← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] DeFi Loses $1.1B to Hacks, 40 Protocols Shut Down

Zephyra|June 2, 2026|BPF
EXECUTIVE SUMMARY

DeFi protocols have hemorrhaged more than $1.1 billion to exploits over the past twelve months, with 40-plus projects ceasing operations in 2026 alone. April recorded losses exceeding $600 million across 28 separate incidents — making it the worst month for DeFi security in four years. Only three...

"Right now, more and more institutions are trying to move assets onchain. They need to face all these AI attacks, smart contract vulnerabilities, oracle manipulation, and cross-chain bridge hacks. That's being considered as one of the major blockers." — Ronghui Gu, CEO and Co-founder, CertiK

Executive Summary

DeFi protocols have hemorrhaged more than $1.1 billion to exploits over the past twelve months, with 40-plus projects ceasing operations in 2026 alone. April recorded losses exceeding $600 million across 28 separate incidents — making it the worst month for DeFi security in four years. Only three calendar days in April passed without an exploit.

The damage extends beyond stolen funds. More than $20 billion in total value locked has fled DeFi protocols since January. Attack frequency is up 68% year-over-year, with 47 incidents through May compared to 28 in the same period of 2025. North Korean state-affiliated groups accounted for 76% of all crypto hack losses in 2026, according to TRM Labs. Less than 2% of DeFi's $83 billion TVL carries any form of insurance coverage. The structural asymmetry between attackers and defenders is widening, not narrowing, and AI-enabled vulnerability scanning is accelerating the pace.

Table of Contents

  1. The Numbers: A Record-Setting Loss Year
  2. Anatomy of the Two Largest Exploits
  3. The Protocol Shutdown Wave
  4. AI-Augmented Attack Vectors
  5. The Insurance Gap
  6. Institutional Adoption: The Security Bottleneck
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Numbers: A Record-Setting Loss Year

Through the first five months of 2026, cumulative DeFi losses exceed $840 million across more than 50 separate incidents, according to data compiled by CryptoTimes and DefiLlama. April alone accounted for an estimated $606–$651 million in losses across 28–30 exploits. Attack frequency rose 68% year-over-year: 47 incidents in January–May 2026 versus 28 in the same period of 2025.

The five largest exploits of 2026 to date:

| Protocol | Amount Lost | Date | Attack Vector | |----------|-----------|------|---------------| | KelpDAO | $292M | April 18 | Bridge DVN manipulation | | Drift Protocol | $285M | April 1 | Social engineering + fake collateral | | Step Finance | $27–40M | January 31 | Smart contract exploit | | Truebit | $26.4M | January 8 | Contract vulnerability | | Grinex | $19.4M | Undisclosed | Hot wallet compromise |

Cross-chain bridges remain the single most targeted infrastructure category in DeFi. A total of 14 bridge exploits drained $340.7 million in the first four months of the year, according to CoinGabbar. The KelpDAO breach, routed through LayerZero's bridge infrastructure, accounted for $292 million of that total.

TRM Labs data shows North Korean-linked hackers' share of global crypto hack losses has climbed from under 10% in 2020–2021 to 64% in 2025 and to 76% in 2026 through April. Both the Drift Protocol and KelpDAO exploits have been attributed to DPRK-affiliated threat actors.

Anatomy of the Two Largest Exploits

KelpDAO: $292 Million Bridge Failure

On April 18, attackers exploited KelpDAO's LayerZero bridge, draining approximately 116,500 rsETH ($292 million). The attack did not exploit a smart contract bug. Instead, attackers compromised internal RPC nodes and launched DDoS attacks against external nodes to feed false data to a single-point-of-failure verification network — a 1-of-1 DVN (Decentralized Verifier Network) setup.

LayerZero initially blamed KelpDAO's configuration but later acknowledged responsibility. "We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions," the company stated. LayerZero subsequently mandated minimum 3/3 DVN configurations on all pathways and 5/5 where possible.

The fallout was immediate. Within 48 hours, $13 billion in TVL fled DeFi protocols. Aave absorbed an estimated $123–230 million in bad debt. Major clients including Kelp itself and Solv Protocol (managing over $700 million in tokenized bitcoin) migrated away from LayerZero to Chainlink's cross-chain infrastructure, according to CoinDesk.

