Wake up and check the project Discord. Everything is in chaos.
Funds are suspended, withdrawals are frozen, and wallet permissions are being reviewed. Another nine-digit vulnerability attack occurred, but the market was hardly shocked.
This is the cryptocurrency world in 2026. Depending on whom you ask, the total amount of stolen funds has exceeded the billion-dollar mark by mid-year.
Wallet has always been a weak link, and several serious incidents in April caused most of the damage.
Why are losses still rising if everyone claims to be "doing security protection"? Let us take a step back and look at it without any whitewash.
First half of 2026: Data reveals the truth
In the first half of 2026, multiple tracking agencies recorded record numbers of intrusions and jaw-dropping losses. TRM Labs counted a total of 207 intrusions in the first half of the year, with approximately US$972 million stolen and a median loss of approximately US$219,000-indicating that a large number of incidents are small to medium-sized attacks, not just large vulnerabilities in the headlines.
CertiK paints a more grim picture: losses of approximately US$1.316 billion in 344 incidents, and net losses of approximately US$1.2 billion after deducting frozen or recovered funds. Crucially, they pointed out that wallet breaches are the most costly attack vector, causing approximately $444.5 million in damage in 33 incidents alone. The two major outbreaks in April-KelpDAO and Drift-accounted for nearly 44% of total first-half losses in its statistics.
According to The Block, Blockaid's analysis is consistent with the conclusion of "more than a billion" and attributed nearly $600 million in losses to North Korea-related actions, including those in April.
Attackers don't need a bull market. They just need liquidity, weak keys, and someone eager to operate.
What are the reasons behind the surge in intrusions in 2026?
Two powerful forces are colliding. On the one hand, cryptocurrencies are expanding horizontally. New Rollup, application chains and mobility layers mean more bridges, repeaters, orators and operation keys. On the other hand, attackers have become professional, even industrial, and national-backed teams and sophisticated ransomware scripts are infiltrating the public surface of cryptocurrencies.
Data conflicts are the norm, not flaws
Disagreements between event tracking agencies are normal. TRM's statistics on total amounts for the first half of 2026 are lower than CertiK because of their different classification of incidents and recovered funds. TRM reported 207 breaches and approximately $972 million was stolen. CertiK recorded 344 incidents with a total loss of approximately US$1.316 billion and a net loss of approximately US$1.2 billion. At the same time, Blockaid emphasized that a large portion of the losses were related to North Korea-related operations and put the losses at nearly $600 million.
The key is not which panel "wins". It's about all three agreeing on the direction: more events, greater absolute losses, and a few vectors and astonishing concentration over a few months.
Liquidity concentration and time pressure
When liquidity is concentrated on a few protocols and two-layer networks, the explosion radius expands. During volatile weeks, teams rushed to fix vulnerabilities, rotate keys, and deploy patches in production. This is the moment an attacker dreams of, specialising in misconfiguration and human error.
How do attackers break through now?
Let's explain the mechanism clearly. Most of the high losses in 2026 will not come from fancy cryptographic crackdowns, but from failures at the control level: keys, permissions and front-ends.
Wallet and Key Infrastructure : According to CertiK, wallet intrusions were the most costly vector in the first half, with 33 incidents causing approximately US$444.5 million in losses. The KelpDAO and Drift cases in April alone accounted for nearly 44% of the losses in the first half of the year in its data set. This is consistent with the observation of many security teams: the most dangerous vulnerabilities are still keys that are leaked, phishing or have inappropriate permissions.
Governance and operator rights : On-chain governance sounds very decentralized until you check the actual thresholds and time locks. Power is often pooled through multiple signatures, guardians, or emergency pause keys with broad rights. A compromised signer, a hasty upgrade or a poor time-lock configuration can be enough to cause damage.
Bridges and cross-chain dependencies Bridges are improving, but they are still complex systems with many moving parts: validators, repeaters, oracles, state proofs, and time-sensitive assumptions. You can harden a component, but still suffer losses due to off-chain credentials or unlocked versions of dependencies.
