
What happened
BlockSec Research links seven out of ten major hacks occurring outside smart contracts to the need for broader testing and points to regulatory expectations.
Why it matters
The material links most of the major hacks from the stated sample to areas outside smart contracts and points to regulatory expectations for broader testing.
BlockSec Research reports that seven out of ten major hacks in the crypto industry occurred outside of smart contracts. On this basis, the authors consider blockchain infrastructure testing as a distinct need for crypto organizations.
According to BlockSec Research, NYDFS, DORA, VARA, SFC, and MAS require or expect such testing to be conducted. The source associates auditing practices with increased regulatory attention to organizational security.
The significance of the material is limited by available data: it is a brief editorial summary rather than the full research text, and independent confirmation is absent. It remains unclear which specific incidents are included in the top ten and how the requirements of the listed regulators differ.
Confirmed facts
- BlockSec Research published a material on blockchain infrastructure testing for crypto organizations.
- The BlockSec Research summary states that seven out of ten major hacks occurred outside smart contracts.
- The BlockSec Research summary claims that NYDFS, DORA, VARA, SFC, and MAS require or expect such testing to be conducted.
- The only provided source has a metadata_only status and is not accompanied by independent confirmation.
Context
The source was published by BlockSec Research; only a metadata summary of the material from 2 September 2026 is available.
What remains unknown
- Which specific ten hacks were included in the indicated sample?
- What exactly does the phrasing "outside smart contracts" mean for each incident?
- What specific requirements or expectations regarding testing have been established by NYDFS, DORA, VARA, SFC, and MAS?
- Are there independent sources confirming the cited ratio and regulatory assertions?
Editorial context
Confidence: medium
Likely consequence: Crypto organizations will have to pay more attention to verifying components beyond smart contracts if the outlined approach becomes entrenched in regulatory practice. The next observable signal would be the publication of specific requirements or methodologies by the listed regulators. Significant uncertainty remains due to the lack of the full text and independent verification of the claims.