DeFi lost $972 million across 207 discrete security incidents in the first half of 2026, according to Immunefi. That is the highest incident count ever recorded for a six-month period — yet total dollar losses fell below $1 billion, down from the $2.62 billion peak logged in H1 2022. The paradox:...
"The $293 million KelpDAO hack shows why DeFi is finally being forced to grow up." — Sam Kessler, CoinDesk
DeFi lost $972 million across 207 discrete security incidents in the first half of 2026, according to Immunefi. That is the highest incident count ever recorded for a six-month period — yet total dollar losses fell below $1 billion, down from the $2.62 billion peak logged in H1 2022. The paradox: attacks are more frequent but individually less damaging. The exception is bridges. Cross-chain bridge exploits accounted for an estimated $351 million in Q2 2026 alone and have now produced more than $2.8 billion in cumulative losses since 2022, representing roughly 40 percent of all value ever stolen in Web3.
Two incidents in April 2026 — the $285 million Drift Protocol exploit and the $292 million KelpDAO bridge drain — accounted for $577 million combined, or 59 percent of all H1 losses. Both were attributed to North Korea's Lazarus Group and its subunits. Neither was a smart contract bug in the traditional sense. Both exploited operational security failures: compromised signers, manipulated oracles, and zero-timelock governance. The audit-centric security model that defined DeFi's first decade is no longer sufficient.
Meanwhile, less than 2 percent of DeFi's $83 billion in total value locked carries any form of on-chain insurance. Nexus Mutual, the largest DeFi insurance provider, has paid out $18.5 million in claims over seven years — equivalent to roughly 1.9 percent of what was stolen in 2026's first six months alone. The insurance gap is not narrowing.
Immunefi's H1 2026 report documents 207 crypto hack incidents — a record. The prior six-month high was 147 incidents in H2 2024. Quarterly breakdown:
| Period | Incidents | Losses | |--------|-----------|--------| | Q1 2026 | 84 | ~$217M | | Q2 2026 | 123 | ~$755M | | H1 Total | 207 | ~$972M |
Q2 2026 was the most-hacked quarter on record by incident count, with DefiLlama logging approximately 70 exploits and $746 million stolen. April alone accounted for more than $600 million, driven almost entirely by two state-sponsored attacks.
Of the 207 incidents, 125 were classified as smart contract exploits. But the costliest events — accounting for more than 60 percent of total dollar losses — stemmed from infrastructure failures, private key compromises, cross-chain configuration errors, and weaknesses in privileged access. The attack surface has shifted from code to operations.
Cross-chain bridges remain the single most exploited category of DeFi infrastructure. Since 2022, bridge exploits have produced more than $2.8 billion in cumulative losses, according to data aggregated by Chainalysis and DefiLlama. That figure represents roughly 40 percent of all value ever hacked in Web3.
In Q2 2026, bridge-related exploits accounted for an estimated $351 million in losses. The KelpDAO incident on April 18 was the largest: attackers linked to North Korea's TraderTraitor subgroup exploited a LayerZero bridge with a 1-of-1 DVN (Decentralized Verifier Network) setup. They compromised internal RPC nodes, DDoS'd external nodes, and fed false verification data to the Ethereum contract, which released 116,500 rsETH — approximately $292 million — based on a phantom token burn on the source chain.
Because rsETH is widely used as collateral in lending markets, the exploit triggered contagion. According to Sherwood News, DeFi's aggregate TVL dropped by $13 billion in the 48 hours following the hack as users withdrew deposits. Aave, SparkLend, and Fluid froze their rsETH markets.
July 2026 brought additional bridge incidents. On July 22-23, two separate bridge attacks drained $31.6 million within seven hours. AFX Trade lost $24.15 million when attackers obtained private keys from five of the protocol's bridge validators on Arbitrum. The Verus-Ethereum bridge was hit for $7.54 million — the second time the same vulnerability was exploited, after an initial $7 million loss in May 2026. On July 17, the Across Protocol's Solana deployment was exploited via spoofed deposit signals. On July 19-20, Allbridge Core lost $1.65 million through a flash loan attack.
North Korea-linked threat actors accounted for 76 percent of global crypto hack value through April 2026, according to TRM Labs, up from 64 percent in 2025. The total haul attributed to DPRK-linked groups in H1 2026 reached approximately $643 million, per Crypto Briefing.
Two operations dominated:
Drift Protocol (April 1, 2026): Lazarus Group operators executed a $285 million drain from Drift Protocol on Solana in approximately 12 minutes. According to Chainalysis, the attack was a social engineering operation: attackers convinced multisig signers to pre-sign hidden authorizations, then pushed a zero-timelock governance migration that removed the protocol's review window. They manufactured a fake asset (CarbonVote Token) and manipulated Drift's oracle into treating it as valuable collateral. On-chain staging began March 11, nearly three weeks before execution. Elliptic logged it as the 18th DPRK-linked operation of 2026.