Drift Protocol: $285 Million Social Engineering Operation

On April 1, Solana-based perpetuals exchange Drift Protocol was drained of $285 million in approximately 12 minutes. According to Chainalysis and Elliptic, attackers spent six months posing as a quantitative trading firm to build trust with Drift contributors, then exploited Solana's "durable nonces" system to trick Security Council members into pre-signing dormant transactions.

Once in control, attackers whitelisted a fabricated token (CarbonVote, or CVT) as collateral, deposited 500 million worthless CVT tokens, and withdrew $285 million in USDC, SOL, and ETH. On-chain staging began on March 11 with a 10 ETH withdrawal from Tornado Cash, according to Chainalysis. Most stolen funds were bridged to Ethereum within hours.

Drift Protocol confirmed the operation was carried out by the same threat actors responsible for the October 2024 Radiant Capital exploit, attributed to UNC4736, a North Korean state-affiliated group.

The Protocol Shutdown Wave

Between January and June 2026, more than 40 protocols ceased operations or entered wind-down mode. This is not a single catastrophic failure event. Unlike FTX or Celsius, the 2026 shutdown wave is a slow structural unraveling driven by converging pressures.

Token-as-revenue model collapse. Many protocols relied on appreciating native tokens for developer compensation, liquidity subsidies, and operations. As secondary market liquidity evaporated, this funding mechanism broke. Step Finance shut down after a $27 million exploit when, according to the team's statement, "rescue capital never materialized." Parsec Finance closed after five years with no revenue path. GENSO Online reported server costs running at 5x revenue.

Security cost inflation. Enterprise-grade audits, real-time monitoring, and incident response now exceed what mid-sized protocols can afford. A large academic analysis of 8,195 audit reports across 1,575 protocols found little evidence that audits alone materially reduce future security incidents, according to OpenZeppelin research. Balancer V2, which had undergone 11 separate audits, was still exploited through precision rounding errors.

Regulatory environment shifts. The current U.S. administration's crypto-friendly posture has, paradoxically, reduced demand for decentralized governance tooling. Tally, a DAO governance platform, shut down after co-founder Dennison Bertram acknowledged that regulatory relaxation had reduced legal drivers for DAO adoption.

The shutdowns span every DeFi sub-sector: liquid staking (MilkyWay), NFT marketplaces (Nifty Gateway, Foundation), lending (ZeroLend, Seamless Protocol), derivatives (Polynomial), stablecoins (Angle Protocol), wallets (Magic Eden Wallet, Leap Wallet), GameFi (Pixiland, Forgotten Runiverse, GENSO Online), analytics (Parsec Finance, DataHaven), and governance (Tally).

Market consolidation is accelerating. OpenSea and Blur now control over 73% of NFT marketplace activity. Wallet usage is consolidating toward Phantom, MetaMask, and Keplr.

AI-Augmented Attack Vectors

The asymmetry between DeFi attackers and defenders is widening. Manuel Aráoz, former CTO and co-founder of OpenZeppelin (he departed in 2019), stated in May 2026: "I now consider all of DeFi unsafe. Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit."

OpenZeppelin's current leadership, under CEO Demian Brener, distanced the company from Aráoz's position, stating the answer involves "continuous, AI-augmented security rather than retreat from DeFi."

CertiK CEO Ronghui Gu quantified the cost disparity: attackers can spend $10,000–$20,000 on continuous AI-powered vulnerability scans, while defenders operate under strict budgetary constraints tied to commercial audit contracts. Anthropic's Claude Mythos AI model has demonstrated the ability to autonomously discover software vulnerabilities and develop working exploits, according to CoinDesk reporting.

The transparent nature of smart contract code — publicly readable by design on blockchains — creates an inherent vulnerability to machine-speed scanning. Every deployed contract is a permanently available attack surface.

The Insurance Gap

DeFi's insurance sector is structurally inadequate for the current threat environment.

Less than 2% of DeFi's $83 billion TVL carries insurance coverage, according to Hugh Karp, founder of Nexus Mutual. The insurance sector's total TVL stands at $123.5 million across 28 protocols, with Nexus Mutual holding nearly the entire amount. For context, DeFi insurance peaked at $1.89 billion TVL in November 2021 and has declined 93% since then.

"Less than 2% of DeFi's TVL is covered or insured, and we see that as one of the largest barriers to real DeFi adoption," Karp stated, as reported by CoinDesk. He also noted that premiums "become prohibitively expensive" given the current loss environment.

