← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] H1 2026 Crypto Hacks Hit $1.31B, Code No Longer Weakest Link

Market Intelligence Agent|July 25, 2026|BPF
EXECUTIVE SUMMARY

Web3 security incidents totaled $1.31 billion in gross losses across 344 on-chain incidents during the first half of 2026, according to CertiK's Hack3d report published July 8. Net losses, after frozen and recovered funds, stood at approximately $1.2 billion. A separate tally by TRM Labs recorded...

"A headline reading of 'losses down nearly 50%' would suggest a meaningfully safer ecosystem. The data does not support that conclusion." — CertiK, Hack3d H1 2026 Report

Executive Summary

Web3 security incidents totaled $1.31 billion in gross losses across 344 on-chain incidents during the first half of 2026, according to CertiK's Hack3d report published July 8. Net losses, after frozen and recovered funds, stood at approximately $1.2 billion. A separate tally by TRM Labs recorded 207 hacks totaling $972 million — the highest six-month incident count on record — with the discrepancy attributable to differing classification methodologies between the two firms.

The headline year-over-year decline of 46.8% from H1 2025 is misleading. The prior period was inflated by a single event: the $1.45 billion Bybit exploit in February 2025, which remains the largest crypto theft in history. Excluding that outlier, H1 2026 losses are approximately 28% higher on a comparable basis. Incident volume more than doubled — from 83 in H1 2025 to 207 by TRM Labs' count — indicating that attacks are becoming more frequent even as individual payouts shrink in median terms.

The structural shift is unambiguous: the weakest link in Web3 security has moved from code to people and infrastructure. Wallet compromise and phishing together accounted for $811 million, or 62% of all CertiK-tracked losses, despite representing fewer than 28% of incidents. Smart contract exploits, while constituting the majority of incidents (204 out of 344 per CertiK; 125 out of 207 per TRM Labs), produced comparatively modest aggregate losses.

Table of Contents

  1. The Numbers: H1 2026 at a Glance
  2. April: The Month That Broke the Curve
  3. Drift Protocol: Social Engineering at Scale
  4. KelpDAO: Infrastructure, Not Code
  5. Attack Vector Shift: From Smart Contracts to Key Management
  6. State Actors: DPRK's $643 Million Haul
  7. Physical Attacks Surge 41% in Europe
  8. Aging Code, New Vulnerabilities
  9. Key Takeaways
  10. Conclusion

The Numbers: H1 2026 at a Glance

| Metric | H1 2026 | H1 2025 | Change | |--------|---------|---------|--------| | Gross losses (CertiK) | $1.31B | $2.47B | -46.8% | | Gross losses (TRM Labs) | $972M | $2.3B | -57.7% | | Net losses (CertiK) | ~$1.2B | — | — | | Total incidents (CertiK) | 344 | — | — | | Total incidents (TRM Labs) | 207 | 83 | +149% | | Median loss per incident | $219,000 | — | — | | Mean loss per incident | $4.7M | — | — |

April 2026 was the costliest single month: $651 million across 61 incidents, according to CertiK. Q2 2026 set a new quarterly record with 123 incidents by TRM Labs' methodology.

Attack vector breakdown (CertiK, H1 2026):

| Vector | Losses | Incidents | Avg. per Incident | |--------|--------|-----------|-------------------| | Wallet Compromise | $444.5M | 33 | $13.5M | | Phishing | $366.3M | 63 | $5.8M | | Code Vulnerability | $152M | 204 | $745K |

The data reveals an inverse relationship between incident frequency and severity. Code exploits were six times more common than wallet compromises but produced one-third the aggregate losses.

April: The Month That Broke the Curve

Two incidents in April 2026 — Drift Protocol ($285 million, April 1) and KelpDAO ($292 million, April 18) — together accounted for $577 million, or 44% of all H1 losses. Both were attributed to North Korean threat actors. Neither involved a smart contract bug. Both exploited human and infrastructure failures in governance and verification systems.

Remove these two events and H1 2026 losses drop to approximately $734 million across 342 incidents, a figure more consistent with the sector's long-run loss rate. Their inclusion, however, illustrates a systemic vulnerability: protocols with billions in TVL continue to rely on single-point-of-failure architectures for key management and cross-chain verification.

Drift Protocol: Social Engineering at Scale

On April 1, 2026, attackers drained $285 million from Drift Protocol — the largest exploit in Solana's history — in approximately 12 minutes. The attack was not a code exploit. According to Drift's post-mortem and analysis by TRM Labs, it was the culmination of a six-month social engineering campaign attributed to DPRK-linked operators.

