April 2026 recorded $650.9 million in cryptocurrency losses across more than 20 separate incidents, according to CertiK. This makes it the worst single month for crypto exploits since March 2022. DeFiLlama's parallel tracker places the figure at $629.69 million, with variance attributable to diff...
"North Korea stole 76% of all crypto hack value in 2026 — with just two attacks." — TRM Labs, Threat Intelligence Report, April 2026
April 2026 recorded $650.9 million in cryptocurrency losses across more than 20 separate incidents, according to CertiK. This makes it the worst single month for crypto exploits since March 2022. DeFiLlama's parallel tracker places the figure at $629.69 million, with variance attributable to differing classification methodologies.
Two incidents — the $285 million Drift Protocol breach on April 1 and the $292 million Kelp DAO exploit on April 19 — account for approximately 89% of the month's total. Both have been attributed with medium-to-high confidence to North Korean state-sponsored hacking groups by TRM Labs, Elliptic, and Chainalysis. Year-to-date losses through April now stand at approximately $1.08 billion across 68 incidents, according to The Currency Analytics, though alternate trackers place the figure between $771.8 million and $1.08 billion depending on inclusion criteria.
The data marks a structural shift in attack methodology. Social engineering and compromised admin keys — not smart contract logic bugs — drove the majority of value lost. DeFi insurance capacity, meanwhile, remains at roughly $200 million in total pooled capital across all providers, covering less than 0.03% of total value locked in DeFi protocols.
| Period | Losses | Incidents | Primary Vector | |--------|--------|-----------|----------------| | January 2026 | ~$340M | ~25 | Phishing/social engineering | | February 2026 | ~$10–26.5M | ~12 | Mixed | | March 2026 | ~$25–52M | ~20 | Smart contract exploits | | April 2026 | $629–651M | 20–24 | Admin key compromise | | YTD 2026 | $771M–$1.08B | 47–68 | Social engineering |
Source figures vary by tracker. CertiK reports $650.9 million for April; DeFiLlama reports $629.69 million. The discrepancy reflects differing treatment of partially recovered funds, bridge losses, and CEX incidents.
For comparison, Q1 2026 total losses stood at $168 million to $482 million depending on the source, meaning April alone exceeded the entire preceding quarter by a factor of 1.3x to 3.9x.
Sector breakdown for April, per CertiK:
Drift, Solana's largest decentralized perpetual futures exchange with approximately $550 million in TVL pre-exploit, was drained through a multi-stage operation that TRM Labs attributes to North Korean state-sponsored group UNC4736 (also tracked as AppleJeus, Citrine Sleet, and Gleaming Pisces).
The attack began in fall 2025. Operators posed as a quantitative trading firm to build trust with Drift contributors over a period of approximately six months, according to Chainalysis and CoinDesk reporting. The technical execution involved:
Drift's TVL fell from $550 million to under $300 million within an hour. The DRIFT token dropped more than 40%, according to Bloomberg.
Kelp DAO's LayerZero-powered bridge was exploited for 116,500 rsETH — approximately 18% of the token's circulating supply — valued at $292 million. The attacker drained wrapped ether stranded across 20 chains.
The exploit prompted emergency pauses at Aave, Lido Finance, and Ethena for rsETH-denominated markets. Kelp DAO subsequently initiated what has been described as DeFi's largest-ever bailout operation, as covered separately in prior webthreepedia analysis.
Beyond the two mega-exploits, April recorded at least 18 additional incidents:
These smaller incidents collectively account for approximately $27–35 million — a fraction of the two headline exploits, but illustrative of the breadth of attack surface across the ecosystem.
TRM Labs data published April 30 shows North Korean-linked groups account for 76% of all crypto hack value in 2026 through April — accomplished through just two operations (Drift and Kelp DAO). Cumulative DPRK-attributed theft since 2017 now exceeds $6 billion, with some estimates from BlockEden placing the all-time figure at $6.75 billion.
The operational profile has shifted. According to The Hacker News reporting on the Drift breach, the attack was traced to a six-month social engineering operation. This represents a departure from the pure-technical exploitation of earlier Lazarus Group campaigns. CoinDesk reported that North Korean operatives spent months in person to build trust before executing the Drift drain.