Front-end phishing and dangerous authorizations : We have also seen "quiet" methods of theft: contaminated websites, malicious advertisements and forged interfaces that trick users into signing harmful authorizations. Taken individually, these may not make nine-figure headlines, but they add up to produce stable, repeatable losses.
Typical attack chain
Reconnaissance: Mapping multiple signatures, guardians, deployers, robots, and emergency roles. Grab code warehouses and documents to get process clues.
Initial access: Phishing signers, hacking vendor accounts, or attacking shared devices. Sometimes it's just a bad VPN.
Privilege escalation: Stealing session tokens, abusing CI/CD keys, or exploiting weak access boundaries between test and production environments.
Execution: Push malicious configuration, redirect withdrawal queues, or trigger privilege upgrades through subtle parameter adjustments.
Cash out: Spread funds across multiple chains, use scripts to semi-automate operations, and race against sanctions and surveillance.
Capital flows: events and patterns
Let's take a look at different views in detail. Each source divides the data slightly differently, but all describe the same storm.
Source: TRM Labs| Period: First half of 2026| Number of incidents: 207| Total loss (USD): approximately 972 million| Adjusted/net loss: Unstated| Notes: The median loss is approximately US$219,000; the average is approximately US$4.7 million
Source: CertiK| Period: First half of 2026| Number of incidents: 344| Total loss (USD): 1,315,676,432| Adjusted/net loss: approximately 1,200,364,925| Note: Wallet intrusions dominate;KelpDAO and Drift accounted for approximately 44% in the first half of the year
Source: The Block / Blockaid| Period: First half of 2026| Number of events: unspecified| Total loss (USD):>1,000,000,000| Adjusted/net loss: Unstated| Note: About US$600 million is related to North Korea-related actions.
Interpretation differences
Why are there differences? Different definitions. Some tracking agencies account for fraud and exit scams, while others focus only on technical loopholes. Some deduct frozen and recovered funds, while others report total losses. Time and ownership will also vary. None of this means that the data is unreliable, it just means that you have to compare with others.
Concentration risks are now evident
Two wallet incidents in April helped push up losses in the first half. Whether you follow CertiK's statistics or Blockaid's attribution, the conclusion is the same: a few high-authority failures can dominate the one-year loss curve.
Why are losses rising despite better "security measures"?
Security expenditures do not equal security outcomes : The team is buying audits, vulnerability bounties and surveillance. That's good. But the biggest checks occur on code paths that are not fully exposed or covered by typical audits: governance scripts, deployment pipelines, signer devices, emergency upgrade levers. The attacker knows where the power lies.
Operational complexity continues to exceed control : New chains and products multiply secrets and endpoints. One hot wallet for whitelisting becomes five. One multiple signature becomes three, and the signers overlap. Each new partner integration adds another API key, Webhook, and dashboard. Most organizations are not able to rotate or limit these resources well under pressure.
Rollup and application chains compress the timeline : Rapid releases are good for users and also good for opponents. Shorter governance windows and faster deployment cycles reduce the chances of catching malicious parameters or confusing proxy patterns before they go online.
Specialized opponents are patient : Country-based teams view cryptocurrencies as a source of income. Blockaid's first-half snapshot of nearly $600 million in losses was attributed to North Korea-related actions, including landmark events. They will wait months to fish the right signer or map the vendor stack. This is a different threat model than the weekend's carpet pulling scam.
Users still sign first and think later : Even if the wallet user experience is better, harmful authorizations are still too easy to occur. Fishing is not glamorous, but it is a stable income for attackers, accumulating to eight figures in a quarter.
What the team can do this quarter
There is no silver bullet, but here is a compact, realistic plan that can drive improvements without freezing product speed.
Limit the key range like code. Inventory each key, token, signer, and administrator role. Write it down. If you can't list them, you can't protect them.
Isolate and minimize. Separate deployers, suspenders and guardians. Remove global authorization. Narrow contract roles to the minimum number of necessary addresses.
