A June preprint compared 23,818 audit findings against 218 real exploits worth $7.76 billion and found private-key theft and phishing accounted for 43.9% of stolen value, almost all of it outside what a smart-contract review is hired to examine.