DeFi protocols lost $972 million across 207 separate hacks in the first half of 2026, according to TRM Labs data published July 3. Incident count doubled year-over-year — 207 vs. 83 in H1 2025 — but total dollar losses fell by more than half from $2.3 billion. The gap between rising frequency and...
"What we are watching is not a North Korean campaign that is broader — it is one that is sharper." — Ari Redbord, TRM Labs
DeFi protocols lost $972 million across 207 separate hacks in the first half of 2026, according to TRM Labs data published July 3. Incident count doubled year-over-year — 207 vs. 83 in H1 2025 — but total dollar losses fell by more than half from $2.3 billion. The gap between rising frequency and falling aggregate loss masks a structural shift in how attackers operate: fewer protocols lost more money to a smaller number of state-backed groups exploiting off-chain infrastructure rather than on-chain code.
Infrastructure and operational compromises accounted for approximately 15% of incidents but 76% of total value stolen. Smart contract exploits still dominate by count (125 of 207 incidents) but increasingly yield smaller payouts. The three largest single losses of the year — KelpDAO ($292 million), Drift Protocol ($285 million), and Humanity Protocol ($32 million) — all originated from off-chain attack vectors: compromised RPC nodes, social engineering of admin key holders, and infected developer machines. None involved a single line of flawed Solidity.
The data implies a DeFi security model that has matured on-chain while leaving its operational plumbing largely unaudited and uninsured. Less than 2% of DeFi's $83 billion TVL carries any insurance coverage.
TRM Labs recorded 207 crypto hack incidents in H1 2026, a record half-year count. Total losses reached $972 million. Median loss per incident was $219,000; mean loss was $4.7 million. The distribution is heavily right-skewed: two incidents in April (Drift and KelpDAO) accounted for $577 million — 59% of the half-year total.
Q2 2026 alone saw 123 incidents, itself a record quarter. April was the worst single month, with over $600 million stolen across multiple events. That figure exceeds any single month since the Bybit breach in early 2025.
The year-over-year decline in aggregate losses from $2.3 billion (H1 2025) to $972 million should not be read as improved security. H1 2025 was distorted by the $1.5 billion Bybit hack, itself an infrastructure compromise. Excluding Bybit, the 2025 baseline drops to approximately $800 million — making H1 2026 slightly worse on a comparable basis.
| Metric | H1 2025 | H1 2026 | Change | |---|---|---|---| | Total incidents | 83 | 207 | +149% | | Total losses | $2.3B | $972M | -58% | | Mean loss/incident | $27.7M | $4.7M | -83% | | Median loss/incident | N/A | $219K | — | | NK-attributed losses | $1.7B | $643M | -62% |
The dominant pattern of 2026 is the migration of high-value attacks from smart contract logic to the operational infrastructure surrounding it. Three incidents illustrate the pattern.
KelpDAO operated a LayerZero-powered bridge for its liquid restaking token, rsETH. The bridge relied on a 1-of-1 Decentralized Verifier Network (DVN) configuration — a single node responsible for validating cross-chain messages before releasing funds.
Attackers, attributed by Chainalysis and LayerZero to TraderTraitor (a Lazarus Group subunit), compromised internal RPC nodes and launched DDoS attacks against external nodes. This fed false data to the lone verifier, enabling the attacker to mint 116,500 unbacked rsETH on Ethereum — approximately 18% of circulating supply — without burning corresponding tokens on Unichain.
The attacker deposited 89,567 rsETH into Aave as collateral, borrowed $190.86 million in wrapped ETH, and began liquidating across multiple venues. At least nine DeFi protocols were affected. Aave's TVL dropped by $10 billion in the aftermath.
The root cause was not code. It was a single-point-of-failure trust assumption in bridge verification infrastructure.
Drift, Solana's largest perpetual futures DEX, was drained of more than 50% of its TVL in 12 minutes. The attack was the culmination of a six-month social engineering campaign attributed to UNC4736, a North Korean state-sponsored group also known as AppleJeus, Citrine Sleet, and Golden Chollima.
According to Drift's post-mortem, attackers spent months building relationships with the Drift team. On-chain staging began March 11. The attackers created CarbonVote Token (CVT), a fabricated token of which they controlled approximately 80% of supply. They established a small trading pool (~$500 in real liquidity) and traded CVT between their own wallets to generate fake market activity at ~$1.
The attackers deployed a controlled price oracle that reported CVT as a legitimate $1 asset. Using Solana's "durable nonces" feature, they obtained pre-signed transactions from Drift Security Council members — who unknowingly authorized admin control handover.
With admin access, the attackers whitelisted CVT as collateral, deposited 500 million CVT, and withdrew $285 million in USDC, SOL, and ETH.
Every smart contract function executed as designed. The attack weaponized trust relationships and governance process, not code.
Resolv, a delta-neutral stablecoin protocol, had undergone at least 14 security audits across five auditing firms. It maintained a $500,000 Immunefi bug bounty and used Fireblocks for custody.
An attacker compromised a single AWS Key Management Service credential. Using that credential, they bypassed all smart contract controls, minted 80 million unbacked USR stablecoins against a deposit of roughly $100,000–$200,000 in USDC (a 500x ratio), and converted the minted tokens into approximately 11,409 ETH worth $23.7 million. Execution took 17 minutes.
Chainalysis characterized the incident as evidence that "DeFi protocols expand their attack surfaces by integrating cloud services and privileged keys."
