
Attackers took $763,971,791 out of crypto in the second quarter of 2026, across 67 separate incidents. That is up 58.3% on Q1’s $482.7 million and the worst quarter the industry has had since Q2 2025.
Almost none of it left through a smart contract.
Data compiled by security and compliance firm Hacken puts 88.3% of the quarter’s losses down to operational and infrastructural failure: compromised keys, exposed signers, broken deployment and access controls. Smart contract bugs caused more incidents than anything else. They accounted for 11% of the money.
Two names, most of the quarter
KelpDAO lost roughly $292 million on April 18. Drift Protocol lost roughly $285 million seventeen days earlier. Between them that is about three quarters of everything stolen in Q2, and more than half of every dollar lost in DeFi this year.
Both were attributed to North Korea. Neither involved a bug in a smart contract.
Quarters have looked like this for two years now: a long tail of five and six-figure incidents, then one or two events large enough to set the headline on their own. What changed in Q2 is the tail itself. Depending on whose database you use, the quarter logged somewhere between 67 and 85 incidents, which by every count on record is the most active three months crypto has ever had. Attackers ran roughly one successful operation per day.
Funds lost by chain

No security firm has published a clean chain-by-chain table for Q2 alone, so the picture below is assembled from incident-level data and framed by Blockaid’s half-year figures.
Solana carried around $290 million, effectively all of it Drift. Raydium added $1.34 million to a fake LP mint attack on June 10, and a compromised Roaring Kitty X account was used to pump a Solana token for $2.86 million in May. Blockaid puts Solana’s H1 losses at roughly $326 million, against about $127 million for the whole of 2025. That is not a code-quality story. Solana’s ecosystem got large enough to be worth the effort.
Ethereum and its layer 2s carried a comparable load, around $332 million across H1 by the same dataset, and remain the most-attacked network by incident count — CryptoRank logged 56 separate Ethereum incidents in H1, ahead of BNB Chain, Base and Arbitrum. The unbacked rsETH from the Kelp exploit was minted on Ethereum mainnet and immediately posted to Aave. Aztec’s abandoned Payments and Connect contracts gave up $2.16 million and $2.1 million in the space of a week in June. The JaredFromSubway.eth MEV bot lost $7.5 million. Taiko, an Ethereum L2, lost $1.7 million on June 22 when its bridge state verification was compromised.
Base recorded $3.175 million in May across two incidents, most of it SquidRouter’s access control failure, which hit Ethereum at the same time. TON lost $2.8 million to a smart contract flaw in TAC Cross-Chain Layer on May 13.
The chain column is the least useful cut of this quarter’s data, and it is worth saying why. Cross-chain bridges accounted for roughly $351 million, about 46% of everything stolen, and a bridge failure does not belong to one chain. rsETH was live on more than 20 networks. When the escrow behind it emptied, holders on Base, Arbitrum, Linea, Blast, Mantle and Scroll were left holding wrapped tokens with nothing behind them. Ask which chain lost the money and there is no clean answer.
Where the money actually left
The 88.3% figure is the one worth sitting with.
Multisig setups, signer devices, deployment pipelines, contractor access, third-party integrations. None of it is covered by a smart contract audit. All of it carries the same authority as the contracts do. A protocol can hold a clean audit report and still lose nine figures because someone’s laptop was compromised, and several of them did.
Smart contract bugs at 11% of losses is not evidence that on-chain code is solved. It is evidence that attackers have moved to the easier target, which is what attackers do.
Top 5 exploits of Q2 2026

1. KelpDAO – $292,000,000 (April 18, bridge infrastructure)
An attacker forged a cross-chain message and minted 116,500 rsETH on Ethereum with nothing behind it, roughly 18% of the token’s circulating supply. Within minutes 89,567 rsETH was sitting on Aave as collateral against about $190 million in borrowed WETH.
There was no bug. Kelp’s contracts ran exactly as written, and Aave’s did too. The failure was in configuration: Kelp’s rsETH bridge ran a 1-of-1 DVN, meaning a single verifier could approve a cross-chain transfer on its own. Attackers gained access to the RPC list that verifier depended on, compromised two nodes on separate clusters, replaced binaries on op-geth nodes and DDoS’d the rest to force failover. The verifier was then fed a phantom burn on the source chain and attested to it. Every transaction on-chain looked valid, which is why monitoring caught nothing.
Kelp’s emergency multisig froze core contracts 46 minutes after the drain. Two follow-up packets attempting another 40,000 rsETH reverted. The Arbitrum Security Council froze $71 million of the attacker’s funds under emergency powers.