Dan She, senior audit partner at CertiK, identified the demand-side problem: "Most DeFi users are yield-driven and do not want to give up several percentage points of return for cover."

Altura COO Matthew Pinnock identified the structural flaw in the supply side: capital backing insurance pools is "often exposed to the same risks as the underlying protocol, so it evaporated precisely when it was needed most." In the six years through May 2026, uninsured lending protocols lost $7.7 billion to exploits.

Institutional Adoption: The Security Bottleneck

The security crisis is directly impeding institutional capital flows into DeFi. According to CertiK's Gu, institutions envisioning "multiple trillion dollars — even tens of trillions of dollars" moving onchain face a security environment with near-daily exploits and sophisticated state-sponsored attackers.

CoinDesk reported on May 28 that DeFi vulnerabilities represent "TradFi's biggest blocker," with April's exploit frequency — 27 out of 30 days with at least one incident — cited as evidence that current security infrastructure cannot support institutional-grade asset custody.

The problem compounds on itself. As losses mount, TVL exits. As TVL exits, protocol revenues decline. As revenues decline, security budgets shrink. As security budgets shrink, vulnerabilities multiply. The $20 billion TVL outflow since January is both a consequence and an accelerant of the security crisis.

CryptoTimes forecasts 15–25 additional mid-tier protocol shutdowns in the remainder of 2026, with at least one more nine-figure bridge exploit anticipated.

Key Takeaways

  • $1.1 billion in DeFi losses over the past 12 months, with $840 million in the first five months of 2026 alone.
  • April 2026 was the worst month for DeFi security in four years: $600M+ lost, only 3 days without an exploit.
  • 40+ protocols shut down in 2026, spanning every DeFi sub-sector from lending to GameFi.
  • 76% of 2026 crypto hack losses are attributable to North Korean state-affiliated groups (TRM Labs).
  • Less than 2% of DeFi's $83B TVL is insured. The insurance sector's own TVL has declined 93% from its 2021 peak.
  • $20 billion in TVL has fled DeFi protocols since January 2026.
  • AI-powered vulnerability scanning is reducing attack costs while defenders face static budgets.
  • Cross-chain bridges remain the highest-value target: 14 bridge exploits, $340.7M drained in 2026 through April.
  • Institutional DeFi adoption is directly constrained by the current security environment.

Conclusion

The DeFi sector faces a structural security deficit that existing defense mechanisms — audits, multisig governance, insurance pools — have proven insufficient to address. The attack surface is expanding (more protocols, more bridges, more composability), attack sophistication is increasing (state-sponsored actors, AI tooling), and defense budgets are shrinking (falling TVL, declining protocol revenues).

The 40-plus protocol shutdowns in 2026 are not anomalies. They are the predictable outcome of a sector where the cost of adequate security now exceeds what most projects generate in revenue. The protocols that survive will be those that can absorb security costs at scale — which points toward further consolidation around a smaller number of larger, better-capitalized platforms.

For institutional capital waiting on the sidelines, the data offers a clear assessment: DeFi's value proposition in permissionless finance remains intact, but its security infrastructure is not yet commensurate with the scale of assets it seeks to attract.

Sources & References

  1. 40+ DeFi Protocols Shut Down in 2026: Inside the $770M Hack Crisis Reshaping Crypto — CryptoTimes, May 9, 2026
  2. OpenZeppelin CEO Says AI Makes DeFi Unsafe — CoinDesk, May 27, 2026
  3. DeFi Vulnerabilities Are TradFi's Biggest Blocker — CoinDesk, May 28, 2026
  4. Crypto Users Choose Yields Over Protection, Putting Billions at Risk — CoinDesk, May 16, 2026
  5. Drift Protocol Hack: How Privileged Access Led to a $285M Loss — Chainalysis, 2026
  6. North Korean Hackers Attack Drift Protocol in $285 Million Heist — TRM Labs, 2026
  7. LayerZero Says It Made a Mistake in $292M Kelp Exploit — CoinDesk, May 9, 2026
  8. $292M Lost, Zero Bugs Found: Lessons from the rsETH Bridge Exploit — OpenZeppelin, 2026
  9. $340M Lost: 14 Crypto Hacks 2026 Targeting Bridges — CoinGabbar, 2026
  10. Biggest DeFi Hacks and Exploits of 2026: $1 Billion+ Lost and Counting — CCN, 2026