Web3 security incidents totaled $1.31 billion in gross losses across 344 on-chain incidents during the first half of 2026, according to CertiK's Hack3d report published July 8. Net losses, after frozen and recovered funds, stood at approximately $1.2 billion. A separate tally by TRM Labs recorded...
"A headline reading of 'losses down nearly 50%' would suggest a meaningfully safer ecosystem. The data does not support that conclusion." — CertiK, Hack3d H1 2026 Report
Web3 security incidents totaled $1.31 billion in gross losses across 344 on-chain incidents during the first half of 2026, according to CertiK's Hack3d report published July 8. Net losses, after frozen and recovered funds, stood at approximately $1.2 billion. A separate tally by TRM Labs recorded 207 hacks totaling $972 million — the highest six-month incident count on record — with the discrepancy attributable to differing classification methodologies between the two firms.
The headline year-over-year decline of 46.8% from H1 2025 is misleading. The prior period was inflated by a single event: the $1.45 billion Bybit exploit in February 2025, which remains the largest crypto theft in history. Excluding that outlier, H1 2026 losses are approximately 28% higher on a comparable basis. Incident volume more than doubled — from 83 in H1 2025 to 207 by TRM Labs' count — indicating that attacks are becoming more frequent even as individual payouts shrink in median terms.
The structural shift is unambiguous: the weakest link in Web3 security has moved from code to people and infrastructure. Wallet compromise and phishing together accounted for $811 million, or 62% of all CertiK-tracked losses, despite representing fewer than 28% of incidents. Smart contract exploits, while constituting the majority of incidents (204 out of 344 per CertiK; 125 out of 207 per TRM Labs), produced comparatively modest aggregate losses.
| Metric | H1 2026 | H1 2025 | Change | |--------|---------|---------|--------| | Gross losses (CertiK) | $1.31B | $2.47B | -46.8% | | Gross losses (TRM Labs) | $972M | $2.3B | -57.7% | | Net losses (CertiK) | ~$1.2B | — | — | | Total incidents (CertiK) | 344 | — | — | | Total incidents (TRM Labs) | 207 | 83 | +149% | | Median loss per incident | $219,000 | — | — | | Mean loss per incident | $4.7M | — | — |
April 2026 was the costliest single month: $651 million across 61 incidents, according to CertiK. Q2 2026 set a new quarterly record with 123 incidents by TRM Labs' methodology.
Attack vector breakdown (CertiK, H1 2026):
| Vector | Losses | Incidents | Avg. per Incident | |--------|--------|-----------|-------------------| | Wallet Compromise | $444.5M | 33 | $13.5M | | Phishing | $366.3M | 63 | $5.8M | | Code Vulnerability | $152M | 204 | $745K |
The data reveals an inverse relationship between incident frequency and severity. Code exploits were six times more common than wallet compromises but produced one-third the aggregate losses.
Two incidents in April 2026 — Drift Protocol ($285 million, April 1) and KelpDAO ($292 million, April 18) — together accounted for $577 million, or 44% of all H1 losses. Both were attributed to North Korean threat actors. Neither involved a smart contract bug. Both exploited human and infrastructure failures in governance and verification systems.
Remove these two events and H1 2026 losses drop to approximately $734 million across 342 incidents, a figure more consistent with the sector's long-run loss rate. Their inclusion, however, illustrates a systemic vulnerability: protocols with billions in TVL continue to rely on single-point-of-failure architectures for key management and cross-chain verification.
On April 1, 2026, attackers drained $285 million from Drift Protocol — the largest exploit in Solana's history — in approximately 12 minutes. The attack was not a code exploit. According to Drift's post-mortem and analysis by TRM Labs, it was the culmination of a six-month social engineering campaign attributed to DPRK-linked operators.
The attack sequence:
The entire extraction took 12 minutes. The preparation took six months. This ratio — months of patient infiltration for minutes of execution — represents the operational signature of state-sponsored crypto theft in 2026.
On April 18, 2026, attackers exploited KelpDAO's cross-chain bridge infrastructure to drain 116,500 rsETH valued at approximately $292 million — the largest DeFi theft of the year. Chainalysis and other blockchain intelligence firms attributed the attack to North Korea's Lazarus Group (TraderTraitor cluster).
Root cause: KelpDAO's cross-chain messaging via LayerZero relied on a 1-of-1 verifier configuration. A single node was responsible for validating cross-chain messages before releasing funds. No secondary approval was required.
Attack mechanics:
Arbitrum successfully froze approximately $75 million of the stolen funds. Lending markets including Aave paused rsETH activity to mitigate cascading collateral risk. A subsequent attempt to drain an additional $95 million was blocked. The remaining funds were rapidly laundered.
The data from both CertiK and TRM Labs converges on one conclusion: the attack surface has migrated from code to operations.
