DeFi protocols lost $1.1 billion to exploits over the past 12 months, with $577 million of $651 million in 2026 year-to-date losses attributed to North Korean state actors, according to TRM Labs. Total value locked across DeFi fell from $172 billion in mid-April to approximately $148 billion by l...
"I now consider all of DeFi unsafe. Coding agents are superhuman at finding vulnerabilities, and smart contract security is too asymmetric: defenders need to fix every bug while attackers need just one exploit to steal funds." — Manuel Aráoz, Co-founder, OpenZeppelin
DeFi protocols lost $1.1 billion to exploits over the past 12 months, with $577 million of $651 million in 2026 year-to-date losses attributed to North Korean state actors, according to TRM Labs. Total value locked across DeFi fell from $172 billion in mid-April to approximately $148 billion by late May — a 14% contraction driven by a combination of capital flight and price-driven compression following a cascade of exploits.
On May 26, OpenZeppelin co-founder Manuel Aráoz publicly declared that he considers "all of DeFi unsafe," citing the asymmetric advantage that AI-powered coding agents now provide to attackers. Three days earlier, Socket disclosed the TrapDoor campaign — a coordinated supply chain attack across npm, PyPI, and Crates.io that planted 34 malicious packages targeting crypto and AI developers. The convergence of on-chain exploit escalation, off-chain supply chain infiltration, and AI-augmented vulnerability discovery has produced a security environment without clear precedent in the sector's history.
DeFi protocols have hemorrhaged capital at an accelerating rate. According to TRM Labs, $651 million was stolen from crypto protocols in the first four months of 2026 alone. April 2026 was the worst single month, with DefiLlama recording 27 separate exploit incidents. May added another 25 through the 27th.
The two largest incidents account for the bulk of losses:
| Incident | Date | Amount | Method | |---|---|---|---| | KelpDAO LayerZero Bridge | April 18, 2026 | $292 million | RPC node compromise; single-verifier config exploited | | Drift Protocol | April 1, 2026 | $285 million | Social engineering; durable nonce abuse on Solana |
Together, these two attacks represent $577 million — 89% of 2026 year-to-date losses — yet constitute only 3% of total hack incidents, according to TRM Labs. The concentration of loss in a small number of high-value targets mirrors a pattern observed in traditional financial crime: sophisticated actors pursue maximum extraction per operation.
The KelpDAO exploit was particularly instructive. Attackers compromised two RPC nodes relied upon by LayerZero's verifier, replacing node software with malicious versions that fabricated cross-chain transaction confirmations. The attack succeeded because KelpDAO used a single-verifier configuration despite LayerZero's recommendation to deploy multiple independent verifiers. One poisoned data source was sufficient to approve a $292 million fraudulent withdrawal spanning 20 chains.
Drift Protocol's breach was different in character but equal in scale. North Korean operatives spent six months embedding themselves through social engineering, ultimately using Solana's durable nonces feature to get Security Council members to pre-sign transactions that transferred admin control. The attackers then whitelisted a worthless token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH within 10 seconds.
TRM Labs data shows that North Korean state-affiliated groups — tracked under designations including Lazarus Group, TraderTraitor, AppleJeus, and Citrine Sleet — accounted for 76% of all cryptocurrency hack losses in the first four months of 2026. This continues a trajectory of escalating dominance:
| Year | North Korea's Share of Global Crypto Hack Losses | |---|---| | 2020-2021 | Below 10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 (Jan-Apr) | 76% |
Cumulative attributed theft by North Korean actors now exceeds $6 billion since 2017, per TRM Labs. The 2025 total included the $1.5 billion Bybit exploit — the single largest crypto theft on record, per Chainalysis.
Two observations follow from this data. First, the state-level resourcing behind these attacks means defenders face adversaries with multi-month operational patience, dedicated social engineering teams, and zero legal risk tolerance. Second, the concentration of losses in North Korean operations suggests that independent criminal groups are extracting a declining share of total value — either because state actors are crowding them out or because the highest-value targets require resources beyond individual hacking groups.
The immediate market consequence has been measurable. Total DeFi TVL dropped from approximately $172 billion in mid-April to $148 billion by late May, according to The Block, citing DefiLlama data — a 14% decline. A Portals.fi weekly report for the fourth week of May pegged total DeFi TVL at $82.08 billion under a different methodology that excludes certain liquid staking and bridged assets.
Lending protocols — the largest DeFi category — experienced the steepest drawdown, declining from approximately $53 billion to $40 billion over the same period, per The Block. This represents a 24.5% contraction in the sub-sector most sensitive to counterparty risk perceptions.
JPMorgan noted in a May research note that DeFi exploits and stagnant TVL "continue to limit institutional appeal," per a report in The Block. The observation is consistent with capital rotation data: market participants are moving toward stablecoins and lower-risk yield venues.
Following the KelpDAO exploit, Aave, SparkLend, and Fluid froze markets involving rsETH. The Arbitrum Security Council, coordinating with law enforcement, froze over 30,000 ETH of downstream attacker funds — demonstrating that emergency response mechanisms exist but are reactive rather than preventive.
