Keys, not codes: The industry lost nearly US$764 million, and security vulnerabilities were concentrated at the operational level.
In the second quarter of 2026, the cryptocurrency industry lost nearly US$764 million due to hacking attacks, but security firm Hacken's bigger discovery lies in the actual flow of funds and the reasons behind it. Hacken's "Second Quarter 2026 Security and Compliance Report" showed that among 67 security incidents, a total of $763.9 million was stolen, making it the deadliest quarter since the second quarter of 2025. The report pointed out that key leaks, failed signers and infrastructure vulnerabilities accounted for 88.3% of the total losses, a finding that challenges the industry's long-standing over-reliance on smart contract audits. Of the 67 incidents, 44 involved smart contract vulnerabilities, but these vulnerabilities only caused approximately 11% of the total damage.
Serious imbalance between monitoring and auditing
Hacken tracked 1427 projects with a market value of more than US$1 million and found that only 9% of the projects deployed third-party surveillance, while only 4% of the projects also had surveillance, active vulnerability bounty plans and audits. The 14 projects utilized this quarter had previously been audited, but most of the losses originated from areas outside the scope of traditional smart contract review. The report states that the most vulnerable interfaces include signature devices, bridge validators, back-end infrastructure and administrator keys. This model reveals a structural flaw: the industry audits code extremely strictly, but provides little protection in terms of operational security, key management, and human access controls.
Two attacks accounted for three-quarters of the damage
The two most serious incidents this quarter were both related to North Korean hacking groups. On April 1, 2026, Solana Ecosystem's Drift Protocol lost approximately $285 million in approximately 12 minutes and did not involve any smart contract vulnerabilities. TRM Labs traced and found that Lazarus Group members used a six-month social engineering attack to disguise themselves as a legitimate trading company and personally attended a cryptocurrency conference, ultimately breaking the signature key of the protocol's multi-signature security committee. On April 18, KelpDAO was compromised due to the LayerZero Bridge, losing $292 million. The North Korean hacker group TraderTraitor breached two RPC nodes that provided data to the LayerZero verifier network. After injecting fake transaction data, it kicked legal nodes offline, forcing the system to fail over to controlled nodes. The bridge uses a single validator design, creating a single point of failure. Together, the two attacks accounted for about three-quarters of the total amount stolen in the second quarter.
Security priorities need to be restructured
Hacken's report makes clear that operational security-not just cleaner code-must be a top priority. The agency concluded that security should run through code, operations and infrastructure throughout the project's entire life cycle, rather than ending after the audit report is issued.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following