The first half of 2026 cost the crypto industry $1.32 billion in direct losses from security incidents. At first glance, this is 46.8% less than in the same period of 2025. However, as my calculations show, this figure is misleading.
The key factor distorting the picture is the single, colossal $1.4 billion hack of Bybit last year. Without this anomalous event, the reduction in losses would not be as significant. Moreover, looking at the dynamics within the half-year, the alarming signal is clear: in the second quarter of 2026, losses surged by 59% compared to the first quarter, reaching $807.5 million. This indicates that attacks are not becoming less frequent, but larger and more targeted.
Threat Structure: From Phishing to Infrastructure Compromise
While phishing was the primary attack vector in the first quarter, direct wallet compromise took the lead in the second. The lion's share of the quarterly damage—over 70%—was caused by just two incidents: attacks on KelpDAO and Drift Protocol. These cases are telling: they combined social engineering with the seizure of administrative procedures, rather than simply stealing private keys.
Data from TRM Labs, although estimating total losses at $972 million (less than half of the $2.3 billion a year earlier), confirms my key point. A record number of incidents—207—were recorded over the half-year. Of these, 60% were smart contract exploits, but the main damage (about 76% of all losses) was caused by infrastructure and operational compromises. These are attacks on private keys, transaction signing systems, and access management to funds. This is where the most serious vulnerability lies.
The North Korean Trail and Geopolitics
According to TRM Labs estimates, groups linked to the DPRK are responsible for stealing approximately $643 million, or 66% of all stolen funds. My analysis confirms that North Korean hackers are most likely behind the attacks on KelpDAO and Drift Protocol. These are not just numbers—this is the financing of weapons programs. It is no surprise that the US, Japan, and South Korea are intensifying coordination to counter this cyber threat.
My comment: The market continues to underestimate the risks associated with key management and administrative infrastructure. As long as protocols rely on centralized signing procedures and weak protection of operational systems, we will see increasingly large and audacious attacks. The record number of incidents in the second quarter is not a coincidence but a pattern that demands an immediate revision of security standards.