Crypto hack incidents hit a record 207 in the first half of 2026, more than doubling the 83 incidents logged in H1 2025, according to TRM Labs data published July 3. Total losses reached $972 million — a figure that, while historically significant, fell below half the $2.3 billion stolen during t...
"Lazarus Group has become especially dangerous. Mach-O Man is a modular malware kit already used beyond Lazarus, and often erases itself before victims realize they have been compromised." — CertiK, Security Disclosure (April 2026)
Crypto hack incidents hit a record 207 in the first half of 2026, more than doubling the 83 incidents logged in H1 2025, according to TRM Labs data published July 3. Total losses reached $972 million — a figure that, while historically significant, fell below half the $2.3 billion stolen during the same window last year. The paradox — more attacks, less total damage — masks a structural shift in how crypto assets are stolen.
The data shows two distinct threat regimes operating simultaneously. Smart contract exploits accounted for 125 of the 207 incidents but produced relatively small per-incident losses. Infrastructure compromises — private key theft, social engineering, and credential hijacking — made up only 15% of incidents yet drove 76% of total dollar losses. North Korea-linked actors, primarily the Lazarus Group and its subgroups, accounted for approximately $643 million, or 66% of all funds stolen in H1 2026.
The implications for the industry are direct: code audits alone no longer constitute an adequate security posture. The attack surface has migrated from on-chain logic to off-chain operations — human trust, cloud infrastructure, and administrative credentials.
TRM Labs' H1 2026 report, released July 3, provides the clearest aggregate picture:
| Metric | H1 2026 | H1 2025 | Change | |--------|---------|---------|--------| | Total incidents | 207 | 83 | +149% | | Total losses | $972M | $2.3B | -57% | | Avg. loss per incident | $4.7M | $27.7M | -83% | | DPRK-attributed losses | $643M | ~$1.0B | -36% | | Smart contract exploits | 125 | N/A | — |
Ethereum remained the most-targeted chain, recording 56 incidents. BNB Chain, Base, and Arbitrum followed. Q2 2026 alone saw 85 separate hacks — the most active quarter by incident count on record — with approximately $755.3 million stolen through June 22, according to blockchain security aggregators.
The decline in total dollar losses relative to 2025 is partly explained by the absence of a single mega-hack comparable to the $1.5 billion Bybit exploit of February 2025. Instead, the damage was distributed across a larger number of smaller exploits, punctuated by two $280M+ incidents in April.
April 2026 was the single worst month in DeFi security history by aggregate losses. DeFiLlama tracked more than 30 separate attacks during the month, with total damages reaching approximately $635 million. Two incidents accounted for 95% of the month's losses.
Drift Protocol — $285 million (April 1)
Solana's largest perpetual futures exchange lost over 50% of its TVL in approximately 12 minutes. The attack was the culmination of a six-month social engineering campaign, attributed with medium confidence to UNC4736 (also tracked as AppleJeus/Citrine Sleet/Golden Chollima), a North Korean state-sponsored group.
The operation began in fall 2025 with attackers posing as a quantitative trading firm to build relationships with Drift contributors. They exploited Solana's "durable nonces" feature — which allows transactions to be signed for later execution — to obtain pre-signed, dormant transactions from legitimate Security Council members. On execution day, the attackers whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million CVT, and withdrew $285 million in USDC, SOL, and ETH. On-chain staging began March 11, nearly three weeks before execution.
KelpDAO — $292 million (April 18)
Attackers drained 116,500 rsETH from Kelp's LayerZero-powered bridge. The exploit targeted a configuration weakness: KelpDAO's bridge relied on a 1-of-1 Decentralized Verifier Network (DVN) setup, with LayerZero Labs as the sole verifier. Attackers compromised two RPC nodes that LayerZero's verifier depended on, then flooded backup servers with junk traffic to force verification through compromised channels.
The incident triggered a blame dispute between KelpDAO and LayerZero. LayerZero acknowledged in May that it "made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions." The fallout drove major clients to competitors: Kelp shifted its rsETH bridge to Chainlink, and Solv Protocol moved more than $700 million in tokenized bitcoin infrastructure away from LayerZero.
Both incidents share a common attribute: the smart contracts performed exactly as programmed. The failures were operational — compromised credentials, flawed verification architecture, and manipulated human trust.
An empirical study published in June 2026 estimated that 49.6% of realized crypto losses since 2022 stem from private-key compromise, phishing, and social engineering — not contract logic failures. For 2026 specifically, CoinDesk reported that private key compromises caused approximately 40% of the year's cumulative $16 billion in historical hack losses.
TRM Labs data confirms the structural trend within H1 2026: smart contract exploits were the most common vector (125 of 207 incidents) but produced disproportionately smaller losses. Infrastructure breaches — comprising private key theft, cloud compromise, and credential hijacking — represented only 15% of incidents but generated 76% of total dollar losses.
