← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] DeFi Loses $942M in H1 as Attack Vectors Shift

Zephyra|July 18, 2026|BPF
EXECUTIVE SUMMARY

DeFi protocols have lost $942 million across 121 separate exploits in the first half of 2026, according to TRM Labs data. Q2 alone produced 85 incidents and approximately $775 million in losses — the highest quarterly total on record. Two April attacks, Drift Protocol ($285 million) and KelpDAO (...

"The root cause was the protocol's 1-of-1 verifier configuration, where only a single node was responsible for checking messages before releasing funds." — Chainalysis, KelpDAO Bridge Exploit Analysis (April 2026)

Executive Summary

DeFi protocols have lost $942 million across 121 separate exploits in the first half of 2026, according to TRM Labs data. Q2 alone produced 85 incidents and approximately $775 million in losses — the highest quarterly total on record. Two April attacks, Drift Protocol ($285 million) and KelpDAO ($293 million), accounted for more than 60% of year-to-date losses. Both were attributed by TRM Labs to North Korea's Lazarus Group.

The damage extends beyond stolen funds. DeFi total value locked has fallen 39% year-to-date, from $115 billion in January to approximately $70 billion by late June, according to DeFiLlama. Ethereum TVL specifically declined 43% to $38.91 billion. The proximate causes are a combination of market drawdown — Bitcoin has dropped more than 50% from its October 2025 all-time high near $126,000 — and a sustained loss of depositor confidence driven by the exploit wave.

This report examines the attack vectors, the protocols hit, the state actors involved, and the structural weaknesses in DeFi architecture that have made 2026 the costliest year for protocol-level security failures since 2022.

Table of Contents

  1. H1 2026 by the Numbers
  2. The Big Two: Drift and KelpDAO
  3. Attack Vector Taxonomy
  4. The July Cluster: Four Protocols in Eleven Days
  5. State Actor Attribution
  6. TVL and Depositor Confidence
  7. Insurance and Recovery
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

H1 2026 by the Numbers

| Metric | H1 2026 | H1 2025 | Change | |--------|---------|---------|--------| | Total incidents | 121 | ~71 | +70% YoY | | Total losses | $942M | $2.3B* | -59% | | Q2 incidents | 85 | — | Record quarter | | Q2 losses | $775M | — | Record quarter | | Largest single exploit | $293M (KelpDAO) | $1.5B (Bybit) | — | | DPRK-attributed share | 66% ($643M) | ~87% | — |

*H1 2025 figure includes the $1.5 billion Bybit exploit, which inflated the total.

The incident count is rising sharply: 121 exploits in H1 2026 versus approximately 71 in the same period of 2025, per TRM Labs. The per-incident average has dropped — from $32 million in H1 2025 to $7.8 million in H1 2026 — but only because 2025 was distorted by the Bybit outlier. Excluding Bybit, H1 2025 produced roughly $800 million in losses across 70 incidents, making 2026 approximately 18% worse on a like-for-like basis.

The Big Two: Drift and KelpDAO

Drift Protocol — $285 Million (April 1, 2026)

Drift, Solana's largest perpetual-futures DEX at the time, lost over 50% of its TVL in roughly 12 minutes. The attack was not a smart contract exploit in the traditional sense. According to Chainalysis, the attackers spent months building relationships with Drift team members through social engineering. They leveraged Solana's "durable nonces" feature to obtain pre-signed transactions from Drift Security Council members, eventually gaining admin control.

Once in control, the attackers whitelisted a fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH. On-chain staging began on March 11 — three weeks before execution. Drift's TVL fell from approximately $550 million to under $300 million within an hour. The DRIFT token dropped more than 40%.

KelpDAO — $293 Million (April 19, 2026)

KelpDAO's liquid restaking protocol lost approximately 116,500 rsETH through its LayerZero bridge contract. The root cause, identified by Chainalysis, was a 1-of-1 Decentralized Verifier Network (DVN) configuration: only a single node validated cross-chain messages before releasing funds. The attackers compromised internal RPC nodes and DDoS'd external nodes to feed false data to the lone verifier.

The contagion spread across at least nine protocols. Aave, SparkLend, and others froze rsETH markets. Wrapped ether was stranded across 20 chains.

Attack Vector Taxonomy

The 2026 exploit landscape has shifted materially from prior years. Traditional reentrancy bugs and arithmetic overflows — the dominant vectors from 2020-2023 — now represent a minority of losses. The primary vectors in 2026:

1. Off-Chain Infrastructure Compromise Compromised RPC nodes, social engineering of key holders, and misconfigured verifier networks accounted for more losses in April 2026 alone than traditional reentrancy or flash loan attacks. The Drift attack is the canonical example: no smart contract vulnerability was exploited. The protocol's code was intact. The humans operating it were not.

