On a Tuesday morning in Tel Aviv, the Grayscale research note landed in my inbox with a subject line that makes an editor pause: 'Bitcoin and crypto hacks hit a nine-year low.' Nine years. I looked at the coffee ring on my desk and asked a question that has followed me through every market cycle: Low according to what? Security is not a single number. It is a story told with statistics. In my years of tracking institutional entry into this industry, I have learned that the most dangerous narratives arrive clean. They ask you to feel good before you ask what was actually measured. This one, as it turns out, is a masterclass in statistical framing.
Grayscale is not a security firm. It is an asset manager built on trust, compliance, and a very particular kind of narrative engineering. Its research arm publishes reports designed to inform, but also to reassure. The latest report does exactly that. It tells us that bitcoin and crypto hacking events have fallen to a nine-year low. It attributes that decline to improved security measures. It then takes a step further, suggesting that the improvement could boost investor confidence and accelerate institutional adoption. All three claims are plausible. All three are also fragile. The problem is not the direction of the trend. The problem is the unit of measurement hidden inside the sentence 'nine-year low.'
I remember 2022 vividly, not because it was the year I nearly burned out chasing algorithmic stablecoin collapses, but because the industry lost an absurd amount of money to exploits. Ronin Bridge lost more than six hundred million dollars. Wormhole lost over three hundred million. Nomad lost close to two hundred million. The list felt endless. Every week brought another post-mortem, another multi-sig key that was never meant to be a single point of failure, another room full of brilliant engineers discovering that their careful code had a flaw someone else had already found. So when a report tells me that we are now living through the safest period for crypto in nine years, my first instinct is not gratitude. It is curiosity. What exactly is being measured?
Three Ways to Read a Nine-Year Low
The first interpretation is the most literal: the number of successful attacks has fallen. This is possible. If you count every phishing wallet drain, every private key leak, every small DeFi exploit, the frequency can indeed decline when market activity contracts. Fewer active users means fewer targets. Lower total value locked means lower rewards for attackers. The bear market itself is a security mechanism, not because security teams got better, but because the expected value of an attack collapsed. That is the uncomfortable truth the report's clean narrative hides.
The second interpretation is dollar-denominated losses. If Grayscale was talking about total dollar value stolen, a nine-year low is far more difficult to believe. In 2021 and 2022, the industry suffered some of the largest single-event losses in its history. In 2023, total losses were still measured in billions. Yes, the numbers declined from the peak, but they remained far above the levels of 2015 or 2016, when the market was small enough that even a million-dollar hack felt like a catastrophe. A nine-year low in dollar terms would require us to forget the recent trauma. I do not think we have earned that amnesia.
The third interpretation is the most insidious: losses denominated in bitcoin. Because the price of bitcoin has risen so dramatically over nine years, an amount stolen in 2015 that was worth, say, one million dollars at the time might represent the same number of bitcoin as a theft that is now worth two hundred million dollars. If the metric is 'bitcoin stolen,' the historical comparison becomes almost meaningless. The denominator moves. The unit of account is no longer stable. A report that does not clarify which measure it uses is not a technical document. It is a marketing artifact.
What Actually Got Safer
The underlying bitcoin protocol did not change in any fundamental way. The proof-of-work consensus mechanism and the UTXO model remain structurally identical to what they were a decade ago. The decline in successful attacks is therefore not about Bitcoin's core security. It is about the ecosystem around it. Custodians moved more assets into cold storage. Multisig arrangements became standard for major treasury operations. Insurance products matured. Chainalysis and Elliptic built monitoring systems that make stolen assets harder to move without detection. Security auditors standardized their processes, and formal verification moved from academic papers into practical tooling. These are real improvements. I have seen them in the field.
Based on my audit experience, the best security teams are not the ones with the most expensive tools. They are the ones that treat security as a boring, continuous process. They review the same code dozens of times. They assume the worst. They design incident-response plans before the incident. That cultural shift is happening, but it is uneven. The technical audit firms that grew up during the DeFi summer are no longer the same cottage industry they used to be. They have methodologies, track records, and reputations to protect. That is a genuine advance.
Yet we should be careful about causality. The report credits security improvements for the decline. But the bear market also deserves credit. When prices fall, attackers have less to gain. The number of people entering crypto drops, which means fewer targets for phishing and social engineering. Some attackers may simply move to other crime vectors. Ransomware groups, pig-butchering scams, and off-chain fraud do not always appear in an on-chain hack statistic. A decline in 'crypto hacks' can coexist with a rise in crypto-related crime that happens outside the contracts.
The Data Supply Chain Nobody Mentions
Grayscale does not run its own nodes. It does not monitor suspicious transactions in real time. Its research team is composed primarily of macro analysts and strategy specialists, not security researchers. This does not make the report wrong, but it means the underlying data almost certainly comes from third-party vendors. The summary I received does not name them. That is a significant omission in an era when institutions demand verifiability.
