Not so long ago, our firm received a cybersecurity alert from a client. Their crypto protocol, which we had audited and which they had recently launched, was being exploited. This was obviously terrible news, so we rushed to look at what happened. After some confusion, we realized that our client had actually deployed the wrong version of their protocol—a test version used during development, not the version we had audited. It was a simple human error, but it cost the client a lot of money. This anecdote illustrates a real, widespread problem in the crypto sector: these days, the most damaging cybersecurity attacks don’t target errors in the code so much as they target operational mistakes. Since 2022, the industry has lost an astonishing $2.2 billion to malicious actors. The industry’s response has been to triple the number of software audits it conducts. But our research shows that the majority of attacks actually focus on human vulnerabilities, which are beyond the scope of ordinary audits. Put differently, the crypto industry needs to change its attitude toward cybersecurity checks. It shouldn’t abandon code audits, but it should seriously ramp up efforts to protect itself from human attack vectors. Otherwise, it will keep bleeding money away and never have the opportunity to go properly mainstream. Traditional Audits Aren’t Enough To be fair, audits have improved the quality of crypto software. Fewer exploits are due to technical coding errors than before. The industry has gotten better at this specific thing. But criminals adapt. Today's most costly attacks involve tricking employees into handing over passwords, manipulating the voting systems that govern how these platforms make decisions, planting malicious software through routine updates, or simply compromising a trusted insider. Meanwhile, AI tools have made it dramatically easier for attackers to craft convincing fake emails, impersonate