Cryptocurrency hacking incidents in the second quarter of 2026: Current status of vulnerabilities and regulations
In the second quarter of 2026, a total of 67 hacking incidents occurred in the cryptocurrency field, with a total of US$763.97 million stolen funds. Among them, access rights vulnerability is the largest single point of failure.
Overview of cryptocurrency hacking incidents in the second quarter of 2026
According to the latest report from blockchain security and compliance firm Hacken, losses caused by cryptocurrency hacking in the second quarter increased by 58.3% from US$482.7 million in the first quarter, setting the highest loss record since the second quarter of 2025.
Drift Protocol and KelpDAO suffered the largest withdrawals, losing approximately $290 million per project.
Although smart contract vulnerabilities are the cause of most attacks, their cumulative losses account for only 11% of the total losses. Operational and infrastructure failures (including keys and signers being compromised) accounted for a larger proportion, reaching 88.3% of the total loss.
On the perpetrator side, 75.5% of stolen funds were attributed to North Korean actors. It is worth noting that Consensus, the company behind the Ethereum wallet MetaMask, recently admitted to hiring a software developer related to North Korea. A month later, the company realized the incident and immediately fired the person and revoked his system access. The company has reported the incident to law enforcement, while also assuring users that there were no financial losses, data breaches or malicious code deployments.
The report also pointed out that in the second quarter, the first incident of leaking funds due to malicious AI prompt injection occurred, with a loss of US$174,000. Hacken pointed out that such failures stem from "insufficient review, lack of variants and weak testing."
Regulatory compliance status in the second quarter of 2026
In terms of regulatory compliance, the U.S. cryptocurrency regulations enacted under the GENIUS Act will take effect in early 2027.
In the European Union, the grace period for cryptocurrency participants to apply for full licenses expired on July 1. As of this time, although 1200 institutions have expressed interest, only about 215 crypto asset service providers have been authorized under the Crypto Asset Markets Regulation. Binance, MEXC and HTX (original Huobi) are the most well-known exchanges forced to close due to this rule. In addition, among the top ten stablecoins with market capitalisation, Circle's USDC is by far the only stablecoin that meets MiCA requirements.
However, Hacken pointed out that the most trusted counterparties in the future will be those who will first prove their safety, regardless of their duration, audit status or total value of locked positions.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH