In the first six months of 2026, the crypto industry incurred losses of $1.32 billion due to security incidents. At first glance, this is 46.8% less than in the same period of 2025. However, such statistics are misleading: without accounting for the historic $1.4 billion Bybit hack, which skewed the comparison base, the actual reduction in losses would be far more modest. In fact, excluding this outlier, the damage for the first half of 2026 would have been approximately 28% higher than a year earlier.
Targeted Attacks and Rising Damage Per Incident
Analysis shows that attacks are becoming more targeted, and the average damage per major incident is steadily increasing. In the second quarter of 2026, losses soared by 59% compared to the first quarter, reaching $807.5 million. The main contributors were the hacks of the KelpDAO and Drift Protocol, which accounted for over 70% of the quarterly damage. Notably, while phishing dominated in the first quarter, direct wallet compromise became the leading threat in the second quarter. Attacks on Drift, for example, combined social engineering with the seizure of administrative procedures, rather than simply stealing keys.
Infrastructure Risks and Record Number of Incidents
Data from TRM Labs paints an even more alarming picture. Over the half-year, 207 separate incidents were recorded — an absolute record for this period. Although most attacks (about 60%) involved smart contract exploits, the bulk of the damage — approximately 76% of all losses — came from just 15% of incidents related to infrastructure compromise: private keys, transaction signing systems, and credentials. This confirms that the industry's main vulnerability is not code, but operational procedures and access management.
TRM Labs estimates half-year losses at $972 million — less than CertiK's figure, which is explained by differing scopes: CertiK accounts for a broader range of Web3 incidents, including scams and exploits. However, both companies agree on the main point: about 66% of all stolen funds ($643 million) went to North Korean hacker groups. They are suspected of orchestrating the attacks on KelpDAO and Drift Protocol.
Geopolitics and Security: A New Threat Vector
The problem extends beyond purely technical security. At the end of June, delegations from the US, Japan, and South Korea discussed in Washington countering North Korea's cyber activities, including cryptocurrency theft and money laundering. These revenues directly finance Pyongyang's weapons programs. Against the backdrop of a record number of hacks in the second quarter (83 incidents with $755.3 million in damage), it becomes clear: the industry needs to radically rethink its approach to protection. Recommendations to strengthen hardware infrastructure security, distribute signatories across different jurisdictions, and strictly control large transfers are not just bureaucratic measures, but an urgent necessity.
Expert Commentary: The record number of attacks amid an apparent decline in total damage is an alarming signal. The market is adapting, but hackers are adapting faster. The industry is transitioning from defending against mass attacks to confronting highly organized, targeted groups operating with state support. Ignoring this shift means putting the entire ecosystem at risk.