Web3 security incidents drained $1.31 billion across 344 exploits in the first half of 2026, according to CertiK's Hack3D report published July 8. The headline figure represents a 46.8% decline from H1 2025's $2.47 billion. Strip out the $1.45 billion Bybit hack that distorted the prior period, a...
"Attackers are getting better returns by targeting key management, multisig governance and operational infrastructure than by looking for code bugs." — Ronghui Gu, CEO, CertiK
Web3 security incidents drained $1.31 billion across 344 exploits in the first half of 2026, according to CertiK's Hack3D report published July 8. The headline figure represents a 46.8% decline from H1 2025's $2.47 billion. Strip out the $1.45 billion Bybit hack that distorted the prior period, and H1 2026 losses are roughly 28% higher on a comparable basis.
The attack surface has shifted. Code vulnerabilities, the historical focal point of audit firms and bug bounties, accounted for 204 incidents but only $152 million in losses. Wallet compromise generated $445 million from just 33 events. Two exploits — the Drift Protocol breach ($285 million, April 1) and the KelpDAO bridge exploit ($292 million, April 18) — accounted for 44% of all losses and have both been attributed to North Korean state-sponsored actors. According to TRM Labs, DPRK-linked groups were responsible for 76% of all crypto hack value in 2026 through April, extending a trend that saw their share climb from under 10% in 2020-2021 to 39% in 2024.
The data describes an industry where smart contract security has improved materially while operational security — key management, bridge architecture, oracle infrastructure — has not kept pace. As CertiK's own analysts wrote: "A surface-level reading that losses fell by nearly 50% could create the impression that the ecosystem has become meaningfully safer. The data does not support that conclusion."
CertiK's Hack3D report logged 344 security incidents between January 1 and June 30, 2026, generating gross losses of $1,315,676,432. After accounting for $115.3 million in frozen and returned funds, adjusted net losses stood at $1.2 billion.
Quarterly distribution was uneven. Q1 produced $508.2 million in losses, driven primarily by phishing campaigns. Q2 spiked to $807.5 million — a 59% quarter-over-quarter increase — as wallet compromises displaced phishing as the dominant vector. April alone accounted for approximately $651 million across 61 incidents.
Incident volume tells a separate story. The 344 total incidents were essentially flat versus H1 2025's 345, but the average loss per incident rose from roughly $7.2 million to $3.8 million — a misleading average depressed by the large number of small code exploits. The median loss for wallet compromises exceeded $13 million per event.
A separate analysis by Finbold placed H1 2026 losses at $955 million, reflecting differences in incident classification methodology. The variance underscores an ongoing problem: the industry lacks a standardized taxonomy for categorizing exploits, hacks, and scams.
The CertiK data reveals a structural shift in how value is extracted from protocols.
Wallet Compromise: $445 million across 33 incidents. This category encompasses administrative key theft, multisig governance manipulation, and privileged access escalation. Despite accounting for fewer than 10% of incidents, wallet compromise generated 34% of total losses. The average take per event — over $13 million — dwarfs every other category.
Phishing: $366 million across 63 incidents. Volume declined 52.3% from H1 2025, but dollar losses fell only 10.8%. The distribution was heavily concentrated: four incidents generated approximately 85% of phishing-related losses. This suggests attackers are targeting higher-value wallets with more sophisticated social engineering rather than running broad-based campaigns.
Code Vulnerability: $152 million across 204 incidents. The most frequent attack type produced the lowest total losses, averaging under $750,000 per event. This is arguably an industry success story: years of investment in formal verification, audit standards, and bug bounty programs have reduced the per-incident cost of code exploits. The problem is that attackers have moved upstream.
The implication is clear. Protocols can pass code audits and still lose nine-figure sums through operational failures. As CertiK CEO Ronghui Gu stated: "Even if a protocol passes a flawless code audit, it can still lose millions of dollars if an admin key is compromised."
April 2026 was the most destructive single month for DeFi security on record outside of the February 2025 Bybit incident. Two events dominated.
Drift Protocol — $285 million (April 1). Solana-based perpetual futures protocol Drift was drained in approximately 12 minutes. According to Chainalysis and TRM Labs, attackers spent months socially engineering members of Drift's Security Council, then exploited Solana's "durable nonces" feature to obtain pre-signed transactions that transferred administrative control. Once in possession of admin keys, the attackers whitelisted a fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH. At least 20 protocols with exposure to Drift's liquidity or vaults experienced downstream disruptions.
KelpDAO — $292 million (April 18). Attackers compromised KelpDAO's internal RPC nodes while simultaneously DDoS-attacking external verification infrastructure. The protocol's LayerZero bridge relied on a single-DVN (Decentralized Verifier Network) configuration — effectively a 1-of-1 trust assumption. The manipulation triggered a phantom token burn on the source chain, causing the Ethereum-side contract to release 116,500 rsETH. In the 48 hours following the breach, $13 billion in TVL exited various DeFi protocols as contagion fears spread. The Arbitrum Security Council froze approximately $75 million in ETH linked to the attacker.
Together, these two incidents generated $577 million in losses — more than Q1's entire total.