KelpDAO (April 18, 2026): The $292 million bridge exploit described above was attributed by TRM Labs to TraderTraitor, a known Lazarus subgroup that specializes in targeting cross-chain infrastructure.
Combined, these two operations accounted for $577 million — 59 percent of all H1 losses and roughly 90 percent of all DPRK-attributed theft in the period. The proceeds fund the regime's nuclear weapons program, according to multiple UN reports.
The 2026 exploit data reveals a structural problem with the prevailing DeFi security model. According to a Crypto Economy analysis, the majority of this year's costliest hacks did not originate from unaudited smart contract code. Both Drift Protocol and KelpDAO had undergone multiple audits. The attack vectors — social engineering of signers, oracle manipulation, governance bypass, infrastructure compromise — fall outside the scope of traditional code audits.
Leading audit firms including Trail of Bits, Certora, and Cyfrin have expanded into formal verification, economic modeling, and operational security reviews. But the industry standard remains a point-in-time code review, typically costing $50,000 to $500,000, that examines smart contract logic. It does not cover:
A dual-audit strategy — engaging two independent firms — has become common among larger protocols. But as the Drift and KelpDAO cases demonstrate, the threat model has evolved beyond what audits alone can address. The attacker walked through the operator, not the code.
Despite $972 million in H1 losses, DeFi insurance covers a negligible fraction of at-risk capital. According to CoinInsider, less than 2 percent of DeFi's $83 billion in TVL carries any form of on-chain insurance coverage.
Nexus Mutual, the sector's largest insurance provider, holds approximately $123.5 million in TVL — representing 0.14 percent of DeFi's total market. Over seven years of operation, Nexus Mutual has paid out $18.5 million in claims. That total is 16 times smaller than the KelpDAO exploit alone.
DefiLlama lists 28 insurance-focused protocols, but Nexus Mutual accounts for the overwhelming majority of actual coverage. The insurance market has not scaled with the risk environment for several documented reasons:
Nexus Mutual's integration with Symbiotic in late 2025 introduced yield-generating reinsurance vaults intended to address capital efficiency. Whether this model can scale to match the loss environment remains to be seen.
Bug bounty programs represent the primary proactive defense mechanism in Web3 security. Immunefi, the largest Web3 bug bounty marketplace, reports 85,303 registered researchers as of April 2026, with 650+ active programs and cumulative all-time payouts exceeding $134 million.
Q1 2026 performance showed notable growth: researcher payouts rose from $2.4 million in Q4 2025 to $7.87 million in Q1 2026, a 228 percent quarter-over-quarter increase across 1,104 paid reports. Average payout per report nearly tripled from $2,516 to $7,131, reflecting a heavier mix of critical-severity findings.
In H1 2026, researchers reported 837 valid vulnerabilities through Immunefi. Approximately $13.45 million was paid in bug bounties. The average critical-severity reward stands at $13,000 for blockchain projects; the overall average is approximately $52,800, with a median of $2,000.
These numbers illustrate a structural imbalance: $13.45 million in bounties paid to prevent exploits versus $972 million lost to attackers in the same period. The ratio is roughly 1:72 — for every dollar spent on proactive defense through bounties, $72 was stolen.
According to Immunefi, 94 percent of long-running bug bounty programs have surfaced at least one critical vulnerability, suggesting the programs do find real issues. But coverage is uneven: many smaller protocols and bridge implementations operate without active bounty programs.
July 2026 has extended the pattern. Beyond the $31.6 million in bridge exploits on July 22-23, additional incidents include:
Lookonchain labeled July 23 as "Hackers' Day," with three separate exploits totaling $35.55 million in a single 24-hour period.
The data from H1 2026 presents a DeFi security environment that is simultaneously improving and deteriorating. Average loss per incident has declined from 2022 peaks, suggesting that smaller protocols are better hardened or hold less exploitable value. But attack frequency is at record levels, the threat actors are state-sponsored and well-resourced, and the most damaging attack vectors — operational security, bridge infrastructure, governance mechanisms — remain largely unaddressed by the industry's primary defensive tools.
The insurance market covers a fraction of a percent of at-risk capital. Bug bounty payouts are dwarfed by attacker profits by a factor of 72. Audits examine code that is increasingly not where the vulnerability lies. The economic incentive structure favors offense overwhelmingly.
For the sector to absorb institutional capital at the scale projected by tokenization advocates, this security deficit represents a material impediment. The $13 billion TVL drawdown following KelpDAO — a contagion event triggered by a single bridge exploit — demonstrates how security failures propagate through interconnected protocols. Until the security model catches up with the threat model, every dollar locked in DeFi carries an unpriced insurance premium that users are implicitly absorbing.