2. Bridge Exploits Cross-chain bridges have produced more than $2.8 billion in cumulative losses since 2022, approximately 40% of all value ever hacked in Web3. KelpDAO's single-verifier bridge configuration was a structural failure. In February 2026, CrossCurve lost funds via weak access controls in its Axelar-based bridge contract.

3. Flash Loan and Price Manipulation Flash loan attacks remain the most frequent exploit type by incident count, though individual losses tend to be smaller. Makina Finance lost $5.1 million in January 2026 via a flash-loan exploit using a $280 million USDC loan to manipulate a Curve pool oracle. Summer.fi lost $6 million in July when an attacker used a $65.4 million Morpho flash loan to manipulate vault accounting across Curve, Uniswap, and Balancer.

4. Supply Chain and Frontend Attacks Polymarket lost $3.1 million in June 2026 when attackers compromised a third-party vendor and injected malicious JavaScript into the platform's frontend, tricking users into signing transactions that drained their wallets. This marked the prediction market platform's third security event in under a year.

5. Legacy Code Exploitation Raydium, Solana's largest DEX, lost $1.34 million in June when attackers exploited deprecated AMM V3 pools that lacked proper LP mint address validation. The vulnerability existed in code that had been superseded but not decommissioned.

The July Cluster: Four Protocols in Eleven Days

Between July 6 and July 17, four separate protocols were exploited in rapid succession:

| Date | Protocol | Loss | Vector | |------|----------|------|--------| | July 6 | Summer.fi | $6M | Flash loan vault manipulation | | July 16 | Cascade | $1.34M | CLS vault exploit (locked funds) | | July 16 | DeFiTuna | $580K | Lending pool exploit | | July 17 | Across Protocol | Undisclosed | Solana spoke pool attack |

Summer.fi (July 6): An attacker borrowed $65.4 million from Morpho and routed funds through Curve, Uniswap, and Balancer to inflate vault share prices in the Lazy Summer Protocol. The protocol's SUMR token fell 18%. TVL before the exploit was $22 million, according to DeFiLlama. Emergency measures suspended all affected vault operations.

Cascade (July 16): The Polychain and Variant-backed perpetuals platform lost 1.34 million USDC from its CLS vault. Funds were bridged from Arbitrum to Solana to Ethereum via Relay Protocol and converted to DAI. The exploited vault held deposits from an invite-only campaign — users had no withdrawal access prior to the attack.

DeFiTuna (July 16): The Solana-native AMM confirmed a $580,000 attack on its USDC lending pool, identified approximately seven hours after the exploit. The attack vector has not been fully detailed. The USDC pool was left with a $580,000 deficit.

Across Protocol (July 17): The cross-chain bridge suffered its first publicly disclosed attack since launching in 2021, after processing $34 billion in bridge volume with zero prior incidents. The attack targeted the Solana spoke pool, built on the Anchor framework. User funds were reportedly unaffected; Risk Labs' operating funds may have been impacted. In April 2026, security firm Asymmetric Research had disclosed a vulnerability in exactly this Solana component, related to Solana's lack of a canonical event system.

State Actor Attribution

North Korea's Lazarus Group — tracked by the FBI as "TraderTraitor" — accounted for 66% of all stolen crypto funds in H1 2026, or approximately $643 million, according to TRM Labs. With just two major attacks (Drift and KelpDAO), DPRK-linked actors captured 76% of all crypto hack value through April.

The operational pattern has evolved. The Drift attack required months of social engineering and three weeks of on-chain staging — a significant departure from the smash-and-grab approach of earlier DPRK operations. DPRK-linked actors have stolen a cumulative $6.75 billion in cryptocurrency, per TRM Labs, with $2.02 billion in 2025 alone (a 51% year-on-year increase) before adding 2026 figures.

Impersonation scams — a Lazarus specialty — surged 1,400% year-over-year in 2026, according to Thirdweb data, making social engineering one of the fastest-growing crypto threat vectors.

TVL and Depositor Confidence

The relationship between exploit volume and TVL outflows is difficult to isolate from broader market conditions, but the direction is clear:

  • DeFi TVL peaked at $127.75 billion on January 18, 2026
  • By June 18, it stood at $71.77 billion (DeFiLlama) — a 43.8% decline
  • Ethereum TVL fell from ~$68 billion to $38.91 billion (43% decline)
  • Thirty-day decline through June 18: 11.8%

Bitcoin's 50%+ drawdown from its October 2025 peak compresses collateral values mechanically. But the exploit wave compounds the effect. When $293 million exits KelpDAO and contagion freezes rsETH markets across nine protocols, the trust cost extends beyond the immediate losses. Depositors face a rational question: does the yield compensate for the tail risk?