TRM Labs data shows DPRK-attributed actors accounted for $577 million, or 76% of all crypto stolen through April 2026. This continues an accelerating trend:
| Period | DPRK Share of Crypto Theft | |--------|---------------------------| | 2020-2021 | <10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 (through April) | 76% |
Cumulative DPRK-attributed crypto theft since 2017 exceeds $6 billion, according to TRM Labs. The operational pattern has evolved: the Drift attack involved months of social engineering preparation followed by a 12-minute execution window. KelpDAO required coordinated compromise of RPC infrastructure and real-time DDoS suppression of fallback verification systems.
TRM analysts assessed that "North Korean operators are incorporating AI tools into their reconnaissance and social engineering workflows," citing increasing attack precision and speed of execution.
Laundering infrastructure has also matured. KelpDAO funds entered an active laundering phase via THORChain and Bitcoin conversion channels. Drift funds, by contrast, remained dormant as of TRM's last reporting — a pattern consistent with prior Lazarus Group operations where funds sit idle for months before moving.
Ethereum absorbed the highest volume of incidents: 153 hacks, scams, and exploits generating $522.8 million in losses. The figure reflects Ethereum's position as the primary settlement layer for DeFi protocols and the largest concentration of TVL.
Solana experienced fewer incidents but outsized losses totaling $315.1 million, driven almost entirely by the Drift Protocol exploit. The Drift breach represented the second-largest exploit in Solana's history, behind only the $326 million Wormhole bridge hack in February 2022.
Cross-chain bridge infrastructure continues to represent a disproportionate source of systemic risk. The KelpDAO exploit targeted LayerZero bridge verification, and bridge-related incidents have historically accounted for several of the largest individual losses in crypto security history.
Losses have continued into Q3. On July 15, 2026, Ostium — an Arbitrum-based RWA perpetuals protocol offering leverage up to 200x on stocks, commodities, and forex — lost approximately $23.7 million in an oracle manipulation attack.
The attacker gained access to an authorized oracle signer key, used a PriceUpKeep Forwarder already registered within the protocol, and submitted a price report carrying a future timestamp. The manipulation drained roughly $18 million in USDC from Ostium's public OLP vault in a five-minute window between 14:18 and 14:23 UTC. PeckShield's broader tracking placed total fund movements closer to $24 million. The vault's TVL dropped from $32.7 million to approximately $9 million — a 72% decline.
Ostium founder Kaledora confirmed the breach timeline and stated that trading contracts were paused within the hour. Stolen USDC was converted to approximately 12,080 ETH, of which 10,540 ETH was routed through Tornado Cash.
Ostium had raised $27.8 million from General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute, and GSR. The exploit underscores that venture backing and institutional investor participation do not constitute a security guarantee.
CertiK CEO Ronghui Gu flagged autonomous AI agents as an emerging attack surface. "AI agents with wallet access are a new type of privileged key holder and may fail to filter malicious inputs if they are not properly secured," he stated.
The concern is structural. As protocols deploy AI agents for trading, yield optimization, and governance participation — a trend that accelerated in mid-2026 with at least five platforms shipping AI agent wallets in a four-week span — each agent becomes a potential vector for key compromise. The agent's decision-making layer, if manipulable through adversarial inputs, offers an attack surface that does not exist with human key holders.
Separately, CertiK's research indicates attackers are using AI-generated deepfake videos and synthetic voice to bypass exchange KYC checks, impersonate executives, and authorize fraudulent transfers. The cost asymmetry favors attackers: generating a convincing deepfake costs orders of magnitude less than defending against one.
The H1 2026 security data presents a concrete obstacle for institutional capital. A CoinDesk analysis from May 2026 described DeFi vulnerabilities as "TradFi's biggest blocker," noting that protocols experienced near-daily exploits during peak periods.
For institutional allocators evaluating on-chain exposure, the data suggests three considerations. First, code audit quality has improved but is insufficient — operational security, key management, and bridge architecture dominate the loss profile. Second, concentration risk is acute: two incidents generated 44% of H1 losses, and a single nation-state actor was responsible for 76% of stolen value through April. Third, the recovery rate remains low — only $115.3 million of $1.31 billion, or 8.8%, was frozen or returned.
These dynamics are not unique to crypto. Traditional financial infrastructure faces analogous threats from nation-state actors and insider compromise. The difference is the finality of on-chain settlement: once funds are bridged through THORChain or mixed through Tornado Cash, recovery is functionally impossible.
The crypto security landscape in H1 2026 is defined by a paradox: smart contract code is safer than it has ever been, yet aggregate losses remain in the billions. The attack surface has migrated from on-chain logic to off-chain infrastructure — key management, bridge verification, oracle signing, and human operators. Two attacks by a single nation-state actor accounted for nearly half of all losses.
The industry's security investment has been concentrated on the wrong layer. Code audits, formal verification, and bug bounties have reduced the per-incident cost of code exploits to under $750,000 on average. But wallet compromises average over $13 million per event, and the gap is widening. Until operational security receives the same systematic attention as smart contract security, the loss profile is unlikely to change materially.