Q2 2026 recorded 83 separate crypto exploit incidents, the highest quarterly count on record, according to analysis by Unfolded based on DefiLlama data. Total losses reached $755 million. April alone accounted for $635 million across 28 exploits — the worst single month in crypto history outside ...
"We're in a vulnerability apocalypse. New AI models have shifted the playing field in favor of attackers." — Mitchell Amador, CEO, Immunefi
Q2 2026 recorded 83 separate crypto exploit incidents, the highest quarterly count on record, according to analysis by Unfolded based on DefiLlama data. Total losses reached $755 million. April alone accounted for $635 million across 28 exploits — the worst single month in crypto history outside of the February 2025 Bybit event.
The data marks a structural shift. Attack frequency increased 70% year-over-year versus Q2 2025, but median loss per incident fell. Cross-chain bridges accounted for $351 million of the quarter's losses, nearly half the total. State-backed actors linked to North Korea's Lazarus Group were responsible for an estimated 76% of all crypto hack value through April 2026, according to Chainalysis and TRM Labs.
More than 40 DeFi protocols have shut down in 2026. The exploit-survival rate has deteriorated; incidents that were previously recoverable are now terminal. Cumulative year-to-date losses through June 2026 exceed $1.5 billion, with the KelpDAO ($293M) and Drift Protocol ($285M) exploits comprising the bulk.
The quarter's exploit data, compiled from DefiLlama, Peckshield, and CertiK tracking:
| Metric | Q2 2026 | Q1 2026 | Q2 2025 (est.) | |--------|---------|---------|----------------| | Incidents | 83 | ~50 | ~49 | | Total Losses | $755M | $450M+ | ~$400M | | Largest Single Exploit | $293M (KelpDAO) | $340M (January cluster) | — | | Bridge-Related Losses | $351M (46.5%) | ~$120M | — | | DPRK-Attributed (%) | ~76% | ~60% | — |
April 2026 was the inflection point. That month saw $635 million drained across 28 separate exploits, roughly quadrupling the $167 million stolen during the entire first quarter's quieter months. May dropped to $68 million in confirmed losses according to CertiK, but June's running total, which includes the $36 million Humanity Protocol exploit and two Aztec Connect drains of $2.1 million each, has pushed the quarter's aggregate past $750 million.
The frequency-versus-severity dynamic is notable. Q2 2026 set the incident count record but fell well below the $3.56 billion lost in Q4 2020 (adjusted for the Ronin/Poly Network era). The data suggest more attackers operating at smaller scale, with two large DPRK-linked operations accounting for the majority of dollar losses.
KelpDAO — $293 million (April 18, 2026)
The quarter's largest exploit targeted KelpDAO's rsETH bridge built on LayerZero's Omnichain Fungible Token (OFT) standard. Chainalysis attributed the attack to North Korea's Lazarus Group, specifically the TraderTraitor cluster.
The attack exploited a single-point-of-failure in KelpDAO's bridge verification setup: a 1-of-1 DVN (Decentralized Verifier Network) configuration that relied exclusively on LayerZero Labs' own infrastructure. Attackers compromised two internal RPC nodes operated by LayerZero while simultaneously DDoS-ing external nodes, then forged a cross-chain message to drain 116,500 rsETH. According to Nexus Mutual's post-incident analysis, the entire drain took under 46 minutes.
The subsequent blame dispute between KelpDAO and LayerZero exposed a systemic governance gap. KelpDAO claimed LayerZero approved the 1-of-1 DVN configuration; LayerZero responded by announcing it would no longer sign messages from applications using single-verifier setups. OpenZeppelin's post-mortem titled the analysis: "$292 Million Lost, Zero Bugs Found" — highlighting that the vulnerability was architectural, not code-level.
Drift Protocol — $285 million (April 1, 2026)
Drift, a Solana-based perpetuals DEX, was drained through a combination of oracle manipulation and admin key compromise. Bloomberg reported the exploit as the second-largest in Solana's history, behind only the $326 million Wormhole bridge hack in 2022.
The attackers manufactured a fictitious asset — CarbonVote Token — with minimal seeded liquidity and wash trades. Drift's oracle infrastructure treated it as legitimate collateral worth hundreds of millions. Simultaneously, attackers exploited Solana's "durable nonces" feature to trick Security Council members into pre-signing dormant transactions, which were later triggered to transfer admin control.
Drift's TVL collapsed from $550 million to under $300 million within an hour. The DRIFT token dropped 40%. TRM Labs and Drift's own assessment attributed the attack with "medium-high confidence" to the same North Korean actors behind the October 2024 Radiant Capital hack (UNC4736/AppleJeus/Citrine Sleet).
Drift's recovery plan involves issuing recovery tokens pegged to verified user losses, funded from a pool starting at $3.8 million with a target of $151 million drawn from protocol revenue and partner contributions including Tether.
Cross-chain bridges accounted for $351 million in Q2 losses — 46.5% of the quarter's total. Peckshield tracked eight bridge-related exploits draining $328.6 million in the first half of 2026 alone.
The data compounds a persistent pattern. Bridges have accounted for more than $2.8 billion in cumulative losses to date, representing approximately 40% of all value hacked in Web3, according to Presto Research.
Q2's bridge exploits included:
The vulnerability taxonomy has not changed. According to 1inch's security analysis: "Signature replay, nonce collision, and chain-id confusion are still draining millions in 2026." Bridge infrastructure produced two of the three largest DeFi exploits of the year. The failure modes are structurally identical to 2022-era attacks, operating at larger scale.
