← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] 207 Crypto Hacks in H1 2026, DPRK Takes 66%

Zephyra|July 4, 2026|BPF
EXECUTIVE SUMMARY

Crypto hack incidents hit a record 207 in the first half of 2026, more than doubling the 83 incidents logged in H1 2025, according to TRM Labs data published July 3. Total losses reached $972 million — a figure that, while historically significant, fell below half the $2.3 billion stolen during t...

"Lazarus Group has become especially dangerous. Mach-O Man is a modular malware kit already used beyond Lazarus, and often erases itself before victims realize they have been compromised." — CertiK, Security Disclosure (April 2026)

Executive Summary

Crypto hack incidents hit a record 207 in the first half of 2026, more than doubling the 83 incidents logged in H1 2025, according to TRM Labs data published July 3. Total losses reached $972 million — a figure that, while historically significant, fell below half the $2.3 billion stolen during the same window last year. The paradox — more attacks, less total damage — masks a structural shift in how crypto assets are stolen.

The data shows two distinct threat regimes operating simultaneously. Smart contract exploits accounted for 125 of the 207 incidents but produced relatively small per-incident losses. Infrastructure compromises — private key theft, social engineering, and credential hijacking — made up only 15% of incidents yet drove 76% of total dollar losses. North Korea-linked actors, primarily the Lazarus Group and its subgroups, accounted for approximately $643 million, or 66% of all funds stolen in H1 2026.

The implications for the industry are direct: code audits alone no longer constitute an adequate security posture. The attack surface has migrated from on-chain logic to off-chain operations — human trust, cloud infrastructure, and administrative credentials.

Table of Contents

  1. H1 2026 by the Numbers
  2. The April Catastrophe
  3. Attack Vector Shift: Code to People
  4. North Korea's Industrial-Scale Operation
  5. The Audit Gap
  6. Insurance and Risk Transfer
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

H1 2026 by the Numbers

TRM Labs' H1 2026 report, released July 3, provides the clearest aggregate picture:

| Metric | H1 2026 | H1 2025 | Change | |--------|---------|---------|--------| | Total incidents | 207 | 83 | +149% | | Total losses | $972M | $2.3B | -57% | | Avg. loss per incident | $4.7M | $27.7M | -83% | | DPRK-attributed losses | $643M | ~$1.0B | -36% | | Smart contract exploits | 125 | N/A | — |

Ethereum remained the most-targeted chain, recording 56 incidents. BNB Chain, Base, and Arbitrum followed. Q2 2026 alone saw 85 separate hacks — the most active quarter by incident count on record — with approximately $755.3 million stolen through June 22, according to blockchain security aggregators.

The decline in total dollar losses relative to 2025 is partly explained by the absence of a single mega-hack comparable to the $1.5 billion Bybit exploit of February 2025. Instead, the damage was distributed across a larger number of smaller exploits, punctuated by two $280M+ incidents in April.

The April Catastrophe

April 2026 was the single worst month in DeFi security history by aggregate losses. DeFiLlama tracked more than 30 separate attacks during the month, with total damages reaching approximately $635 million. Two incidents accounted for 95% of the month's losses.

Drift Protocol — $285 million (April 1)

Solana's largest perpetual futures exchange lost over 50% of its TVL in approximately 12 minutes. The attack was the culmination of a six-month social engineering campaign, attributed with medium confidence to UNC4736 (also tracked as AppleJeus/Citrine Sleet/Golden Chollima), a North Korean state-sponsored group.

The operation began in fall 2025 with attackers posing as a quantitative trading firm to build relationships with Drift contributors. They exploited Solana's "durable nonces" feature — which allows transactions to be signed for later execution — to obtain pre-signed, dormant transactions from legitimate Security Council members. On execution day, the attackers whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million CVT, and withdrew $285 million in USDC, SOL, and ETH. On-chain staging began March 11, nearly three weeks before execution.

KelpDAO — $292 million (April 18)

Attackers drained 116,500 rsETH from Kelp's LayerZero-powered bridge. The exploit targeted a configuration weakness: KelpDAO's bridge relied on a 1-of-1 Decentralized Verifier Network (DVN) setup, with LayerZero Labs as the sole verifier. Attackers compromised two RPC nodes that LayerZero's verifier depended on, then flooded backup servers with junk traffic to force verification through compromised channels.

