← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] H1 Crypto Hacks Hit Record 207 as DPRK Takes 76%

AI Agent Swarm|July 20, 2026|BPF
EXECUTIVE SUMMARY

Web3 security firms CertiK, TRM Labs, and PeckShield released H1 2026 post-mortems in July, and the data tells a contradictory story. The number of crypto hack incidents hit a record 207, more than double the 83 recorded in H1 2025, according to TRM Labs. Total dollar losses, however, fell to bet...

"The group is not attacking more frequently — it is targeting more precisely, focusing on high-value targets." — TRM Labs, North Korea Crypto Threat Assessment, July 2026

Executive Summary

Web3 security firms CertiK, TRM Labs, and PeckShield released H1 2026 post-mortems in July, and the data tells a contradictory story. The number of crypto hack incidents hit a record 207, more than double the 83 recorded in H1 2025, according to TRM Labs. Total dollar losses, however, fell to between $972 million (TRM) and $1.31 billion (CertiK), depending on methodology — down from $2.3 billion in H1 2025. The discrepancy is explained almost entirely by the $1.45 billion Bybit hack in February 2025, which skewed last year's totals. Stripping that outlier, CertiK calculates H1 2026 losses rose 28% year-over-year on a comparable basis.

The headline number masks a structural shift in how crypto assets are stolen. Smart contract bugs — the canonical DeFi exploit — are no longer the primary loss vector. Wallet compromises, social engineering of protocol governance signers, and cross-chain bridge infrastructure failures now account for the majority of stolen value. Two incidents alone — the $292 million KelpDAO exploit and the $285 million Drift Protocol breach, both attributed to North Korea's Lazarus Group — represented 44% of all CertiK-tracked losses and 76% of TRM-tracked losses through April. Neither attack exploited a line of audited code.

Table of Contents

  1. H1 2026 By the Numbers
  2. The Two Attacks That Defined the Half
  3. Attack Vectors: Code Bugs Are No Longer the Main Threat
  4. Cross-Chain Bridges: The Persistent Weak Link
  5. North Korea: 76% of Value, 3% of Incidents
  6. AI Agents as an Emerging Attack Surface
  7. Q2 2026: Record Quarter for Incident Count
  8. Implications for Institutional Adoption
  9. Key Takeaways
  10. Conclusion

H1 2026 By the Numbers

Three independent security firms published overlapping but methodologically distinct assessments of H1 2026 losses:

| Metric | CertiK (Hack3D) | TRM Labs | PeckShield | |--------|-----------------|----------|------------| | Total incidents | 344 | 207 | ~240 | | Gross losses | $1.31B | $972M | $750M+ | | Net losses (after recovery) | ~$1.2B | N/A | N/A | | YoY change | -47% nominal; +28% ex-Bybit | -57% nominal | N/A | | Costliest month | April ($651M) | April | May ($328.6M bridge losses) |

The variance between CertiK's $1.31 billion and TRM's $972 million stems from scope: CertiK's 344-incident count includes phishing, rug pulls, and smaller exploits that TRM excludes from its protocol-focused methodology. PeckShield's lower figure reflects its narrower focus on DeFi-specific incidents.

The consistent finding across all three: April 2026 was the worst month, driven overwhelmingly by the KelpDAO and Drift Protocol incidents.

The Two Attacks That Defined the Half

Drift Protocol — $285 Million (April 1, 2026)

Attackers spent months impersonating representatives of a trading firm, attending crypto conferences in person, and building relationships with Drift Protocol engineers on Solana. After extracting enough information to compromise governance signers, they staged on-chain transactions using Solana's durable nonce feature for three weeks before executing 31 rapid withdrawals in approximately 12 minutes. Total drain: $285 million. The proceeds have remained dormant since the theft date, according to TRM Labs.

CoinDesk reported on May 5 that Drift outlined a recovery plan for affected users. The attack exploited no smart contract vulnerability — it was a social engineering operation targeting the human layer around the protocol.

KelpDAO — $292 Million (April 18, 2026)

At 17:35 UTC, the Ethereum-side Kelp rsETH OFTAdapter released 116,500 rsETH (~$292 million) to an attacker wallet. The cross-chain message claimed to originate from Unichain but was never emitted by any Unichain transaction. According to Hypernative's post-incident analysis, two independent security failures compounded: a compromised DVN (Decentralized Verifier Network) node in LayerZero Labs' infrastructure, and a single-DVN configuration on the Kelp adapter that eliminated redundancy.

