
Crypto hacks exceeded $1 billion in H1 2026, led by wallet compromise and two April incidents. TRM Labs, CertiK, and Blockaid all track rising losses as attackers target control-plane failures.
Crypto hacks across the first six months of 2026 exceeded $1 billion in stolen funds, according to three separate tracking firms. TRM Labs counted 207 incidents with about $972 million lost, a median loss of $219,000. CertiK logged 344 incidents with roughly $1.316 billion gross and $1.2 billion net after frozen or recovered funds. Blockaid, in data reported by The Block, put the total over $1 billion and attributed nearly $600 million to North Korea-linked operations.
Wallet compromise was the costliest vector, CertiK said, driving about $444.5 million across just 33 incidents. Two April cases, KelpDAO and Drift, accounted for almost 44% of H1 losses on CertiK's tally. The same two incidents featured in Blockaid's DPRK attribution, the firm said.
Attackers are not waiting for a bull market. They need liquidity, weak keys, and a team in a hurry. Two forces are colliding. Crypto keeps scaling with new rollups, appchains, and liquidity layers, which multiply bridges, relayers, oracles, and operational keys. On the other side, attackers have professionalized. State-linked crews treat crypto exploits as a revenue line, with polished playbooks targeting control-plane failures.
Most high-dollar hits in 2026 were not cryptographic breaks, security teams said. They were control-plane failures: keys, permissions, and front-ends. Per CertiK, wallet compromise drove the largest losses. That tracks with what many security teams see: the most dangerous bug is a leaked, phished, or mis-scoped key.
On-chain governance often funnels power through multisigs, guardians, or emergency pause keys with broad authority. A single compromised signer, rushed upgrade, or bad timelock config can be enough, several security analysts said. Bridges remain complex systems with validators, relayers, oracles, state proofs, and time-sensitive assumptions. Hardening one component does not protect against an off-chain credential or a dependency that is not version-locked.
The quiet drain also continues: poisoned websites, malicious ads, and spoofed interfaces that trick users into signing toxic approvals. These may not make nine-figure headlines by themselves, but in aggregate they produce steady, repeatable loss, TRM Labs said.
Attackers time their moves around volatile weeks when teams rush hotfixes, rotate keys, and deploy patches in production. The riskiest period is right after a fix ships, because teams relax once the fire is out, several security engineers said.
What would reduce the risk? Tight role scoping, hardware-backed signers, higher multisig quorums for high-value actions, timelocks for upgrades, scheduled key rotation, and strict separation of staging from production. For users, treating hot wallets like cash in a pocket rather than a vault, revoking allowances often, and pausing when front-ends behave oddly, multiple security firms said.
What would make it worse? Continued scaling of endpoints and secrets without matching security headcount. New chains and products multiply secrets and endpoints. One hot wallet for an allowlist turns into five. One multisig becomes three with overlapping signers, the analysts said. Every new partner integration adds another API key, webhook, and dashboard. Most organizations do not rotate or scope those well under pressure, several security audits noted.
State-linked crews will wait months to phish the right signer or to map a vendor stack. Blockaid's H1 snapshot attributes nearly $600 million in losses to DPRK-linked operations, including the April marquee incidents. They will continue to target operators and vendors, the firm said.
TRM Labs noted that the median loss of $219,000 across 207 incidents points to a persistent threat from smaller-scale attacks, not just headline breaches. The count of incidents is rising alongside absolute dollar losses, even if the trackers define events differently and net out recoveries in varied ways. The trend alignment across all three major trackers confirms the direction: more incidents, larger absolute losses, and a concentration in wallet compromise.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.