The first half of 2026 was a period of significant financial losses for the crypto industry. According to my data analysis, total damages from security incidents amounted to $1.32 billion. At first glance, this is 46.8% less than in the same period last year. However, such statistics are misleading.
The key factor distorting the picture is the single, yet colossal, $1.4 billion hack of the Bybit exchange in 2025. If this outlier is excluded, the real increase in losses for the half-year would be about 28%. This suggests that attacks are becoming not less dangerous, but rather more targeted and costly.
The dynamics of the second quarter are particularly alarming: losses increased by 59% compared to the first quarter, reaching $807.5 million. The main contributors were hacks of the KelpDAO and Drift Protocol protocols, which accounted for over 70% of the quarterly damages. Notably, attack methods are evolving: while phishing dominated in the first quarter, wallet compromise took the lead in the second. Moreover, incidents like the Drift hack represent complex combinations of social engineering and administrative procedure takeover, rather than simple key theft.
It is interesting to compare this data with estimates from TRM Labs, which record losses of $972 million for the same period. The discrepancy is explained by different methodologies: CertiK considers a broader range of Web3 incidents, including scams and exploits. However, both sources agree on the main point: the number of attacks is breaking records. TRM Labs counted 207 separate incidents in the half-year, 60% of which were smart contract hacks. But the main damage — about 76% of all losses — was caused by infrastructure compromises, which account for only 15% of the total number of incidents.
The activity of North Korean hacker groups deserves special attention. TRM Labs estimates their share of stolen funds at approximately $643 million, or 66% of the total. CertiK directly links them to the attacks on KelpDAO and Drift Protocol. This confirms that cryptocurrencies remain a key tool for funding state programs, including the development of weapons of mass destruction. Unsurprisingly, the US, Japan, and South Korea are intensifying joint efforts to counter this threat.
My expert commentary: The figures for the first half of 2026 are not just statistics, but a wake-up call. The industry is transitioning from mass, but relatively cheap, attacks to highly targeted, costly operations where hundreds of millions of dollars are at stake. Recommendations for strengthening hardware infrastructure security, managing signatures, and monitoring large transfers are not just a formality, but a necessity. Without fundamental changes in approaches to asset protection, we risk seeing new loss records in the second half of the year.