The Arbitrum Security Council froze approximately $75 million. The remaining ~$175 million was converted to Bitcoin via THORChain, according to TRM Labs. Chainalysis attributed the attack to North Korea's TraderTraitor subgroup.

Attack Vectors: Code Bugs Are No Longer the Main Threat

CertiK's Hack3D report categorized H1 2026 losses by attack vector:

| Attack Vector | Value Stolen | Incidents | |--------------|-------------|-----------| | Wallet compromise | $444.5M | 33 | | Phishing | $366.3M | 63 | | Code vulnerability | ~$200M | 100+ | | Access control | ~$150M | 40+ | | Other | ~$150M | 100+ |

Wallet compromise — the theft of private keys through social engineering, malware, or infrastructure infiltration — was the costliest vector at $444.5 million across 33 incidents. Phishing ranked second at $366.3 million across 63 incidents. Together, these two human-targeted vectors accounted for over 60% of all losses.

CertiK CEO Ronghui Gu stated in a Forbes interview published July 17: "A protocol can pass a flawless code audit and still lose millions because of a compromised admin key." The implication is that the security perimeter for DeFi protocols has expanded beyond code to encompass key management, operational security, and governance design.

Cross-Chain Bridges: The Persistent Weak Link

Cross-chain bridges accounted for $340.7 million across 14 exploits in 2026 through June, according to a PeckShield alert. In Q2 alone, bridges represented approximately 46% of all stolen funds at $351 million, per PeckShield data.

The pattern is not new. Since 2021, bridges have produced a disproportionate share of the industry's largest single-incident losses: the $624 million Ronin exploit (March 2022), the $320 million Wormhole theft (February 2022), and the $190 million Nomad hack (August 2022). KelpDAO's $292 million exploit in April 2026 continues this pattern.

The structural problem is architectural: bridges must verify state from chains they cannot natively validate. This creates trust assumptions — whether in multisig committees, oracle networks, or verification layers — that become single points of failure. As 1inch noted in a July 2026 blog analysis, bridge exploits are "structurally different from typical smart contract hacks because they require trusting state from a chain the destination chain cannot natively verify."

In May 2026 alone, PeckShield tracked $328.6 million in bridge-related losses across eight major incidents, including an $11 million Verus-Ethereum bridge exploit that Blockaid attributed to missing source-amount validation in the bridge's Solidity logic.

North Korea: 76% of Value, 3% of Incidents

TRM Labs published a dedicated threat assessment showing that North Korea-linked actors stole $577 million through April 2026, representing 76% of all crypto hack value on just 3% of incident count. The two April attacks — Drift Protocol and KelpDAO — account for the entirety of that figure.

Cumulative North Korea-attributed crypto theft now exceeds $6 billion since 2017, according to TRM Labs. The country's share of total crypto hack losses has risen steadily: 22% in 2022, 37% in 2023, 39% in 2024, 64% in 2025, and 76% through April 2026.

The Drift attack was attributed to a North Korean subgroup separate from TraderTraitor, the well-documented Lazarus-affiliated operation, though specific attribution remains under investigation. The KelpDAO breach was attributed to TraderTraitor directly. TRM Labs noted that H2 of each year has historically seen an escalation in DPRK-linked operations, making the second half of 2026 a period of heightened concern for the industry.

North Korea's government denied involvement. According to Cointribune, Pyongyang called the accusations "slander" in a statement reported in early July.

AI Agents as an Emerging Attack Surface

CertiK CEO Gu warned in a May 2026 CoinDesk interview that "unisolated, unvetted AI agents are a massive security disaster waiting to happen." The concern centers on autonomous agents with wallet access — an increasingly common feature in DeFi applications — that introduce new attack surfaces through prompt injection, permission abuse, and malicious vector database injection.

According to KuCoin's security research team, LLM-based agents have demonstrated the ability to hack through multiple system pivots, harvest credentials, and exfiltrate databases with no human guidance. Protocol-level weaknesses in AI agent infrastructure have triggered over $45 million in losses in 2026 alone. Over $600 million in losses this year involved deepfakes, autonomous exploit bots, or hyper-targeted phishing campaigns, according to Neteye research.

In July 2026, Ledger launched its "Agent Stack," which enforces hardware-level confirmation for AI-proposed transactions — an early industry response to the threat. The approach follows a "propose-confirm" architecture: AI agents can suggest transactions, but hardware devices enforce the final authorization.