On May 24, Socket disclosed the TrapDoor campaign, a coordinated supply chain attack that planted 34 malicious packages across 384+ versions in three package ecosystems:
wallet-security-checker, web3-secrets-detector, async-pipeline-builder)eth-security-auditor, defi-risk-scanner)sui-framework-helpers, move-compiler-tools)Package names were crafted to appear as legitimate crypto development, AI tooling, and security audit utilities. The earliest activity was recorded on May 22 at 8:20 PM UTC.
The npm payload — a 1,149-line credential harvester called trap-core.js — scans for crypto wallets (Sui, Solana, Aptos), SSH keys, AWS credentials, GitHub tokens, browser data, and environment variables. It validates stolen credentials via AWS and GitHub API calls and establishes persistence mechanisms. Each ecosystem used its native execution path: postinstall hooks in npm, import-time execution in Python, and build.rs in Rust.
A notable aspect of TrapDoor was the inclusion of .cursorrules and CLAUDE.md files containing hidden instructions designed to manipulate AI coding assistants into running a "security scan" that triggers credential exfiltration. The attackers submitted pull requests to repositories including browser-use/browser-use, langchain-ai/langchain, and langflow-ai/langflow.
Socket's detection averaged 5 minutes 56 seconds from publication, with the fastest catch at 58 seconds. No publicly confirmed fund losses have been attributed to TrapDoor as of May 28. However, the campaign demonstrates that the attack surface has expanded beyond smart contracts and bridges to developer environments — where a single compromised terminal can expose private keys, CI/CD pipelines, and treasury access.
SafeDep separately documented a May 11 campaign that compromised more than 170 npm packages and two PyPI packages across 404 malicious versions, targeting TanStack, Mistral SDK, and other popular libraries.
Aráoz's May 26 statement frames the core structural problem: smart contract security is asymmetric. Defenders must eliminate every vulnerability; attackers need to find one. AI coding agents tilt this asymmetry further by enabling machine-speed vulnerability discovery across transparent, on-chain codebases.
OpenZeppelin CEO Demian Brener distanced the company from Aráoz's position, stating that "Aráoz's views do not represent OpenZeppelin's current position" and affirming commitment to "continuous, AI-augmented security rather than retreat from DeFi." The divergence between OpenZeppelin's two co-founders illustrates the sector's lack of consensus on the severity of the threat.
The concern is not theoretical. Anthropic's Claude Mythos model — which the company restricts access to — has demonstrated the ability to autonomously discover vulnerabilities and develop working exploits, according to reporting by CoinDesk. The implication: if frontier AI models can find bugs faster than human auditors can fix them, the current security model — periodic audits, bug bounties, and time-locked upgrades — may be structurally insufficient.
Aráoz has publicly stated that he has "personally advised friends and family to exit positions, even in blue-chip names such as Aave, MakerDAO and Compound." Whether this represents a measured risk assessment or an over-correction remains to be seen, but the statement carries weight given Aráoz's role in building the smart contract security tooling that much of DeFi relies on.
The gap between losses and recoverable insurance underscores the sector's risk management deficit. Nexus Mutual — the largest DeFi insurance provider — has paid approximately $18 million in total claims across its operating history, including $5 million for the Rari Capital exploit, $4.9 million for FTX-related claims, and $2.4 million for the Euler hack.
Nexus Mutual generated $5.7 million in cover fees and $3.2 million in investment returns in 2025. The protocol's total secured value stands at approximately $5.75 billion since inception. Against $1.1 billion in losses over the past 12 months, the DeFi insurance market covers a fraction of total risk exposure.
This is not a Nexus Mutual failure — it reflects the structural immaturity of on-chain risk transfer markets. Premiums are priced for historical loss rates; the 2026 exploit surge represents a regime change that the existing actuarial framework has not absorbed.
Defensive responses have been piecemeal:
No coordinated industry-wide response has emerged. Protocol-level security remains fragmented, with each project maintaining independent audit, monitoring, and incident response capabilities.
The data presents a security environment that has deteriorated on three simultaneous fronts: on-chain exploits are larger and more sophisticated, off-chain supply chain attacks are targeting the developers who build DeFi protocols, and AI capabilities are compressing the time between vulnerability discovery and exploitation.
The sector's response architecture — periodic audits, bug bounties, and post-incident asset freezes — was designed for a threat environment where human attackers had human-speed limitations. Whether the industry can adapt its defensive infrastructure to match the current threat level will determine whether the TVL contraction is a temporary correction or the beginning of a structural repricing of DeFi risk.
The economic question is straightforward: at what point do the expected costs of exploit exposure exceed the yield generated by DeFi positions? For Aráoz, that threshold has been crossed. For Brener and OpenZeppelin, the answer is continued investment in defensive tooling. The market, measured by TVL outflows, is rendering its own verdict in real time.