The crypto industry has spent years obsessing over smart contract exploits. Sun Raghupathi, CEO of onchain vault infrastructure provider Veda, thinks it’s time to update the threat model. In his view, the biggest risk facing onchain vaults today isn’t a rogue line of Solidity. It’s who holds the keys.
Raghupathi’s argument is straightforward: as smart contract code matures and gets battle-tested through repeated audits and real-world usage, the attack surface shifts. The weakest link is increasingly the humans and processes managing access controls, not the contracts themselves.
From code exploits to operational failures
But Raghupathi is pointing to a different pattern. Several high-profile incidents in recent memory didn’t involve exploiting a vulnerability in a protocol’s smart contracts at all. They involved compromised private keys, insider threats, or sloppy operational security that gave attackers a backdoor into systems that were technically sound.
Veda, founded in 2024, has routed more than $16 billion through its vault infrastructure without a reported security incident on its smart contracts.