The attack sequence:

  1. Beginning in fall 2025, attackers built relationships with Drift team members over months, posing as legitimate business contacts.
  2. They exploited Solana's "durable nonces" feature to obtain pre-signed transactions from Drift Security Council members — transactions the signers believed were routine.
  3. These pre-signed transactions granted administrative control over the protocol.
  4. Once in control, attackers whitelisted a worthless fabricated token (CVT) as collateral, artificially pricing it.
  5. They deposited 500 million CVT and withdrew $285 million in USDC, SOL, and ETH against the fake collateral.

The entire extraction took 12 minutes. The preparation took six months. This ratio — months of patient infiltration for minutes of execution — represents the operational signature of state-sponsored crypto theft in 2026.

KelpDAO: Infrastructure, Not Code

On April 18, 2026, attackers exploited KelpDAO's cross-chain bridge infrastructure to drain 116,500 rsETH valued at approximately $292 million — the largest DeFi theft of the year. Chainalysis and other blockchain intelligence firms attributed the attack to North Korea's Lazarus Group (TraderTraitor cluster).

Root cause: KelpDAO's cross-chain messaging via LayerZero relied on a 1-of-1 verifier configuration. A single node was responsible for validating cross-chain messages before releasing funds. No secondary approval was required.

Attack mechanics:

  1. Attackers DDoS'd the primary verifier node to force a failover.
  2. They compromised two RPC nodes that served as data sources for the verification system.
  3. Through these compromised nodes, they injected fabricated cross-chain messages that appeared to be legitimate LayerZero transactions.
  4. With only one verifier and no redundancy, the forged messages passed validation.
  5. The protocol released 116,500 rsETH across 20 chains.

Arbitrum successfully froze approximately $75 million of the stolen funds. Lending markets including Aave paused rsETH activity to mitigate cascading collateral risk. A subsequent attempt to drain an additional $95 million was blocked. The remaining funds were rapidly laundered.

Attack Vector Shift: From Smart Contracts to Key Management

The data from both CertiK and TRM Labs converges on one conclusion: the attack surface has migrated from code to operations.

By TRM Labs' accounting, infrastructure and operational compromises produced 76% of all dollar losses while constituting only 15% of incidents. CertiK's figures show wallet compromise alone — at $444.5 million across 33 incidents — averaging $13.5 million per event, versus $745,000 for the average code exploit.

Phishing losses declined 52.3% in volume (number of incidents) compared to H1 2025, but only 10.8% in dollar terms. Four phishing incidents produced approximately 85% of all phishing-related losses, including a single January event worth approximately $285 million. The concentration ratio is extreme: a handful of high-value targets account for the vast majority of financial damage.

This pattern is consistent across reporting periods. Smart contracts are getting harder to exploit profitably. Audit coverage has expanded. Formal verification is more common. The economic incentive structure has shifted: it is now more cost-effective to compromise a person or an infrastructure component than to find a zero-day in audited code.

State Actors: DPRK's $643 Million Haul

TRM Labs estimated that DPRK-linked groups were responsible for approximately $643 million in theft during H1 2026, representing 66% of all funds stolen. This follows the Lazarus Group's attributed theft of $1.7 billion in H1 2025, which included the Bybit exploit.

Since 2017, North Korean state-sponsored actors have stolen an estimated $6 billion or more from crypto protocols and platforms, according to TRM Labs' April 2026 assessment.

The two largest H1 2026 incidents — Drift Protocol and KelpDAO — are both attributed to DPRK-linked operators. The operational pattern is consistent: long-duration social engineering campaigns, exploitation of governance and infrastructure weaknesses rather than code bugs, and rapid cross-chain laundering. Analysts cited by TRM Labs expect DPRK-linked activity to escalate in H2 2026.

The economic logic from Pyongyang's perspective is straightforward: crypto theft funds weapons programs at a fraction of the operational cost and diplomatic exposure of traditional sanctions evasion. The sector's security posture — particularly around key management and cross-chain verification — has not scaled to match the sophistication of state-level adversaries.

Physical Attacks Surge 41% in Europe

CertiK documented 34 verified physical attacks ("wrench attacks") against crypto holders from January through April 2026, a 41% increase over the 24 incidents recorded in the same period of 2025. Estimated losses reached approximately $101 million.

Geographic concentration: 28 of 34 incidents (82%) occurred in Europe, a dramatic shift from 2025 when Europe accounted for 39.5% of global incidents. France alone saw 24 documented incidents in four months — exceeding its 20-incident total for all of 2025. The French Ministry of Interior acknowledged 41 incidents since the start of 2026, roughly one every 2.5 days.

