Q2 2026 is now crypto's most-hacked quarter on record. DefiLlama logged approximately 70 exploits between April and June, roughly double the previous quarterly record for incident count, draining a combined $746 million from protocols across multiple chains. April alone accounted for $630 million...
"DeFi's cross-chain complexity makes it a target-rich environment — bridges consistently produce the largest single-incident losses." — Ari Redbord, Global Head of Policy, TRM Labs
Q2 2026 is now crypto's most-hacked quarter on record. DefiLlama logged approximately 70 exploits between April and June, roughly double the previous quarterly record for incident count, draining a combined $746 million from protocols across multiple chains. April alone accounted for $630 million of that total — the worst single month since DeFi record-keeping began — driven by the $292 million KelpDAO bridge breach and the $285 million Drift Protocol admin-key compromise.
The pattern has shifted. Rather than a small number of mega-exploits, the quarter produced a sustained stream of mid-size incidents. According to TRM Labs, North Korean state-linked actors were responsible for 76% of all crypto hack losses through April 2026, up from 64% in 2025, with cumulative DPRK-attributed theft since 2017 now exceeding $6 billion. Meanwhile, less than 2% of DeFi's remaining $72.5 billion in TVL carries any form of insurance coverage, according to Nexus Mutual founder Hugh Karp. Year-to-date losses across the industry have surpassed $840 million through five months — a 70% increase over the same window in 2025.
| Metric | Q2 2026 | Q1 2026 | Q2 2025 | |---|---|---|---| | Total exploits | ~70 | ~34 | ~30 | | Total losses | $746M | $169M | est. $220M | | Worst single month | April: $630M | March: $86M | — | | Bridge-related incidents | 14+ | 6 | 4 | | Largest single exploit | KelpDAO: $292M | — | — |
April 2026 was confirmed by CertiK, PeckShield, and DefiLlama as the worst month on record. CertiK tracked $651 million across 29 incidents; PeckShield's figure came in at $630 million across 30. The discrepancy reflects differing classification methodologies — some firms include centralized exchange incidents — but the order of magnitude is consistent.
May saw a sharp drop in dollar terms. Approximately 14 DeFi protocols were hit, with collective losses near $68.3 million, according to crypto-economy.com. Eight of those were bridge-related, according to PeckShield, which tracked $328.6 million in cumulative bridge exploits through May.
June, through mid-month, has added the $36 million Humanity Protocol breach — a private-key compromise linked by Quantstamp to North Korean threat actors — plus several smaller incidents still being catalogued.
Drift Protocol — $285 million (April 1)
Attackers spent months building trust with Drift's development team through social engineering. The technical vector exploited Solana's "durable nonces" feature: Security Council members were induced to pre-sign transactions that, when later assembled, transferred admin control to the attackers. Once in control, the attackers whitelisted a fabricated token (CVT) as collateral, deposited 500 million CVT at an artificially inflated price, and withdrew $285 million in USDC, SOL, and ETH across 31 transactions in approximately 12 minutes.
Drift's TVL fell from $550 million to under $300 million within one hour. The DRIFT token dropped over 40% in a single session. TRM Labs has stated preliminary on-chain indicators are consistent with previously attributed DPRK operations, though formal attribution remains pending.
KelpDAO — $292 million (April 18)
This was not a smart contract logic exploit. Attackers compromised KelpDAO's internal RPC nodes and simultaneously DDoS'd external nodes to isolate LayerZero's verification network. LayerZero's default 1-of-1 RPC quorum — identified by Chainalysis as a systemic design flaw — meant a single compromised node could authorize fraudulent cross-chain messages. The attackers minted 116,500 unbacked rsETH tokens and moved them across 20+ chains.
KelpDAO's team paused contracts in time to block a second $95 million theft. The Arbitrum Security Council froze over 30,000 ETH ($75 million) in attacker-linked downstream wallets. Chainalysis attributed the attack to TraderTraitor, a Lazarus Group-affiliated subunit. Stolen funds were laundered through THORChain.
Together, these two incidents accounted for 93% of April's total outflows.
TRM Labs data shows a clear, monotonic trend in DPRK's share of global crypto hack losses:
| Year | DPRK Share of Losses | |---|---| | 2020–2021 | <10% | | 2022 | 22% | | 2023 | 37% | | 2024 | 39% | | 2025 | 64% | | 2026 YTD (through April) | 76% |
The $577 million attributed to North Korea through April 2026 came from just two attacks (Drift and KelpDAO), representing only 3% of total incident count but 76% of total dollar losses. Cumulative DPRK-attributed theft since 2017 now exceeds $6 billion, according to TRM Labs.
