The second quarter of 2026 closed as the most-hacked quarter in cryptocurrency history by incident count, with 83 exploits draining $755.3 million from protocols, according to DefiLlama data. The figure brought H1 2026 losses to approximately $972 million across 207 incidents — more than double t...
"We made a mistake. We own that." — Bryan Pellegrino, CEO, LayerZero Labs, on the $292M KelpDAO exploit (May 2026)
The second quarter of 2026 closed as the most-hacked quarter in cryptocurrency history by incident count, with 83 exploits draining $755.3 million from protocols, according to DefiLlama data. The figure brought H1 2026 losses to approximately $972 million across 207 incidents — more than double the 83 incidents recorded in H1 2025, per TRM Labs.
Two attacks accounted for 76% of Q2 losses: the $292 million KelpDAO bridge exploit and the $285 million Drift Protocol hack, both attributed to North Korea's Lazarus Group. The quarter exposed a structural shift in how attackers operate. Smart contract exploits represented 125 of 207 H1 incidents but only 24% of total dollar losses. Infrastructure and operational compromises — private key theft, compromised admin accounts, and manipulated off-chain systems — accounted for just 15% of incidents but 76% of total funds stolen.
The data presents a paradox: DeFi-specific exploits dropped 89% year-over-year in Q1 2026 as audit coverage and formal verification matured. Yet total incident counts doubled. Attackers have shifted from exploiting code to exploiting people, infrastructure, and configuration errors.
| Metric | Q2 2026 | Q1 2026 | H1 2026 Total | |--------|---------|---------|---------------| | Incidents | 83 | 124 | 207 | | Total losses | $755.3M | ~$217M | ~$972M | | Largest single exploit | $292M (KelpDAO) | — | $292M (KelpDAO) | | Bridge-related losses | $351M | — | — |
Monthly Q2 breakdown:
The $755.3M in Q2 losses remains well below the $3.56 billion lost in Q4 2020, which holds the record for costliest quarter by dollar amount. But Q2 2026's 83 incidents represent the highest quarterly incident count ever recorded, according to multiple data aggregators including DefiLlama and CoinTelegraph.
The largest exploit of 2026 was not a smart contract bug. Attackers compromised internal RPC nodes and launched DDoS attacks against external nodes to feed false data to KelpDAO's verification network. The protocol used a single-verifier (1-of-1 DVN) configuration on LayerZero's cross-chain messaging layer, which allowed the attackers to trick the bridge into releasing 116,500 rsETH to an attacker-controlled address.
The incident triggered a public dispute between KelpDAO and LayerZero Labs. LayerZero initially blamed KelpDAO for choosing a 1-of-1 verifier setup despite warnings to adopt multi-verifier security. KelpDAO countered that LayerZero personnel had approved the configuration. A Dune Analytics review later revealed that 47% of all active LayerZero OApp contracts used identical 1-of-1 DVN setups at the time of the exploit.
LayerZero CEO Bryan Pellegrino ultimately acknowledged the company "made a mistake" in allowing its own verifier network to secure high-value assets in a minimal configuration.
Aftermath: KelpDAO shifted its rsETH bridge to Chainlink's CCIP infrastructure. Solv Protocol moved more than $700 million in tokenized bitcoin infrastructure away from LayerZero. LayerZero migrated all default configurations to a minimum of 3-of-3 DVN verification, with 5-of-5 where possible.
On Solana's largest perpetuals exchange, an attacker created a fabricated token called "CarbonVote Token" (CVT), minted approximately 750 million units, and seeded a $500 liquidity pool on Raydium. Over time, wash trading built a price history near $1 that was picked up by oracles, making CVT appear legitimate. Using inflated CVT collateral, the attacker executed 31 rapid withdrawals within approximately 12 minutes, draining tens of millions in USDC, JLP, and other tokens.
TRM Labs attributed the attack to North Korean state-backed actors. Bloomberg reported the attack as "the largest DeFi exploit on Solana since the $326 million Wormhole bridge hack in 2022."
Recovery: Drift outlined a plan to issue recovery tokens pegged to verified user losses, with a pool starting at $3.8 million and potentially growing to $151 million from revenue, Tether support, and partner contributions against $295.4 million in total verified losses.
The distribution of attack methods in H1 2026, according to TRM Labs:
| Attack Vector | Share of Incidents | Share of Dollar Losses | |--------------|-------------------|----------------------| | Smart contract exploits | 60% (125 of 207) | ~24% | | Infrastructure/operational compromises | ~15% | ~76% | | Bridge exploits (subset) | — | $351M in Q2 alone | | Private key compromises | — | 40% of Q2 losses per CryptoNews |
The data reveals that code-level security has improved substantially. The problem has migrated upstream — to key management, admin access controls, cloud infrastructure, and human operational security. Attackers are increasingly targeting the people and systems around the code, not the code itself.
