Web3 recorded between $972 million (TRM Labs) and $1.32 billion (CertiK) in theft losses during the first half of 2026, depending on methodology. The headline figure represents a 47–58% decline from H1 2025, but the comparison is distorted by a single event: the $1.45 billion Bybit exploit in Feb...
"The decline in total dollars stolen should not be mistaken for a safer environment. The lower total reflects the absence of another record-setting theft, not a reduction in attacker capability." — TRM Labs, H1 2026 Crypto Hacks Report
Web3 recorded between $972 million (TRM Labs) and $1.32 billion (CertiK) in theft losses during the first half of 2026, depending on methodology. The headline figure represents a 47–58% decline from H1 2025, but the comparison is distorted by a single event: the $1.45 billion Bybit exploit in February 2025. Excluding Bybit, H1 2026 losses were approximately 28% higher on a comparable basis, according to CertiK.
The incident count tells a starker story. TRM Labs recorded 207 separate attacks in H1 2026, more than double the 83 incidents in the same period last year. Q2 2026 alone set a new quarterly record with 123 incidents. The median loss per incident was approximately $219,000, while the mean stood at $4.7 million — a distribution shaped by two state-sponsored attacks that together accounted for $577 million. North Korea-linked actors were responsible for approximately 66% of all stolen funds, according to TRM Labs.
CertiK and TRM Labs — the two most-cited Web3 security trackers — published their H1 2026 reports within days of each other. Their topline figures diverge:
| Metric | CertiK | TRM Labs | |--------|--------|----------| | Total losses | $1.32B | $972M | | Incident count | 344 | 207 | | YoY change (losses) | -46.8% | -57.8% |
The discrepancy stems from scope. CertiK counts a broader set of Web3 security incidents including scams and rug pulls alongside protocol exploits. TRM Labs applies a narrower definition focused on confirmed hacks. Both firms, however, reached the same conclusion: the apparent decline is an artifact of the Bybit outlier, not a sign of improved security posture.
CertiK flagged that, excluding Bybit, H1 2026 losses were ~28% higher than the adjusted H1 2025 figure of $1.03 billion. TRM Labs noted that "attacker capability" has not diminished. The risk profile has shifted — not shrunk.
The most consequential finding across both reports is the inversion of attack economics. Smart contract exploits remain the most frequent attack type — 125 of TRM Labs' 207 incidents — but they account for a diminishing share of total dollar losses. Infrastructure breaches made up only 15% of incidents yet drove approximately 76% of total losses, according to TRM Labs.
CertiK's data corroborates this pattern with more granularity:
| Attack Vector | Losses (H1 2026) | Incidents | |--------------|-------------------|-----------| | Wallet compromises | $444.5M | 33 | | Phishing | $366.3M | 63 | | Smart contract exploits | Remainder | 125+ |
Wallet compromises displaced phishing as the costliest vector. Attackers stole $444.5 million through just 33 wallet compromise incidents — an average of $13.5 million per incident. Phishing incidents fell from 132 in H1 2025 to 63, but the total amount stolen declined by only ~11%, indicating higher-value targeting.
CertiK described private keys and multisignature wallet management as the "most consequential security surface" in the ecosystem and an "area where security investment yields asymmetric returns."
The implication is structural. Protocols that pass smart contract audits may still hold existential risk in their operational infrastructure — RPC configurations, admin key management, and off-chain verification systems. Code audits alone are insufficient.
North Korea-linked actors stole approximately $643 million in cryptocurrency during H1 2026, representing roughly 66% of all stolen funds tracked by TRM Labs. Two attacks in April accounted for $577 million of that total.
Drift Protocol — April 1, 2026 — $285 million: Attackers conducted a months-long social engineering campaign targeting Drift Protocol's Security Council members on Solana. Using Solana's "durable nonces" feature, they obtained pre-signed transactions that transferred admin control. The attackers then whitelisted a worthless fabricated token (CVT) as collateral, deposited 500 million units, and withdrew $285 million in USDC, SOL, and ETH. Elliptic attributed the attack to DPRK-linked operators based on on-chain laundering patterns.
Kelp DAO — April 18, 2026 — $292 million: Attackers compromised internal RPC nodes and DDoS'd external nodes to force failover, tricking LayerZero's verification network into approving a fraudulent cross-chain transaction. The root cause was a 1-of-1 verifier configuration — a single node responsible for validating cross-chain messages before releasing funds. LayerZero attributed the exploit to North Korea's Lazarus Group. The Arbitrum Security Council subsequently froze 30,766 ETH ($71 million) at an address linked to the attacker.
Both attacks exploited operational infrastructure, not smart contract logic. Both involved sophisticated social engineering and infrastructure manipulation rather than code vulnerabilities. The pattern is consistent with Lazarus Group methodology observed in previous years: patient reconnaissance, infrastructure compromise, and rapid fund extraction through bridges and mixing services.
According to TRM Labs, the stolen funds remain "largely unrecovered" as DPRK operators have become proficient at laundering proceeds through chain-hopping pathways and OTC networks.
The half-year aggregate obscures sharp intra-period divergence.
Q1 2026:
Q2 2026:
April 2026 was an outlier month driven almost entirely by the Drift and Kelp DAO exploits. Strip out those two incidents and Q2 losses fall below $200 million. The concentration of damage in a narrow window underscores how a small number of state-sponsored attacks dominate aggregate statistics.
Fund recovery continues to deteriorate. Available data points suggest:
The only consistently successful recovery mechanism is negotiated white-hat returns. GMX V1 recovered $40.5 million of $42 million stolen after the attacker accepted a $5 million bounty. These cases are the exception. State-sponsored actors do not negotiate.
The bug bounty market provides partial context for the industry's defensive posture. Immunefi, the largest Web3 bug bounty marketplace, reports:
Total available bug bounty rewards across all platforms exceed $162 million. Compared to $972 million–$1.32 billion in actual losses during H1 2026 alone, the ratio of prevention spending to theft remains heavily skewed.
The data suggests a structural misallocation. Security spending concentrates on smart contract audits and code-level bounties, while the largest losses stem from infrastructure compromise, key management failures, and social engineering — areas less amenable to traditional audit frameworks.
The H1 2026 security data presents a paradox: fewer dollars stolen in aggregate, but more attacks, higher per-incident damage when infrastructure is the target, and a near-total concentration of economic impact in state-sponsored operations. The ecosystem is not safer. The attack surface has migrated from code to infrastructure, and the industry's defensive spending has not followed.
CertiK and TRM Labs both identify the same structural vulnerability: private key management, multisig governance, and off-chain infrastructure represent the highest-impact attack surface, yet receive disproportionately less security investment than smart contract auditing.
For protocols managing significant TVL, the data implies that operational security — key custody, RPC configuration, social engineering defense, and verifier redundancy — is now the binding constraint on protocol safety. The $577 million lost to two DPRK-attributed infrastructure attacks in a single month makes the case in dollar terms.