Crypto Hacks Rose to $763M in Q2 2026 as Operational Failures Drove Losses
Key Takeaways
- •Crypto hack losses reached approximately $764 million across 67 incidents in Q2 2026, representing a 58.3% increase from the previous quarter.
- •Operational and infrastructure failures such as compromised keys and signers accounted for 88.3% of total losses, while smart contract bugs caused only 11% despite being more frequent.
- •Hacken attributed 75.5% of all stolen funds to actors linked to the Democratic People's Republic of Korea.
- •The report documented the first known case of a malicious AI prompt injection resulting in the theft of $174,000 during the quarter.
- •Under the EU's MiCA regulation, only about 215 crypto-asset service providers obtained full authorization by the July 1 deadline, while major exchanges including Binance, MEXC, and HTX were forced to shut down.

Crypto hacks resulted in $763,971,791 in stolen funds across 67 incidents in Q2 2026, with access-control weaknesses identified as the largest single point of failure, according to a recent report by blockchain security and compliance firm Hacken.
Crypto hack losses reached the highest level since Q2 2025
Hacken’s Q2 2026 security report said crypto hack losses increased 58.3% from $482.7 million in Q1, reaching the highest quarterly total since Q2 2025. The report is available at
Drift Protocol and KelpDAO recorded the two largest capital extractions during the quarter, at about $290 million each.
Although smart contract bugs accounted for the largest number of incidents, they represented only 11% of total losses. Operational and infrastructure failures, including compromised keys and compromised signers, accounted for a much larger share, at 88.3% of all losses. That split underscores Hacken’s finding that major losses increasingly depend not only on code defects, but also on how protocols manage privileged access, signer permissions and internal security processes.
Hacken attributed 75.5% of the drained funds to actors linked to the Democratic People’s Republic of Korea (DPRK).
The report also noted a recent disclosure by Consensys, the company behind Ethereum wallet MetaMask, which acknowledged that it had hired a software developer linked to North Korea. Consensys said it discovered the issue a month later, dismissed the individual and revoked system access. The firm reported the matter to law enforcement and said no user funds were lost, no data was leaked and no malicious code was deployed.
Hacken also documented what it described as the first case in Q2 of malicious AI prompt injection leading to an exfiltration of $174,000. The firm said the failure stemmed from “inadequate review, missing variants and weak testing.” The case adds AI tooling and review controls to the operational risks that security teams are being asked to monitor alongside traditional private-key and access-management practices.
Regulatory compliance developments in Q2 2026
On regulatory compliance, Hacken said U.S. crypto rules under the GENIUS Act are expected to take effect in early 2027.
In the European Union, the grace period for crypto companies to pursue a full license expired on July 1. By that date, only about 215 Crypto-Asset Service Providers (CASPs) had obtained authorization under the Markets in Crypto-Assets Regulation (MiCA), despite 1,200 entities expressing interest.
Binance, MEXC and HTX, formerly Huobi, were among the most prominent exchanges forced to shut down under the rule. Hacken also said Circle’s USDC is currently the only MiCA-compliant stablecoin among the top 10 by market capitalization.
The compliance figures show how security and regulatory readiness are converging for crypto firms, with authorization, stablecoin status and counterparty due diligence becoming part of the same risk assessment for users and institutions.
Hacken said the most trusted counterparties in the future will be those that prove safety first, regardless of how long they have existed, their audits or their total value locked.