NewsCryptoCrypto Hacks Caused $1.32 Billion in Losses in First Half of 2026

Crypto Hacks Caused $1.32 Billion in Losses in First Half of 2026

Author: The Market Periodical·

Key Takeaways

  • •Crypto protocols lost $1.32 billion in the first half of 2026 across hundreds of publicly disclosed hacks.
  • •Access-control failures drove many of the largest losses, including $292 million at Kelp DAO and $280 million at Drift Protocol.
  • •Phishing and social engineering attacks accounted for $282 million in losses during the period.
  • •TRM Labs reported that the average loss per hack was about $220,000, the lowest for any prior six-month period.
  • •Industry experts differed on whether artificial intelligence will accelerate crypto attacks or lead major protocols to improve defenses.
Crypto Hacks Caused $1.32 Billion in Losses in First Half of 2026

Crypto protocols lost $1.32 billion in the first half of 2026 across hundreds of publicly disclosed hacks, with the largest losses tied to access-control failures, phishing and social engineering attacks, and oracle-related exploits.

The Market Periodical’s source data cited 224 crypto hacks in its key insights, while the article body reported $1.32 billion in losses across 244 publicly disclosed hacks during the period. Onchain Lens shared related data on X, saying most of the losses came from a small number of incidents: https://x.com/onchainlens/status/2080920931623682522?s=46.

The first-half total shows that hacks remain a major risk for crypto protocols, though the losses were lower than in the prior year. The Bybit hack in February 2025 alone caused $1.4 billion in losses. The concentration of losses in a few large incidents also underscores how privileged access, governance controls, and cross-chain infrastructure can create high-impact failure points when they are compromised.

Access-Control Failures and Phishing Led Major Losses

According to Onchain Lens, most of the highest-loss attacks in the first half of 2026 stemmed from access-control failures. These incidents included cases in which attackers compromised permissions or obtained privileged access to protocols.

The two largest incidents during the period occurred in April and involved access-control failures. Kelp DAO and Drift Protocol were hacked for $292 million and $280 million, respectively.

In the Kelp DAO attack, hackers compromised off-chain RPC nodes to exploit the LayerZero verifier setup and trick it into releasing ETH. The Drift Protocol incident involved social engineering to gain access to the protocol’s Security Council and pre-sign transactions.

Other large crypto hacks involved attackers using different methods to compromise access and steal funds. BonkDAO lost $21 million from its treasury through a governance exploit.

Phishing and social engineering attacks accounted for $282 million in losses. Oracle issues were the third major attack vector, with Bonzo Finance, Ostium, and the Blend protocol each losing millions of dollars through oracle exploits. Oracle attacks are especially significant for DeFi because protocols often use external price feeds or market data to determine collateral values, liquidations, and settlement outcomes.

Smaller Attacks Increased as AI Risks Drew Attention

A notable pattern in the first half of 2026 was the prevalence of smaller attacks. Blockchain security firm TRM Labs said in its 2026 H1 report that the period saw more crypto hacks, while the average loss per hack was about $220,000. That figure was lower than in any previous six-month period.

Most of the hacks were smart contract exploits targeting DeFi protocols, token projects, and decentralized exchanges. The data points to a security environment in which large, highly publicized incidents remain important, but routine attacks against smaller projects also account for a growing share of disclosed exploit activity.

Some experts, including OpenZeppelin founder Manuel Aráoz, have said advances in artificial intelligence could affect all of DeFi. Aráoz discussed the issue on X: https://x.com/maraoz/status/2059413451265441990?s=20.

A few months earlier, an AI system discovered a vulnerability that would have allowed unlimited ZEC tokens to be minted on the Zcash network. Anthropic also released a report in December 2025 showing that its AI agent successfully exploited 63% of 405 smart contracts that had been breached between 2020 and 2025.

However, not everyone agrees that AI will accelerate crypto attacks. DragonFly managing partner Haseeb Qureshi said the concern is mostly a false alarm because major crypto protocols will also strengthen their defenses. Qureshi commented on the issue on X: https://x.com/hosseeb/status/2076682247168827849?s=20.

Qureshi noted that while the number of hacks has increased, the size of attacks has declined. He said this suggests attackers are focusing on smaller protocols and projects that have not improved their code against AI-related threats.