Crypto hacks fell 47% in H1 but the ecosystem is no safer
Crypto hacks fell but headline totals mask a harder fight: CertiK says first-half 2026 exploit losses dropped roughly 47% year-on-year to $1.32 billion, yet the blockchain security firm warns the ecosystem is no safer. Q2 losses surged 59% quarter-on-quarter to $807.5 million as attackers grew more sophisticated and destructive.
CertiK's latest analysis challenges optimism behind falling loss figures. While totals are down from a period dominated by the record $1.4 billion Bybit hack in 2025, the firm told Cointelegraph that a superficial reading would wrongly suggest meaningful security gains.
Key Takeaways
- H1 2026 crypto exploit losses fell about 47% year-on-year to $1.32 billion, per CertiK.
- Q2 losses rose 59% quarter-on-quarter to $807.5 million, driven partly by KelpDAO and Drift Protocol hacks.
- North Korean state-sponsored hackers are believed responsible for more than 70% of Q2 losses.
- The year-on-year decline is skewed by 2025's $1.4 billion Bybit incident, the largest exploit on record.
- Private keys and multisignature wallet management remain the most consequential attack surface.
Why did crypto hack losses fall 47% in the first half of 2026?
The 46.8% year-on-year decline to $1.32 billion looks encouraging at first glance. CertiK cautioned, however, that last year's comparable period was inflated by the $1.4 billion Bybit exploit — still the largest crypto hack in history.
Excluding that outlier, CertiK said the industry is absorbing a structurally higher rate of attack activity than last year. Individual incidents are becoming more targeted and financially destructive, even when aggregate totals fall.
What drove the 59% spike in Q2 crypto exploits?
Crypto exploits rose 59% quarter-on-quarter to $807.5 million in Q2 2026. Phishing drove the bulk of first-quarter losses, totaling $508.2 million, while wallet compromises became the dominant attack vector in Q2.
More than 70% of Q2 losses traced to the KelpDAO and Drift Protocol exploits. CertiK attributed both to North Korean state-sponsored hackers — a pattern that shows how geopolitical threat actors are shaping the security landscape.
Are North Korean hackers behind the biggest breaches?
CertiK's report links North Korean state-sponsored groups to the quarter's most damaging incidents. The KelpDAO and Drift Protocol attacks alone accounted for the majority of Q2's $807.5 million in stolen funds.
CertiK told Cointelegraph that a headline reading of losses down nearly 50% would suggest a meaningfully safer ecosystem — but the data does not support that conclusion when attack frequency and per-event damage are considered.
What should crypto firms do to reduce exploit risk?
CertiK urged protocols and institutions holding significant on-chain assets to harden every layer of private key management — from hardware security and multisignature governance to geographically distributing signers.
The warning lands as regulators tighten oversight. Belgium's FSMA recently flagged six unauthorized crypto providers on its fraudulent list days after the EU's MiCA transitional deadline expired, while Strategy sold 3,588 Bitcoin for $216 million to fund dividends without touching its $2.55 billion reserve. For ongoing coverage, see our Fintech & Crypto Alerts section.