In 2026, compromised keys overtook smart contract bugs as the leading cause of DeFi losses, the first time that has happened on record. This episode is about what that changes for teams shipping onchain.
Andrés runs security at Hashlock. He joins dOrg Hot Seat to walk through what a smart contract audit does and doesn't cover, why one exploit rarely stays contained to a single protocol, and the attack surface almost nobody prices in: private keys left behind in repositories that later go public. He watched that one mistake cost around $1M, then watched it happen again.
We also get into the three questions he says every audit should answer, what a human reviewer adds that automated tooling can't, where an auditor's responsibility ends, and his unfiltered take on vendors selling AI security.
Hashlock's free AI audit tool (Solidity + Solana Rust): aiaudit.hashlock.com
Where to find Hashlock ABOUT dOrg dOrg is a Web3 and AI development agency. We build protocols, onchain applications and agent infrastructure for teams shipping in production.
Website: dorg.tech
X: @dOrg_tech
GUEST Andrés Altuve - Hashlock hashlock.com
#SmartContractSecurity #web3security #defi #auditready