Raise governance thresholds. Increase the multi-signature quorum for high-value operations and add visible delays to upgrades. Make exceptions rare and documented.
The signer uses hardware first. Force operators to use hardware wallets or secure enclaves, and use anti-phishing certification for dashboards.
Secrets to regular rotation. Sensitive keys are rotated at least quarterly. Automatic cancellation upon resignation. Enforce the unique device policy.
Really separate the test and production environments. There are no shared keys, shared RPCs, or shared credentials. Prevent production signers from accessing test domain names and vice versa.
Simulated emergency drill. Conduct a live-fire desktop drill: lost key, contaminated front end, suspended bridge. Time your response and assign responsibility.
Remove harmful authorizations. Add an authorization dashboard to the application to remind you of revocation and clearly display risks. Consider default limits on authorization limits.
Conduct due diligence on suppliers rather than going through the motions. Ask them about their key policies, event response times and isolation models. Let them show you.
Don't skip after-the-fact re-offers. Publish what went wrong and what changed. This will attract better talent and stop duplicate vectors.
For users and funds: Think of hot wallets as cash in your pockets, not a vault. Diversify risk exposure. Authorizations are frequently revoked. Suspend the operation when the front-end behavior is abnormal.
Risks and possible mistakes
Reuse of keys across multiple protocols or signers is compromised, amplifying the cross-chain impact.
Bridge or oracle dependencies fail when the network is congested, causing mispriced clearing or withdrawal stuck.
Front-end supply chain attacks via ad networks, analytics scripts, or package managers.
False sense of security from audits that do not override governance or operating keys.
Sanctions or enforcement actions freeze liquidity during an incident, complicating recovery plans.
Copying the imitation activity of the successful phishing kit and adjusting it for the cryptocurrency user experience.
The riskiest period is after the fix is released. The attacker knew that the team would let down their vigilance once the fire was extinguished.
FAQs
Are intrusions really increasing, or are we just seeing more? Both. The number of incidents is rising, and absolute dollar losses are also rising. TRM counted 207 intrusions in the first half of the year, with approximately US$972 million stolen, while CertiK recorded 344 incidents, with a total loss of approximately US$1.316 billion, with a net loss of approximately US$1.2 billion after recovery. Even if you choose the lowest number, six months is a large number.
Why are the totals reported differently from different sources? They define events differently. Some include scams or exit scams, and some focus only on technical loopholes. Some deduct frozen or refunded funds, and some report total losses. Reporting windows and attributions are also different. The key is trend consistency, which all major trackers share in the first half of 2026.
What made April's KelpDAO and Drift events so bad? Privileges are centralized. CertiK said wallet breaches caused the largest losses in the first half of the year, with these two April incidents alone accounting for nearly 44% of its data set's first-half losses. When high-authority keys or wallets are touched, the consequences can spread rapidly.
How does the protocol reduce the risk of wallet intrusion while maintaining speed? Strictly limit the scope of roles, force the use of hardware signers, increase the quorum of multi-signature for high-value operations, add time locks for upgrades, rotate keys regularly, and separate test and production environments. This is not risk-free, but it improves probability.
Is it basically safe for retail users to avoid new tokens? Not necessarily. Front-end phishing and malicious authorization can also attack veterans. Use a hardware wallet for any meaningful asset, verify URLs, use bookmarked whitelists, keep authorization limits low, and revoke authorizations regularly. If dapp suddenly requests extensive permissions, stop and check.
What role does national-background actors play? A big role. Blockaid's first-half view (reported by The Block) attributed nearly $600 million in losses to North Korea-related actions. These actors are patient, targeting operators and suppliers, and viewing cryptocurrency vulnerabilities as systemic revenue rather than one-time crimes.
What should the team pay attention to in the second half of 2026? More attacks on keys, targeted compromises on vendors, and boundary cases of bridge dependence under network pressure. Look forward to more sophisticated phishing attacks targeting mobile wallets and signer dashboards. Before the next wave of fluctuations arrives, start strengthening key hygiene and emergency drills now.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following