There is countervailing data. Aave's V3 deployment on Monad attracted $100 million in deposits within 48 hours of launching in early July, with the Monad Foundation committing $15 million in first-year incentives. Aave's V4 crossed $250 million in deposits the same weekend. Capital continues to flow into DeFi — but it is flowing selectively, toward protocols with multi-year track records and institutional-grade governance structures.

Insurance and Recovery

DeFi insurance remains structurally undersized relative to the risk. Nexus Mutual, the sector's largest decentralized insurance provider, has paid out $18.5 million across all historical claims — less than 2% of 2026 losses alone. The protocol generated $5.7 million in cover fees in 2025 and manages over $5.75 billion in protected assets across 10,000+ policies.

The coverage gap is significant. Standard DeFi insurance explicitly excludes phishing, loss of private keys, malware, and social engineering — the exact vectors that produced the two largest exploits of 2026. A protocol whose admin keys are compromised through social engineering receives no payout.

Recovery rates vary. Raydium pledged full restitution from its treasury for the $1.34 million exploit. Polymarket committed to refunding $3.1 million to affected users. Drift and KelpDAO, with losses exceeding $285 million each, have not outlined comprehensive restitution plans.

The smart contract audit market, with individual audits ranging from $15,000 to $500,000, is increasingly viewed as necessary but insufficient. The Drift exploit bypassed all code-level protections. The industry is moving toward audit-backed coverage models, where security firms couple reviews with capital reserves, but adoption remains early-stage.

Key Takeaways

  • $942 million lost across 121 DeFi exploits in H1 2026. Incident count up 70% year-over-year; Q2's 85 incidents and $775 million in losses set records.

  • Attack vectors have shifted. Off-chain infrastructure compromise and social engineering now produce larger losses than traditional smart contract bugs. The Drift exploit involved zero code vulnerabilities.

  • North Korea accounted for 66% of stolen funds. Two attacks (Drift, KelpDAO) captured 76% of all hack value through April, with DPRK cumulative lifetime theft at $6.75 billion.

  • DeFi TVL declined 39% year-to-date to ~$70 billion. Market drawdown and exploit-driven confidence erosion are mutually reinforcing.

  • Insurance covers less than 2% of losses. Standard policies exclude social engineering and key compromise — the dominant 2026 vectors.

  • Capital is concentrating. New deposits favor protocols with established track records (Aave) while smaller and newer protocols face disproportionate risk.

Conclusion

The H1 2026 exploit data reveals a structural mismatch. DeFi protocols have hardened their smart contract code — reentrancy and arithmetic bugs are increasingly rare. But the attack surface has expanded to encompass off-chain infrastructure, human operators, bridge verification networks, and frontend supply chains. The two largest exploits of the year bypassed code-level protections entirely.

The economic value at stake is significant. With $70 billion in TVL and $942 million in losses, the annualized loss rate exceeds 2.5% of locked capital — a drag that compresses net yields and concentrates capital in a shrinking set of protocols perceived as safer. For DeFi to function as infrastructure rather than a high-risk yield experiment, the security model must extend beyond code audits to encompass operational security, multi-party verification, and insurance products that actually cover the dominant attack vectors of 2026.

Sources & References

  1. TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026 — Attribution data and H1 2026 statistics
  2. Chainalysis: Drift Protocol Hack Analysis — Attack methodology and privileged access analysis
  3. Chainalysis: Inside the KelpDAO Bridge Exploit — 1-of-1 DVN configuration analysis
  4. CoinDesk: KelpDAO Hack Shows Why DeFi Is Being Forced to Grow Up — KelpDAO contagion and rsETH market freezes
  5. CoinDesk: Summer.fi Halts Lazy Summer Vaults After $6M Exploit — Flash loan vault manipulation details
  6. CoinDesk: Polymarket Hack Updated to $3.1 Million — Frontend supply chain attack
  7. Bloomberg: Drift DeFi Project on Solana Suffers $285 Million Exploit — Drift Protocol exploit reporting
  8. CryptoTimes: Across Protocol Reports First Attack on Solana — Bridge security incident
  9. CryptoTimes: DeFiTuna Hit by $580K Exploit — Solana lending pool exploit
  10. CryptoTimes: Cascade Hacked for $1.34M — Locked user fund exploit
  11. Yahoo Finance: DeFi TVL Slides Every Month in 2026 — TVL decline statistics
  12. Decrypt: Solana Exchange Raydium Hit With $1.34M Exploit — Legacy code exploitation
  13. Thirdweb: DeFi Security Crisis 2026 — Attack vector taxonomy and statistics
  14. Altfins: DeFi Hacks 2026: $840M+ Lost — Quarterly breakdown and incident data
  15. CryptoBriefing: North Korea-linked Hackers Steal $643M in H1 2026 — DPRK attribution data