Need help? Support
BITCOIN
Tether Dominance USDT.D

H1 crypto hacks hit nearly $940M

Published 494 words 3 min read

TLDR

Hackers stole nearly $940 million from crypto projects in the first half of 2026, heavily concentrated in a few large exploits and driven mostly by key and bridge failures.

  1. Around $939.86 million was taken across 135 incidents, with two mega-hacks accounting for about 61 percent of the losses.
  2. Most stolen funds came from compromised keys, cross-chain bridges, and gaps in outdated or narrowly scoped security audits.
  3. For everyday users, the risk is shifting toward complex DeFi stacks and custody flaws, making key management and venue choice more important than single audit badges.

Deep Dive

1. Scale Of The Losses

Security firm Ack3 found that hackers stole about $939.86 million in the first half of 2026 across 135 verified exploits, averaging $6.96 million per incident. The biggest single hits were Kelp DAOs rsETH (about $292 million) and Solana derivatives platform Drift (about $285 million) after attackers abused cross-chain infrastructure and admin keys, together representing roughly 61 percent of all losses in the period according to the Ack3 report. A long tail of smaller breaches affected projects like Step Finance, Humanity Protocol, Resolv USR, Verus, Syscoin, Taiko, Polymarket, CoW Swap, and Truebit.

2. How The Attacks Happened

Ack3 reports that audited projects still lost about $681 million, but 94.4 percent of that came through attack paths outside audit scope, usually integrations or operational infrastructure not reviewed. Common patterns included: compromised signing keys and admin wallets, forged cross-chain messages on bridges, domain hijacks and front-end supply-chain attacks, and classic smart contract bugs in unaudited code. Many relevant audits were more than six months old, and Ack3s CEO warned that AI tools make it easier to probe entire systems for weak links across contracts, bridges, and infrastructure.

What this means

Audited only helps if you know what was checked, how recently, and who controls the keys and infrastructure around that code.

3. Why It Matters For Crypto Users

Separate research on the Coldcard hardware wallet exploit and other incidents shows tens of millions more lost to predictable or compromised private keys, with Blockaid estimating that most early 2026 crypto losses were driven by key and operational failures rather than pure on-chain bugs. For users, the risk focus is shifting from is this smart contract safe to how are keys, bridges, and front-ends secured, and how often are they reviewed. One way to view safety is as layers: high-quality audits that cover integrations, strong key management (including multisig and limited hot keys), cautious use of cross-chain bridges, and avoiding opaque platforms that promise high yields without transparent security disclosures.

What this means

The biggest single decision is not which coin to hold, but how and where you hold it, especially when DeFi, bridges, and hardware wallets are involved.

Conclusion

The nearly $940 million stolen in the first half of 2026 reflects a maturing attacker landscape that targets keys, bridges, and outdated audits more than simple contract bugs. For crypto users, treating audit badges as one small data point and focusing more on key management, venue quality, and integration risk is increasingly important as AI-enhanced exploits and large cross-chain systems become central to the market.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top