In the first half of 2026, the crypto industry lost $1.32 billion due to security incidents. At first glance, this is a 46.8% drop compared to the same period in 2025. However, behind these figures lies a worrying trend: if the anomalous $1.4 billion Bybit hack from last year is excluded from the statistics, the actual damage for the half-year turned out to be about 28% higher than a year earlier.
Quarterly Surge: $807.5 Million in Q2
The situation in the second quarter is particularly telling. Losses increased by 59% compared to the first quarter, reaching $807.5 million. The main drivers were two major attacks — on the KelpDAO and Drift Protocol protocols. They accounted for more than 70% of the quarterly damage. Analysts note that attacks are becoming increasingly targeted and costly: the average damage per major incident is steadily rising.
Shifting Priorities: From Phishing to Wallet Compromise
In the first quarter, the main attack vector was phishing. In the second quarter, wallet compromise took the lead. At the same time, incidents like the Drift Protocol hack often represent complex combined attacks involving social engineering and the seizure of administrative procedures, rather than just the theft of private keys. This points to a growing professionalism among attackers.
TRM Labs Data: Record Number of Incidents
Analysts at TRM Labs estimate half-year losses at $972 million — less than half of the $2.3 billion in 2025. The discrepancy with CertiK's data is explained by the latter's broader coverage of Web3 incidents, including scams and exploits. Meanwhile, TRM Labs recorded a record 207 incidents in the half-year. Of these, 125 attacks (about 60%) targeted smart contracts. However, the main damage — roughly 76% of all losses — came from infrastructure and operational compromises, such as the theft of private keys and access to transaction signing systems.
The North Korean Trail: $643 Million and Geopolitical Context
TRM Labs estimates that groups linked to North Korea are responsible for stealing about $643 million, or 66% of all stolen funds. CertiK also links the attacks on KelpDAO and Drift Protocol to North Korean hackers. This data underscores the systemic nature of the threat: Pyongyang's cyber activity, according to U.S. State Department estimates, directly finances programs for creating weapons of mass destruction and ballistic missiles. At the end of June, delegations from the U.S., Japan, and South Korea already discussed strengthening coordination against such schemes in Washington.
My Expert Conclusion: The half-year figures are not a reason for optimism, but an alarm signal. The industry has still not adapted to the new level of threats. CertiK's recommendations for strengthening hardware infrastructure security, distributing signatories across different jurisdictions, and monitoring large transfers are not just theory, but an urgent necessity. Without systemic changes at the level of key management and access procedures, we risk seeing new loss records in the coming quarters.