H1 2026 Loss Estimates by Security Firm
Published 7/29/2026, 1:21:21 PM
Crypto hack losses in H1 2026 reached between $972 million and $1.32 billion, driven by a record-breaking surge in the number of incidents and a structural shift toward high-value infrastructure breaches. While total losses were lower than the $2.3–$2.47 billion recorded in H1 2025, the frequency of attacks increased by approximately 149%, totaling up to 344 incidents [Source: https://certik.com/resources/blog/hack3d-h1-2026-report].
H1 2026 Loss Estimates by Security Firm
| Source | Incidents | Total Losses | Key Finding |
|---|---|---|---|
| Global Ledger | 224 | $1.32 Billion | Three incidents generated 63.9% of all losses [Source: https://globalledger.io/h1-2026-analysis] |
| CertiK | 344 | $1.31 Billion | Net losses ~$1.2B after $115M in recoveries [Source: https://certik.com/resources/blog/hack3d-h1-2026-report] |
| Blockaid | 212 | $1.1 Billion | More exploits verified in H1 2026 than all of 2025 [Source: https://blockaid.com/h1-2026-security-report] |
| TRM Labs | 207 | $972 Million | Incident count hit record highs despite lower total value |
Primary Attack Vectors and Contributing Factors
The crossing of the $1 billion threshold was primarily due to the concentration of value in infrastructure failures rather than smart contract bugs.
- Infrastructure & Credential Compromise: While representing only ~15% of total incidents, these accounted for 72% to 76% of all dollar losses [Source: https://blockaid.com/h1-2026-security-report]. Attackers increasingly targeted private keys, signing systems, and RPC nodes.
- North Korean (DPRK) Dominance: The Lazarus Group remained the most destructive force. Despite being linked to only ~1.8% of incidents, they were responsible for $600M–$643M (45%–66%) of all stolen value [Source: https://globalledger.io/h1-2026-analysis].
- The Rise of "Wrench Attacks": Physical coercion emerged as a significant threat, with $124.1 million in recorded losses and ransom demands across 52 verified incidents [Source: https://globenewswire.com/certik-intel3d-h1-2026-wrench-attacks-report]. Approximately 79.6% of these attacks occurred in Europe, with France identified as a major epicenter (33 incidents) [Note: France-specific incident count not independently confirmed].
Notable Individual Incidents
Two massive breaches in April 2026 accounted for the bulk of the period's losses:
- KelpDAO (~$291M–$292M): A cross-chain bridge exploit where attackers compromised internal RPC nodes and fed false data to forge LayerZero cross-chain messages [Source: https://globalledger.io/h1-2026-analysis].
- Drift Protocol (~$285M): A breach resulting from a sophisticated six-month social engineering campaign combined with the abuse of pre-signed durable nonces [Source: https://globalledger.io/h1-2026-analysis].
In summary, H1 2026 was characterized by a "hardening" of smart contract code but a "softening" of operational and physical security, allowing a small number of sophisticated infrastructure attacks to drive losses past the $1 billion mark.