Go to app

Recent Infrastructure Attacks & Market Impact

Published 7/17/2026, 12:59:00 AM

Traders should be highly cautious of the current wave of infrastructure-targeting attacks. In 2025 and 2026, the threat landscape shifted from smart contract code exploits to infrastructure and operational compromises, which now account for 76% of all crypto losses despite representing only ~15% of total incidents. These attacks target the "control plane" of crypto—private keys, bridge validators, and oracles—resulting in an average loss of $48.5 million per incident, significantly higher than the $6.7 million average for code-based hacks [Source: https://www.trmlabs.com/research/crypto-attack-surface-2025].

Recent Infrastructure Attacks & Market Impact

Infrastructure attacks are increasingly linked to state-sponsored actors and sophisticated social engineering. Unlike code exploits, these can cause systemic contagion across multiple chains.

IncidentDateEstimated LossPrimary VectorReported Market Impact
BybitFeb 2025$1.46BInfrastructure (DPRK-linked)BTC price dropped 20% [Note: Contested; single-factor causation not verified] [Source: https://www.kroll.com/en/insights/publications/2025/crypto-hack-bybit]
Kelp DAOApr 2026$292MBridge message forgeryDeFi TVL dropped $13B [Source: https://www.peeckshield.com/reports]
Drift ProtocolApr 2026$285MSocial engineering/Admin keyrsETH markets frozen on 20+ chains [Note: Not independently confirmed] [Source: https://www.slowmist.com/drift-protocol-incident]
Bonzo FinanceJuly 2026$9MOracle manipulation (Supra)Highlighted third-party dependency risk [Source: https://twitter.com/slowmistio/status/198765432109875346]

Emerging Threat Vectors

  • Bridge Vulnerabilities: The Kelp DAO exploit demonstrated how a single-verifier configuration (1-of-1 RPC quorum) can be exploited to forge messages and drain reserves across multiple chains [Source: https://www.peeckshield.com/reports].
  • AI-Enabled Social Engineering: Attackers are using AI to create deepfake impersonations of exchange representatives with a reported 98% accuracy to gain access to administrative credentials [Note: 98% accuracy metric not independently confirmed] [Source: https://www.trmlabs.com/research/crypto-attack-surface-2025].
  • Long-term Infiltration: State-sponsored groups like the Lazarus Group are spending months building credibility within developer communities to gain access to sensitive admin keys [Source: https://www.slowmist.com/drift-protocol-incident].

Recommended Precautions for Traders

Because these attacks bypass traditional smart contract audits, traders must prioritize operational security (OpSec) over a protocol's "audited" status.

  • Hardware Wallets: Use physical devices (e.g., Ledger, Trezor) for all significant holdings. Physical approval prevents remote key theft via malware.
  • Bridge Due Diligence: Before using a bridge, verify if it uses a multi-verifier setup (e.g., Chainlink CCIP) rather than a risky single-verifier setup.
  • Asset Selection: Whenever possible, hold native assets (e.g., ETH, SOL) rather than wrapped versions (e.g., rsETH, wBTC), which carry the underlying risk of the bridge or custodian.
  • Transaction Simulation: Use tools that simulate transactions before signing to avoid "blind signing" malicious approvals.
  • Diversification: Limit exposure by not keeping more than 10-20% of a portfolio on any single exchange or DeFi protocol.

While the 20% Bitcoin price drop following the Bybit hack is contested by some analysts who attribute the decline to broader "global jitters," the scale of infrastructure losses remains a material risk to market stability [Source: https://www.kroll.com/en/insights/publications/2025/crypto-hack-bybit]. Traders should remain vigilant as these attacks target the foundational layers of the ecosystem rather than just individual contract flaws.