DeFi protocols have lost $840 million across more than 50 separate incidents in the first five months of 2026, a 68% increase in attack frequency over the same period in 2025. April 2026 set a record as the single most-hacked month in crypto history, with 30 confirmed exploits draining $629 milli...
"Smart contracts become safer, so hackers look for supply chain, operational security, and so on. It's an unfair game." — Ronghui Gu, CEO, CertiK
DeFi protocols have lost $840 million across more than 50 separate incidents in the first five months of 2026, a 68% increase in attack frequency over the same period in 2025. April 2026 set a record as the single most-hacked month in crypto history, with 30 confirmed exploits draining $629 million. Two DPRK-linked operations — the $285 million Drift Protocol breach and the $293 million Kelp DAO bridge exploit — accounted for 93% of April losses and 76% of all 2026 crypto hack value through April, according to TRM Labs.
More than 40 protocols, wallets, marketplaces, and infrastructure entities have wound down since January. The attrition is not fraud-driven in the manner of FTX or Celsius. It is a combination of business-model failures, security-driven insolvencies, and consolidation casualties. DeFi TVL has declined from approximately $130–140 billion at the start of the year to roughly $78–85 billion as of early June, per DefiLlama data, reflecting both exploit-driven capital flight and broader market drawdowns.
The attack surface has shifted. The dominant vectors in 2026 are not smart contract bugs but cross-chain bridge infrastructure, operational security failures, and social engineering campaigns. This structural shift has prompted ecosystem-level responses — Solana Foundation launched the STRIDE program and SIRN incident response network; Aave mobilized a $300 million recovery effort after the Kelp DAO contagion — but neither initiative would have prevented the attacks that triggered them.
The first quarter of 2026 closed with $501 million in confirmed losses across 145 separate incidents, according to Immunefi and DefiLlama data. April alone added $629 million across 30 exploits, pushing the year-to-date total past $840 million by end of May.
| Period | Incidents | Losses (USD) | |--------|-----------|-------------| | Q1 2026 | 145 | $501M | | April 2026 | 30 | $629M | | May 2026 (est.) | ~15 | ~$50M+ | | YTD through May | ~190+ | ~$840M+ |
For context, the first five months of 2025 recorded 28 incidents across the same timeframe. The 2026 figure of 50+ major incidents represents a 68% year-over-year increase in frequency. April 2026 averaged close to one attack per day; prior monthly peaks rarely exceeded 12–15 incidents.
The June tally has already begun climbing. On June 1, Gnosis Pay disclosed an active exploit of its Zodiac Delay Module — a smart contract modifier designed as a security backstop — that allowed an attacker to bypass verification gates and drain funds from Safe accounts with the module enabled. Gnosis pledged full user compensation. Separately, TesseraDAO lost $2.5 million in a distinct exploit during the same week.
Drift Protocol, the largest perpetual futures exchange on Solana with over $500 million in TVL, was drained of $285 million on April 1 — more than 50% of its total value locked. The attack was not a smart contract exploit in the traditional sense.
According to Chainalysis and TRM Labs, the attackers — assessed with medium-high confidence by Drift's own team as the same North Korean state-affiliated group (UNC4736) behind the October 2024 Radiant Capital hack — spent six months conducting a social engineering campaign. They posed as a quantitative trading firm, building trust with Drift contributors through in-person meetings and fake professional identities.
The technical mechanism exploited Solana's "durable nonces" system, a feature that allows transactions to be signed now and executed later. The attackers tricked legitimate Security Council members into pre-signing dormant transactions that, when triggered, transferred admin control to attacker-controlled wallets. Once in control, the attackers whitelisted CarbonVote Token (CVT), a worthless token they had created on March 12, 2026, with a manipulated oracle price of ~$1. They deposited 500 million CVT and withdrew $285 million in USDC, SOL, and ETH.
A class-action lawsuit was filed against Drift Protocol on April 15 by Gibbs Mura, A Law Group.
Seventeen days after Drift, Kelp DAO's LayerZero-powered bridge was exploited for 116,500 rsETH — approximately $292–293 million and roughly 18% of the token's circulating supply. The root cause was a "1-of-1 verifier configuration" in which a single node validated cross-chain messages before releasing funds.
The Lazarus Group launched a coordinated DDoS attack against the protocol's RPC nodes, forcing legitimate infrastructure offline and isolating the single verifier. They then fed fraudulent cross-chain messages authorizing the release of rsETH to attacker-controlled addresses. Kelp's emergency pauser multisig froze core contracts 46 minutes after the drain at 18:21 UTC.
The contagion was immediate. Aave froze rsETH markets on V3 and V4 within hours. SparkLend and Fluid followed. Aave recorded a $6 billion TVL drop as depositors withdrew across the protocol. The broader DeFi ecosystem shed $13 billion in TVL in the days following the exploit, according to Sherwood News.
TRM Labs published analysis in late April confirming that DPRK-linked operations were responsible for 76% of all crypto hack value in 2026 through April — $577 million out of approximately $760 million total. This was achieved through just two attacks (Drift and Kelp DAO), representing only 3% of the total incident count.
Cumulative DPRK-linked crypto theft now exceeds $6 billion since 2017, per Chainalysis estimates. The 2025 total alone reached $2.06 billion, driven primarily by the $1.5 billion Bybit hack in February of that year.
The operational sophistication has increased. The Drift attack involved months of in-person social engineering — a significant escalation from the phishing emails and malicious code repositories that characterized earlier DPRK campaigns. The Kelp DAO attack exploited infrastructure architecture rather than code vulnerabilities, targeting bridge verifier design and node availability.
