Private Keys Surpass Smart Contract Bugs as Top DeFi Hack Risk
The DeFi hacking landscape has shifted in favor of compromised private keys and wallet infrastructure over smart contract code flaws, according to recent data from CertiK and QuillAudits. In the first half of 2026, compromised private keys and wallet compromise accounted for $1.3 billion in losses across DeFi protocols, surpassing the total lost to smart contract bugs.
The two incidents that had the most significant impact on this shift were the Kelp DAO and Drift Protocol hacks. On April 18, attackers exploited a LayerZero-based bridge to drain $292 million from Kelp DAO's rsETH token through compromised internal RPC infrastructure. Just days earlier, on April 1, Drift Protocol lost around $285 million after attackers obtained compromised administrative keys tied to protocol governance.
The Liquid Network sidechain incident is an exception to this trend, as it was caused by a software bug in Elements, the codebase used by Liquid. However, most of 2026's largest losses have been attributed to operational and key-management failures rather than logic bugs in underlying protocol code.