Grayscale has announced that cryptocurrency hacks are at a nine-year low. The sentence is not false. It is also not informative. A security metric without a defined denominator is a symptom, not a diagnosis. Lines of code do not lie, but they obscure. The report obscures the one variable that matters: what exactly is falling? Incident counts, dollar-denominated losses, or BTC-denominated losses produce three different histories. The first can look benign while a single attack drains a bridge. The second can be inflated by market indices rather than attacker behavior. The third can move with the Bitcoin price instead of security practice. Grayscale does not tell us which one it used. That omission does not make the report fraudulent. It makes it a narrative instrument, not a forensic artifact.
I have spent my career tracing the entropy from whitepaper to collapse. The gap between a claimed security property and an independently verified one is usually where failure hides. This report is a textbook case of that gap.
Grayscale is not a security lab. It is an asset manager that converted its Bitcoin Trust into an ETF and now competes with BlackRock and Fidelity for institutional allocation. Its research arm exists to make the asset class legible to fiduciaries. A report titled "hacks are at a nine-year low" is more than a state-of-the-network update. It is a trust signal sent to pension funds, family offices, and compliance officers. The timing is exquisite: post-FTX institutional hesitation, spot ETF inflows, and the SEC's gaze on custody rules. In that environment, a self-interested party claiming the asset class is safer is marketing with a chart.
What Exactly Is Falling?
Take the claim at face value and immediately ask: what is the unit of measurement?
If the metric is incident count, then severity is being ignored. The crypto industry has seen hundreds of small attacks in any given year. A drop in frequency does not mean a drop in systemic risk. One Ronin Bridge event in 2022 moved more value than dozens of smaller exploitations combined. If the data excludes bridges, DeFi, or non-Bitcoin ecosystems, then the "nine-year low" applies to a narrow island while the surrounding ocean still carries pirates.
If the metric is USD-denominated losses, then the claim is harder to defend. The 2021 to 2023 period included multi-billion-dollar failures. Unless the reporting window stops before those events or changes the classification rules, a nine-year low in absolute dollars is implausible. It might be true if Bitcoin-denominated losses are measured against a higher BTC price today. Ten bitcoins stolen in 2015 were not worth what ten bitcoins are worth in a post-ETF bull market. The portfolio value of the theft is not the same as the security improvement.
If the metric is BTC-denominated losses, then the claim tells us more about the price chart than the attack surface. A declining BTC-denominated loss amount can occur simply because the price in 2024 is higher than in 2015. The attacker took the same number of coins. The report labels the same event as less significant because fiat conversion changed. That is not security. That is accounting.
Architecture Has Not Changed
Bitcoin's core protocol has not undergone a paradigm shift in nine years. Proof-of-Work, UTXO accounting, and the settlement model remain structurally identical. The network's attack surface is intentionally narrow. Bitcoin script is constrained by design. Most hacks in crypto do not happen on Bitcoin's consensus layer. They happen in custody systems, bridges, wallet software, and application layers built on top of the network. Grayscale's report may be measuring an environment that is safer because the enemy does not live there.
This is where the report becomes dangerous. It invites investors to infer that Bitcoin is safer because the surrounding ecosystem has matured. Cold storage adoption has increased. Multisignature setups are more common. Audits have become standardized. Bug bounty programs exist. I have audited enough protocol code to know these practices are real. In 2020, I found a subtle reentrancy vector in Uniswap V2's update function, a technical result that could not have emerged without this maturation. That was genuine improvement.
But improvements at the periphery do not rewrite the fundament. Architecture outlasts hype, but only if it holds. The base layer held. The application layer still fails. Attackers adapt. They moved from protocol exploits to private key theft, governance attacks, and social engineering against privileged signers. The technical sophistication of defensive tooling reduces the attack surface, but the operational attack surface grows with custody complexity and institutional onboarding.
The Missing Denominator
My forensic instinct asks for the extraction rule. Allow me to state plainly: there is no peer-reviewed, independently reproducible methodology in a Grayscale press release. The report likely draws on third-party data suppliers such as Chainalysis, TRM Labs, or Rekt. Those vendors have their own definitions, thresholds, and sampling windows. Without those definitions being published, the number is not an entity. It is a rumor dressed as an index.
In my own work, I require the raw event log, the parser version, and the accounting rule for timestamping a loss. I want to know whether a failed attack is counted. I want to know whether a partial recovery reduces the loss. I want to know whether a project's self-reported reimbursement is subtracted from the numerator. Grayscale provides none of this. A reader is being asked to accept a conclusion without the predicate. That is not the style of engineering. It is the style of PR.
The Contrarian View: Security Theater as a Forward-Looking Risk
The deeper issue is not whether hacks are down. It is whether the narrative creates a new vulnerability: complacency. If institutional investors believe the nine-year low marks a structural turning point, they will discount tail risk in pricing. They will execute custody arrangements with reduced scrutiny. They will rely on reports instead of audits. I have seen this pattern before. After the FTX collapse, I examined the leaked UI code and found a single sign-off vulnerability that allowed administrative accounts to bypass auditing. The failure was not an off-chain accident. It was an engineering failure enabled by an organizational belief that governance complexity would never be tested.
That belief is what Grayscale's report, whether intentionally or not, feeds.
The decline in reported hacks may also reflect attacker resource allocation rather than defense. When a bull market brings opportunities in other criminal sectors, on-chain exploitation may become less attractive. When new protocols are launched slowly, as they are after a bear market, there are fewer immature targets to attack. The relationship between security improvements and hack frequency is not linear. It is asynchronous and structural. The report assumes causality from correlation. The truth may be that fewer bad contracts were deployed, not that the same number of contracts became more resistant.
Deconstructing the myth of decentralized trust has never been a popular exercise. The myth says that the network, by itself, protects the user. In reality, the network is the final settlement layer for an enormous amount of centralized decision-making. The nine-year low headline does not measure that. It measures a slice of activity, filtered by a data vendor, and interpreted by an asset manager with a commercial stake in optimism.
What Would Convince Me?
I would be convinced by a report that breaks losses down by attack vector, asset type, and custody model. I would want to see a time series denominated in both USD and BTC, with event frequency plotted separately. I would want to see the exclusion criteria: whether bridge exploits, exchange hot wallet thefts, and private key compromises are separated or aggregated. If the report shows that hacks are down because cold storage and multisig have become the default for custodians, then I will accept the claim as true for that category. If it merely shows that fewer hacks have been reported, then I will assume the denominator is missing.
I will also remember the recent history of institutional security. In 2024, I analyzed node software choices of major asset managers ahead of the spot Bitcoin ETF approvals. Several custodial wallets relied on outdated forked versions of Bitcoin Core, missing privacy enhancements and known bug fixes. The attack surface increased by a percentage I quantified in a technical brief. That was not a nine-year low. That was a warning. The security industry may be improving, but the clients it serves are still deploying legacy software in a new market.
The Takeaway
Treat the nine-year low as a point estimate, not a risk distribution. The next major hack will write its own headline regardless of what this report claims. The network will survive it. The narrative may not. After the crash, the stack remains, but the credibility of self-interested security reporting will be collateral damage. The question is not whether security is improving. It is whether we are measuring the kind of security that prevents the next collapse or merely the kind that looks good in a press release. The file has not changed. Only the narrative has.