Beyond headline exploits, 2026 has seen a sustained wave of protocol closures. More than 40 DeFi protocols, wallets, marketplaces, and infrastructure entities have shut down since January, a phenomenon industry observers have termed the "Great Protocol Attrition."
January closures included MilkyWay, Pixiland, Sound.xyz, Nifty Gateway, Entropy, Slingshot, and Forgotten Runiverse. February saw Polynomial, ZeroLend, Parsec Finance, Step Finance, Solana Floor, and Remora Markets wind down. Angle closed in March. More recently, Everclear and ZERO Network joined the list.
The pattern differs from the 2022 collapse cycle. These are not fraud-driven failures like Celsius, FTX, or Terra. They are business-model failures in protocols that could not sustain operations at current fee levels and TVL, security-driven insolvencies where exploit losses exceeded treasury reserves, and consolidation casualties where market share concentrated into fewer, larger platforms.
Industry analysts project an additional 15–25 mid-tier protocol shutdowns by year-end, concentrated in lending, perpetual futures, and chain-specific DeFi tooling on low-activity L1s and L2s.
A defining feature of the 2026 exploit landscape is the shift in attack vectors. Smart contract code auditing standards have improved materially since 2021–2022. CertiK CEO Ronghui Gu has noted that as smart contracts become safer, attackers have pivoted to supply chain vulnerabilities, operational security gaps, and bridge infrastructure.
The two largest 2026 exploits illustrate this shift:
Cross-chain bridges have produced the largest single-day losses in crypto history because they hold large pools of locked assets and rely on cross-chain messaging systems that are difficult to verify independently. According to CoinDesk, bridges remain structurally one of the industry's weakest links.
The asymmetry problem is compounding. Gu has described DeFi security as "an unfair game" in which defenders must patch all vulnerabilities while attackers need to find only one. AI is accelerating this imbalance by enabling attackers to scan for vulnerabilities at scale while providing defenders with no equivalent capability to prove code is bug-free.
Five days after the Drift exploit, the Solana Foundation announced two security initiatives. STRIDE (Solana Trust, Resilience, and Infrastructure for DeFi Enterprises) is a tiered security program led by Asymmetric Research that evaluates DeFi protocols, provides 24/7 monitoring for protocols with TVL above $10 million, and funds formal verification for those above $100 million.
The Solana Incident Response Network (SIRN) is a membership-based crisis response group with founding members including OtterSec, Neodyme, Squads, and ZeroShadow.
However, as multiple analysts have noted, neither initiative would have prevented the Drift attack. The exploit used valid on-chain transactions — legitimate multisig approvals obtained through compromised devices — that were indistinguishable from normal administrative operations until executed. The gap was between on-chain correctness and off-chain human trust.
Following the Kelp DAO exploit's contagion into Aave markets, founder Stani Kulechov mobilized a $300 million recovery effort called DeFi United. Kulechov personally contributed 5,000 ETH. Mantle Network added a 30,000 ETH backstop. By late April, Arkham reported that Aave had raised $160 million of a $200 million target to cover bad debt from the Kelp DAO contagion.
Kulechov rejected characterizations that all DeFi is unsafe, stating that "DeFi infra today is materially more resilient than in prior cycles."
Gnosis Pay's June 1 exploit of the Zodiac Delay Module was contained within 24 hours. By June 2, the team announced operations would resume in phases, with every affected user receiving a new card-linked Safe funded with their pre-exploit balance. The total stolen amount and number of impacted accounts have not been publicly disclosed.
The security environment is directly affecting institutional DeFi adoption timelines. According to CoinDesk reporting from May 28, traditional financial institutions are interested in moving assets on-chain but are deterred by the frequency and scale of exploits. CertiK's Gu stated that near-daily hacks are "a major barrier to large-scale institutional adoption."
A Jefferies analyst note published after the Kelp DAO exploit warned that the breach "may force big banks to rethink their blockchain plans." Standard Chartered's digital assets research team published analysis in late April noting that while DeFi absorbed the $292 million shock and showed resilience through the Aave-led response, the incident exposed structural risks in cross-chain infrastructure that institutional participants cannot accept at current security levels.
The insurance layer remains underdeveloped relative to losses. Nexus Mutual, the largest DeFi insurance protocol, generated $5.7 million in cover fees in 2025 — a fraction of 2026's $840 million in losses. Coverage uptake across the sector remains low, and payouts for the largest 2026 incidents have been limited by coverage caps and exclusion clauses for social engineering attacks.
The first half of 2026 has produced a security environment that challenges the economic viability of the long-tail DeFi ecosystem. The largest protocols — Aave, Uniswap, Lido — have demonstrated resilience through treasury reserves, insurance backstops, and coordinated recovery efforts. But for protocols below $50 million in TVL, a single exploit can exceed treasury capacity and force shutdown.
The attack vector evolution poses a structural challenge. Formal verification, code audits, and monitoring address smart contract risk. They do not address the social engineering, governance manipulation, and bridge infrastructure vulnerabilities that produced the largest 2026 losses. The Drift attack demonstrated that valid on-chain transactions, executed through compromised but legitimate signers, are invisible to conventional security tooling.
The data suggests the DeFi sector is entering a consolidation phase in which security infrastructure costs — audits, formal verification, insurance, incident response, multisig governance — create minimum viable scale thresholds that smaller protocols cannot sustain. The result is a sector that is materially safer at the top end but increasingly inhospitable at the margins.