TRM Labs attributes approximately $643 million — 66% of H1 2026 total losses — to North Korean-linked actors. Chainalysis placed the figure higher at 76% through April 2026. The Drift and KelpDAO operations alone accounted for $577 million.
The concentration is significant. North Korea did not conduct more operations than other threat actors. It conducted larger ones. TRM Labs noted that "the rest of the ecosystem experienced fewer large-scale thefts than in 2025. A single successful operation against a major target can still outweigh months of losses from every other attacker combined."
Since 2017, North Korean state-linked groups have stolen over $6 billion in cryptocurrency, according to TRM Labs estimates published via The Block. The 2026 H1 total of $643 million is below the $1.7 billion attributed in H1 2025, which was inflated by the Bybit breach.
North Korea's Foreign Ministry, via the Korean Central News Agency, dismissed the TRM Labs data as "absurd slander" and described it as a political tool used to justify U.S. hostile policy.
The operational pattern has evolved. In 2022–2023, DPRK-linked groups primarily targeted bridge smart contract vulnerabilities (Ronin, Harmony Horizon). In 2025–2026, the emphasis shifted to social engineering, validator key compromise, and infrastructure infiltration. The Drift attack required six months of in-person relationship building before execution.
The Resolv incident crystallized a problem the industry has been slow to acknowledge: smart contract audits examine bytecode and Solidity logic but do not audit the operational trust model of off-chain infrastructure the contract depends on.
Industry statistics indicate that 90% of exploited smart contracts had been previously audited. The median time between a DeFi protocol passing an audit and being exploited is 47 days, according to security research aggregated by CoinLaw.
Resolv passed 14 audits. KelpDAO's smart contracts functioned correctly. Drift's on-chain logic executed as programmed.
The audit industry, valued at an estimated $350 million annually according to Sherlock's 2026 market reference, is optimized for a threat model that no longer accounts for the majority of value lost. Smart contract exploits still dominate by count (125 of 207 H1 2026 incidents) but represent a shrinking share of aggregate losses.
The implication is not that audits are worthless. It is that the security perimeter has expanded beyond what audits currently cover, and protocols, users, and insurers have not adjusted their risk models accordingly.
Fewer than 2% of DeFi's $83 billion in TVL carries any form of insurance coverage. The entire DeFi insurance sector — 28 protocols combined — holds $123.5 million in TVL. Nexus Mutual accounts for nearly all of it, at approximately 0.14% of DeFi's broader market.
Since 2019, Nexus Mutual has covered over $6.5 billion in notional value and paid out $18.5 million in claims. In April 2026, a single month's losses ($600 million+) exceeded the total value locked in all insurance protocols combined by nearly 5x.
Hugh Karp, Nexus Mutual founder, stated: "Less than 2% of DeFi's TVL is covered or insured, and we see that as one of the largest barriers to real DeFi adoption."
The insurance gap has a structural cause. Dan She of CertiK noted: "Most DeFi users are yield-driven and do not want to give up several percentage points of return for cover." Insurance premiums reduce effective yield, creating adverse selection: the protocols most likely to need coverage are least likely to attract insurance capital.
Matthew Pinnock, COO of Altura, identified a second structural flaw: capital backing insurance pools is often exposed to the same risks as the protocols being covered. During a major exploit, insurance capital "evaporated precisely when it was needed most."
The off-chain attack shift compounds the problem. Traditional DeFi insurance policies typically cover smart contract failures. Key compromise, social engineering, and cloud infrastructure breaches may fall outside standard policy language.
The shift toward infrastructure-layer attacks has direct implications for how economic value flows through DeFi protocols.
When smart contract code is the attack surface, the security investment (audits, formal verification, bug bounties) produces a measurable return: fewer code-level exploits. The $350 million annual audit market has, by the numbers, succeeded in driving down the per-incident loss from code bugs.
When the attack surface shifts to AWS credentials, RPC node configurations, bridge verifier counts, and admin key management, the protocols that capture the most economic value (highest TVL, most bridge liquidity) become the highest-value targets — not because their code is weaker, but because their operational infrastructure carries the most embedded trust.
This creates an asymmetry: the economic value a protocol captures is proportional to the off-chain risk it accumulates, but neither users nor auditors are pricing that risk. The Resolv case is illustrative — 14 audits and a $500,000 bug bounty addressed on-chain risk while a single AWS key controlled $25 million in extraction potential.
For the DeFi ecosystem to sustain the economic value it captures, operational security must be capitalized and priced at a level commensurate with the assets it protects. At present, it is not.
The first half of 2026 produced a paradox: DeFi's on-chain code has never been more thoroughly audited, and its protocols have never lost more value to attacks that bypass that code entirely.
The industry's security investment is concentrated in a perimeter that no longer contains the highest-value threats. Smart contract audits, formal verification, and bug bounties address approximately 60% of incidents by count but less than 25% of losses by value. The remaining 75%+ of losses originate in infrastructure layers — cloud credentials, bridge verifiers, admin key management, social engineering of governance participants — that sit outside the scope of standard security reviews.
For protocols managing billions in TVL, the implication is concrete: operational security infrastructure requires the same level of capitalization, audit rigor, and insurance coverage as smart contract logic. The 1-of-1 DVN configuration that enabled the $292 million KelpDAO breach, the durable-nonce social engineering that drained $285 million from Drift, and the single AWS key that unlocked $25 million from Resolv are not edge cases. They are the primary attack surface of 2026.
Until the security model expands to match the actual threat landscape, the gap between what DeFi protocols earn and what they lose to exploitation will remain structurally mispriced.