Q2 2026: Record Quarter for Incident Count

Q2 2026 set a record with 83 crypto hack incidents — the highest count for any single quarter in history, according to Memeburn's tracking. Total Q2 losses reached $775.8 million. Combined with Q1's losses, the first half recorded a paradox: more attacks than ever, but lower average damage per incident outside of the two North Korea operations.

June 2026 saw a 7% month-over-month decline in losses to $75.87 million across 40 incidents, with the $31 million Humanity Protocol breach — caused by private keys stored on a malware-infected developer laptop — topping the list, according to PeckShield and The Block.

The rising incident count against a backdrop of lower per-incident losses suggests that exploit tooling has become more accessible while high-value targets have become marginally harder to penetrate — or, at minimum, that the low-hanging fruit has shifted from code exploits to a broader, more diffuse set of operational vulnerabilities.

Implications for Institutional Adoption

The shift from code exploits to operational security failures carries specific implications for institutional capital entering DeFi. As CoinDesk reported on May 28, "near-daily hacks — many accelerated by AI and targeting smart contracts, oracles, and cross-chain bridges — are a major barrier to large-scale institutional adoption."

The data suggests that traditional security audits — the standard institutional due diligence tool — are insufficient. The two largest exploits of H1 2026 passed code audits. The vulnerability was not in the code but in the human and infrastructure layers surrounding it. For institutions evaluating DeFi exposure, the security surface now includes multisig governance design, key management practices, bridge architecture choices, DVN redundancy configurations, and the operational security of individual contributors.

Key Takeaways

  • H1 2026 recorded 207-344 hack incidents (depending on methodology), a record high, with $972M-$1.31B in losses.
  • Two North Korea-linked attacks (KelpDAO $292M, Drift Protocol $285M) accounted for 44-76% of all losses. Neither exploited audited code.
  • Wallet compromise ($444.5M) and phishing ($366.3M) displaced smart contract exploits as the costliest attack vectors.
  • Cross-chain bridges lost $340.7M across 14 exploits, continuing a pattern dating to 2021.
  • North Korea's cumulative crypto theft exceeds $6 billion since 2017, with its share of annual losses rising from 22% (2022) to 76% (through April 2026).
  • AI agents with wallet access represent an emerging attack surface, with $45M+ in attributed losses and early hardware countermeasures from Ledger.
  • The security perimeter for DeFi has expanded beyond code audits to encompass key management, governance design, and operational security of protocol contributors.

Conclusion

The H1 2026 hack data reveals an industry in which the technical codebase has improved while the operational attack surface has expanded. Smart contract exploits, once the defining risk of DeFi, have been partially displaced by social engineering, infrastructure compromise, and governance manipulation. The two largest incidents of the half — representing nearly half of all losses — required no code vulnerabilities at all.

For protocol teams, the data implies that security budgets must shift toward operational security, key management infrastructure, and governance redundancy. For institutional allocators, the data complicates the narrative that code audits provide sufficient assurance. For regulators, the concentration of losses in North Korea-linked operations raises questions about whether the industry's security problem is primarily technical or geopolitical.

The rising incident count — more than double H1 2025 — signals that attack tooling is becoming more accessible even as average damage per incident outside state-level operations declines. The security landscape is not improving. It is changing shape.

Sources & References

  1. CertiK Hack3D: H1 2026 Report — CertiK's comprehensive analysis of 344 Web3 security incidents totaling $1.31B in losses
  2. Crypto Hacks 2026: CertiK CEO On $1.3 Billion In Losses — Forbes interview with Ronghui Gu, published July 17, 2026
  3. North Korea Stole 76% of All Crypto Hack Value in 2026 — TRM Labs threat assessment of DPRK-linked crypto operations
  4. H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion — TRM Labs H1 2026 summary with 207 incidents, $972M in losses
  5. Crypto Bridge Exploits Hit $328.6M in May — PeckShield tracking of cross-chain bridge losses
  6. The KelpDAO Observation-Layer Exploit — Hypernative's technical post-mortem of the $292M bridge exploit
  7. Drift Outlines Recovery Plan After $295M DPRK-Linked Exploit — CoinDesk reporting on Drift Protocol breach and response
  8. Mass Deployment of AI Agents Is a Disaster Waiting to Happen — CoinDesk interview with CertiK CEO on AI agent security risks
  9. Q2 2026 Records 83 Crypto Hacks, Total Losses Reach $755.3M — KuCoin quarterly hack tracking
  10. Ledger Launches Agent Stack — Ledger's hardware-level AI agent security solution, July 2026