Different security vendors count different things. Some include only on-chain exploits of smart contracts. Others include private key compromises, phishing, and social engineering. Some count the total value lost at attack time. Others use the market value at the time of reporting, which may be lower or higher depending on the volatility of the stolen asset. I have spent months in Tel Aviv trying to reconcile datasets from different security firms for a research collective focused on AI and crypto convergence. I can tell you that the same incident can appear twice in one vendor's data and not at all in another's. The variance is not trivial. It can change a trend line from 'sharp decline' to 'flat' with one methodology adjustment.
This matters because the report's persuasive power depends on the credibility of its data. If Grayscale sourced the numbers from a well-known firm like Chainalysis or TRM Labs, it should say so. If it used a proprietary index, it should disclose the methodology. Without that disclosure, the 'nine-year low' is a headline in search of a footnote. The absence of a footnote is not proof of deception. It is, however, a signal about the intended audience. This report was not written for technical reviewers. It was written for institutional investors who need a reason to feel good about a decision they have already made.
The Institutional Signal Beneath the Numbers
Grayscale is not a neutral observer. It manages billions in digital asset trusts. Its parent company, Digital Currency Group, has been through a brutal cycle, including the bankruptcy of Genesis. The company's legal victory against the SEC in 2023 helped clear the path for spot bitcoin ETFs. Since then, the competitive landscape has changed. Grayscale is no longer the only regulated gatekeeper. It is competing with BlackRock, Fidelity, and other financial giants. In that context, a report claiming that crypto is safer than it has been in nearly a decade is not just an observation. It is a product feature.
I do not say that to dismiss the report. Every asset manager produces research that supports its own franchise. Goldman Sachs publishes bullish fixed-income research. JP Morgan publishes its own economic forecasts. The conflict of interest is structural, not personal. The question is how much discount you apply when you read the results. A nine-year low in hacks, if true, is a genuine reason for cautious optimism. But the same report that contains that data also contains an incentive to frame it in the best possible light. The framing choices matter.
The report also functions as a bridge between the security industry and institutional capital. Fireblocks, Ledger Enterprise, and dozens of other security providers have excellent products but limited influence over traditional finance. Grayscale, as a regulated issuer with a recognized brand, can translate security infrastructure improvements into a language that pensions and family offices understand. That is valuable. It is also one-directional. The report tells institutions that the industry is becoming safer, but it does not tell them where the remaining risks are concentrated. It does not tell them that DeFi protocols still live on unproven code, that bridges remain a favorite target, or that the same monitoring tools that catch thieves can be outsmarted by a sufficiently patient adversary.
The Regulatory Shadow
The timing of the report matters. The SEC has spent years wrestling with custody standards, employee accounting bulletin SAB 121, and the question of whether crypto assets can be safely held for clients. Every large hack gives regulators ammunition. Every quiet quarter gives industry participants an opportunity to say: See, we are becoming responsible. Grayscale's report lands in that open window. It is a piece of evidence in a broader argument that the industry should be trusted with institutional money because it has learned to protect it.
This is not necessarily a bad thing. It is, though, a lobbying document as much as a research product. In the same way that a decline in bank robberies might be cited by a banking association as proof of effective regulation, the decline in crypto hacks can be used to soften regulatory resistance. The SEC may not change its position because of a single Grayscale report. But the accumulation of such reports shapes the cognitive environment in which regulations are written. If the official narrative becomes 'the security problem is solved,' the next regulatory cycle could be less punitive.
There is also a domestic political angle. Grayscale is headquartered in the United States. Its regulatory battles were fought in American courts. A report highlighting improved security helps the entire American crypto industry, but it especially helps Grayscale and its competitors in the ETF space. The more comfortable regulators feel with custody and security, the easier it becomes to launch new products. Grayscale has filed for trusts covering other assets. Those applications will be reviewed by the same SEC that has read this report. The report, if it gets traction in the press, becomes part of the submission file, even if it is not formally filed.
The Team Behind the Report
The report's authorship matters. Grayscale is a registered investment company, not a security lab. Its research team's expertise is in markets, macro, and regulation. That does not disqualify their security analysis, but it means they are one step removed from the source data. When a market analyst interprets a security trend, the framing tends to follow the story that serves the audience. The audience here is institutional investors who might be nervous about custody risk.
I have written enough research notes to know that every editorial decision in a report is a worldview in miniature. The absence of a methodology section is a choice. The verb 'suggest' instead of 'prove' is a choice. The decision to say 'bitcoin and crypto' rather than 'bitcoin network and DeFi ecosystem' is a choice. None of these choices are necessarily dishonest. They are the fingerprints of an organization that wants to avoid technical complexity while still appearing rigorous.