North Korea's Foreign Ministry dismissed the allegations as "absurd slander," describing them as a political instrument to justify U.S. hostility. TRM Labs noted that the DPRK's operational toolkit has grown more sophisticated, with better laundering pipelines and diversified social engineering tactics.
The composition of Q2 2026 exploits marks a structural shift in attack methodology. According to Blockaid co-founder Raz Niv: "The common thread isn't complexity per se. It's that each layer of abstraction introduces trust assumptions that attackers methodically probe."
Niv identified three recurring patterns across the quarter's incidents:
The Humanity Protocol breach on June 8–9 underscored pattern (1): a single employee stored multiple bridge admin keys on one laptop. Attackers gained access via a phishing email impersonating South Korean exchange Bithumb, drained $36 million across Ethereum and BNB Chain, and minted 100 million additional $H tokens. The H token fell over 80% from $0.67 to $0.13.
Security firms report a measurable increase in AI-assisted attack preparation in 2026. According to CertiK senior audit partner Natalie Newson, the firm has observed "a rise in older and unverified contracts being exploited," suggesting AI tools are being used for automated vulnerability discovery at scale.
Blockaid's Niv stated the concern is not AI replacing human attackers but "amplifying attackers by handling reconnaissance." A February 2026 benchmark study (EVMBENCH) by OpenAI, Paradigm, and OtterSec found that the best-performing AI agent detected 45.6% of vulnerabilities and successfully exploited 72.2% of a curated subset across 120 known contract flaws.
Halborn has confirmed that a purpose-built AI security agent detected vulnerabilities in 92% of real-world exploited DeFi contracts — nearly triple the 34% rate achieved by general-purpose coding agents. The implication: a criminal with $500 in compute can now scan thousands of deployed contracts for known vulnerability patterns.
The defensive side is also deploying AI. Continuous monitoring services have replaced static one-time audits at most major protocols. But the asymmetry persists — attackers need to find one flaw; defenders must cover all of them.
Despite $840 million in year-to-date losses and $7.7 billion in cumulative uninsured protocol losses since DeFi's inception, on-chain insurance remains a marginal market. According to Nexus Mutual founder Hugh Karp: "Less than 2% of DeFi's TVL is covered or insured, and we see that as one of the largest barriers to real DeFi adoption."
The numbers reflect the mismatch:
| Metric | Value | |---|---| | DeFi TVL (June 2026) | ~$72.5B | | Insured TVL | <2% (~$1.5B) | | On-chain insurance TVL | $123.5M (28 protocols) | | Nexus Mutual market share | ~95% of on-chain insurance | | 2026 YTD exploit losses | $840M+ | | Cumulative uninsured losses (6 years) | $7.7B |
CertiK senior audit partner Dan She explained the demand-side problem: "Most DeFi users are yield-driven and do not want to give up several percentage points of return for cover." Spectra Finance founder Gaspard Peduzzi noted a supply-side issue with earlier insurance models: "You were just stacking counterparty risk on top of the counterparty risk."
Altura COO Matthew Pinnock added that in previous exploit events, "the capital backing the cover was often exposed to the same risks as the underlying protocol, so it evaporated precisely when it was needed most."
The global crypto insurance market was valued at $9.49 billion in 2025, with projections reaching $192.7 billion by 2033. But most of that is custodial and exchange-level coverage. On-chain protocol insurance remains structurally underwritten.
DeFi's total value locked has declined from approximately $178 billion in late 2025 to $72.5 billion as of mid-June 2026, a 59% drawdown. The exploit wave is one driver, but not the only one. Stablecoin lending rates on major platforms range between 3.5% and 9%, reflecting weaker borrowing demand. Stablecoin supply remains near $315 billion, indicating that liquidity has not left the ecosystem — it has moved to the sidelines.
The BeInCrypto research team noted that exploit-driven TVL losses have pushed DeFi leverage ratios back to 2021 levels, suggesting a structural de-risking across the sector.
The data from Q2 2026 challenges two common assumptions. First, that DeFi security improves monotonically as the industry matures — the record exploit count suggests the opposite, with attack surface expanding faster than defensive capacity. Second, that smart contract audits are sufficient — the quarter's costliest breaches exploited human processes, infrastructure dependencies, and off-chain trust assumptions that no code audit would catch.
The DPRK attribution trend, if sustained, implies that a single state actor now dominates the loss landscape for an entire asset class. The insurance gap suggests the market has not yet priced this risk. And the 59% TVL drawdown indicates that capital allocators, institutional and retail alike, are responding to the cumulative security record with reduced exposure.
The quarter's lessons are operational, not theoretical. Bridge quorum thresholds, admin-key storage practices, and social engineering countermeasures are process problems with known solutions. Whether the industry implements them at scale before the next quarter's data arrives remains an open question.