In the first half of 2026, the crypto industry lost approximately $972 million as a result of 207 incidents. This is an important milestone: for the first time in a long while, the total damage has fallen below the psychological threshold of $1 billion. However, the number of attacks has reached a record high—we are observing a paradoxical trend: there are more hacks, but they are becoming less "costly" for projects.

Data from the Immunefi platform shows that the average damage per incident has significantly decreased compared to 2025. This is a direct consequence of the evolution of security systems: the implementation of bug bounty programs, regular audits, and the growing number of qualified cybersecurity specialists are paying off.

DeFi: a 74% drop in losses from the 2022 peak

The dynamics in the decentralized finance (DeFi) sector are particularly impressive. In the first half of 2026, losses here amounted to $680.3 million—74% less than in the peak year of 2022 ($2.62 billion). This sharp decline is the result of comprehensive efforts: from improving smart contract writing standards to implementing formal verifications and automated vulnerability search tools.

Shift in the threat vector

Analysis of incidents reveals a shift in the nature of the main risks. While code errors in smart contracts were once the primary headache, the focus has now shifted to infrastructure vulnerabilities. Compromised private keys, validator malfunctions, and—particularly alarming—errors in cross-chain configurations are the three pillars of the modern threat landscape.

This is logical: as cross-chain bridges and multichain protocols become more complex, the attack surface expands precisely at the interaction points between different blockchains. Hackers are increasingly targeting not the code itself, but the logic of its execution and integration points.

My comment: The reduction in damage is undoubtedly a positive signal for the market, but the record number of attacks is concerning. It indicates that attackers are adapting faster than we are implementing defenses. The industry urgently needs to reassess its approaches to cross-chain infrastructure security—this, in my assessment, is where the biggest time bomb for 2026–2027 lies hidden.