Crypto Hacks Top $1 Billion in 2026 Amid Scaling and Professionalized Threats
In 2026, the total value of cryptocurrency hacks surpassed $1 billion by mid-year, with wallet compromises being the most costly vector. According to TRM Labs, there were 207 hacks in the first half of 2026, resulting in approximately $972 million stolen. CertiK reported even higher figures: 344 incidents and over $1.316 billion lost, with about $444.5 million attributed to wallet compromise alone.
The April blowups of KelpDAO and Drift accounted for nearly 44% of H1 losses on CertiK's tally. Blockaid's analysis attributed nearly $600 million in losses to DPRK-linked operations, including the same incidents. The increasing number of hacks can be attributed to the scaling of cryptocurrency, with new rollups, appchains, and liquidity layers introducing more bridges, relayers, oracles, and operational keys.
Attackers have professionalized and industrialized, using state-linked crews and polished ransomware-style playbooks. This has led to an increase in high-permission failures, which can dominate a year's loss curve. Security spend is not the same as security outcomes, with teams focusing on audits, bug bounties, and monitoring while neglecting governance scripts, deploy pipelines, and signer devices.
New chains and products multiply secrets and endpoints, making it difficult for organizations to rotate or scope them well under pressure. Rollups and appchains compress timelines, narrowing the chance to catch malicious parameters or confused-deputy patterns before they're live. Professionalized adversaries with patience are waiting months to phish the right signer or map a vendor stack.