It seems as if every day we see reports of “smart” (they are not smart) “contracts” (they are not contracts) being hacked, misused and abused for nefarious purposes. This set me wondering. How does the plundering of not-smart not-contracts in the emerging token economy compare to the plundering of fiat currency from banks in the old economy?
When I say not-smart not-contracts are being subverted on a daily basis I am not by any means exaggerating. Here are two such events, chosen at random from a single day when I was writing something about risk recently: Fogo and Avici. An attacker subverted the Fogo token contract to siphon off 4% of Fogo’s “genesis” supply and more than 10% of current circulating supply while the Solana-based crypto card platform Avici, a self-custodial wallet connected to a secured Visa card, suffered a security breach where an attacker drained more than $1 million from user collateral accounts (while using only about $190 in initial capital). The exploit sent the AVICI token down roughly 49% in 24 hours.
Not all are smart contract raids
xxx
Blockstream’s Liquid Network, one of the oldest and most widely used Bitcoin sidechains, lost roughly 4,000 BTC — worth about $320 million — after attackers exploited a software flaw on September 6. The Liquid Network hack drained the federation’s reserves from more than 4,200 BTC down to just around 197 BTC in a matter of hours, instantly ranking among the biggest security incidents to hit Bitcoin-adjacent infrastructure this year.
From: Liquid Network Hack Drains 4,000 BTC in Major Security Breach.
xxx
the flaw sat upstream, in the software that validates transactions before they reach the 11-of-15 signing federation.
Is this crypto-native LLM-powered larceny a genuine replacement for old-school bank robbery or is it just grabbing the headlines in my feeds? Rather than do any useful work, I decided to find some figures. Given the romanticised stories of Bonnie and Clyde and the like, I turned to Depression-era America for the baseline statistic. It turns out that only around one or two bank branches per day were robbed during 1932, the first year that has vaguely reliable statistics.
That didn’t seem too bad to me, given the size of the United States, the number of bank branches and the number of guns and actually, it wasn’t that bad. In fact, when it comes to bank robbery, the Depression was far, far below America’s peak year of 1991, when the FBI recorded 9,388 bank robberies. Since then, the number has fallen considerably, presumably because there are fewer bank branches, because branches have less cash in them and because branch security has continued to improve.
Even so, there were still 1,788 bank robberies in the US in 2020 and I could not help but note that by comparison, in largely cash-free Sweden, there were five bank robberies in 2020 (and only three of these were armed robberies), down from the the 2011 peak of 43.
Rather than rob banks, criminals with a need for cash have shifted to target places outside vaults where cash is more vulnerable. ATMs, for example. There is a plague of ATM robberies in many countries, where criminals will either blow up ATMs or wreck buildings to carry off ATMs whole. Cash-in-Transit (CIT) is another target for cash-hungry criminals and the robberies can be very violent.
(At a conference I attended recently, one presenter showed some particularly graphic security camera footage of armoured cars being blown up on busy streets by criminals with no thought for the lives of the crews or passers-by.)
Bank robbery is a poor career choice. Franky, if you think that robbing banks is the way to a comfortable life then you would be better off going to work for one. Apart from anything else, if you get caught you’ll do a lot less time. In England and Wales, official figures show that people receiving immediate custody for robbery received an average term of about 3 years and 4½ months in 2023, compared with about 1 year and 10½ months for fraud overall.
(The disparity is probably larger for genuinely armed robbery, but official statistics do not isolate either armed robbery or, for that matter, fraud perpetrated specifically by bank employees.)
Blockchain robbery seems like a much better career path than bank robbery. Chainalysis report $3.2 billion stolen from the cryptoverse in 2025. DefiLlama has logged 233 separate incidents so far in 2026, worth roughly $1.31 billion. Over the last decade, DeFi projects and crypto exchanges are estimated to have lost more than $14 billion to hacks and exploits, a figure that is undoubtedly conservative as it does not account for individual wallet hacks (or the secondary damage caused by an erosion of trust across the ecosystem).
Decision Time
So: as an unscrupulous capitalist investor hoping to steal my way to early retirement, should I invest money in bank robbery or smart contract robbery? It’s a no brainer. The rewards for bank robbery are limited and the perpetrators have a high likelihood of getting caught. The FBI no longer records the losses, but in 2019 the average haul was only $4,000-$4,200. Meanwhile,
I asked AI to put some figures to my suspicion and it told me that the average not-smart not-contract vulnerability incident in the Beosin/Alert 2025 dataset was around $9 million, which means by my calculations the typical 2025 blockchain exploit was more than 2,000 times the size of a typical physical bank robbery.
Overall, then, it looks like one of the vocations that will vanish from history under the onslaught of AI, alongside management consulting and hacking (Elon Musk says that AI will be better than people at hacking by the end of next year), is that of the bank robber.