The incident triggered a blame dispute between KelpDAO and LayerZero. LayerZero acknowledged in May that it "made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions." The fallout drove major clients to competitors: Kelp shifted its rsETH bridge to Chainlink, and Solv Protocol moved more than $700 million in tokenized bitcoin infrastructure away from LayerZero.

Both incidents share a common attribute: the smart contracts performed exactly as programmed. The failures were operational — compromised credentials, flawed verification architecture, and manipulated human trust.

Attack Vector Shift: Code to People

An empirical study published in June 2026 estimated that 49.6% of realized crypto losses since 2022 stem from private-key compromise, phishing, and social engineering — not contract logic failures. For 2026 specifically, CoinDesk reported that private key compromises caused approximately 40% of the year's cumulative $16 billion in historical hack losses.

TRM Labs data confirms the structural trend within H1 2026: smart contract exploits were the most common vector (125 of 207 incidents) but produced disproportionately smaller losses. Infrastructure breaches — comprising private key theft, cloud compromise, and credential hijacking — represented only 15% of incidents but generated 76% of total dollar losses.

The pattern reflects improved smart contract security tooling. Automated auditing, formal verification, and bug bounty programs have raised the cost of exploiting on-chain code. Attackers have responded by shifting to the softer target: the humans and cloud systems that control administrative access.

North Korea's Industrial-Scale Operation

North Korea-linked threat groups stole approximately $643 million in H1 2026, accounting for 66% of all crypto theft during the period, according to TRM Labs. The concentration is extreme: two attacks in April — Drift Protocol and KelpDAO — accounted for the majority of DPRK-attributed losses.

Cumulative DPRK crypto theft since 2017 now exceeds $6.7 billion across attributed incidents, according to TRM Labs. The Chainalysis 2026 Crypto Crime Report notes that DPRK-linked hackers stole $2.02 billion in 2025 alone, a 51% year-over-year increase. A UN panel of experts estimates that illicit cyber activity funds approximately 40% of Pyongyang's weapons programs.

The operational sophistication continues to escalate. In April 2026, CertiK disclosed a campaign called "Mach-O Man" — a modular macOS malware kit deployed by Lazarus Group's Chollima division. The attack uses a social engineering technique called ClickFix: targets receive urgent meeting invitations via Telegram for Zoom, Microsoft Teams, or Google Meet calls. When the victim encounters a staged "communication error," they are instructed to paste a terminal command that grants attackers access to corporate and financial systems.

The malware uses native Mach-O binaries tailored for Apple environments prevalent in crypto and fintech firms. It is modular, meaning components can be swapped depending on the target's environment, and it erases itself before detection in many cases, making forensic analysis difficult.

This represents an evolution from earlier DPRK tactics. The Lazarus Group has progressed from placing operatives in remote jobs at crypto firms to orchestrating fake hiring processes, and now to weaponizing routine business communication channels.

The Audit Gap

The security audit market is scaling. The smart contract vulnerability detection AI market was valued at $1.8 billion in 2025 and is projected to reach $9.7 billion by 2034, according to Dataintelo, expanding at a 20.5% CAGR. CertiK reports having audited over 4,200 projects and certified more than $360 billion in on-chain assets. OpenZeppelin's Solidity contracts library is deployed across Aave, Uniswap, Compound, and thousands of other protocols. Halborn claims $1 trillion in secured assets across networks including Polygon and Avalanche.

The problem is structural mismatch. The audit industry is optimized for smart contract logic review. The attack vectors that drive the largest losses — private key management, cloud infrastructure security, insider threat, and social engineering — fall outside the scope of standard contract audits. CryptoDaily reported in June 2026 that the industry faces a "crypto audit gap" where private-key and phishing losses systematically evade the smart contract audit model.

Three of the four largest incidents in H1 2026 did not involve a single line of flawed Solidity. The smart contracts executed exactly as designed. The failures occurred in operational security layers that most audit firms do not evaluate.

Insurance and Risk Transfer

The crypto insurance market was estimated at $9.49 billion in 2025 and is projected to reach $13.75 billion in 2026, according to Grand View Research. Growth is projected at 45.8% CAGR through 2033. Despite this expansion, coverage penetration remains minimal: approximately 1% of the crypto market carries insurance, with premiums typically running 2-5% annually for institutional holders.