LayerZero initially blamed Kelp’s configuration choice, then reversed in May: “We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions.” It has since refused to sign for any 1-of-1 application. At the time of the hack, 47% of active LayerZero OApp contracts were running that configuration. Kelp migrated rsETH to Chainlink CCIP. Chainalysis and LayerZero both point to DPRK-linked TraderTraitor.
2. Drift Protocol – $285,000,000 (April 1, governance compromise)
The largest DeFi loss on Solana since Wormhole, and it started three weeks before anyone noticed.
Attackers spent months building relationships with the Drift team, including in-person meetings. On March 11 they pulled 10 ETH from Tornado Cash to fund infrastructure. On March 23 they created durable nonce accounts — a legitimate Solana feature that lets a transaction be signed now and executed later — tied to Drift Security Council signers. Council members signed what they believed were routine transactions. They were pre-approving the handover of admin control.
The attackers then manufactured CarbonVote Token, seeded it with a few thousand dollars of liquidity across DEXs, washed-traded it, and whitelisted it as collateral. Drift’s oracles priced it as real. 500 million CVT went in. Roughly $285 million in USDC, SOL, JLP and WBTC came out, over about twelve minutes and dozens of withdrawals.
TVL fell from around $550 million to under $300 million within an hour. DRIFT dropped more than 40%. Funds were bridged to Ethereum via Circle’s CCTP; ZachXBT publicly criticised the absence of a timely freeze. A dozen Solana protocols with exposure to Drift paused or moved to reimburse. TRM Labs and Elliptic both attribute the operation to Lazarus.
3. Humanity Protocol – $36,000,000 (June 8, private key compromise)
Private keys were pulled from a developer’s malware-infected machine. Estimates range from $31 million to $36 million depending on the tracker. The proceeds were laundered across Bitcoin, Solana, Hyperliquid and BNB Chain, and on-chain analysts found them mixing with funds from the Kelp exploit — which, if it holds, puts the same operators behind two of the quarter’s five largest incidents.
4. THORChain – $10,700,000 (May 15)
The largest single incident in an otherwise quiet May, which closed with roughly $84 million lost across 41 reported incidents.
5. Syscoin Bridge 0 $10,000,000 (June)
A validation flaw lets the attacker mint SYS on one side without a corresponding burn on the other. Structurally the same failure as Kelp, three orders of magnitude cheaper, and the second bridge verification failure of the quarter to work exactly that way.
North Korea took three quarters of it
Actors linked to the DPRK were behind 75.5% of the funds drained this quarter.
The clearest illustration came from Consensys. The company behind MetaMask hired a software developer who turned out to be linked to North Korea. It took about a month to work that out. The developer was fired, system access was revoked, and Consensys reported the incident to law enforcement. No funds were lost, no data leaked, no malicious code shipped.
That one ended clean, which is exactly why it is worth reading. The attack did not start at the wallet or the contract. It started with a job application. Hiring pipelines, onboarding and access provisioning are security controls now, and very few teams staff them like security controls.
First recorded AI prompt injection loss
$174,000 was exfiltrated this quarter through a malicious AI prompt injection. It is the first case on the record.
Hacken traces the failure to inadequate review, missing variants and weak testing. Nobody is going to notice $174,000 in a quarter that lost $764 million, but the date is worth writing down. Agentic tooling is moving into treasury operations and transaction construction faster than anyone is testing it. Anything shipping AI-assisted workflows near signing authority now has a documented reason to test harder.
Regulation stopped being theoretical
In the US, the GENIUS Act takes effect in early 2027.
In Europe it already has. MiCA’s grace period ended on 1 July. Around 1,200 firms had expressed interest in authorisation. About 215 finished the process.
Binance, MEXC and HTX are among the venues that shut down European operations under the rule. Circle’s USDC is still the only MiCA-compliant asset in the top ten stablecoins by market cap, which solves one problem and quietly creates another for European liquidity.
Closing thoughts
Nothing about Q2 2026 was clever. The two largest losses of the quarter did not need a novel exploit, and the state actor responsible for most of the stolen value has been running the same playbook, more or less publicly, for years.
What changed is where the failures happened. Key management and access governance now deserve the budget that smart contract auditing spent five years earning. Personnel vetting is a live control, not paperwork. AI integration has opened a vector nobody is testing properly and it has already produced an invoice.
Hacken’s own read is that the counterparties worth trusting will be the ones that can demonstrate their control. Not the ones that have been around longest, collected the most audits, or hold the most TVL.

