Crypto projects lost $972 million across 207 incidents in H1 2026, according to TRM Labs data published July 3. The incident count is the highest ever recorded in a six-month period — more than double the 83 incidents logged in H1 2025. Dollar losses, however, fell 57% from H1 2025's $2.3 billion...
"A headline reading of 'losses down nearly 50%' would suggest a meaningfully safer ecosystem. The data does not support that conclusion." — CertiK, Hack3d H1 2026 Report
Crypto projects lost $972 million across 207 incidents in H1 2026, according to TRM Labs data published July 3. The incident count is the highest ever recorded in a six-month period — more than double the 83 incidents logged in H1 2025. Dollar losses, however, fell 57% from H1 2025's $2.3 billion figure, a decline that CertiK warns is statistically misleading: the prior-year total was inflated by the $1.4 billion Bybit hack, the largest single exploit in crypto history. Excluding Bybit, H1 2026 losses were approximately 28% higher on a like-for-like basis.
The attack surface has migrated. Smart contract exploits accounted for 125 of 207 incidents but a minor share of stolen value. Infrastructure and operational compromises — private key theft, multisig manipulation, cross-chain bridge exploitation — represented roughly 15% of incidents but 76% of total losses. Two state-sponsored attacks attributed to North Korea's Lazarus Group accounted for $577 million combined, or 66% of all funds stolen.
DeFi TVL fell 39% year-to-date to approximately $70 billion, with security breaches cited as a contributing factor alongside compressed yields and risk-off rotation.
TRM Labs, Immunefi, and CertiK each published H1 2026 security assessments in the first two weeks of July. The datasets differ in methodology — TRM tracks on-chain theft broadly, CertiK includes phishing and wallet compromises, Immunefi focuses on protocol-level exploits — but converge on core trends.
| Metric | H1 2025 | H1 2026 | Change | |---|---|---|---| | Total incidents | 83 | 207 | +149% | | Total losses | ~$2.3B | ~$972M | -57% | | Losses excl. Bybit | ~$1.03B | ~$972M | -6% | | Avg. loss per incident | ~$27.7M | ~$4.7M | -83% | | Q2 incidents | N/A | 123 | Record | | DeFi-specific losses | N/A | ~$680M | -74% vs 2022 |
CertiK's Hack3d report logged $1.32 billion in total Web3 losses for the same period, a higher figure reflecting its broader scope that includes phishing ($508.2 million in Q1) and wallet compromises ($807.5 million in Q2). Immunefi reported paying $13.45 million to researchers who surfaced 837 valid bugs before exploitation.
Two incidents dominated H1 2026 loss totals, both attributed to North Korean state-sponsored actors.
Drift Protocol — $285 million (April 1, 2026)
The Solana-based perpetuals platform suffered its breach through governance manipulation, not a smart contract bug. According to Chainalysis, the attacker spent weeks manufacturing legitimacy for a fabricated token — CarbonVote Token (CVT) — by minting 750 million units, seeding liquidity on Raydium, and wash trading to establish a $1 price history. The attacker then social-engineered multisig signers into pre-signing hidden authorizations, eliminated the Security Council's timelock, listed CVT as valid collateral, and executed 31 withdrawal transactions in 12 minutes. Real assets including USDC and JLP were drained against fabricated collateral value. TRM Labs attributed the attack to North Korea's Lazarus Group.
KelpDAO — $292 million (April 18, 2026)
The Ethereum liquid restaking protocol lost 116,500 rsETH — approximately 18% of the token's circulating supply — through a cross-chain bridge compromise. According to Messari's post-mortem, the attacker compromised RPC nodes used by KelpDAO's LayerZero-powered bridge, which relied on a single decentralized verifier network (DVN) rather than the industry-standard multi-DVN configuration. Forged withdrawal messages were approved, minting unbacked rsETH across 20 chains. DeFi TVL dropped $13 billion over the following weekend to $85.64 billion, according to Sherwood News, as contagion fears triggered withdrawals from interconnected protocols. Aave, Lido Finance, and EtherFi coordinated a bailout to cover bad debt and prevent cascading liquidations.
The H1 data confirms a structural shift in how DeFi protocols are compromised. Traditional smart contract bugs — reentrancy, oracle manipulation, integer overflow — still generate the most incidents but increasingly modest losses. The high-value attacks target operational layers: private keys, multisig governance, RPC infrastructure, cross-chain message verification.
According to TRM Labs, infrastructure and operational compromises represented roughly 15% of H1 2026 incidents but approximately 76% of stolen value. CertiK identified private keys and multisignature wallet management as the "most consequential security surface" for attackers.
The July 6 Summer.fi exploit illustrated the other end of the spectrum: a $65.4 million flash loan sourced from Morpho was used to manipulate the totalAssets() accounting function in the Lazy Summer Protocol's Fleet Commander contract, netting $6 million in DAI. This was a classic smart contract vulnerability — no social engineering, no key compromise — but its financial impact was two orders of magnitude smaller than the infrastructure-level attacks.
