April 2026 is now the most-exploited month in cryptocurrency history by incident count. Thirty separate attacks drained $629 million from DeFi protocols, 3.7 times the entire Q1 2026 loss figure of $168 million. Two incidents — KelpDAO ($292 million, April 18) and Drift Protocol ($285 million, Ap...
"North Korean hackers stole 76% of all crypto hack value in 2026 — with just two attacks." — Ari Redbord, Global Head of Policy, TRM Labs
April 2026 is now the most-exploited month in cryptocurrency history by incident count. Thirty separate attacks drained $629 million from DeFi protocols, 3.7 times the entire Q1 2026 loss figure of $168 million. Two incidents — KelpDAO ($292 million, April 18) and Drift Protocol ($285 million, April 1) — accounted for 93% of the month's dollar losses. Both were attributed by TRM Labs to North Korea's Lazarus Group.
The contagion effects proved as damaging as the exploits themselves. Aave's total value locked fell $8.45 billion in 48 hours. Total DeFi TVL across all protocols dropped from $99.5 billion to $86.3 billion — a $13.2 billion wipeout in two days. Seven protocols subsequently coordinated "DeFi United," the sector's first cross-protocol bailout, raising over $314 million in pledged ETH to restore rsETH backing.
The month exposed three structural weaknesses: single-point-of-failure verification systems in cross-chain bridges, unprotected admin keys without timelocks or multisigs, and the systemic risk posed by liquid restaking tokens used as collateral across multiple lending protocols.
| Metric | April 2026 | Previous Record | |--------|-----------|-----------------| | Total losses | $629M | $1.4B (Feb 2025, Bybit) | | Incident count | 30 | 16 (Jan 2026) | | Largest single exploit | $292M (KelpDAO) | $1.4B (Bybit, Feb 2025) | | DeFi TVL outflow (48hr) | $13.2B | N/A | | Recovery rate | $18.2M (2.9%) | ~20% historical avg |
April's incident count exceeded the previous monthly record by 81%. The 30 exploits averaged approximately one per day across the month. According to DeFiLlama, DeFi protocols accounted for $614 million of the $629 million total — 97.6% of losses.
Year-to-date through April 30, 2026, the industry recorded approximately 68 incidents and $771.8 million in total theft. April alone represented 81.5% of the year's total dollar losses.
The attack targeted Kelp DAO's LayerZero-powered cross-chain bridge, which held reserves backing rsETH across more than 20 networks. The core vulnerability was a 1-of-1 verifier configuration: a single node responsible for confirming incoming cross-chain messages before releasing funds.
Attack sequence:
TRM Labs attributed the exploit to North Korea based on on-chain funding analysis traceable to a Bitcoin wallet controlled by Wu Huihui, a Chinese crypto broker indicted in 2023 for laundering Lazarus Group proceeds.
The Drift Protocol attack on Solana involved months of social engineering to compromise protocol signers, followed by execution in approximately 12 minutes.
Attack sequence:
According to CoinDesk, the attackers spent months building in-person relationships with Drift team members before exploiting operational access.
The remaining 28 exploits included:
The KelpDAO exploit triggered the most severe contagion event in DeFi history. Because rsETH functioned as collateral across multiple lending protocols, the loss of backing created cascading failures.
Timeline of contagion (April 18-20):
According to CoinDesk, the withdrawals spread to Solana-based protocols and other unaffected platforms, indicating market-wide loss of confidence rather than rational risk assessment.
Bad debt accumulation: Aave confirmed between $123.7 million and $230.1 million in protocol-level bad debt. The range depends on how rsETH losses are distributed — if spread across all holders, Aave faces ~$124M; if isolated to Layer 2 networks, the figure reaches $230M.
On April 23, five days after the exploit, Aave service providers launched "DeFi United" — the first coordinated cross-protocol relief fund in DeFi history. The target: raise 100,000 ETH to restore rsETH backing.
Pledges as of May 1:
| Contributor | Amount | Structure | |-------------|--------|-----------| | Mantle Network | 30,000 ETH | Low-interest loan | | Aave DAO | 25,000 ETH | Treasury contribution | | Lido | ~5,000 ETH | Direct contribution | | EtherFi | Undisclosed | Direct contribution | | Ethena | Undisclosed | Direct contribution | | Ink Foundation | Undisclosed | Direct contribution | | BGD Labs | Undisclosed | Direct contribution | | Individual contributors (14) | ~$161M combined | Various |
Total pledged: approximately 69,534 ETH ($314M+ at current prices).
Governance votes in progress (as of May 1-2):
April's exploits clustered around three attack categories, marking a structural shift from earlier years when smart contract bugs dominated.
1. Infrastructure compromise (93% of dollar losses)
Both major attacks targeted off-chain verification infrastructure rather than on-chain code. KelpDAO's bridge relied on a single verifier node. Drift's admin key lacked timelock protection. Neither vulnerability was a smart contract bug — both were operational security failures.
2. Admin key compromise (multiple incidents)
Wasabi Protocol's $4.55M loss on April 30 resulted from a compromised deployer wallet granting ADMIN_ROLE to a malicious contract. The protocol lacked safeguards such as timelocks or multisig requirements on the admin role.
3. Social engineering (Drift, various smaller incidents)
The Drift attack involved months of in-person relationship building. CoW Swap's $1.2M loss came from attackers impersonating company staff. The shift toward human-targeted attacks represents an evolution from 2023-2024 when code exploits dominated.
According to TRM Labs, the common thread is "precision and speed" — attackers now invest months in preparation before executing in minutes.
Security researchers have flagged artificial intelligence as an emerging factor in the exploit acceleration. According to a SANS Institute emergency briefing issued in April 2026, AI-driven vulnerability discovery has compressed exploit timelines from weeks to hours.
Key data points:
However, no verified public evidence currently confirms that the April 2026 attacks used fully autonomous AI systems. The Wasabi Protocol exploit prompted renewed discussion about AI-assisted hacking after BeInCrypto reported security researchers flagged AI involvement, but attribution remains unconfirmed.
The defensive application of AI is also advancing. CoinDesk reported in February 2026 that specialized AI detects 92% of real-world DeFi exploits — suggesting the technology functions as both sword and shield.
2026 quarterly progression:
North Korea attribution (TRM Labs):
Comparison to prior years:
The data shows that 2026 losses are heavily concentrated in two state-sponsored incidents rather than distributed across many independent actors. This concentration risk means a single successful operation can swing annual totals by hundreds of millions.
April 2026 demonstrated that DeFi's systemic risk is no longer theoretical. A single bridge exploit can cascade through the lending stack within hours, triggering billions in withdrawals from protocols with zero direct exposure to the compromised asset. The architecture that enables composability — tokens flowing freely as collateral across protocols — simultaneously transmits losses at network speed.
The industry response through DeFi United represents an institutional maturation: protocols committing hundreds of millions in coordinated rescue funds within days. But the 2.9% recovery rate and the continued dominance of state-sponsored attackers suggest that defensive capabilities have not kept pace with offensive sophistication.
The structural question facing DeFi governance in May 2026 is whether the sector can implement meaningful verification redundancy (multi-verifier bridges, timelocked admin functions, collateral exposure limits) before the next state-level operation deploys. The data from April provides the answer's urgency but not its timeline.