The crypto industry recorded 207 hack incidents in H1 2026, the highest six-month count ever logged, according to TRM Labs. Losses totaled $972 million — a 57% decline from H1 2025 — creating an apparent paradox: attacks are multiplying while individual payouts shrink. The paradox dissolves on cl...
"Neither attack required finding a vulnerability in any smart contract. Both required finding the humans who could authorize the transactions — and then systematically deceiving them." — TRM Labs, H1 2026 Crypto Crime Report
The crypto industry recorded 207 hack incidents in H1 2026, the highest six-month count ever logged, according to TRM Labs. Losses totaled $972 million — a 57% decline from H1 2025 — creating an apparent paradox: attacks are multiplying while individual payouts shrink. The paradox dissolves on closer inspection. Smaller protocols with thinner liquidity pools now account for the bulk of incidents, while a handful of state-sponsored operations — notably North Korea's Lazarus Group — continue to extract nine-figure sums from infrastructure and operational failures that no smart contract audit is scoped to catch.
August 2026 has intensified the trend. Sixteen publicly logged incidents in the first 21 days of the month — roughly one every 31 hours — have drained funds from a hardware wallet vendor (Coldcard, $116 million), a cross-chain DEX (Maya Protocol, $1.7 million direct / $11 million pool impact), an AI-focused Layer 1 (Oraichain), and a centralized exchange (Coinsbuy, $8 million). The attack surface is no longer confined to DeFi smart contracts. It extends to firmware supply chains, bridge validation logic, key management infrastructure, and human operators.
The Web3 security market is valued at $2.86 billion in 2026 and projected to reach $6.84 billion by 2030, according to Research and Markets. Yet 75% of 2026 losses occurred outside the scope of conventional smart contract audits, per CORE3 analysis. The industry is spending billions to secure the wrong perimeter.
TRM Labs documented 207 crypto hacks in the first six months of 2026, more than double the 83 incidents logged in H1 2025. Despite this surge in frequency, aggregate losses fell to $972 million, down from $2.26 billion in H1 2025.
The composition of attacks explains the divergence:
By early August, cumulative 2026 losses had crossed $1.2 billion across 276 incidents, according to Stingrai. The figure does not include indirect losses such as token price crashes triggered by exploits — Maya Protocol's CACAO token, for instance, fell 89% following its August 18 hack, wiping approximately $11 million in pool value beyond the $1.7 million directly extracted.
Blockaid's independent count diverges slightly, recording 212 exploits and $1.1 billion stolen through H1, reflecting differences in incident classification methodology. The directional signal is identical: more attacks, concentrated losses.
August 2026 has produced at least 16 publicly disclosed incidents in 21 days. Four illustrate the breadth of attack vectors now in play:
Coldcard Hardware Wallet ($116 million, July 30 – August) A firmware flaw present since version 4.0.0 (March 2021) caused Coinkite's Coldcard devices to bypass their dedicated hardware random number generator during seed generation, instead relying on a deterministic software PRNG. According to Galaxy Research, attackers drained approximately 1,816 BTC from over 5,200 addresses across four waves. TechCrunch reported losses exceeding $130 million; TRM Labs settled on $116 million. The vulnerability persisted for five years before exploitation. Every user who generated a seed on affected firmware must treat their keys as compromised.
Coinsbuy Exchange ($8 million, August 9) A coordinated attack spanning Tron and Ethereum wallets drained the centralized exchange in under an hour. The incident occurred the same day Oraichain halted its network, contributing to what became a 48-hour, multi-protocol security crisis.
Oraichain Network Halt (August 9) A vulnerability in Oraichain's EVM cross-chain transfer path enabled unauthorized minting of ORAI tokens. The AI-focused Layer 1 halted its entire network at 04:00 UTC, restricting bridges, cross-chain routes, and public interfaces. As of publication, the team is preparing to burn unauthorized mints and reconcile protocol state.
Maya Protocol ($1.7 million direct, $11 million pool impact, August 18) Six chained software bugs in MAYAChain allowed an attacker to execute a 23-message transaction that falsely triggered a slash subsidy mechanism, deposited minimal liquidity to claim 99% pool ownership, and extracted 48.87 million CACAO tokens from the Asgard vault. Co-founder Aaluxx confirmed roughly 20 BTC ($1.4 million) plus $300,000 in other assets were taken. MAYAChain remained halted as of August 21, with all cross-chain operations suspended.
Additionally, a repeat phishing attack on August 12 drained $25.6 million from a whale wallet that had previously lost $24.2 million to the same vector in 2023 — a reminder that human-layer vulnerabilities do not require novel attack research.
