I keep seeing headlines celebrating a drop in crypto hack losses this year, and I think that framing misses the real story.
Key Takeaways
- Crypto hacks totaled $1.315 billion across 344 incidents in the first half of 2026, a 46.8% decline from the prior year’s figure.
- Nearly 44% of all losses came from just two incidents — Kelp DAO and Drift Protocol — neither of which involved a smart contract bug.
- Wallet compromise, not code exploits, is now the costliest attack category, averaging more than $13 million per event.

What happened
| Loss Source | Amount | Share of H1 2026 Total |
|---|---|---|
| Kelp DAO + Drift Protocol (2 incidents) | $578M | ~44% |
| Remaining 342 incidents | ~$737M | ~56% |

According to CertiK’s Hack3D report, $1,315,676,432 was stolen across 344 on-chain incidents between January and June 2026. On paper, that’s meaningfully lower than the year before. But security researchers quickly pointed out why the number looks smaller: last year’s total was inflated by a single massive hack, and this year’s losses are simply more concentrated.
Two incidents — Kelp DAO, which lost $293 million, and Drift Protocol, which lost $285 million — accounted for nearly 44% of the entire half-year total. In both cases, the smart contract code itself was clean.
Kelp’s loss traced back to a compromised validator handling cross-chain message verification. Drift’s came from a manipulated signing interface. Neither was the kind of bug a code audit would have caught.
CertiK’s data shows wallet compromise is now the single costliest attack vector, totaling more than $444 million across the half. Code bugs remained the most frequent category by count, but they’re also the least profitable per incident.
Attackers, in other words, have shifted their attention from hunting bugs to attacking the humans and processes that manage keys, multisig approvals, and validator infrastructure. Analysts also flagged an emerging concern: AI agents with wallet access, and increasingly sophisticated nation-state actors, including North Korea-linked groups.
What the per-incident averages reveal
Running CertiK’s own numbers makes the shift clearer. Dividing $1.315 billion by 344 incidents puts the overall average loss near $3.8 million per hack. Wallet compromise, at more than $13 million per event, runs more than three times higher than that baseline.
That gap matters because frequency and severity moved in opposite directions. Code bugs stayed the most common category by count, yet they no longer produce the biggest paydays.
Attackers appear to be trading volume for precision — going after fewer targets that pay out far more per hit, rather than scanning broadly for exploitable code.
Kelp DAO’s $293 million loss and Drift Protocol’s $285 million loss both fit that pattern. Neither required finding a flaw in deployed code.
Both required getting close to the infrastructure that controls keys and cross-chain verification — a different skill set than auditing a smart contract line by line.
None of this means the smaller 342 incidents don’t matter. Together they still added up to roughly $737 million, more than half the half-year total.
That pool is spread across code bugs, phishing, and other categories CertiK tracks separately. The industry’s bug-hunting defenses are working; they’re just no longer where the biggest checks get written.
The two lenses
Lens one: Progress is real, even if it’s incomplete. A 46.8% year-over-year decline is not nothing. It suggests that the crypto industry’s years of investment in smart contract auditing, bug bounties, and formal verification tools are paying off in exactly the area they were designed to address — code-level vulnerabilities.
Fewer projects are getting drained through reentrancy bugs or flash loan exploits than in prior cycles. That’s a genuine engineering win, and it reflects a maturing security culture across DeFi protocols that have learned from a decade of costly lessons.
This kind of steady improvement in code review practices has been building for years.
Lens two: The attack surface just moved, it didn’t shrink. The more sobering reading is that total dollar losses barely changed in structure — they just concentrated into fewer, more surgical hits. When 44% of losses come from two incidents involving compromised validators and manipulated signing interfaces, that’s not evidence of a safer ecosystem.
It’s evidence that sophisticated attackers, including nation-state groups, have simply redirected their resources toward the weakest link: human and operational security around key management. A protocol can have flawless code and still lose hundreds of millions if the people or systems controlling its keys are compromised. That’s a much harder problem to audit away.
Why key management is harder to outsource than code review
Smart contract audits are a service the industry has standardized around: a third party reviews code before deployment and signs off. Validator custody and signing infrastructure don’t have an equivalent standard yet.
That gap is part of why CertiK’s report flagged wallet and key compromise as the newer, costlier risk category this half.
A protocol can pay for the best audit available and still depend on a handful of people or servers to approve transactions correctly. If that layer is compromised, the audit certificate becomes irrelevant to the outcome.
This is why the report’s own recommendation — publishing operational security practices with the same rigor as code audits — is a harder ask than it sounds.
Hardware security modules, distributed key management, and validator redundancy all cost money and slow operations down, which is exactly why many projects have skipped them so far.
Why it matters
This shift matters most for institutional players and treasury managers who assume “audited code” equals “safe.” It doesn’t, not anymore.
Multisig governance, validator key custody, and signing infrastructure are now the primary targets, and those are organizational and procedural weaknesses rather than technical ones.
For everyday users, the takeaway is narrower but still relevant: platforms handling your funds need to demonstrate operational security, not just point to a code audit certificate.
What to watch going into the second half of 2026 is whether exchanges and protocols start publishing operational security practices with the same rigor they’ve applied to code audits — things like distributed key management, hardware security module usage, and validator redundancy. If that doesn’t happen, expect the “fewer but more surgical” pattern to keep repeating.
The number went down. The risk didn’t.
FAQ
Q. Were these hacks caused by hackers exploiting smart contract bugs?
A. No. CertiK’s report specifically notes that the two largest incidents, Kelp DAO and Drift Protocol, involved compromised validator infrastructure and a manipulated signing interface rather than flaws in the smart contract code itself.
Q: Is crypto actually getting safer overall?
A: The total dollar amount stolen did decline year-over-year, but researchers caution this partly reflects one unusually large hack inflating the prior year’s figure, while the underlying attack surface has simply shifted toward wallet and key management rather than disappearing.
What would change our view
My read is that the concentration in Kelp DAO and Drift Protocol, not the headline decline, is the real signal here.
That view would weaken if next year’s report shows losses spreading back out across many smaller code-exploit incidents — the pattern CertiK says is fading now.
It would also weaken if protocols widely adopt the operational security practices CertiK flagged and wallet-compromise losses drop in the second half of 2026 without another concentrated hit taking their place.

Leave a Reply