Fifteen DeFi exploits drained $137 million in Q1 2026, according to aggregate data from CoinGenius, CryptoRank, and DefiLlama. The figure surpasses Q1 2025 totals and arrives as total DeFi TVL sits at $95.4 billion — down roughly 30% from $130–140 billion in early February 2026. The composition o...
"It was a case of overly trusting off-chain infrastructure." — Chainalysis, Lessons from the Resolv Hack (March 2026)
Fifteen DeFi exploits drained $137 million in Q1 2026, according to aggregate data from CoinGenius, CryptoRank, and DefiLlama. The figure surpasses Q1 2025 totals and arrives as total DeFi TVL sits at $95.4 billion — down roughly 30% from $130–140 billion in early February 2026.
The composition of attack vectors has shifted. Three of the four largest Q1 incidents — Step Finance ($27.3 million), Resolv ($25 million), and IoTeX ($2 million) — stemmed from compromised private keys or cloud infrastructure breaches, not smart contract logic errors. Only the Truebit exploit ($26.2 million) traced to a conventional code vulnerability (integer overflow in an unaudited 2021 contract). The Balancer Labs corporate entity announced shutdown on March 24 after a $110–128 million v2 exploit in November 2025 that it could not financially absorb.
The data points to an uncomfortable conclusion: as smart contract auditing has matured — audited protocols experienced 94% fewer hacks in 2025, per Halborn — attackers have migrated to the softer target of off-chain key management. Protocols with 18 completed audits (Resolv) still fell when a single AWS key was compromised.
Fifteen confirmed DeFi exploits occurred between January 1 and March 29, 2026, totaling approximately $137 million in losses.
| Rank | Protocol | Date | Loss | Vector | |------|----------|------|------|--------| | 1 | Step Finance | Jan 31 | $27.3M | Treasury wallet compromise | | 2 | Truebit | Jan 8 | $26.2M | Integer overflow (unaudited 2021 contract) | | 3 | Resolv | Mar 22 | $25.0M | AWS KMS key compromise | | 4 | SwapNet | Jan 25 | $13.4M | Arbitrary-call smart contract flaw | | 5–15 | Various | Jan–Mar | ~$45.1M | Mixed vectors |
Sources: CoinGenius, CryptoRank, DefiLlama Hacks Database, The Block
The top four incidents account for $91.9 million, or 67% of total Q1 losses. Of these, two ($52.3 million combined) involved key or wallet compromise rather than code-level bugs. A third — SwapNet — exploited an arbitrary-call vulnerability that allowed attackers to drain funds from users who had granted infinite token approvals, a design pattern increasingly flagged by auditors.
For context, Chainalysis reported $3.4 billion in total crypto hack losses for all of 2025, with the $1.5 billion Bybit exchange hack accounting for 44% of that figure. Q1 2026's $137 million DeFi-specific figure, while smaller in absolute terms, represents a pace that would annualize to approximately $548 million — above the DeFi-specific loss run rate from 2024–2025.
The pattern across 2025–2026 is clear. According to Chainalysis's 2026 Crypto Crime Report, the biggest shift is that the most expensive attacks are no longer smart contract bugs — they are key management failures.
Three categories of off-chain compromise dominated Q1 2026:
1. Cloud Infrastructure Breach (Resolv) The attacker compromised Resolv's AWS Key Management Service environment, gaining access to the protocol's privileged signing key. With that key, the attacker authorized minting operations directly — bypassing all on-chain controls. The smart contracts functioned exactly as designed; the inputs they received were fraudulent.
2. Treasury Wallet Compromise (Step Finance) CertiK's analysis revealed that attackers unstaked and extracted 261,854 SOL from Step Finance's treasury and fee collection wallets. The specific access method — whether smart contract flaw, key theft, or insider access — was never publicly confirmed. The protocol shut down permanently on February 23, 2026.
3. Individual Wallet Compromise (Industry-wide) Chainalysis reported that individual wallet compromises surged to 158,000 incidents in 2025, though total value stolen from individuals declined from $1.5 billion to $713 million year-over-year. North Korean state-sponsored actors accounted for $2.02 billion in cryptocurrency theft in 2025, a 51% increase over 2024.
Resolv had undergone 18 third-party security audits before its March 22 breach, according to Chainalysis. The protocol's USR stablecoin maintained a standard collateralization mechanism: users deposited USDC and received USR in return at a defined ratio.