Elliptic flagged the Drift exploit as a "likely North Korea-linked operation" within 24 hours, citing on-chain patterns consistent with prior DPRK laundering infrastructure. The Kelp DAO attack was subsequently attributed to the same cluster by TechCrunch and UPI citing multiple blockchain forensics firms.
The implications are material: two state-sponsored operations accounted for $577 million of the $650 million monthly total. The remaining $73 million was distributed across 20+ non-state incidents — suggesting the baseline rate of non-state exploitation remains consistent with prior months while state-level activity has sharply escalated.
The April data reveals a pattern: the largest losses stem not from smart contract vulnerabilities but from compromised administrative access.
This aligns with CertiK's January 2026 forecast that "AI deepfakes and phishing will drive the biggest crypto hacks in 2026." The firm reported that $306 million — nearly two-thirds of Q1 2026 losses — came from phishing and social engineering attacks, not code exploits.
The structural issue is that many DeFi protocols, despite managing hundreds of millions in user deposits, rely on single externally-owned accounts or small multisig setups for upgrade authority. When Wasabi's sole deployer key was compromised, the attacker granted themselves admin privileges and upgraded vault contracts within a single transaction — no governance vote, no timelock delay, no community notification.
A parallel development complicates the security outlook. Research published by Anthropic demonstrated that AI agents have improved from exploiting 2% of benchmark vulnerabilities to 55.88%, increasing total exploit revenue from $5,000 to $4.6 million in controlled testing. Agents uncovered two novel zero-day vulnerabilities independently.
A systematic study published on arXiv on April 8, 2026 tested 428 AI API routers and found 9 actively injected malicious code, 17 accessed researcher AWS credentials, and at least one free router drained ETH from a researcher-controlled wallet.
The Wasabi Protocol exploit revived what BeInCrypto described as the "AI hacker theory" — the hypothesis that some exploits may be identified or partially executed by autonomous AI agents scanning for common vulnerability patterns such as unprotected admin keys and upgradeable proxies. No confirmed AI-driven exploit has been publicly attributed, but the technical feasibility has been demonstrated.
The OECD AI Incident Monitor flagged AI-driven attacks as contributing to major crypto thefts in 2026, noting that North Korean groups have incorporated AI for social engineering, deepfake creation, and automated vulnerability scanning.
Recovery rates have collapsed. Immunefi recorded only 0.4% of Q1 2025 stolen funds recovered, down from 21.2% in Q1 2024. For the Bybit hack of February 2025 ($1.5 billion), recovery remained below 5% as of early 2026, with the bulk laundered through OTC networks.
No recovery has been reported for the Drift Protocol funds. Kelp DAO's bailout operation is ongoing. Grinex's funds appear unrecoverable given the exchange's sanctioned status.
DeFi insurance capacity remains structurally inadequate. Nexus Mutual, the largest provider, holds a capital pool of approximately $200 million, mostly in ETH. The protocol generated $5.7 million in cover fees in 2025. Total DeFi TVL across all chains exceeds $100 billion. The insurance-to-TVL ratio is approximately 0.2%, meaning that 99.8% of deposited value carries no exploit coverage.
Nexus Mutual explicitly does not cover team malfeasance or lost private keys — precisely the attack vectors responsible for the majority of April 2026 losses.
April 2026 exposes a persistent structural asymmetry in DeFi security architecture. Protocols holding hundreds of millions in user deposits continue to concentrate administrative authority in single keys or small multisig arrangements, while state-sponsored adversaries invest months of operational planning to compromise those chokepoints.
The economic value distribution matters here: when users deposit funds into DeFi protocols, they are implicitly trusting not just audited code but the operational security practices of anonymous or pseudonymous teams managing upgrade keys. The $650 million April total represents a direct transfer of user-deposited value to adversaries — value that, based on current recovery rates, is overwhelmingly non-recoverable.
The insurance market has not scaled to match the risk. At 0.2% coverage of TVL, the DeFi insurance sector would require roughly 500x growth in capital pools to approach meaningful coverage levels — and would need to expand its coverage definitions to include the admin key and social engineering vectors that now dominate losses.
Until the gap between attack surface and defensive infrastructure closes, monthly loss figures of this magnitude remain a structural feature, not an anomaly, of the current DeFi landscape.