The second quarter of 2026 recorded 83 crypto security incidents — the highest count for any single quarter in the history of the industry. Total losses reached approximately $755 million, according to data compiled by DefiLlama and PeckShield. Two North Korea-attributed exploits — Drift Protocol...
"Less than 2% of DeFi's TVL is covered or insured. That's one of the largest barriers to real DeFi adoption." — Hugh Karp, Founder, Nexus Mutual
The second quarter of 2026 recorded 83 crypto security incidents — the highest count for any single quarter in the history of the industry. Total losses reached approximately $755 million, according to data compiled by DefiLlama and PeckShield. Two North Korea-attributed exploits — Drift Protocol ($285M) and KelpDAO ($292M) — accounted for 76% of all hack value through April 2026, per TRM Labs.
Cross-chain bridges emerged as the dominant attack surface, absorbing $340.7 million in losses across 14 exploits year-to-date through June 1. The pattern represents a structural shift: attackers are increasingly targeting the operational layer — compromised keys, social engineering, exposed credentials — rather than exploiting smart contract logic. DeFi's total value locked has declined 39% year-to-date to $71.77 billion, and less than 2% of that capital carries any form of insurance coverage.
This report examines the anatomy of Q2 2026's record-breaking quarter, the concentration of losses in bridge infrastructure, the role of state-sponsored actors, and the widening gap between the capital at risk and the mechanisms available to protect it.
According to DefiLlama, PeckShield, and multiple blockchain analytics firms, Q2 2026 set a new record for the most crypto hacks in a single quarter:
| Metric | Q2 2026 | Previous Record | |--------|---------|-----------------| | Incident Count | 83 | ~40 (Q1 2026 est.) | | Total Losses | $755.3M | $3.56B (Q4 2020, by value) | | Largest Single Exploit | $292M (KelpDAO) | — | | Bridge-Related Losses | ~$351M (46%) | — | | Average Exploit Size | $9.1M | — |
The data reveals a structural divergence: while the total dollar value of Q2 2026 losses remains well below the $3.56 billion peak from Q4 2020, the frequency of attacks has reached an unprecedented level. Crypto protocols were exploited at a rate of approximately once per day across the quarter.
CryptoBreaking and FinanceFeeds report that the shift reflects a change in attacker strategy — more frequent, smaller-scale operations rather than occasional mega-heists. The average exploit size of $9.1 million, while significant, is substantially below the $100M+ exploits that characterized previous peak quarters.
Two incidents dominate Q2 2026's loss figures, both attributed by TRM Labs and Mandiant to North Korea's Lazarus Group (also tracked as UNC4736, AppleJeus, Citrine Sleet, and TraderTraitor).
Drift Protocol — $285 million (April 1, 2026)
The Solana-based decentralized exchange was drained in approximately 12 minutes. The Hacker News reported that the attack was the culmination of a six-month social engineering campaign. Lazarus operatives posed as a quantitative trading firm, approached Drift contributors at multiple crypto conferences in person, and convinced multisig signers to pre-sign hidden authorizations.
The attackers then pushed a zero-timelock governance migration that removed the protocol's review window, created a fake asset (CarbonVote Token), and manipulated Drift's oracle into treating it as valuable collateral. CoinDesk reported that Drift subsequently outlined a recovery plan centered on issuing recovery tokens and establishing a restitution pool starting at $3.8 million, with a target of growing to $151 million.
KelpDAO — $292 million (April 18, 2026)
Attackers targeted KelpDAO's bridge built on LayerZero, siphoning approximately 116,500 rsETH (restaked ETH tokens). According to Chainalysis and CoinDesk, the attack exploited a single-verifier configuration: LayerZero's default RPC quorum was set at 1-of-1, meaning one compromised node could authorize fraudulent cross-chain messages.
The attackers compromised two RPC nodes and launched a DDoS attack to force failover, tricking LayerZero's verifier into approving a fraudulent cross-chain transaction. Stolen funds were routed through Tornado Cash. A follow-up attempt to drain an additional 40,000 rsETH (~$95 million) was blocked. The Arbitrum Security Council froze 30,766 ETH (over $71 million) linked to the exploit.
LayerZero publicly attributed responsibility to KelpDAO's configuration choices rather than its own protocol.
The final month of Q2 produced its own sequence of exploits, demonstrating that the pace of incidents did not slow:
Humanity Protocol — $32 million (June 9) A private key belonging to a Humanity Foundation member was stolen via malware on a developer machine. CoinDesk reported that attackers drained $30M+ from 17 wallets on Ethereum, then extended the exploit to BNB Chain by seizing proxy admin control and minting 100 million additional $H tokens (~$12.9 million). The H token fell from approximately $0.67 to $0.05 — a decline exceeding 90%.
Taiko Bridge — $1.7 million (June 21-22)
The Defiant reported that an SGX signing key (enclave-key.pem) was committed to Taiko's public taikoxyz/raiko GitHub repository. Attackers used the exposed key to forge withdrawal proofs against Taiko's bridge and ERC20 vault on Ethereum. The Ethereum Layer 2 halted block production and instructed users to withdraw from all bridges deployed on the chain.
