's also consider what the 'nine-year low' narrative says about our sense of market cycles. We are currently in a sideways/consolidation market. There's no strong trend in price, and many investors are waiting for signals. Reports like Grayscale's fill that vacuum. They give people a sense that we are moving toward a more mature phase, that 'the worst is over.' That can be true, but it can also be a self-fulfilling narrative that encourages complacency. I've seen this movie before. In 2019, after the Bitfinex recovery and calm markets, institutions began to relax. Then March 2020 happened, and the crypto market crashed 50% in a day. The lesson: market structure changes, but human psychology is constant.
Now let's talk about the contrarian angle that I believe the mainstream misses. The 'nine-year low' may not be due to security improvements at all. It could be the consequence of a bear market. When prices fall, the incentive to hack fades because stolen assets are harder to sell without triggering the very patterns that monitoring tools detect. We saw a spike in hacks during the bull market of 2021, when liquidity was abundant and laundering was easier. In a quiet market, the attack surface still exists, but the looting is less profitable. So the decline in incidents could be cyclical, not secular. If that's the case, we should not expect the trend to continue indefinitely. Instead, the next bull cycle may bring a new wave of exploits—just as it did in 2021. And because the current security infrastructure is designed to protect custody rather than code, the next wave may target the new DeFi constructs that are still being built.
Moreover, the report may inadvertently create a moral hazard. If institutions and retail investors alike begin to believe that hacks are a thing of the past, they may take bigger risks, chase higher yields in unaudited protocols, and ignore the fundamentals of self-custody. That's not a problem with the report itself, but with the way it is absorbed by the market. As a community, we have a tendency to replace critical thought with comfort. The 'nine-year low' is comfortable. It makes us feel good about an industry that has seen its share of disasters. But the worst time to feel safe is when everyone is talking about safety. That is when vulnerabilities are quietly accumulating on the periphery, waiting for the next wave of liquidity.
I remember the early days of the FTX collapse, when the industry was in free fall. I initiated a 'Transparent Risk' series, publishing weekly newsletters to more than 10,000 subscribers, detailing our fund's exposure and our hedging strategies. Instead of hiding losses, we opened the books and let people ask questions. That transparency kept 85% of our capital during the worst downturn. When I see an authoritative institution release a reassuring statistic without full methodology, I worry that we are losing the very practices that got us through the last crisis. Trust is not built by confident headlines; it is built by consistent transparency.
So where does this leave us? As a community, we should welcome any sign that the ecosystem is harder to steal from. But we should also demand rigor. I want to see the data behind the headline. I want to know whether the 'nine-year low' is a nine-year low in frequency, in dollars, or in bitcoin. I want to know which attack vectors are declining and which are emerging. Without that detail, the metric is little more than a faint green number on a trading terminal—a number that could change with a single transaction.
The forward-looking question isn't whether the past nine years have gotten safer. It's whether the next nine months will. As we position for the next leg of the cycle, we should allocate to projects that have survived multiple downturns, that maintain transparent security processes, and that treat users as partners rather than counterparties. History repeats, but liquidity decides the tempo. And culture is the code that compels human adoption. In the end, what matters is not the headline—either 'nine-year low' or 'next big hack'—but how our community reacts when the next test arrives. I know this because I've spent the past nine years watching cycles turn, and every time the narrative felt safest, the market taught us something new. We must demand more than a headline; we need the full dataset, methodology, sector breakdown, data sources, and a definition. This is our responsibility.


