Q2 2026 recorded 85 separate crypto security incidents with approximately $775 million in aggregate losses, making it the most active quarter for exploits in the history of the crypto industry by incident count, according to data from PeckShield and Immunefi. The figure follows Q1 2026's 36 incid...
"The attacker relied on tooling and techniques commonly associated with North Korean hacking groups." — Quantstamp, post-incident analysis of the Humanity Protocol breach (June 2026)
Q2 2026 recorded 85 separate crypto security incidents with approximately $775 million in aggregate losses, making it the most active quarter for exploits in the history of the crypto industry by incident count, according to data from PeckShield and Immunefi. The figure follows Q1 2026's 36 incidents and $450 million in losses, bringing H1 2026 estimated theft to approximately $1.22 billion across 121 incidents.
Two attacks — the $292 million KelpDAO bridge exploit on April 18 and the $285 million Drift Protocol drain on April 1 — accounted for over 75% of Q2's total damage. Both have been attributed with medium-to-high confidence to North Korea's Lazarus Group by TRM Labs and Chainalysis. Cross-chain bridges remained the single largest attack surface, responsible for roughly 46% of Q2 stolen funds. The pattern is not new; it is intensifying.
The data represents a structural escalation: more frequent attacks, persistent bridge vulnerabilities, and an expanding share of losses attributable to a single state actor. For protocols and their users, the economic cost of security failure is compounding faster than the industry's ability to contain it.
The quarter's aggregate figures, compiled from PeckShield, Immunefi, and Chainalysis tracking, paint a clear picture of escalation:
| Metric | Q1 2026 | Q2 2026 | Change | |---|---|---|---| | Total incidents | 36 | 85 | +136% | | Total losses | ~$450M | ~$775M | +72% | | Largest single exploit | $340M (Jan) | $292M (KelpDAO) | — | | Average loss per incident | $12.5M | $9.1M | -27% |
The increase in incident count — 49 more than Q1 — represents a shift toward more frequent, smaller-scale attacks alongside the headline-grabbing megahacks. Q2's 85 incidents are the highest quarterly count ever recorded in crypto security tracking.
Despite the record incident count, Q2's $775 million in losses remains below the all-time quarterly record of $3.56 billion set in Q4 2020 and well below Q1 2025's $1.63 billion (dominated by the $1.5 billion Bybit exploit in February 2025). The distinction matters: 2026 is characterized by volume and frequency rather than a single catastrophic event.
An attacker exploited Kelp DAO's LayerZero-powered bridge to drain 116,500 rsETH — approximately $292 million and roughly 18% of the token's circulating supply. According to Chainalysis's post-incident analysis, the exploit was not a traditional smart contract vulnerability.
The attack mechanism: Lazarus Group operatives compromised internal RPC nodes and DDoS'd external nodes to feed false data to a single-point-of-failure verification network. KelpDAO's rsETH bridge was configured with a single verifier — the LayerZero Labs DVN — with no second DVN required for consensus. The attacker tricked the Ethereum contract into releasing funds based on a phantom token "burn" on the source chain.
Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes after the initial drain. Two follow-up attempts at 18:26 and 18:28 UTC — each carrying another 40,000 rsETH (~$100 million) — reverted against the frozen contracts. Had the response been slower, total losses could have exceeded $390 million.
Because the bridge held reserves backing rsETH across more than 20 networks, the exploit triggered contagion: Aave, SparkLend, and Fluid all froze rsETH-related markets. According to The Defiant, Aave was left with over $200 million in bad debt from the incident.
The Drift exploit on Solana represented a different attack class entirely. According to The Hacker News, the breach was the culmination of a six-month social engineering operation attributed to DPRK-linked group UNC4736 (also tracked as AppleJeus, Citrine Sleet, and Gleaming Pisces).
The attackers used Solana's "durable nonces" feature to get Drift Security Council members to unknowingly pre-sign transactions that eventually transferred admin control. Once in possession of protocol admin privileges, the attackers whitelisted a fabricated token (CVT) as collateral, deposited 500 million units, and used it to withdraw $285 million in USDC, SOL, and ETH — all within approximately 12 minutes.
TRM Labs attributed the theft to North Korean operators. The attack was the second-largest in Solana's history behind only the $326 million Wormhole bridge hack of 2022.
June 2026 closed with 40-45 recorded incidents (the count varies by tracker) and approximately $75.87-$79.06 million in disclosed losses, according to PeckShield and Cryip data respectively.
The month's largest incident was the Humanity Protocol private key compromise on June 9, which accounted for $32 million — approximately 40% of June's total. Attackers compromised private keys backed up to a malware-infected developer machine. The H token fell from $0.67 to approximately $0.05 intraday, an ~90% decline. On-chain investigator ZachXBT publicly questioned whether the incident was "possibly staged," noting that a single compromised key should not have been able to issue new token supply — a power normally reserved for project administrators.
