The 2026 Crypto Hack Tracker: Every Major Exploit, the Money Lost, and Where the Chain Says It Went
Crypto lost more to theft in the first half of 2026 than most people realize, and far less than the headlines during the worst weeks suggested. Security firm TRM Labs counted 207 separate hacks in H1 2026 that drained about $972 million, while CertiK, using a broader definition that folds in scams, put the figure at $1.32 billion. Both agree on the direction: the number of attacks hit a record, but total dollars fell sharply, less than half of the roughly $2.3 billion stolen in the first half of 2025.
This page is our running tracker of the year's major incidents: what was taken, how, on which chain, and where the money went. For the exploits marked Decoded, DEXTools News did not just report the press release; we opened the chain and traced the funds ourselves. Here is the full picture.
The biggest exploits of 2026
The year is defined by a handful of enormous thefts. Two April attacks alone, the $292 million Kelp DAO bridge compromise and the $285 million Drift Protocol takeover, account for $577 million, and both are attributed to North Korea. A third nine-figure event, a $282 million theft from a single individual tricked by fake wallet-support staff, was not a protocol hack at all. Below those three, the drop is steep: the next-largest incident is a fraction of the size.
The full 2026 tracker
Every major incident we track, sorted by amount. "DPRK" marks North-Korea-attributed thefts; "Decoded" links to our own on-chain forensic report where we traced the funds ourselves. Amounts are the most-cited security-firm figures and are gross (before any recovery).
| Incident | Date | Amount | Attack type | Chain(s) | North Korea | DEXTools report |
|---|---|---|---|---|---|---|
| 1. Kelp DAO (rsETH) | 2026-04-18 | $292M | Bridge / infra | Ethereum + LayerZero (~20 chains) | DPRK | Decoded > |
| 2. Drift Protocol | 2026-04-01 | $285M | Social engineering | Solana (bridged to Ethereum) | DPRK | Decoded > |
| 3. Trezor 'Value Wallet' victim (personal) | 2026-01-10 | $282M | Social engineering | Bitcoin, Litecoin | - | - |
| 4. Step Finance | 2026-01-31 | $27M | Private key | Solana | - | - |
| 5. Truebit Protocol | 2026-01-08 | $26M | Smart-contract bug | Ethereum | - | - |
| 6. Resolv Labs (USR) | 2026-03-22 | $25M | Private key | Ethereum | - | - |
| 7. 'Sillytuna' victim (personal) | 2026-03-05 | $24M | Social engineering | Ethereum | - | - |
| 8. Kraken user (personal) | 2026-03-31 | $18M | Social engineering | Ethereum -> Bitcoin | - | - |
| 9. Ostium | 2026-07-16 | $18M | Oracle | Arbitrum | - | Decoded > |
| 10. SwapNet | 2026-01-26 | $13M | Smart-contract bug | Ethereum | - | - |
| 11. Cork Protocol | 2026-05-25 | $12M | Smart-contract bug | Ethereum (wstETH) | - | Decoded > |
| 12. Triple-A | 2026-07-27 | $12M | Infra / hot wallet | 7 chains | - | Decoded > |
| 13. Verus-Ethereum Bridge (1st) | 2026-05-18 | $12M | Bridge | Verus / Ethereum | - | Decoded > |
| 14. THORChain | 2026-05-15 | $11M | Cryptography bug | 9+ chains | - | - |
| 15. YieldBlox | 2026-02-21 | $10M | Oracle | Stellar | - | - |
| 16. Verus-Ethereum Bridge (2nd) | 2026-07-23 | $8M | Bridge | Verus / Ethereum | - | - |
| 17. Saga (SagaEVM) | 2026-01-21 | $7M | Smart-contract bug | Saga (Cosmos EVM) | - | - |
| 18. Summer.fi (Lazy Summer) | 2026-07-06 | $6M | Smart-contract bug | Ethereum | - | Decoded > |
| 19. IoTeX (ioTube) | 2026-02-21 | $4M | Private key | IoTeX / Ethereum | - | - |
| 20. Makina | 2026-01-20 | $4M | Oracle | Ethereum | - | - |
| 21. Venus (vTHE) | 2026-03-15 | $4M | Oracle | BNB Chain | - | - |
| 22. Aperture Finance | 2026-01-26 | $4M | Smart-contract bug | Multiple EVM | - | - |
| 23. CrossCurve | 2026-02-01 | $3M | Bridge | Multi-chain (Axelar) | - | - |
| 24. Solv Protocol | 2026-03-05 | $3M | Smart-contract bug | BNB Chain | - | - |
| 25. Foom.Cash | 2026-03-02 | $2M | Smart-contract bug | Ethereum, Base | - | - |
| 26. Thetanuts Finance | 2026-06-17 | $2M | Smart-contract bug | Ethereum | - | Decoded > |
| 27. TMX | 2026-01-15 | $1M | Smart-contract bug | Arbitrum | - | - |
| 28. Hinkal Protocol | 2026-07-03 | $820K | Smart-contract bug | Ethereum | - | Decoded > |
| 29. WEMIX (WEMIX$) | 2026-07-26 | $724K | Private key (owner) | WEMIX3.0 | - | Decoded > |
| 30. Garden Finance | 2026-07-28 | $450K | Infra / solver | 4 chains | - | - |
| 31. Edel Finance | 2026-07-01 | $403K | Smart-contract bug | Ethereum | - | Decoded > |
It is not the code. It is the keys and the people.