The Web3 security market reached $2.86 billion in 2026, per Research and Markets, with 65% of organizations planning budget increases. Financial institutions account for 44% of spending. Yet the data shows a persistent structural mismatch between what gets audited and what gets exploited.
Drift Protocol offers the clearest case study. The Solana-based perpetual futures exchange held audited smart contracts when it was exploited on April 1, 2026, for $285 million. The attack did not target the contracts. It targeted the governance function — a component generally outside audit scope — enabling an insider-facilitated drain in twelve minutes.
CORE3's analysis found that approximately 75% of 2026 losses were extracted through vectors no standard audit was scoped to examine. These include:
The implication is not that audits lack value. Smart contract exploits still account for the majority of incidents by count. But the economic damage concentrates in the 25% of attacks that bypass audited code entirely — infrastructure compromises, key management failures, and human deception campaigns.
According to Hypernative's 2026 State of Web3 Security report, the industry faces what it terms a "Red Queen Race": security tooling improves continuously, but attack sophistication — now augmented by AI-assisted vulnerability discovery — advances in parallel.
TRM Labs attributes approximately $643 million — 66% of all H1 2026 losses — to North Korea-linked hackers. The figure rises to 76% when measured against losses through April, driven by two operations:
Neither operation involved a smart contract vulnerability. Both were multi-month human intelligence operations targeting the individuals who controlled authorization keys. The Lazarus Group's documented crypto theft now exceeds $6 billion since 2017, per CryptoImpactHub, including the $1.5 billion Bybit breach in February 2025.
The concentration of losses in state-sponsored attacks distorts the industry's aggregate risk profile. Excluding Lazarus-attributed incidents, H1 2026 losses fall to roughly $329 million across 205 incidents — an average of $1.6 million per hack. This bifurcation suggests two distinct threat landscapes: a high-volume, low-severity environment of opportunistic contract exploits, and a low-volume, catastrophic-severity tier of nation-state operations targeting infrastructure.
Cross-chain bridges sustained $328.6 million in losses across eight major incidents through May 2026, according to PeckShield. By late July, the figure had grown further with concentrated attacks on AFX Trade ($24.15 million) and Verus ($7.54 million) occurring within hours of each other on July 22-23.
August added Maya Protocol and Oraichain to the tally. Bridge TVL reached $21.94 billion as of March 2026, according to industry data, meaning the attack surface grows proportionally with adoption.
The structural vulnerability is well-documented: bridges aggregate liquidity at choke points while requiring secure cross-chain message verification — a problem that combines the worst aspects of key management (centralization risk) and consensus design (verification complexity). As Yellow Research noted, "key compromise and message forgery are the two biggest categories, but they are not really coding problems; they are operational and design problems."
ERC-7683, an emerging cross-chain intent standard, aims to abstract bridge complexity away from users, but does not address the underlying validator security and message verification challenges that produced the majority of 2026 bridge losses.
Of 224 incidents tracked through H1 2026, funds were recovered in 16 cases — a 7.1% success rate. Returned assets represented 10.86% of total stolen value. Both figures improved over H1 2025 (recovery share up 69%; returned value share up 136%), but remain marginal in absolute terms.
Bounty-based negotiations have emerged as the most effective recovery mechanism. Verus recovered 4,052 ETH after its bridge hacker retained 1,350 ETH (~$2.8 million) as a bounty. The FOOMCASH incident saw 81% recovery ($1.84 million of $2.26 million) through white-hat intervention, with $420,000 paid in combined bounties.
Maya Protocol has publicly requested the return of its funds in exchange for a bug bounty. If unsuccessful, the team stated it would seek to replace the roughly 20 BTC through investments in Aztec Chain and other means.
For large-scale thefts — particularly those attributed to state-sponsored actors — recovery rates approach zero. Once funds cross a bridge and pass through mixers or chains with weaker compliance tooling, traceability degrades rapidly. No meaningful recovery has been reported from the Drift or KelpDAO incidents.
The data from 2026 presents a clear pattern: the crypto industry's security apparatus is calibrated for a threat model that accounts for a minority of actual economic losses. Smart contract audits address the most common attack vector by count but not by value. The majority of capital destruction occurs through operational failures — compromised keys, manipulated insiders, firmware supply chain attacks, and bridge validation logic errors — that sit outside the scope of conventional code review.
The 57% decline in aggregate losses masks a more concerning dynamic. Excluding two Lazarus Group operations, the remaining 205 incidents still produced $329 million in losses — a figure that exceeds total crypto hack losses in any full year before 2020. The long tail of smaller exploits, each individually manageable, collectively represents a persistent tax on protocol capital and user trust.
Until the security spending distribution shifts to match the actual loss distribution — from code-level auditing toward operational security, key management infrastructure, and personnel security — the gap between security investment and security outcomes will persist.