Other notable June incidents included the Syscoin bridge exploit ($10 million, with 5 billion unauthorized SYS tokens minted via a proof validation flaw), a Polymarket phishing campaign targeting users ($3 million), and losses at SecondFi and TESSERA ($2.4 million combined).
Protocol logic flaws were the most common attack category in June, accounting for 30 of 45 recorded incidents (66.7%), according to Cryip's classification.
The Syscoin incident offered a rare outcome: the attacker returned all 5 billion minted tokens to a designated recovery address after the Syscoin team traced the funds and made on-chain contact. Full recoveries remain exceptional.
Cross-chain bridges accounted for $351 million — approximately 46% — of Q2 2026's total stolen funds. For the full H1 period, PeckShield tracked 14 bridge exploits totaling $340.7 million through early June, with additional incidents pushing the figure higher by quarter's end.
In May 2026, bridges represented 42% of all crypto exploit losses despite holding a fraction of total DeFi TVL, a ratio that has remained persistently elevated since 2022, according to CoinDesk analysis.
The failure modes have not changed. According to a CoinDesk post-mortem of the KelpDAO exploit, the attackers are not finding new vulnerabilities but rather exploiting the same structural weaknesses in cross-chain message verification and human key management, at larger scale, because bridge TVL keeps growing. The Verus-Ethereum bridge lost $11 million in May through a similar verification failure.
Key bridge vulnerabilities identified in 2026 exploits include single-point-of-failure verification (KelpDAO's 1-of-1 DVN setup), proof validation errors (Syscoin's parsing flaw), and insufficient operational security around admin keys (Drift's social engineering vector).
DPRK-linked actors represented 76% of all crypto hack value through April 2026, according to TRM Labs — $577 million out of $759 million total — despite accounting for only 3% of total hack incidents by count.
The concentration is extreme. Two attacks — KelpDAO ($292 million) and Drift ($285 million) — account for the majority of DPRK-attributed losses in 2026. In 2025, Lazarus Group stole $2.02 billion, a 51% year-on-year increase, pushing their cumulative all-time total to $6.75 billion, according to Chainalysis data.
A now-disbanded U.N. panel of experts estimated in a 2024 report that illicit cyber activity accounted for approximately 40% of funding for Pyongyang's weapons programs. Crypto theft is not a side operation; it is a structural component of DPRK's revenue model.
The attack methodology is evolving. The Drift Protocol hack required six months of social engineering groundwork. CertiK flagged a new "Mach-O Man" attack vector deployed by Lazarus Group in April 2026, targeting macOS development environments used by protocol teams. The shift from code exploits to human infrastructure suggests that smart contract audits alone are insufficient as a defense.
| Period | Total Losses | Notable Events | |---|---|---| | H1 2024 | ~$1.1B | Multiple protocol exploits | | Full Year 2024 | ~$2.2B | 21% increase over 2023 | | H1 2025 | ~$2.47B | Exceeded full-year 2024 total | | Full Year 2025 | ~$3.4B | Bybit $1.5B; DPRK $2.02B | | H1 2026 | ~$1.22B | KelpDAO $292M; Drift $285M |
H1 2026's $1.22 billion trails H1 2025's $2.47 billion, largely because 2025's figure was inflated by the singular $1.5 billion Bybit exploit. Removing Bybit from 2025's H1 tally yields approximately $970 million — making H1 2026's non-outlier baseline roughly 26% higher year-over-year.
The more relevant comparison may be incident frequency. H1 2026's estimated 121 incidents significantly exceeds the pace of prior years. The average loss per event has compressed — from roughly $15 million in 2025 to approximately $10 million in H1 2026 — suggesting a broadening of the attacker base beyond state-sponsored groups to smaller, more opportunistic operators.
Based on Q2 2026 data aggregated from PeckShield, Immunefi, and Cryip:
By attack surface (Q2 2026, % of losses):
By chain (notable Q2 incidents):
The dominance of bridge and credential-based attacks — together representing 83% of Q2 losses — underscores that the largest economic risks are infrastructure and operational, not algorithmic. Protocol logic exploits, while the most frequent by count, accounted for only 10% of total value stolen.
The data from Q2 2026 presents a security environment that is deteriorating in frequency even as individual incident severity moderates relative to 2025's outliers. The crypto industry's aggregate security spend — on audits, bug bounties, insurance, and incident response — has not kept pace with the expanding attack surface created by cross-chain bridges and multi-chain deployments.
The concentration of losses in bridge infrastructure (46% of Q2 value) and social engineering vectors (37%) implies that the most effective risk mitigation is not better code review but better operational security: multi-party verification for bridge message passing, hardware security modules for admin keys, and adversarial red-teaming that simulates state-actor social engineering campaigns.
The DPRK dimension adds a geopolitical overlay that the industry has limited ability to address unilaterally. With 76% of theft value attributed to a single state actor, crypto security is no longer purely a technical problem. It is a national security problem with protocol-level consequences. Protocols that hold significant TVL without state-actor-grade operational security are, in effect, subsidizing the very threat they cannot individually contain.