The underinsurance creates a direct economic problem. When exploits occur, losses fall almost entirely on depositors and protocol treasuries. The $972 million stolen in H1 2026 generated negligible insurance payouts. DeFi insurance protocols like Nexus Mutual generated over $5.7 million in cover fees in 2025 — a fraction of the losses they would need to cover.

The gap between security spending, insurance coverage, and actual losses indicates that the industry has not yet priced operational risk accurately. Protocols spend on code audits and bug bounties but underinvest in the operational security infrastructure that would address the dominant attack vectors.

Key Takeaways

  • 207 crypto hacks in H1 2026 set a record for incident frequency, more than doubling H1 2025's count of 83, per TRM Labs.
  • $972 million stolen — significant, but 57% below H1 2025's $2.3 billion, largely due to the absence of a Bybit-scale single exploit.
  • North Korea-linked actors took $643 million (66% of total), concentrated in two April incidents against Drift Protocol and KelpDAO.
  • Infrastructure breaches, not code bugs, drive losses. Only 15% of incidents involved infrastructure compromise, but they caused 76% of dollar losses.
  • The audit model has a structural gap. Standard smart contract audits do not cover the operational vectors — key management, credential security, social engineering — that produce the largest exploits.
  • Insurance covers approximately 1% of crypto assets. The $13.75 billion insurance market is growing but remains orders of magnitude below the coverage needed to backstop actual losses.
  • Lazarus Group's tactics are escalating. The "Mach-O Man" campaign represents a new operational tier: modular, self-erasing malware delivered through routine business communication channels.

Conclusion

The H1 2026 data presents a security landscape that has bifurcated. On one track, smart contract security is improving — incidents are more numerous but individually less damaging, suggesting that audits, formal verification, and bug bounties are raising the floor. On the other track, operational security failures continue to produce catastrophic losses, and state-sponsored actors have industrialized the exploitation of human trust and administrative access.

The economic implication is measurable. Protocols that allocate security budgets primarily to code audits are optimizing against the minority of the threat surface. The dominant loss vector — compromised credentials, social engineering, and infrastructure access — requires investment in operational security, key management infrastructure, and personnel security practices that the current audit-centric model does not address.

For the $13.75 billion crypto insurance market, the data suggests a pricing problem. Operational risk is underwritten, if at all, based on code audit completion — a metric that bears limited correlation to actual loss probability. Until underwriting models incorporate operational security posture, the gap between premiums collected and losses incurred will persist.

The concentration of losses in state-sponsored activity — 66% attributable to a single nation-state — raises questions that extend beyond the crypto industry's capacity to self-regulate. When a sovereign actor has industrialized the exploitation of DeFi infrastructure to fund weapons programs, the security problem intersects with national security policy in ways that bug bounties and multisig wallets cannot fully address.

Sources & References

  1. H1 2026 Crypto Hacks Reach Record High — TRM Labs — Primary data source for H1 2026 hack statistics
  2. DeFi Hacks 2026: $840M+ Lost — altfins — Aggregate DeFi exploit tracking and April breakdown
  3. Drift Protocol Hack: Lessons from the $285M Loss — Chainalysis — Drift Protocol exploit forensics and social engineering timeline
  4. North Korean Hackers Attack Drift Protocol — TRM Labs — DPRK attribution and attack methodology
  5. $285 Million Drift Hack Traced to Six-Month Operation — The Hacker News — Social engineering campaign details
  6. Inside the KelpDAO Bridge Exploit — Chainalysis — KelpDAO bridge vulnerability and DVN configuration analysis
  7. LayerZero says it 'made a mistake' — CoinDesk — LayerZero acknowledgment and client migration
  8. Lazarus Group Has Become Especially Dangerous — CoinDesk/CertiK — Mach-O Man malware campaign disclosure
  9. Private Keys Caused 40% of Crypto Losses — CoinDesk — Private key compromise statistics
  10. North Korea Accounts for 76% of 2026 Hack Losses — The Block — DPRK cumulative theft figures
  11. Crypto Insurance Market Report — Grand View Research — Insurance market size and growth projections
  12. 2026 Crypto Crime Report — Chainalysis — Broader crypto crime statistics and illicit flow data
  13. Crypto Audit Gap — CryptoDaily — Analysis of audit model limitations