The single most important lesson of 2026 is where the money actually leaks from. The popular image of a crypto hack is a clever attacker finding a bug in a smart contract. The data says otherwise. Across the incidents we track, social engineering and infrastructure or private-key compromises account for the overwhelming majority of the dollars lost, while smart-contract bugs, the most common type of incident, cause a small fraction of the losses. TRM's own H1 breakdown says the same thing in numbers: infrastructure compromises were about 15% of incidents but roughly 76% of all losses, and smart-contract exploits, though 60% of incidents, took far less. The attacks that empty the treasury are not exotic code; they are stolen keys, tricked humans, and compromised operational infrastructure.
North Korea is the story behind the numbers
The concentration is not random. TRM Labs estimates that DPRK-linked groups were responsible for about $643 million, roughly 66% of all funds stolen in the first half of 2026. In our tracker, the two April mega-thefts that are attributed to North Korea account for the entire April spike. These operations follow a pattern our own reporting keeps running into: months of patient social engineering to compromise a key or an insider, a sudden drain, and then laundering through mixers like Tornado Cash and cross-chain bridges. It is why the losses cluster in a few huge events rather than spreading evenly across the 207 incidents.
The ones we decoded ourselves
For a growing share of these incidents, we did our own on-chain forensics rather than relaying a firm's summary, decoding the exploit transactions, naming the attacker wallets, and following the money. Those investigations feed this tracker:
- Drift Protocol ($285M): we tracked the exploiter moving $44.4M into Tornado Cash and confirmed the wallet was emptied.
- Triple-A ($11.8M): we traced 5,287 ETH swept through two consolidation wallets, both now empty.
- WEMIX$ exploit: we decoded the doubling mint loop and published the attacker addresses no outlet had.
- Ostium ($18M), Summer.fi ($6M), Hinkal and Edel Finance: fund traces and forensic breakdowns.
How to read this tracker (methodology and caveats)
A few things matter for using these numbers responsibly.
- Firm totals versus our table. The $972M (TRM) and $1.32B (CertiK) figures are those firms' H1 estimates across all 207+ incidents. Our table lists the major individual incidents we track; it is not a substitute for a firm's full tally and the two should not be added together.
- Gross, not net. Amounts are the value taken at the time of the exploit. Several were partially recovered (for example YieldBlox, Foom.Cash and Venus), so permanent losses are lower than the headline figures.
- Individuals versus protocols. Three of the largest entries, the $282M Trezor-support victim, the $24M "Sillytuna" theft and the $18M Kraken user, were personal social-engineering thefts, not protocol exploits, and are excluded from protocol-only trackers. We mark them "(personal)".
- Ranges. Where firms disagree, we use the most-cited figure and note the range in our reporting. North-Korea attribution follows TRM, Elliptic and Chainalysis.
The bottom line
2026 is the year crypto theft got more frequent but, in dollar terms, more concentrated: a record number of attacks, fewer dollars overall, and a small cluster of North-Korea-linked operations doing most of the damage through stolen keys and social engineering rather than clever code. The defensive takeaway follows directly. Audits matter, but the biggest money is lost at the human and operational layer, private keys, admin access, insider trust, which is exactly where the largest 2026 thefts began. We will keep this tracker updated as the year continues.
Data note. H1 2026 totals are from TRM Labs (~$972M across 207 hacks; ~$643M / 66% North-Korea-linked) and CertiK ($1.32B, broader Web3-incident definition), read by DEXTools News on July 28, 2026. Per-incident amounts are the most-cited figures from security firms (Chainalysis, PeckShield, Halborn, Elliptic, CertiK, SlowMist and others) and our own on-chain analysis where marked "Decoded"; they are gross and pre-recovery. This is an information resource, not financial or security advice, and figures are updated as reporting evolves.
Frequently asked questions
How much crypto was stolen in 2026?
In the first half of 2026, TRM Labs counted 207 separate hacks that drained about $972 million, while CertiK, using a broader Web3-incident definition, estimated $1.32 billion. Both note the number of attacks hit a record while total dollars fell sharply, less than half of the roughly $2.3 billion stolen in H1 2025.
What were the biggest crypto hacks of 2026?
The largest were the Kelp DAO bridge compromise (~$292M, April, North-Korea-linked), the Drift Protocol takeover (~$285M, April, North-Korea-linked) and a $282M theft from a single individual via fake wallet-support impersonation. Below those three the size drops steeply, with incidents like Step Finance, Truebit, Resolv Labs and Ostium in the tens of millions.
How much did North Korea steal in crypto in 2026?
TRM Labs estimates DPRK-linked groups stole about $643 million in H1 2026, roughly 66% of all funds taken. In our tracker the two April mega-thefts attributed to North Korea (Kelp DAO and Drift) account for the entire April spike, following a pattern of social engineering, sudden drains and laundering through mixers and cross-chain bridges.
What causes the biggest crypto losses, smart-contract bugs or something else?
Not code. Across 2026's incidents, social engineering and infrastructure or private-key compromises account for the large majority of dollars lost, while smart-contract bugs, the most common incident type, cause a small share. TRM found infrastructure compromises were about 15% of incidents but roughly 76% of losses. The biggest money is lost at the human and operational layer.
Which 2026 hacks did DEXTools News investigate on-chain?
We did our own forensic analysis on several, including Drift ($285M, tracing $44.4M into Tornado Cash), Triple-A ($11.8M, tracing 5,287 ETH through two wallets), the WEMIX$ exploit (decoding the mint loop and attacker wallets), Ostium ($18M), Summer.fi ($6M), Hinkal and Edel Finance. Those incidents are marked 'Decoded' in the tracker table.