The ETF Competition Effect
The report also enters a specific competitive battlefield. Since the approval of spot bitcoin ETFs in early 2024, Grayscale has been forced to defend its market share against lower-fee competitors. The conversion of GBTC into an ETF ended years of locked-in capital. In the first few months after the conversion, the fund experienced significant outflows. A security-improvement narrative helps in at least two ways. It reassures existing holders that their decision to stay is rational. It also provides a reason for new investors to choose a product tied to a research operation that publishes proactive safety data.
That is not the same as saying the report is a cynical attempt to stop outflows. It is simply to say that the institutional moment is overdetermined. A report about security from a firm that sells security-adjacent products will always be pulled toward commercial optimism. The readers of the report should therefore subtract the commercial bias before extracting the factual content. The correct subtraction is not obvious, but a good starting point is to discount any claim that is not accompanied by a precise methodology.
The Confidence Interval of a Nine-Year Low
Let me get technical for a moment. A 'nine-year low' is not a precise term. It could mean a rolling twelve-month sum of incidents, ending at the latest quarter. It could mean a calendar-year total for the most recent full year. It could mean a monthly average over the past nine years. Each definition produces a different data point. If I were grading this report as a peer reviewer, I would mark it as insufficiently identified.
The confidence interval around security data is also wide. Smaller vendors may not have visibility into certain types of attacks. The same incident can be reported in different weeks depending on when a blockchain forensics team completes its tracing. Some thefts are discovered months after they occur. A report published today could be missing an exploit that happened three months ago, simply because the protocol did not notice it yet. That makes the 'nine-year low' potentially a lagging indicator of a problem that has not yet emerged.
This is not just academic. In 2021, the industry was celebrating its security improvements. We had learned from the DAO hack. We had learned from the Parity wallet freeze. We had built better tooling and more mature auditing markets. Then the cross-chain bridge attacks arrived and reset the entire conversation. The lesson was not that security had failed. The lesson was that security improvements in one domain can push attackers into another domain. The nine-year low may be a similar moment. We are safer in the areas we know to measure. The next attack may come from an area we have not thought to measure.
The Human Cost of the Narrative
There is also a human dimension that the report misses. Every headline about security improvements should be weighed against the people who lost money in the attacks that did happen. Nine years of declining frequency does not comfort the victim of a phishing attack last week. In my ethnographic work on DeFi, I have interviewed women in Lagos and Rio who lost their savings to poorly audited protocols. Their stories are not in Grayscale's report. Their losses do not fit the narrative of institutional maturation.
I am not asking Grayscale to produce a sociology study. But I am asking us to remember that security metrics are not neutral. The choice to measure frequency rather than victim count is a choice. The choice to celebrate a statistical low while hundreds of individuals are still recovering from losses is a choice. The industry's move toward institutional legitimacy is real, but it is incomplete. The security improvements are unevenly distributed. Retail users who cannot afford insurance or custody services remain exposed. Their exposure is hidden by aggregate statistics.
The Geographic Distribution of Attackers
Another omitted variable is geography. The crypto attacker community is not evenly distributed around the world. When one jurisdiction improves its enforcement, attackers move to another. Some of the decline in on-chain heists may be offset by an increase in attacks launched from jurisdictions with weak cybercrime enforcement. The operational cost of laundering stolen funds has also changed. Mixers, cross-chain bridges, and privacy protocols have been targeted by regulators, forcing attackers to adapt. This is progress from a law-enforcement perspective, but it does not mean the attacks have stopped. It means they have become more sophisticated.
I have spoken to security engineers who say that the current moment is characterized not by less hacking, but by more professional hacking. The old image of a lone coder draining a pool was always mythological. Today, the teams that attack protocols resemble venture-backed startups. They have project managers, quality assurance, and post-exploit analytics. They specialize in particular types of vulnerabilities. They pass knowledge between generations of attackers. The bear market may have reduced the number of opportunistic attackers, but it did not reduce the capability of the professionals.
The Institutional Blind Spot
Institutions face a different kind of security problem. They do not just need to protect private keys. They need to protect their clients' assets from malicious actors inside their own organizations. The FTX collapse demonstrated that a lack of internal segregation of duties can destroy more value than any outside hacker. Grayscale's report does not address this. It says nothing about governance controls, employee vetting, audit trails, or operational resilience. These are the risks that matter most to institutional investors. A report on external hackers cannot reassure them about internal fraud.
During the LUNA collapse, I realized that the biggest risk in crypto was not code. It was leverage. The biggest risk during the FTX collapse was not cryptography. It was accounting. The biggest risk now, even with hacks at a nine-year low, is the ability of institutions to trust the people who manage access to their assets. Security infrastructure can prevent external theft. It cannot prevent a trusted operator from making a catastrophic mistake. The report's silence on that topic is not an accident. It is the boundary of the institutional narrative.
