← MoonWire

Crypto glossary

What Is a Crypto Exploit? How Attacks on Code, Keys and Contracts Differ

A crypto exploit is an attack that uses a defect in software - a smart contract, a bridge, a wallet or a chain's own rules - to move assets without the owner's consent. It differs from a scam, which relies on persuading the owner to act.

A crypto exploit is an attack that takes assets by using a defect in code rather than by deceiving a person. The defect can sit almost anywhere in the stack, and where it sits decides who is affected and what can be done afterwards.

The layers an exploit can hit

Why the layer matters more than the headline number

Two incidents of the same dollar size can have very different consequences. A contract flaw is usually patchable, and the protocol can pause, fork or compensate. A flaw in how keys were generated is not patchable for anyone already holding an affected key: a software fix protects keys created after it, and funds sitting behind an older key stay exposed until they are moved.

Exploit, scam and physical attack are not synonyms

An exploit uses a defect in code. A scam persuades the owner to sign or send. A physical attack coerces them. Loss tallies published by research firms combine these categories differently, which is a common reason totals for the same period disagree.

In MoonWire analysis

We track incidents by layer and by what the response revealed — see our comparison of three firms' disagreeing theft counts and the crypto security hub. Related reading: self-custody. A description of an incident is not a security recommendation.

Further reading

Where this appears in MoonWire analysis (2)

Join MoonWire Early Access →

Real-time signal intel — AI-read crypto news, importance-scored and de-noised.

Glossary

Full explanation →