TLDR
Security firms estimate that crypto hacks stole about $972 million in the first half of 2026, even as the number of attacks hit a record high.
- Immunefi and TRM Labs both put H1 2026 losses near $972 million across roughly 207 hacks, less than half the $2.3 billion stolen in H1 2025.
- A few major DeFi exploits on Ethereum and Solana drove most of the damage, while typical hack sizes and overall DeFi exploit losses have shrunk.
- Attackers are shifting from pure smart contract bugs toward keys, infrastructure and social engineering, which changes where users and projects need to focus their defenses.
Deep Dive
1. Scale Of 2026 Losses
Immunefis June 2026 Ecosystem Update and a summary via Yahoo Finance report that crypto projects lost about $972 million across 207 hacks in the first half of 2026, below $1 billion and less than half H1 2025s losses.
TRM Labs finds a similar total, citing roughly $972 million stolen in 207 incidents, while highlighting that this still represents the highest six month hack count recorded so far. Other trackers such as Blockaid estimate slightly above $1 billion, but all agree that incident volume is at record levels even as aggregate losses fall compared with the Bybit dominated 2025 figures.
Dollar losses look better mainly because 2025 had a few enormous breaches, not because attackers stopped targeting crypto. Frequency remains a clear red flag.
2. Where The Money Was Stolen
Multiple reports attribute most of the 2026 losses to a handful of high profile DeFi exploits. Research from Finbold and Blockaid points to KelpDAO on Ethereum and Drift Protocol on Solana, together accounting for roughly $577 million.
Blockaids H1 2026 security report shows Ethereum based projects losing about $332 million and Solana based projects about $326 million, with DeFi liquid staking, trading and yield platforms especially exposed. TRM Labs notes that North Korea linked groups were behind about two thirds of global hack losses, concentrating on these large DeFi targets.
DeFi specific exploit losses have fallen sharply from their 2022 peak. Immunefi calculates a 74 percent drop from roughly $2.62 billion to around $680.3 million, with median losses per exploit down about 75 percent, suggesting many newer hacks are smaller.
3. Evolving Attack Patterns
Immunefis and TRMs data show a shift in how attackers steal funds. Smart contract bugs and classic bridge exploits are still present, but an outsized share of value now comes from operational failures: compromised private keys, multi signer breaches, governance manipulation and cross chain configuration mistakes.
TRM Labs notes that infrastructure and key compromises represent a minority of incidents yet generate most of the dollar losses, while Blockaid highlights LinkedIn style social engineering and signing infrastructure breaches as key drivers on Solana and some Ethereum projects.
The biggest risk is increasingly above the contract layer. For users and protocols, controls around keys, multisig signers, governance processes and off chain operations matter as much as audits of on chain code.
Conclusion
Crypto security in 2026 is paradoxical. The industry has managed to cut headline losses compared with the Bybit skewed totals of 2025, yet the number of hacks is at an all time high and value is concentrated in a few large, infrastructure driven breaches on major chains.
If the current pattern continues, the main edge will go to projects and users that treat keys, signers and governance as live attack surfaces and harden them, rather than assuming that audited smart contracts alone are enough.
