The first half of 2026 recorded 207 successful crypto attacks — the highest incident count for any six-month period on record — yet aggregate losses totaled $972 million, falling below the $1 billion mark and representing a 74% decline from 2022's $2.62 billion peak. The data, compiled by Immunef...
"The median critical bounty costs $20,000. The hack it prevents costs $25,000,000 and three months of your life." — Immunefi, via official platform communications
The first half of 2026 recorded 207 successful crypto attacks — the highest incident count for any six-month period on record — yet aggregate losses totaled $972 million, falling below the $1 billion mark and representing a 74% decline from 2022's $2.62 billion peak. The data, compiled by Immunefi, reveals a structural shift: attackers are moving from smart-contract code exploits toward infrastructure-layer compromises, including private key theft, RPC node manipulation, and social engineering of privileged access holders.
Two incidents — the $285 million Drift Protocol exploit on April 1 and the $292 million KelpDAO breach on April 18 — accounted for more than half of all H1 losses. Both were attributed by blockchain forensics firms to North Korea's Lazarus Group, which according to Chainalysis data was responsible for roughly 76% of all crypto hack value through April 2026. Meanwhile, fewer than 2% of DeFi's $83 billion in total value locked carries any insurance coverage, according to DeFiLlama and CoinInsider data — an exposure gap that the KelpDAO crisis forced the industry to confront through "DeFi United," the first multi-protocol coordinated bailout in DeFi history.
Immunefi's mid-year report documented 207 confirmed attacks between January 1 and June 30, 2026. Of these, 125 were smart-contract exploits, though they accounted for a minority of stolen value. The remaining 82 involved infrastructure compromises — private key theft, social engineering, compromised RPC endpoints, and cross-chain configuration errors.
Total losses reached $972 million, distributed unevenly across quarters:
April alone accounted for more than $640 million, driven by two mega-exploits. The concentration is notable: the top five incidents represented roughly 80% of all value stolen, while the median exploit yielded under $500,000.
DeFi exploit losses have fallen 74% from the 2022 peak of $2.62 billion to $680.3 million in DeFi-specific losses for H1 2026, according to Immunefi. Attack frequency, however, continues to climb — up from 167 incidents in H1 2025 to 207 in H1 2026, a 24% increase.
The most consequential finding in Immunefi's H1 data is the migration of attack surfaces. Compromised accounts and infrastructure failures now account for more than 50% of all DeFi attack losses by value — overtaking traditional smart-contract exploits as the primary damage vector for the first time.
Smart-contract bugs still dominate by incident count (125 of 207), but individually these tend to produce smaller losses. The large-scale thefts increasingly stem from:
This represents a structural change in the threat landscape. Auditing firms have improved their ability to catch code-level vulnerabilities — automated scanners now identify 70-80% of low-level flaws, according to industry data from CoinLaw. But operational security, key management, and infrastructure hardening remain underinvested relative to the risk they carry.
North Korea's Lazarus Group (also tracked as APT38, TraderTraitor, and UNC4736) has become the dominant threat actor in crypto security. According to Chainalysis data, DPRK-linked actors were responsible for approximately 76% of all crypto hack value through April 2026.
The group's cumulative all-time theft stands at approximately $6.75 billion across documented incidents, according to data compiled by Chainalysis and TRM Labs. Major attributed incidents include:
| Date | Target | Amount | Attribution Source | |------|--------|--------|--------------------| | Mar 2022 | Ronin Network | $625M | FBI | | May 2024 | DMM Bitcoin | $308M | FBI | | Feb 2025 | Bybit | $1.5B | FBI / TraderTraitor | | Apr 2026 | Drift Protocol | $285M | Elliptic / Mandiant | | Apr 2026 | KelpDAO | $292M | Chainalysis / TRM Labs |
The UN Panel of Experts has estimated that crypto theft funds a material proportion of North Korea's ballistic missile and nuclear weapons development programs. Cryptobriefing reported that North Korea-linked hackers stole $643 million in crypto in H1 2026 alone.
The operational sophistication has increased. The Drift exploit used social engineering to trick legitimate Security Council members into signing delayed transactions that transferred admin control. The KelpDAO attack compromised RPC nodes feeding LayerZero's verification system, then executed a coordinated DDoS attack to force fallback to compromised infrastructure. Lazarus Group was also linked to $577 million in losses during April alone, using fileless RAM malware in some campaigns, according to AI Weekly reporting.
Drift, the largest DeFi protocol on Solana by TVL, lost $285 million after attackers used social engineering to gain admin control. The attacker deposited 500 million units of a fabricated token and used it to withdraw $285 million in USDC, SOL, and ETH. Bloomberg reported the incident as the year's largest at the time.
At least 20 other protocols that relied on Drift's liquidity experienced disruptions. Drift subsequently announced a recovery plan centered on issuing recovery tokens pegged to verified user losses, according to CoinDesk reporting from May 5.
KelpDAO's exploit targeted its LayerZero-powered cross-chain messaging system, which relied on a single decentralized verifier network (DVN) — below the industry-recommended multi-DVN configuration. The attacker minted 116,500 unbacked rsETH tokens, which were then used to borrow ETH from Aave.
The incident caused $13 billion in DeFi TVL drawdown over the subsequent weekend, pushing total DeFi TVL to $85.64 billion — its lowest point since April 2025, according to Sherwood News. At least nine DeFi protocols reported direct exposure.