By TRM Labs' accounting, infrastructure and operational compromises produced 76% of all dollar losses while constituting only 15% of incidents. CertiK's figures show wallet compromise alone — at $444.5 million across 33 incidents — averaging $13.5 million per event, versus $745,000 for the average code exploit.
Phishing losses declined 52.3% in volume (number of incidents) compared to H1 2025, but only 10.8% in dollar terms. Four phishing incidents produced approximately 85% of all phishing-related losses, including a single January event worth approximately $285 million. The concentration ratio is extreme: a handful of high-value targets account for the vast majority of financial damage.
This pattern is consistent across reporting periods. Smart contracts are getting harder to exploit profitably. Audit coverage has expanded. Formal verification is more common. The economic incentive structure has shifted: it is now more cost-effective to compromise a person or an infrastructure component than to find a zero-day in audited code.
TRM Labs estimated that DPRK-linked groups were responsible for approximately $643 million in theft during H1 2026, representing 66% of all funds stolen. This follows the Lazarus Group's attributed theft of $1.7 billion in H1 2025, which included the Bybit exploit.
Since 2017, North Korean state-sponsored actors have stolen an estimated $6 billion or more from crypto protocols and platforms, according to TRM Labs' April 2026 assessment.
The two largest H1 2026 incidents — Drift Protocol and KelpDAO — are both attributed to DPRK-linked operators. The operational pattern is consistent: long-duration social engineering campaigns, exploitation of governance and infrastructure weaknesses rather than code bugs, and rapid cross-chain laundering. Analysts cited by TRM Labs expect DPRK-linked activity to escalate in H2 2026.
The economic logic from Pyongyang's perspective is straightforward: crypto theft funds weapons programs at a fraction of the operational cost and diplomatic exposure of traditional sanctions evasion. The sector's security posture — particularly around key management and cross-chain verification — has not scaled to match the sophistication of state-level adversaries.
CertiK documented 34 verified physical attacks ("wrench attacks") against crypto holders from January through April 2026, a 41% increase over the 24 incidents recorded in the same period of 2025. Estimated losses reached approximately $101 million.
Geographic concentration: 28 of 34 incidents (82%) occurred in Europe, a dramatic shift from 2025 when Europe accounted for 39.5% of global incidents. France alone saw 24 documented incidents in four months — exceeding its 20-incident total for all of 2025. The French Ministry of Interior acknowledged 41 incidents since the start of 2026, roughly one every 2.5 days.
Other regions declined sharply: North America fell from 9 to 3 incidents; Asia from 25 to 2.
The escalation has a supply-side explanation. CertiK's analysis identified a data breach at DGFiP, the French tax administration, where an official (identified as Ghalia C.) is accused of using government software to query crypto-asset holder profiles and selling the data to criminal networks. Crypto accounting firm Waltio issued a breach warning on January 23, 2026. Investigators established an "operational link" between these leaks and the kidnapping wave.
Notable incidents included the kidnapping of Nancy Guthrie, the 84-year-old mother of journalist Savannah Guthrie, with a $6 million Bitcoin ransom demand, and the armed robbery of crypto figure "Sillytuna" in the UK for approximately $24 million. France's PNACO indicted 88 suspects — including more than ten minors — across 12 investigations.
One underreported trend: the number of monthly incidents targeting smart contracts older than one year rose from 7 in October 2025 to 18 in May 2026. Legacy code that survived initial deployment without exploit is now being targeted as attackers apply newer techniques — including AI-assisted vulnerability discovery — to contracts written before current auditing standards.
This presents a long-tail risk for DeFi. Protocols that consider themselves "battle-tested" because they survived their first year may be carrying unpatched vulnerabilities that modern tooling can identify. The economic incentive to audit aging code is low — there is no revenue upside — but the exposure is material.
The Web3 security landscape in H1 2026 presents a paradox. Smart contract code is, by most measures, more secure than at any prior point. Audit penetration is higher. Formal verification is spreading. Yet aggregate losses remain above $1 billion per half-year, and incident frequency has more than doubled.
The explanation is that attackers have adapted faster than defenders. The most lucrative attack vectors — social engineering, key compromise, infrastructure manipulation — target the human and organizational layer that sits above the code. A protocol can pass every audit and still lose $285 million if three Security Council members sign the wrong transaction.
For the broader industry, the economic value distribution implications are clear. Security spending that focuses exclusively on smart contract auditing addresses only 12% of H1 2026 losses (the $152 million in code exploits). The remaining 88% requires investment in operational security, key management infrastructure, cross-chain verification redundancy, and employee security training — categories that receive a fraction of current security budgets.
Until the industry's security expenditure matches the actual threat profile — not the perceived one — the $1 billion half-year loss floor is likely to persist.