TLDR
2026 is on track to become the worst year on record for crypto hacks by both incident count and total losses.
- Security firms report roughly $1.1$1.32 billion in losses in the first half of 2026 and project a record number of major hacks by year end.
- The spike is driven by AI-assisted attacks, wallet phishing, bridge and oracle exploits, and operational failures across exchanges and infrastructure.
- Bug bounties, new licensing rules, and security funds are expanding, but users still need to treat security practices and venue choice as core risk decisions.
Deep Dive
1. Scale Of 2026 Losses
Immunefi counts 164 crypto hacks through August 3, with 67 incidents each causing more than $1 million in losses, and projects 114 such major hacks in 2026, surpassing the previous record of 72 set in 2024, when only 49 had occurred by this point in the year. This includes about $110 million lost in July alone, according to its latest review of protocol exploits and exchange incidents.
A separate Blockaid study cited in the same coverage estimates total crypto security losses at around $1 billion in the first six months of 2026, while CertiKs Hack3d tracking puts the figure at $1.32 billion across 344 incidents in H1, with $444.5 million from wallet compromises and $366.3 million from phishing campaigns. CertiK also highlights that April 2026 alone saw about $364 million lost, making it the most hacked month on record for crypto, largely driven by phishing-heavy attacks.
Recent incidents fit this pattern: DeFi protocols such as Ostium and AFX contributed more than $47 million in July losses, and centralized platforms like Coinsbuy have seen multi-million thefts despite replenishing user balances from reserves. Hardware and wallet infrastructure failures, including the Coldcard vulnerability tied to over 1,400 confirmed BTC losses, add to the total.
On aggregate, crypto security risk is clearly trending upward, so treating hacks as a rare edge case is no longer realistic.
2. Why Hacks Are Accelerating
Attackers are increasingly using local AI models to automate malware and phishing. A report on North Korea-linked group Kimsuky describes custom environments built with tools like Ollama and GPT4All to generate crypto-targeted phishing and malware at scale, while avoiding safeguards in commercial AI systems.
Wallet-focused compromises and social engineering now account for a large share of losses. CertiK notes that the two biggest H1 2026 incidents, at $291 million and $285 million, stemmed from operational and infrastructure failures rather than pure smart contract bugs, underscoring weaknesses in custody processes and backend systems.
Onchain, DeFi-related exploits remain costly. Oracles and bridges are recurring weak spots: Ostiums 23.75 million USDC loss came from manipulated price data, and AFX suffered a major bridge exploit. DefiLlama data underpinning Aprils most hacked month label points to dozens of protocol incidents clustered in a single month, reflecting how composable systems amplify any single misconfiguration or oracle reliance mistake.
3. Defensive Shifts And User Signals
Defensive activity is rising, but it is still catching up to the threat level. Immunefi reports that bug bounty payouts hit $2.32 million in July, with 374 threats prevented that month and cumulative researcher rewards reaching $143.1 million. Its analysis shows competitive audit contests finding far more serious issues than traditional private audits, arguing for continuous, crowd-sourced review rather than one-off signoffs.
On the policy and venue side, regulators and industry groups are tightening expectations. Brazils Central Bank, for example, is forcing all virtual asset service providers to seek authorization and undergo detailed assurance reporting, a move explicitly framed against a backdrop of over $1.32 billion in global 2026 hack losses. In parallel, Bitcoin ecosystem participants have launched security funds and a coalition urging AI labs to grant vetted defenders access to frontier models, aiming to match attacker capabilities.
For individual crypto users, the practical lens is simple: security posture and venue selection are now primary risk levers. That includes favoring platforms that disclose audits and proof-of-reserves, using hardened wallet setups, being extremely cautious with links and signing requests, and preferring DeFi protocols that rely on robust oracle networks rather than fragile single-feeds.
The record pace of hacks makes operational due diligence a core part of any crypto exposure; ignoring security signals can be as risky as ignoring price and liquidity.
Conclusion
Crypto in 2026 is experiencing a convergence of factors that push hacks to record levels: more capital onchain, more complex infrastructure, and attackers empowered by AI and weak operational controls. At the same time, bug bounty ecosystems, licensing regimes, and dedicated security funding are strengthening the defensive side. For crypto participants, the key shift is that security quality and venue choice have become central elements of risk management, not optional extras, in a market where exploits are now a structural, not episodic, feature.