The Humanity Protocol hack in June illustrates the pattern. An employee's laptop was compromised, exposing private keys for multisig wallets. Attackers gained three of five keys attached to a BNB Chain bridge configuration, added a malicious contract with an infinite mint function, and generated H tokens at will. The H token crashed 81%, from $0.708 to $0.135. On-chain investigator ZachXBT flagged the incident as potentially an exit scam, though Quantstamp noted that tooling and techniques matched those commonly attributed to North Korean groups.
North Korea-linked threat actors accounted for $643 million — 66% of all stolen funds in H1 2026, according to TRM Labs. Chainalysis has attributed approximately 76% of crypto-related hack losses globally through April 2026 to state-backed actors linked to the Lazarus Group.
The Lazarus Group's cumulative attributed crypto theft now exceeds $6.75 billion across all incidents since 2017, per BlockEden analysis. DPRK-linked actors stole $2.02 billion in 2025 alone, a 51% year-over-year increase.
The two largest Q2 2026 exploits — KelpDAO and Drift — were both attributed to DPRK-linked groups by blockchain analytics firms TRM Labs and Chainalysis respectively. The FBI previously confirmed the Lazarus Group's involvement in the $1.5 billion Bybit hack of February 2025, the largest single cryptocurrency theft on record.
The concentration of losses among state-backed actors raises a structural question about the security model of decentralized finance. These are not opportunistic hackers exploiting known vulnerabilities. They are well-resourced intelligence operatives conducting sustained campaigns against infrastructure weaknesses.
Cross-chain bridges continue to be disproportionately targeted. Bridge-related exploits accounted for $351 million in Q2 losses alone, led by the KelpDAO incident. Through May 2026, PeckShield tracked eight major bridge-related exploits totaling $328.6 million.
The structural vulnerability is well-understood: bridges must trust state information from a chain that the destination chain cannot natively verify. This creates a fundamental reliance on off-chain verification infrastructure — exactly the kind of operational component that has proven most vulnerable to sophisticated attackers.
Notable bridge incidents in 2026 beyond KelpDAO:
Following the KelpDAO exploit, LayerZero implemented significant security changes:
The smart contract audit market reached $890 million in 2024 and is projected to grow at 22.8% CAGR to $6.1 billion by 2033, according to Dataintelo. Top-tier audits in 2026 cost $80,000-$350,000 per scope. Formal verification adoption crossed an inflection point in 2025, with roughly one-third of high-value engagements now shipping with at least one Certora or Halmos invariant suite.
DeFi insurance remains underdeveloped relative to the scale of losses. Nexus Mutual, the largest on-chain insurance protocol, generated $5.7 million in cover fees in 2025 and holds approximately $6 billion in total protection. However, the protocol explicitly excludes phishing, loss of private keys, malware, and exchange hacks — precisely the attack vectors responsible for the majority of 2026 losses.
The most counterintuitive finding from H1 2026 data: smart contract security has materially improved, and yet total losses remain high. DeFi-specific exploits dropped 89% year-over-year in Q1 2026, per industry data. Formal verification, invariant testing, and multi-audit mandates have meaningfully reduced code-level vulnerabilities.
But the attack surface has expanded beyond code. The $972 million in H1 losses was driven overwhelmingly by operational failures — compromised keys, misconfigured infrastructure, social engineering, and supply chain attacks on off-chain components.
The audit industry's $890 million market is optimized for code review. It is not optimized for auditing DevOps pipelines, key management practices, employee security training, or cloud infrastructure configurations. The gap between what gets audited and what gets exploited continues to widen.
The H1 2026 data tells a clear story: the crypto industry is winning the battle on smart contract security while losing the war on operational security. Code audits, formal verification, and bug bounties have substantially reduced code-level exploits. But the $972 million in losses was overwhelmingly driven by compromised keys, misconfigured infrastructure, and sophisticated social engineering — attack vectors that exist outside the scope of traditional code audits.
The dominance of state-backed actors in the loss statistics — 66% of H1 2026 losses attributed to DPRK-linked groups — suggests that the threat model for high-value DeFi infrastructure should assume nation-state-level adversaries. The industry's security spending, estimated at $890 million annually for audits alone, needs to expand beyond code review to encompass operational security, infrastructure hardening, and key management. Until it does, quarterly incident records will likely continue to fall.