Need help? Support
BITCOIN
Tether Dominance USDT.D

TRM report shows record 207 crypto hacks

Published 508 words 3 min read

TLDR

TRM Labs reports a record 207 crypto hacks in the first half of 2026, but total losses are lower than in 2025.

  1. Hacks more than doubled year on year, yet stolen value dropped to about $972 million from $2.3 billion in H1 2025.
  2. Most incidents hit smart contracts, but the biggest losses came from operational failures like compromised keys and infrastructure.
  3. For users and projects, the main risk is no longer just buggy code, but weak key management, bridge exposure, and poor incident response.

Deep Dive

1. Record Hack Count, Smaller Average Losses

TRM Labs H1 2026 report finds 207 crypto hacks, up sharply from 83 in the first half of 2025, making it the highest incident count on record. At the same time, total losses fell to about $972 million, less than half the $2.3 billion lost in H1 2025, with a median loss near $219,000 and a mean around $4.7 million per incident, according to a summary by CryptoSlate that cites TRMs data.

This points to a shift from a few mega-exploits to more frequent, smaller attacks. From a market perspective, that kind of background drip of hacks still erodes confidence, but it is less immediately catastrophic than single multihundred-million dollar events.

Confidence: high, based on TRM Labs 2026 crime statistics and independent reporting.

2. Smart-Contract Bugs vs Operational Failures

TRM Labs says smart-contract issues still dominate in count, with 125 of the 207 incidents involving code-level exploits. However, it highlights that infrastructure and operational compromises, such as leaked keys, compromised signing systems, and misuse of privileged access, represented only about 15 percent of incidents but roughly 76 percent of stolen value.

North Korea-linked actors are a major driver. TRM attributes about $643 million, or roughly two thirds of all funds stolen in H1 2026, to two April attacks, on Drift Protocol and KelpDAOs LayerZero bridge, which combined technical intrusion with social engineering and infrastructure compromise. Funds often moved through cross-chain bridges and low-KYC swaps, making recovery difficult.

What this means

Audits alone are not enough; the most damaging attacks are targeting humans, keys, and off-chain infrastructure rather than just on-chain code.

3. Practical Implications For Crypto Users And Builders

For everyday users, the main takeaway is that platform-level security and operational discipline matter as much as smart-contract safety. TRMs report urges teams to harden key management, require hardware-backed signing, enforce multi-party approvals for privileged actions, and monitor developer devices and access paths.

For protocols and treasuries, the guidance is to plan for infrastructure compromise, not only contract bugs: have tested incident-response playbooks, diversified treasury storage, and clear communication plans if keys or verifier infrastructure are ever at risk. On the monitoring side, single-hop screening of addresses is no longer sufficient; multi-hop tracking across bridges and exchanges is becoming standard in compliance.

Conclusion

TRM Labs finding of 207 hacks with under $1 billion in losses suggests attackers are more active but not weaker, shifting toward numerous smaller incidents plus occasional large infrastructure breaches. The highest-value risks now sit at the intersection of code, human behavior, and off-chain systems, which means both users and projects should focus less on audit and forget and more on ongoing operational security, cross-chain risk monitoring, and clear response plans when something goes wrong.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top