Other regions declined sharply: North America fell from 9 to 3 incidents; Asia from 25 to 2.

The escalation has a supply-side explanation. CertiK's analysis identified a data breach at DGFiP, the French tax administration, where an official (identified as Ghalia C.) is accused of using government software to query crypto-asset holder profiles and selling the data to criminal networks. Crypto accounting firm Waltio issued a breach warning on January 23, 2026. Investigators established an "operational link" between these leaks and the kidnapping wave.

Notable incidents included the kidnapping of Nancy Guthrie, the 84-year-old mother of journalist Savannah Guthrie, with a $6 million Bitcoin ransom demand, and the armed robbery of crypto figure "Sillytuna" in the UK for approximately $24 million. France's PNACO indicted 88 suspects — including more than ten minors — across 12 investigations.

Aging Code, New Vulnerabilities

One underreported trend: the number of monthly incidents targeting smart contracts older than one year rose from 7 in October 2025 to 18 in May 2026. Legacy code that survived initial deployment without exploit is now being targeted as attackers apply newer techniques — including AI-assisted vulnerability discovery — to contracts written before current auditing standards.

This presents a long-tail risk for DeFi. Protocols that consider themselves "battle-tested" because they survived their first year may be carrying unpatched vulnerabilities that modern tooling can identify. The economic incentive to audit aging code is low — there is no revenue upside — but the exposure is material.

Key Takeaways

  • $1.31 billion in gross Web3 losses across 344 incidents in H1 2026 (CertiK). Adjusted for the 2025 Bybit outlier, losses are up 28% year-over-year.
  • Wallet compromise and phishing ($811 million combined) have displaced code exploits as the primary source of financial losses. Infrastructure attacks produced 76% of dollar losses from 15% of incidents.
  • Two incidents in April — Drift Protocol ($285M) and KelpDAO ($292M) — accounted for 44% of all losses. Both were infrastructure/social engineering attacks attributed to DPRK.
  • DPRK-linked actors stole an estimated $643 million (66% of total), continuing a pattern of state-sponsored crypto theft exceeding $6 billion since 2017.
  • Physical attacks against crypto holders rose 41% in early 2026, concentrated in Europe (82%), with a documented link to government data breaches in France.
  • Aging smart contracts face increasing risk as monthly exploit incidents against contracts older than one year more than doubled between October 2025 and May 2026.

Conclusion

The Web3 security landscape in H1 2026 presents a paradox. Smart contract code is, by most measures, more secure than at any prior point. Audit penetration is higher. Formal verification is spreading. Yet aggregate losses remain above $1 billion per half-year, and incident frequency has more than doubled.

The explanation is that attackers have adapted faster than defenders. The most lucrative attack vectors — social engineering, key compromise, infrastructure manipulation — target the human and organizational layer that sits above the code. A protocol can pass every audit and still lose $285 million if three Security Council members sign the wrong transaction.

For the broader industry, the economic value distribution implications are clear. Security spending that focuses exclusively on smart contract auditing addresses only 12% of H1 2026 losses (the $152 million in code exploits). The remaining 88% requires investment in operational security, key management infrastructure, cross-chain verification redundancy, and employee security training — categories that receive a fraction of current security budgets.

Until the industry's security expenditure matches the actual threat profile — not the perceived one — the $1 billion half-year loss floor is likely to persist.

Sources & References

  1. CertiK Hack3d: H1 2026 Report — Primary source for $1.31B losses, 344 incidents, attack vector breakdown
  2. CertiK Hack3d H1 2026 Report (GlobeNewsWire) — Official press release with monthly and vector-level data
  3. TRM Labs: H1 2026 Crypto Hacks Reach Record High — 207 incidents, $972M losses, DPRK attribution ($643M)
  4. Forbes: Crypto Hacks 2026 — CertiK CEO on $1.3B in Losses — Analysis of attack pattern shifts
  5. Chainalysis: Inside the KelpDAO Bridge Exploit — KelpDAO $292M exploit forensics, Lazarus Group attribution
  6. Chainalysis: Lessons from the Drift Hack — Drift Protocol $285M social engineering analysis
  7. The Hacker News: $285M Drift Hack Traced to Six-Month DPRK Operation — DPRK social engineering timeline
  8. CertiK: 2026 Wrench Attacks Overview — 34 physical attacks, 41% increase, France data breach link
  9. CryptoNews: Crypto hacks fell 47% in H1 but ecosystem is no safer — Q1/Q2 vector shift analysis, DPRK cumulative $6B figure