The most recent exploit targeted Summer.fi's Lazy Summer Protocol. An attacker used a $65.4 million flash loan from Morpho, routed through Curve, Uniswap, and Balancer to manipulate vault liquidity and share prices, netting approximately $6 million. Blockaid identified the exploit as a flaw in the protocol's share accounting mechanism. Summer.fi paused all Lazy Summer vaults.
While smaller in absolute terms, the Summer.fi exploit highlighted a newer risk category: AI-automated yield strategies operating at machine speed create attack surfaces that cannot be manually monitored in real time. CryptoSlate reported that the incident demonstrated how AI automation now sits above smart-contract risk as a new layer of vulnerability.
The KelpDAO crisis produced a first-of-its-kind response: "DeFi United," a coordinated multi-protocol recovery initiative organized by Aave founder Stani Kulechov. Seven protocols and individual contributors pledged capital to restore rsETH backing and prevent cascading liquidations across Aave.
According to CoinDesk and Phemex reporting, the coalition raised 69,534 ETH (approximately $161 million) from:
DeFi United represents the first coordinated, multi-protocol recovery effort in the industry's history. It established a de facto precedent for mutual aid among composable protocols — but also raised questions. Who decides which exploits warrant a bailout? What governance structures prevent moral hazard? The answers remain undefined. The coalition operated through ad hoc coordination, not through any pre-existing framework.
The economic logic is straightforward: Aave's TVL dropped by $10 billion following the KelpDAO incident. The cost of the bailout ($161 million) was substantially less than the systemic damage of allowing cascading bad debt. But this calculus only works when major protocols have aligned incentives, which may not hold in every future incident.
The DeFi insurance market remains structurally undersized relative to the risk it is supposed to cover. According to CoinInsider, fewer than 2% of DeFi's $83 billion in TVL carries any form of insurance coverage.
DeFiLlama lists 28 active insurance protocols, but Nexus Mutual alone accounts for nearly all of the sector's $123.5 million in TVL — approximately 0.14% of DeFi's broader market. Nexus Mutual's capital pool holds approximately $190 million, with active coverage underwritten at around $194 million.
Since 2019, Nexus Mutual has covered more than $6.5 billion in cumulative value and paid out just $18.5 million in claims — a claims ratio that suggests either effective risk selection or, more likely, insufficient adoption to generate statistically meaningful claims volume.
The gap between insured and uninsured value creates a structural dependency on ad hoc responses like DeFi United. Without systematic risk transfer mechanisms, the DeFi ecosystem relies on the goodwill of well-capitalized protocols to absorb losses that, in traditional finance, would be handled by insurance and clearinghouse guarantee funds.
Nexus Mutual's recent integration with Symbiotic to create yield-generating reinsurance vaults represents one attempt to address the capital supply side. But the demand side — protocols and users purchasing coverage — remains underdeveloped. As Nexus Mutual's own data shows, generating $5.7 million in annual cover fees against a $190 million capital pool reflects a utilization rate far below what is needed to build a viable insurance market.
On the defensive side, Immunefi's platform paid researchers approximately $13.45 million to surface 837 valid bugs before attackers could exploit them in H1 2026. The platform has paid out over $115 million to date across more than 400 active bug-bounty programs.
The economics are asymmetric: the median critical bounty payout is $20,000, while the mean is $114,355 — pulled up by outlier payouts including a $10 million award to researcher satya0x for a Wormhole vulnerability and $2 million to researcher Saurik for an Optimism bug.
Immunefi data shows that 93.9% of bug-bounty programs active for five years or longer have logged at least one confirmed, paid critical-severity disclosure. This suggests that sustained security monitoring via bounty programs reliably surfaces material vulnerabilities — but only for protocols that invest in them.
The Aptos case provides a recent illustration. In February 2026, Hexens identified a stale-cache bug in the Aptos Move virtual machine that created a type-confusion vulnerability. Researchers demonstrated a successful attack simulation with over 90% success rate using servers costing only $3,000. Hexens assessed the broader systemic risk at approximately $70 billion, accounting for exposure through bridges, cross-chain messaging, stablecoin admin flows, and centralized exchanges. Aptos Labs patched the issue on February 27; the finding was disclosed publicly on July 4, according to CoinDesk.
The H1 2026 data presents a paradox: DeFi security is simultaneously improving and deteriorating. Per-incident losses are down sharply from prior years, code auditing has become more rigorous, and white-hat programs are surfacing critical bugs at scale. But the attack surface has expanded upstream — into infrastructure, key management, and operational processes that sit outside the scope of traditional smart-contract audits.
The industry's response mechanisms remain improvised. DeFi United demonstrated that major protocols can coordinate under crisis conditions, but the absence of standing insurance infrastructure or formalized loss-sharing frameworks means each new incident requires ad hoc negotiation. With fewer than 2% of assets insured and state-backed actors responsible for three-quarters of stolen value, the gap between the capital at risk and the capital allocated to protect it remains the defining structural weakness of the DeFi ecosystem.
The economic value generated by DeFi protocols — fees, yields, settlement efficiency — is real. But so is the cost of inadequate security infrastructure. Until the industry builds systematic risk transfer mechanisms proportionate to the capital it custodies, each quarter's loss figures will remain a function of whether well-resourced attackers happen to find exploitable configurations, rather than a managed risk with predictable bounds.