The cryptocurrency industry recorded its highest-ever six-month incident count in the first half of 2026. Immunefi tracked 207 separate hack events totaling $972 million in losses. Blockaid's independent tally put the figure at 212 incidents and $1.1 billion. CertiK, using a broader methodology t...
"We made a mistake. The 1-of-1 DVN configuration directly contradicted our standing recommendation." — Bryan Pellegrino, CEO, LayerZero Labs
The cryptocurrency industry recorded its highest-ever six-month incident count in the first half of 2026. Immunefi tracked 207 separate hack events totaling $972 million in losses. Blockaid's independent tally put the figure at 212 incidents and $1.1 billion. CertiK, using a broader methodology that includes phishing, logged $1.32 billion across 344 incidents — a 46.8% decline year-over-year in dollar terms, but only because H1 2025 was inflated by the $1.5 billion Bybit hack. Remove that single outlier, and H1 2026 losses were approximately 28% higher than the comparable period.
Two North Korean operations — the $292 million KelpDAO bridge exploit on April 18 and the $285 million Drift Protocol governance hijack on April 1 — accounted for more than 70% of Q2 losses. TRM Labs estimated DPRK-linked groups stole $643 million in H1 2026, representing 66% of all funds stolen. The attack surface has shifted decisively: compromised accounts and social engineering now cause more damage than smart contract bugs, and AI-agent infrastructure is emerging as the next exploit frontier.
Three independent security firms published H1 2026 retrospectives in late July, each using different methodologies. Their findings converge on a single conclusion: more attacks, more often.
| Metric | Immunefi | Blockaid | CertiK | |--------|---------|---------|--------| | Incidents | 207 | 212 | 344 | | Total Losses | $972M | $1.1B | $1.32B | | YoY Change (Losses) | -57% | N/A | -46.8% | | Record? | Highest incident count ever | Most incidents in any H1 | Most-hacked quarter (Q2) |
The discrepancies reflect scope: Immunefi covers protocol exploits and bridge hacks; Blockaid adds wallet-level attacks; CertiK includes phishing campaigns. What all three confirm is that H1 2026 set the highest-ever six-month incident count, regardless of methodology.
CertiK's quarterly breakdown shows acceleration. Q1 recorded $508.2 million in losses, driven primarily by phishing. Q2 surged 59% to $807.5 million, with two state-sponsored attacks responsible for the bulk. Q2 2026 logged 83 separate exploits through June 22, making it the most attack-heavy quarter on record by incident count.
The longer trend line offers limited comfort. DeFi exploit losses have fallen 74% from the 2022 peak of $2.62 billion to $680.3 million, according to Immunefi. But median loss per exploit also dropped 75% over the same period — meaning attackers are launching far more operations at smaller individual scale, a pattern consistent with industrialized, state-backed campaigns rather than opportunistic lone actors.
The largest single exploit of 2026 did not involve a smart contract vulnerability. On April 18, attackers drained 116,500 rsETH from KelpDAO's bridge, built on LayerZero's cross-chain messaging protocol.
The attack chain began on March 6, when an attacker socially engineered a LayerZero Labs developer, harvesting session keys and pivoting into LayerZero's RPC cloud environment. From there, the attacker poisoned internal RPC nodes while simultaneously DDoS-ing external nodes. This fed false data into what KelpDAO had configured as a 1-of-1 DVN (Decentralized Verifier Network) setup — a single-point-of-failure verification architecture. A phantom token burn convinced the Ethereum-side contract to release the rsETH.
LayerZero Labs acknowledged the flaw, stating the 1-of-1 DVN configuration "directly contradicted" its recommendation for diversified multi-DVN setups. The company subsequently committed to migrating all defaults to 5/5 DVN where possible and no less than 3/3. Mandiant, CrowdStrike, and independent researchers attributed the attack to TraderTraitor (UNC4899), a known Lazarus Group subunit.
The second-largest exploit of 2026 was a months-long social engineering campaign targeting Drift Protocol, a Solana-based perpetuals DEX. Attackers spent months building relationships with the Drift team, then exploited Solana's "durable nonces" feature to get Drift Security Council members to unknowingly pre-sign transactions that transferred admin control.
Once in possession of governance keys, the attackers whitelisted a worthless, artificially priced fake token (CVT) as collateral, deposited 500 million CVT, and withdrew $285 million in USDC, SOL, and ETH — all within approximately 12 minutes. TRM Labs attributes the attack to North Korean operators tied to the Lazarus Group. Elliptic logged it as the 18th DPRK-linked operation of 2026.
Cross-chain bridges remain the most expensive single category of DeFi failure. PeckShield data through mid-May 2026 documented eight significant bridge-related incidents resulting in cumulative losses of approximately $329 million. Bridges accounted for 42% of May losses alone.
Historically, bridge exploits have produced more than $2.8 billion in cumulative losses since 2022, representing roughly 40% of all value hacked in Web3, according to multiple security firms.
The Verus-Ethereum Bridge illustrated the persistent nature of bridge vulnerabilities. On May 18, an attacker drained approximately $11.58 million — 1,625 ETH, 103.6 tBTC, and 147,000 USDC — by exploiting a validation flaw where the bridge verified state roots and transaction hashes but failed to confirm actual backing asset amounts during settlement. The attacker swapped stolen assets for 5,402.4 ETH and routed funds through Tornado Cash. Security researchers noted the exploit resembled the same verification flaw class behind the 2022 Wormhole and Nomad bridge attacks.