The pattern reflects improved smart contract security tooling. Automated auditing, formal verification, and bug bounty programs have raised the cost of exploiting on-chain code. Attackers have responded by shifting to the softer target: the humans and cloud systems that control administrative access.
North Korea-linked threat groups stole approximately $643 million in H1 2026, accounting for 66% of all crypto theft during the period, according to TRM Labs. The concentration is extreme: two attacks in April — Drift Protocol and KelpDAO — accounted for the majority of DPRK-attributed losses.
Cumulative DPRK crypto theft since 2017 now exceeds $6.7 billion across attributed incidents, according to TRM Labs. The Chainalysis 2026 Crypto Crime Report notes that DPRK-linked hackers stole $2.02 billion in 2025 alone, a 51% year-over-year increase. A UN panel of experts estimates that illicit cyber activity funds approximately 40% of Pyongyang's weapons programs.
The operational sophistication continues to escalate. In April 2026, CertiK disclosed a campaign called "Mach-O Man" — a modular macOS malware kit deployed by Lazarus Group's Chollima division. The attack uses a social engineering technique called ClickFix: targets receive urgent meeting invitations via Telegram for Zoom, Microsoft Teams, or Google Meet calls. When the victim encounters a staged "communication error," they are instructed to paste a terminal command that grants attackers access to corporate and financial systems.
The malware uses native Mach-O binaries tailored for Apple environments prevalent in crypto and fintech firms. It is modular, meaning components can be swapped depending on the target's environment, and it erases itself before detection in many cases, making forensic analysis difficult.
This represents an evolution from earlier DPRK tactics. The Lazarus Group has progressed from placing operatives in remote jobs at crypto firms to orchestrating fake hiring processes, and now to weaponizing routine business communication channels.
The security audit market is scaling. The smart contract vulnerability detection AI market was valued at $1.8 billion in 2025 and is projected to reach $9.7 billion by 2034, according to Dataintelo, expanding at a 20.5% CAGR. CertiK reports having audited over 4,200 projects and certified more than $360 billion in on-chain assets. OpenZeppelin's Solidity contracts library is deployed across Aave, Uniswap, Compound, and thousands of other protocols. Halborn claims $1 trillion in secured assets across networks including Polygon and Avalanche.
The problem is structural mismatch. The audit industry is optimized for smart contract logic review. The attack vectors that drive the largest losses — private key management, cloud infrastructure security, insider threat, and social engineering — fall outside the scope of standard contract audits. CryptoDaily reported in June 2026 that the industry faces a "crypto audit gap" where private-key and phishing losses systematically evade the smart contract audit model.
Three of the four largest incidents in H1 2026 did not involve a single line of flawed Solidity. The smart contracts executed exactly as designed. The failures occurred in operational security layers that most audit firms do not evaluate.
The crypto insurance market was estimated at $9.49 billion in 2025 and is projected to reach $13.75 billion in 2026, according to Grand View Research. Growth is projected at 45.8% CAGR through 2033. Despite this expansion, coverage penetration remains minimal: approximately 1% of the crypto market carries insurance, with premiums typically running 2-5% annually for institutional holders.
The underinsurance creates a direct economic problem. When exploits occur, losses fall almost entirely on depositors and protocol treasuries. The $972 million stolen in H1 2026 generated negligible insurance payouts. DeFi insurance protocols like Nexus Mutual generated over $5.7 million in cover fees in 2025 — a fraction of the losses they would need to cover.
The gap between security spending, insurance coverage, and actual losses indicates that the industry has not yet priced operational risk accurately. Protocols spend on code audits and bug bounties but underinvest in the operational security infrastructure that would address the dominant attack vectors.
The H1 2026 data presents a security landscape that has bifurcated. On one track, smart contract security is improving — incidents are more numerous but individually less damaging, suggesting that audits, formal verification, and bug bounties are raising the floor. On the other track, operational security failures continue to produce catastrophic losses, and state-sponsored actors have industrialized the exploitation of human trust and administrative access.
The economic implication is measurable. Protocols that allocate security budgets primarily to code audits are optimizing against the minority of the threat surface. The dominant loss vector — compromised credentials, social engineering, and infrastructure access — requires investment in operational security, key management infrastructure, and personnel security practices that the current audit-centric model does not address.
For the $13.75 billion crypto insurance market, the data suggests a pricing problem. Operational risk is underwritten, if at all, based on code audit completion — a metric that bears limited correlation to actual loss probability. Until underwriting models incorporate operational security posture, the gap between premiums collected and losses incurred will persist.
The concentration of losses in state-sponsored activity — 66% attributable to a single nation-state — raises questions that extend beyond the crypto industry's capacity to self-regulate. When a sovereign actor has industrialized the exploitation of DeFi infrastructure to fund weapons programs, the security problem intersects with national security policy in ways that bug bounties and multisig wallets cannot fully address.