In the first six months of 2026, the crypto industry lost $1.32 billion due to security incidents. At first glance, this is 46.8% less than in the same period in 2025. However, as my calculations show, this figure is misleading.

The key distorting factor is the $1.4 billion hack of the Bybit exchange last year. If we exclude this one-time historical outlier, losses in H1 2026 are approximately 28% higher than in the same period a year earlier. This suggests that the real threat is not weakening but transforming.

Quarterly Dynamics: Acceleration of Attacks

In the second quarter of 2026, losses increased by 59% compared to the first quarter, reaching $807.5 million. The main contributors were attacks on the KelpDAO and Drift Protocol protocols, which accounted for over 70% of quarterly losses. This confirms the trend towards targeted but extremely destructive hacks of DeFi infrastructure.

The nature of threats is changing: while phishing dominated in the first quarter, wallet compromise took over in the second. At the same time, incidents like the Drift attack often combine social engineering with the seizure of administrative procedures, going beyond ordinary key theft.

TRM Labs Data: Record Number of Incidents

An alternative estimate from TRM Labs shows losses of $972 million for the half-year — less than half of the $2.3 billion in 2025. The discrepancy with CertiK is explained by different coverage: I account for a broader range of Web3 incidents, including hacks, scams, and exploits. Meanwhile, TRM Labs recorded 207 separate attacks — a record for a half-year period. Of these, 125 (about 60%) were smart contract hacks, but the main damage (76% of all losses) was caused by infrastructure and operational compromises.

North Korean Trail: $643 Million Stolen

According to TRM Labs, groups linked to North Korea are responsible for stealing approximately $643 million, or 66% of all stolen funds. CertiK also links the attacks on KelpDAO and Drift Protocol to North Korean hackers. This underscores the systemic nature of the threat: Pyongyang uses cryptocurrency thefts to finance weapons programs, as confirmed by recent trilateral consultations between the US, Japan, and South Korea in Washington.

Conclusions and Recommendations

The second quarter of 2026 set a record for the number of incidents — 83 hacks with losses of $755.3 million. I recommend strengthening the protection of hardware infrastructure, signature management, and fund access procedures. Special attention should be paid to distributing signatories across different jurisdictions and additional control over large transfers. Without these measures, the industry risks facing even greater losses, despite the apparent decline in statistics.