A Finextra analysis of 8,195 audit reports across 1,575 DeFi protocols found limited evidence that code audits alone materially reduce future security incidents, reinforcing CertiK's warning that the industry's security posture requires hardening across hardware security, multisig governance, and geographic distribution of key signers — not just pre-deployment code review.
North Korea-linked actors accounted for approximately $643 million in stolen crypto during H1 2026, or 66% of all losses, according to TRM Labs. The figure is down from $1.7 billion in H1 2025 in absolute terms but represents an increased proportional share.
The Drift Protocol ($285 million) and KelpDAO ($292 million) exploits together totaled $577 million, attributed by the FBI and blockchain analytics firms to the Lazarus Group cluster tracked as TraderTraitor. Chainalysis has attributed approximately 76% of crypto-related hack losses globally in 2026 through April to state-backed DPRK actors.
Cumulative DPRK crypto theft reached $6.75 billion as of early 2026, per TRM Labs historical data. The February 2025 Bybit hack alone — $1.5 billion in ETH — represented the single largest cryptocurrency theft in history, also attributed to the same group.
The concentration of losses in state-sponsored attacks creates a statistical problem for industry security metrics: the majority of stolen value is driven by a single, heavily resourced threat actor whose capabilities exceed those of most protocol security teams.
Monthly data from TRM Labs and DefiLlama reveals clustering in Q2:
| Month | Incidents | Losses (est.) | |---|---|---| | January | ~18 | ~$52M | | February | ~22 | ~$47M | | March | ~28 | ~$70M | | April | ~34 | ~$631M | | May | ~41 | ~$104M | | June | ~36 | ~$68M | | H1 Total | ~207 | ~$972M |
April accounted for approximately 65% of all H1 losses despite representing only 16% of incidents, driven entirely by the Drift and KelpDAO exploits. Excluding those two events, April losses were roughly in line with other months.
May recorded the highest incident count at 41, though individual exploit sizes were smaller. The pattern suggests a broadening attacker base pursuing lower-value targets alongside the concentrated state-sponsored operations.
Fund recovery remained structurally poor. Of H1 2026's largest hacks, only one project fully recovered stolen assets, according to DefiLlama data. Two others managed to freeze just over $74 million combined. More than $620 million remains effectively unrecoverable.
Specific recovery examples were limited:
The low recovery rate reflects the sophistication of laundering infrastructure. State-sponsored actors in particular use layered mixing, cross-chain hops, and extended dormancy periods that make asset freezing difficult once the initial window closes.
DeFi TVL fell from approximately $115 billion in January 2026 to $70 billion by early July — a 39% decline. Security incidents were one of several contributing factors, alongside compressed yields and broader risk-off positioning.
Chain-level breakdown, per DefiLlama:
The KelpDAO exploit alone triggered a $13 billion TVL drawdown over a single weekend. The compounding effect of repeated security incidents on depositor confidence is difficult to isolate from price action, but governance-token devaluations following exploits directly reduce incentive structures that attract liquidity.
The security industry is adapting, though the pace of adaptation lags the pace of attack evolution.
Bug bounty economics: Immunefi paid $13.45 million to whitehats who identified 837 valid vulnerabilities in H1 2026. The ratio of bounty spending to exploit losses — roughly 1:72 — suggests significant underinvestment in pre-emptive discovery relative to the cost of post-exploit damage.
Audit limitations: The academic analysis of 8,195 DeFi audit reports cited by Finextra found little statistical evidence that audits materially reduce future breaches. This does not mean audits are useless — they catch code-level bugs — but it confirms that the attack surface has expanded beyond what code review can cover.
Emerging defensive frameworks: Security firms are advocating a three-phase model: pre-deployment prevention (formal verification, fuzzing), runtime mitigation (monitoring, circuit breakers, pause mechanisms), and post-incident response (forensics, insurance, reserves). The July 2026 CVE-2026-34219 disclosure — a remotely triggerable vulnerability in Ethereum's libp2p gossipsub layer, scored CVSS 8.2 HIGH — demonstrated that even infrastructure-level bugs are being caught through coordinated disclosure rather than in-the-wild exploitation.
CertiK's recommendation: Protocols holding significant on-chain assets should harden private key management across hardware security, multisig governance structures, and geographic distribution of signers.
The H1 2026 data presents a paradox: DeFi is simultaneously more attacked and — on a per-incident basis — less damaged than at any point in its history. The median exploit is smaller. The long tail, however, is dominated by state-sponsored actors whose operational sophistication exceeds the defensive capabilities of most protocol teams.
The industry's security challenge is no longer primarily a code problem. It is an infrastructure, governance, and operational security problem. Auditing smart contracts, while necessary, addresses less than a quarter of stolen value. The protocols that lost the most in H1 2026 were compromised through social engineering, key management failures, and single-point-of-failure bridge configurations.
Until the cost structure shifts — through higher bug bounty investment, mandatory operational security standards, and multi-layer verification for cross-chain operations — the current trajectory suggests continued high incident volume with periodic state-sponsored mega-exploits driving the majority of losses.