The Verus bridge was then hit a second time on July 23 for $7.54 million, with the original flaw still unfixed.
The institutional response is consolidating around fewer, more audited infrastructure providers. On August 4, BitGo announced it selected Chainlink CCIP as its exclusive cross-chain infrastructure provider, covering more than $7.7 billion of Wrapped Bitcoin. Chainlink Labs completed a SOC 2 Type 2 examination by Deloitte & Touche LLP in April, validating the operating effectiveness of CCIP's security controls — making it the only oracle platform to hold this certification tier. CCIP's architecture includes 16 independent validator nodes and built-in rate-limit protections.
North Korean state-sponsored hackers have become the dominant threat actor in cryptocurrency security. TRM Labs reported DPRK-linked groups stole $643 million in H1 2026 — 66% of all cryptocurrency stolen during the period. In the first four months alone, DPRK accounted for 76% of all hack value, concentrated in just two operations (KelpDAO and Drift).
The scale is cumulative and accelerating. DPRK-linked actors stole $2.02 billion in 2025, a 51% year-on-year increase, pushing their all-time cumulative total to $6.75 billion since 2017, according to Chainalysis and TRM Labs. Proceeds are funneled toward the regime's nuclear weapons program.
The operational pattern has evolved. Where earlier campaigns targeted exchange hot wallets through malware, 2025-2026 operations increasingly rely on long-duration social engineering, governance manipulation, and infrastructure-level compromise. Both the KelpDAO and Drift attacks required months of preparation and targeted human relationships rather than code vulnerabilities.
A structural shift in attack methodology is now statistically confirmed. Compromised accounts now represent more than 50% of all DeFi attacks by incident count, overtaking traditional smart contract exploits as the primary source of losses for the first time, according to multiple H1 reports.
CoinDesk's analysis of 2025 data — $3.4 billion stolen that year — concluded it "wasn't a smart contract problem. It was a people problem." That assessment extends into 2026. Wallet compromise is now the costliest attack vector, with attackers targeting key management, multisig governance, and operational security failures rather than on-chain logic.
The attack taxonomy is shifting accordingly:
Blockaid's H1 report identified AI agent exploits as a primary threat category for H2 2026. AI agent deployments are growing roughly tenfold per year, and Blockaid expects multiple AI agent incidents with prompt injection attacks leading.
UC Berkeley researchers documented malicious AI API routers actively draining ETH wallets and injecting code into autonomous agent tools. The attack targets the routing layer between AI agents and language models — infrastructure that currently operates without meaningful security standardization.
SlowMist classified a major 2026 incident as "AI agent permission chain abuse," a category where one AI system's output is treated as trusted financial authorization by a second AI system with no independent verification of intent or source. On May 10, the first fully autonomous post-exploitation attack orchestrated by an LLM-driven agent was documented: the agent fanned out API requests through Cloudflare Workers, exfiltrated SSH private keys, pivoted to bastion servers, and enumerated SQL databases within one hour.
A 2026 Dark Reading poll found 48% of security professionals rank agentic AI as the top attack vector for the year.
Recovery rates for stolen crypto remain structurally low for large-scale incidents. CertiK's H1 data shows $1.32 billion in gross losses and approximately $1.2 billion net after recoveries — implying roughly 9% recovery across all incidents. For individual large hacks, the picture is worse: Bybit's recovery rate sat below 5% as of early 2026.
Smaller incidents fare better. The Verus incident saw $8.5 million returned. Stellar Blend validators quarantined $7.3 million, approximately 73% of the $10.2 million stolen. A white hat working with BTCC recovered $1.8 million (78% recovery rate). But these are exceptions.
The insurance gap is significant. Nexus Mutual, the largest onchain insurance provider, reports $5.2 billion in crypto assets safeguarded and $18 million in total claims paid out — across the platform's entire history. DeFi insurance covers smart contract failures, custody events, and depeg scenarios, but excludes phishing, user error, and social engineering — precisely the attack categories now causing the most damage.
The mismatch between insured risk and actual risk is growing. If 50%+ of losses stem from compromised accounts and social engineering, and insurance policies explicitly exclude these categories, the effective coverage ratio for the industry's actual threat profile is near zero for the dominant attack vector.
The first half of 2026 confirms a structural transformation in cryptocurrency security risk. The threat is no longer primarily technical — it is operational, organizational, and increasingly state-sponsored. North Korea's Lazarus Group and its subunits have industrialized crypto theft, running patient, months-long campaigns that target people and governance structures rather than smart contract code.
The industry's defensive infrastructure has not kept pace with this shift. Bridge architectures still concentrate verification in single points of failure. Governance structures remain vulnerable to social engineering. Insurance products exclude the attack categories now responsible for the majority of losses. And AI agent infrastructure is being deployed at scale without standardized security frameworks.
The data suggests a divergence: individual protocol security is improving (per-exploit losses down 75% from 2022), but systemic risk from state-sponsored actors and infrastructure-level compromise is increasing. The $643 million attributed to DPRK in six months represents a geopolitical problem that smart contract audits alone cannot address.