The attack sequence, as documented by Chainalysis and The Block:
completeSwap with inflated output amounts.Chainalysis characterized the incident as "a case of overly trusting off-chain infrastructure," noting that while on-chain code was sound, the protocol's reliance on a cloud-hosted signing key created a single point of failure that no number of smart contract audits could address.
Resolv has not announced a compensation plan. IoTeX, which suffered a separate $2 million key compromise, opened a claims portal offering 100% restitution to affected users.
Step Finance, described as "the front page of Solana," was exploited on January 31, 2026, when attackers drained approximately $27 million in SOL from its treasury wallets. The STEP token fell 96% in the days following the breach.
According to CoinDesk, the protocol explored multiple recovery paths:
All failed. On February 23, Step Finance announced permanent shutdown, affecting three platforms: Step Finance itself, NFT analytics outlet SolanaFloor, and trading platform Remora Markets.
The closure illustrates a structural vulnerability in DeFi protocol economics: most protocols operate with thin revenue margins and limited treasury reserves. A single exploit can exceed the protocol's entire financial capacity to recover. Step Finance joins a growing list of protocols — including Balancer Labs — that have ceased operations following security breaches.
On March 24, 2026, Balancer co-founder Fernando Martinelli announced that Balancer Labs, the corporate entity behind the decentralized exchange, would shut down. The trigger: a v2 exploit in November 2025 that drained between $110 million and $128 million in assets in under an hour.
Martinelli stated: "BLabs, as a corporate entity, has become a liability rather than an asset to the protocol's future and is just not sustainable as is without any sources of revenue."
Key data points:
The Balancer situation exposes a tension in DeFi governance: corporate entities provide development resources and legal accountability, but also concentrate liability. When a $110 million exploit occurs, the corporate entity absorbs the legal and financial shock, potentially forcing shutdown even if the protocol's smart contracts continue to function.
The Q1 2026 data surfaces a paradox in DeFi security spending. According to Sherlock and industry surveys:
These investments have measurably reduced smart contract vulnerabilities. But the Resolv case demonstrates their limit: 18 audits could not prevent an exploit that originated outside the smart contract layer. The attack surface has expanded beyond code to include cloud infrastructure, operational security, key custody, and human factors.
The industry's security spending — estimated at 5–10% of development budgets — remains concentrated on code review. Operational security, key management practices, and incident response capabilities receive comparatively less systematic investment. According to multiple audit firms, the recommended allocation is 70% of security budget to audits and 30% to insurance premiums, but adoption of this framework remains low.
As previously documented in webthreepedia's analysis of DeFi insurance gaps, coverage rates remain below 0.5% of total DeFi TVL. Nexus Mutual, the largest DeFi insurance provider, has paid approximately $18 million in total claims since 2019 and protected over $6 billion in digital assets.
For context: $18 million in total historical payouts represents approximately 13% of Q1 2026 losses alone. Insurance premiums range from 2–10% annually, with some coverage dropping below 1% for select protocols in early 2025. But uptake remains limited, particularly among smaller protocols where a single exploit can be terminal.
The SwapNet incident illustrated how approval-based vulnerabilities can affect end users directly: the largest single loss was approximately $13.34 million to one user who had disabled the platform's default One-Time Approval setting.
The Q1 2026 exploit data describes a security landscape in transition. The industry's multi-year investment in smart contract auditing has produced measurable results: audited protocols are substantially safer at the code level. But attackers have adapted. The most financially damaging incidents now exploit the gap between on-chain security and off-chain operations — AWS keys stored in cloud environments, treasury wallets with insufficient access controls, and legacy contracts deployed before current audit standards existed.
Two protocol shutdowns in a single quarter — Step Finance and Balancer Labs — underscore the financial fragility of many DeFi entities. When exploits exceed treasury reserves and insurance coverage is negligible, protocol death is a realistic outcome. The economic value that users, liquidity providers, and token holders had allocated to these protocols was destroyed not by market forces but by security failures in systems adjacent to the blockchain itself.
For the DeFi sector to sustain the institutional capital flows now entering through tokenized treasuries and regulated staking products, security frameworks must extend beyond code review to encompass operational security, key management architecture, and incident response capacity. The data suggests the industry recognizes this — but spending and organizational practices have not yet caught up.