A Practical Reading List for the Skeptic
Let me leave you with a practical framework. When you read the next security report, ask the following: Is the metric frequency or loss? Is the loss denominated in dollars or in bitcoin? Is the data source named? Is the methodology public? Does the report distinguish between bitcoin network security and DeFi security? Does it mention internal governance risks? Does it include near misses and attempted attacks? Does it show the distribution of losses by sector and geography? If the report cannot answer at least five of those seven questions, treat it as a narrative document.
Grayscale's report may be a perfectly accurate description of a specific and narrow statistic. It may be the result of an honest research team doing its best with incomplete data. It may even be correct in the way that matters. But in a world where a nine-year low can be produced by a bear market, by a changed counting methodology, or by an attacker community that has moved off-chain, the claim cannot stand on its own. It needs a footnote. It needs a data source. It needs a comparison of the same metric across multiple vendors. Without those things, it is not a finding. It is an advertisement for a worldview.
That worldview holds that crypto is getting safer because it is becoming institutionalized. There is real evidence for that worldview. Custody has improved. Compliance has improved. Insurance has improved. The people building the infrastructure are more professional than they were in 2017. But the institutions are also bringing new risk. The more capital is pooled into a small number of custody wallets, the more attractive those wallets become. The more complex the DeFi system becomes, the harder it is to model. The more confident the narrative becomes, the more complacent the community becomes. Complacency is a security vulnerability. It is just not one that appears in a chart.
The Broken Clock That Tells the Right Time Twice a Day
Now we come to the contrarian angle. The nine-year low is a lagging indicator. It describes the past, not the future. Every security improvement in crypto has been met by a new wave of attacks. The industry's history is not a straight line of progress. It is a spiral. Multisig becomes standard, so attackers target governance processes. Auditors find one class of vulnerabilities, so attackers move to oracle manipulation. White-hat monitoring improves, so thieves turn to cross-chain bridges where tracing becomes harder. The security static improves, but the game changes.
I have lived through enough cycles to know that a period of calm often precedes a period of exceptional violence. The attacker community is patient. The one thing a bear market cannot buy is permanent safety. It can only buy time. If the next bull market arrives, total value locked will rise, new retail users will pour in, new protocols will launch with unaudited code, and the attack surface will expand faster than the security industry can respond. The nine-year low may prove to be the high-water mark of institutional confidence before the next wave of chaos.
The report also ignores the problem of concentration. Security improvements are not evenly distributed across the ecosystem. Bitcoin is relatively safe because it has a small application layer. The same cannot be said for DeFi. The most damaging hacks of the last three years were not Bitcoin hacks. They were attacks on bridges and lending protocols. If you break the ecosystem down by sector, the safety trend is far less impressive. Bitcoin is secure because there is less to attack. That is not a triumph. It is a structural feature.
Another blind spot is the definition of 'hack.' The report may count successful exploits, but it may not count failed attacks. It may not count near misses. It may not count bugs that were found and fixed before they were exploited. It may not count social engineering attacks where the victim willingly signed a transaction. In 2023, a significant share of losses involved phishing approvals, where users granted permissions to malicious contracts. Those are not always classified as hacks. Yet they drain user funds just as effectively as a smart contract exploit. If those incidents are excluded, the nine-year low becomes a tautology: we counted fewer of the thing we chose to count.
What Comes After Safety
The industry is now entering a period where safety is a marketing category. We will see security-score products, insurance-backed staking yields, and audit reports cited as if they were credit ratings. Some of this is useful. Some of it is theater. The difference is whether the underlying practices have genuinely improved or whether the labels have merely been polished. Based on my audit experience, the truth is mixed. There are protocols with excellent security cultures. There are also protocols that buy an audit report the way a student buys a term paper. The market cannot tell the difference until it is too late.
The next wave of institutional adoption will not be driven by the security improvements themselves. It will be driven by the perception of security. Grayscale's report is a contribution to that perception. It is not false, but it is not complete. The question for the reader is whether you can hold two ideas at once: security is improving, and catastrophic risk remains. The first idea justifies participation. The second justifies caution. Both are necessary for survival in a bear market and in the bull market that follows.
Yield wasn't the only thing that disappeared when the last cycle turned. The promise of safety will disappear too, the moment the market decides that the risks are repriced. The only way to stay ahead is to keep asking the questions that the report does not want to answer. What is the denominator? Why should we trust the source? What happened in the months that are not displayed on the chart? And if we know the next attack is already being planned, why are we building our confidence on the calm before it arrives?
The calm is real. The low is real. The institutional shift is real. But the reality that matters is not the one in the headline. It is the one that waits quietly in the metadata, where the counting was done, where the choices were made, and where the next vulnerability is already taking shape. That is where I will keep looking. That is the only place in this market where the truth still hides.