DPRK-linked actors stole approximately $635 million from crypto protocols in April 2026 alone across 12 separate attacks, according to KuCoin research citing TRM Labs data. The two largest — KelpDAO and Drift — accounted for $578 million combined.
TRM Labs reported that North Korea accounted for 76% of all crypto hack value in 2026 through April, achieved with just two primary operations. The cumulative DPRK theft total now exceeds $6 billion in attributed incidents since 2017. The 2025 figure was $2.02 billion, a 51% year-over-year increase, including the $1.5 billion Bybit hack attributed by the FBI to TraderTraitor.
The operational pattern identified by Chainalysis and Elliptic shows consistent methodology: compromise of off-chain infrastructure (RPC nodes, admin laptops, oracle feeds) rather than on-chain smart contract exploits. In the Humanity Protocol case ($36M, June 8), a single phishing email impersonating South Korean exchange Bithumb compromised an employee laptop hosting multiple bridge admin keys — three of six Ethereum keys and three of five BNB Chain keys stored on the same device. Quantstamp attributed the malware to North Korean threat actors.
The DPRK's operational tempo has accelerated. Mandiant's tracking of UNC4736 shows the group now targets multiple protocols simultaneously, rather than sequencing attacks as in prior years.
Immunefi CEO Mitchell Amador described the current environment as a "vulnerability apocalypse" at the WAIB Summit in Monaco, attributing the surge in exploits to frontier AI models that have expanded attackers' capabilities to identify and exploit weaknesses. According to Amador, the crypto industry faces a 3-4 year window to develop defensive AI capabilities before attack tooling matures further.
The claim aligns with observable data: Q2 2026's 83 incidents represent a 70% increase over the same window in 2025. April's 28 separate exploits in a single month suggest either a larger pool of capable attackers or existing actors operating more efficiently.
The data is inconclusive on direct AI causation. Correlation between AI model releases and exploit frequency does not establish that attackers are using these specific models. However, the shift toward more frequent, smaller-scale attacks — diverging from the historical pattern of fewer, larger breaches — is consistent with tooling that lowers the skill floor for exploit development.
CoinDesk reported that Elliptic CEO James Smith warned crypto security is "turning into an AI arms race" in which AI-assisted threat detection may be overwhelmed by AI-assisted attack generation. Elliptic observed that attackers are increasingly using AI agents to automate reconnaissance of smart contracts and identify configuration weaknesses in bridge infrastructure.
Over 40 DeFi protocols have shut down in 2026, according to CryptoTimes. The pattern suggests that major exploits have become terminal events rather than survivable setbacks.
In prior cycles, exploited protocols typically survived through community rallies, treasury backstops, and governance-authorized recovery plans. In 2026, the recovery rate has deteriorated. CryptoTimes projects an additional 15-25 mid-tier protocol shutdowns by year-end, concentrated in lending, perpetuals, and chain-specific DeFi tooling on low-activity L1s and L2s.
The economic logic is straightforward. The blockchain sector generates approximately $13.7 billion in identifiable on-chain revenue annually against $55-71 billion in annual subsidy mechanisms. Protocols operating on thin margins — particularly those dependent on inflationary token rewards rather than fee revenue — cannot absorb eight-figure or nine-figure exploit losses. When exploits exceed a protocol's total fee revenue, the math no longer works.
The cascade effect compounds losses. KelpDAO's $293 million drain triggered $1.3 billion in withdrawals from related protocols, according to CoinDesk. Drift's exploit knocked $250 million off Solana DeFi TVL within hours, beyond the directly stolen funds.
DeFi insurance coverage remains a fraction of the assets at risk. Nexus Mutual, the sector's largest on-chain insurer, generated $5.7 million in cover fees in 2025, according to the protocol's public disclosures. That figure implies total insured value of roughly $570 million to $1.14 billion, depending on premium rates (0.5%-1% annually).
Against Q2 2026's $755 million in losses alone, the coverage gap is stark. Total DeFi TVL exceeded $277.6 billion in 2025. If insurance penetration remains below 1% of TVL, the sector is self-insuring 99%+ of exploit risk — and doing it poorly.
Traditional Lloyd's-backed coverage exists (Coincover offers plans from $159/year for up to $10,000) but scales poorly to institutional-grade positions. Premium rates of 0.5%-2% of insured value are prohibitive for protocols managing hundreds of millions in TVL, particularly when those premiums must come from fee revenue that, for most protocols, is already insufficient to cover operating costs.
The recovery mechanism for the quarter's two largest exploits illustrates the ad hoc nature of post-exploit remediation. Drift's recovery pool targets $151 million against $285 million in losses — a 53% recovery rate at best, contingent on future revenue generation and partner goodwill. KelpDAO's recovery remains entangled in the LayerZero blame dispute, with rsETH stranded across 20 chains.
The Q2 2026 data presents a sector where security infrastructure has not scaled with asset growth. The dominant attack vectors — bridge verification weaknesses, admin key management failures, oracle manipulation — are not novel. They are the same classes of vulnerabilities that produced the Ronin, Wormhole, and Nomad exploits in 2022. Four years later, the failure modes persist at larger scale.
The economic implications are measurable. The blockchain sector's $13.7 billion in annual on-chain revenue loses roughly 10% annually to exploits at the current run rate. For an industry where 85-90% of value flows are already subsidy-driven, that leakage rate compounds the sustainability gap.
The shift toward more frequent, lower-value exploits alongside persistent state-sponsored megahacks suggests the threat surface is widening in both directions. Whether AI-augmented attack tooling is the proximate cause, as Immunefi's Amador argues, or simply a contributor to an existing structural trend, the data shows the problem is worsening in 2026, not improving.