Aztec Private Rollup Bridge — $2.16 million (June 17) Attackers exploited an immutable escape-hatch function in Aztec's deprecated bridge contract that lacked proper ownership checks.
Secret Network — $4.67 million (June) An attacker exploited a vulnerability in Secret Network's modified CW20-ICS20 contract, minting approximately $4.67 million in unbacked "saTokens" that were redeemed through the legitimate bridge channel. Axelar subsequently disabled its Secret Network bridge routes.
Cross-chain bridges accounted for approximately $351 million — 46% — of Q2 2026's total stolen funds, according to PeckShield. Year-to-date through June 1, bridge losses totaled $340.7 million across 14 exploits, per a PeckShield alert.
In May 2026 alone, PeckShield tracked 8 major bridge incidents totaling $328.6 million. CoinDesk reported that bridges represented 42% of all crypto exploit losses in May despite holding a fraction of total DeFi TVL.
The concentration of risk is structural. Bridges require trust assumptions that single-chain applications do not: cross-chain message verification, relayer honesty, and multi-signature coordination. When any of these layers fail, the entire liquidity locked in the bridge is at risk.
SpazoCrypto and Yellow Research attribute the persistence of bridge vulnerabilities to a design-level problem: bridges are inherently complex multi-system integrations that combine consensus verification, message passing, and asset custody — each of which presents a distinct attack surface. According to Chainlink's analysis of cross-chain bridge vulnerabilities, seven distinct vulnerability categories exist, ranging from forged message attacks to validator collusion.
A defining characteristic of Q2 2026 is the shift from smart contract exploits to operational security failures. Crypto Economy and Altfins note that auditing code no longer addresses the primary threat vectors.
The data bears this out:
Compromised administrator attacks and private key compromises accounted for approximately 43% of Q2 losses. According to the existing body of research, smart contract logic bugs — the attack vector that defined DeFi exploits from 2020 to 2023 — now represent a diminishing share of total losses.
This shift has implications for the security industry. Code audits, which command fees of $50,000 to $250,000+ per engagement according to industry data, address only a subset of the current threat landscape. The protocols that lost the most capital in Q2 2026 had been audited.
TRM Labs reported that North Korea stole 76% of all crypto hack value in 2026 through just two attacks (Drift and KelpDAO). The combined $577 million from those two exploits alone exceeds the GDP of several small nations.
DPRK-linked actors stole $2.02 billion in 2025, per TRM Labs — a 51% year-on-year increase. Cumulative attributed DPRK crypto theft now exceeds $6.75 billion since 2017. The UN Panel of Experts has documented links between crypto theft proceeds and North Korea's ballistic missile and nuclear weapons development programs.
The operational sophistication is increasing. The Drift exploit required a six-month, in-person social engineering campaign — a level of investment that suggests state-level resources and planning. Sanctions.io notes that compliance teams face a persistent challenge: DPRK actors operate through multiple sub-groups (TraderTraitor, AppleJeus, Citrine Sleet, Golden Chollima, Gleaming Pisces) with overlapping but distinct operational signatures.
Against this backdrop of record incident frequency, DeFi's insurance infrastructure remains negligible. According to Nexus Mutual founder Hugh Karp, less than 2% of DeFi's $71.77 billion TVL carries any form of insurance coverage.
DefiLlama lists 28 insurance protocols, but Nexus Mutual alone accounts for nearly the entire sector's $123.5 million in TVL — representing just 0.14% of the broader DeFi market.
CoinDesk reported in May 2026 that in the last six years, uninsured lending protocols have lost $7.7 billion to exploits. Over $600 million was lost in April 2026 alone. The publication noted that DeFi users consistently choose yield over protection, and insurance pools often share the same vulnerabilities as the protocols they purport to cover.
The crypto insurance market is projected to grow from $9.49 billion in 2025 to $192.72 billion by 2033, according to Grand View Research — a 45.8% CAGR. Whether this growth materializes depends on whether insurance products can price the operational security risks that now dominate the loss landscape.
Q2 2026 marks a structural inflection in DeFi security. The record is not defined by dollar losses — Q4 2020's $3.56 billion remains the peak — but by frequency. The industry now sustains approximately one exploit per day, a pace that implies systemic rather than episodic vulnerability.
The concentration of losses in bridge infrastructure and operational security failures points to a mismatch between where security spending is directed (code audits) and where value is actually lost (key management, social engineering, configuration errors). The two largest exploits of the quarter required no smart contract vulnerability whatsoever.
The insurance gap compounds the problem. With less than 0.14% of DeFi TVL covered by insurance protocols, the industry operates without the risk-transfer mechanisms that underpin every other financial market. Until that changes, the economic cost of each exploit is borne entirely by depositors.
The data suggests that DeFi's security challenge is no longer primarily a software engineering problem. It is an operational security, governance, and risk management problem — one that the current infrastructure is not equipped to address.