Crypto’s 10 Biggest Hacks of 2026: What Broke, How Attackers Got In, and Who Lost Millions

By Dilip Kumar Patairya // August 27, 2026 @ 01:05 PM Make AlphaWire Logo preferred on Google News

Share

Ledger Hardware Wallet ‘Hacked’ as OneKey Reveals Transaction-Swapping Flaw

Share

Points of Focus

  • Crypto suffered about $1.3 billion in losses across more than 200 incidents in H1 2026.
  • Kelp DAO and Drift Protocol led the year’s biggest losses at $292 million and $285 million, respectively.
  • Private keys, multisig signers, oracles, validators, and administrative privileges have emerged as critical attack surfaces.

 

Twelve minutes was all it took to drain $285 million across nearly 20 vaults on Drift Protocol. The theft left no cracked smart contracts or zero-day exploits in its wake. It was just the fallout of a social engineering campaign months in the making.

Seventeen days later, Kelp DAO surrendered another $292 million to a compromised cross-chain infrastructure.

By mid-summer, Coldcard users watched legacy Bitcoin (BTC) holdings disappear due to weak seed phrase entropy.

In the first half of 2026, the industry lost around $1.3 billion across more than 200 incidents. A common thread in crypto hacks is that the primary threat vector in 2026 has migrated outside the code.

Attackers are bypassing audits entirely to target protocol administrators, cryptographic key custody, and foundational offchain infrastructure. They have ridden on subtle human and system vulnerabilities into nearly $1.3 billion in losses. The industry’s long-standing reliance on smart contract audits as a bulletproof defense has reached a breaking point, proving that airtight code offers little protection when the ecosystem built around it remains fundamentally exposed.

Here are crypto’s 10 biggest hacks of 2026.

1. Kelp DAO: $292 million (April 18)

The largest single hack of 2026 struck Kelp DAO, a liquid restaking protocol, on April 18. The protocol relied on LayerZero’s cross-chain messaging to transfer its rsETH token across more than 20 blockchains. It operated with a single-verifier setup — a “1-of-1” configuration that left the entire system dependent on one node.

Attackers linked to North Korea’s Lazarus Group are suspected of social-engineering a LayerZero developer. They obtained session keys and infiltrated LayerZero’s own remote procedure call infrastructure, compromising two internal nodes while flooding the backups with a denial-of-service attack. With the verifier under their control, the attackers minted 116,500 unbacked rsETH tokens, worth about $292 million, out of thin air. The fallout was immediate and messy.

LayerZero initially pointed the finger at Kelp for choosing the risky configuration. Kelp countered that LayerZero staff had approved it and that nearly half of all LayerZero applications used the same design. Weeks later, LayerZero made a turnaround, issuing a public apology and acknowledging its own mistake. By then, the fabricated rsETH was accepted as collateral on Aave, enabling further borrowing and helping trigger $8.45 billion in deposits fleeing the lending protocol within 48 hours. Kelp has since migrated to Chainlink’s cross-chain infrastructure.

How the KelpDAO attack was executed. Source: Chainalysis

2. Drift Protocol: $285 million (April 1)

Seventeen days earlier, on April 1, Solana’s largest decentralized perpetuals exchange, Drift Protocol, lost $285 million in just 12 minutes. A group tracked as UNC4736, also known as AppleJeus and Citrine Sleet and suspected to have North Korean links, spent months posing as a legitimate quantitative trading firm.

Attackers met Drift contributors in person at an industry conference, deposited more than $1 million of their own capital to build credibility, and asked detailed product questions to earn the team’s trust. Thereafter, exploiting Solana’s durable-nonce feature, the attackers induced Drift’s Security Council multisig signers to pre-authorize transactions that appeared routine. They then whitelisted CarbonVote, a fabricated token, seeding it with a few thousand dollars of wash-traded liquidity. Drift’s oracle treated the token as legitimate collateral worth hundreds of millions. Real assets — USDC (USDC), Solana (SOL), Ether (ETH), and more — were then withdrawn from nearly 20 protocol vaults before anyone could intervene. The blockchain itself had not been compromised in the attack, and it was a failure of human judgment.

How withdrawal transactions happened on Drift Protocol. Source: TRM Labs

3. Coldcard hardware wallet: $116 million-$130 million (July 30)

The year’s strangest hack chapter, however, unfolded far from any decentralized finance (DeFi) protocol. Coldcard, a widely used hardware wallet, carried a latent firmware vulnerability dating back to 2021. A code change had discreetly diverted seed phrase generation from the device’s True Random Number Generator (TRNG) to a weaker source, reducing entropy from 128 bits to roughly 40, which was low enough for offline brute-force attacks.

No device was stolen for this hack, nor was any user tricked into signing a transaction. Attackers simply zeroed in on the seed phrases and reconstructed the private keys. On July 30, they drained 1,196 addresses in 41 minutes before Coinkite had even issued its advisory. By early August, researchers had confirmed at least three, and likely four, distinct waves of theft affecting more than 7,300 Bitcoin addresses.

The patched firmware protects only newly generated wallets, while those created before the fix remain permanently exposed. As of the latest tracing, around 90% of the stolen Bitcoin still sits untouched in attacker-controlled wallets, suggesting the perpetrators are in no rush to liquidate or have yet to find a safe way to do so.

TRNG module; Source: Cadence

4. Humanity Protocol: $33 million-$36 million (June)

Sometimes the most sophisticated element of a crypto heist is not the exploit itself, but the quiet preparation that precedes it. Attackers compromised a developer’s laptop at Humanity Protocol, a biometric identity project often compared to a “Chinese Worldcoin.” They gained root access via malware that extracted seven private keys stored as backups. Those keys unlocked bridge administration on both Ethereum and BNB Chain.

The attackers seized ProxyAdmin control, upgraded contracts to malicious versions, drained roughly 141 million H tokens on Ethereum, and minted hundreds of millions more on BNB Chain. Total losses reached about $36 million. The H token plunged 85%-90% in hours, underscoring how operational key-management failures can prove as catastrophic as smart contract bugs. Investigators later linked the breach to actors with possible North Korean ties.

5. Step Finance: $27 million-$30 million (January)

Step Finance, which was the year’s first major breach, was almost old-fashioned by crypto standards. Attackers compromised private keys and devices belonging to Step Finance executives, seizing control of the Solana-based platform’s treasury and fee wallets. They transferred stake authority, unstaked 261,000-262,000 SOL, and withdrew the funds within about 90 minutes.

Losses totaled $27 million-$30 million, and the STEP token crashed more than 80%-90%. The project recovered about $4.7 million via Token-22 freezes but ultimately shut down operations in February after failing to secure a recovery path.

6. Truebit: $26 million-$27 million (Q1)

Truebit’s loss stemmed from an Ethereum-based unaudited contract. An integer-overflow bug, long warned about by security researchers, surfaced in the TRU token purchase-pricing logic. Compiled with Solidity 0.6.x, which lacked automatic overflow checks, the function allowed an attacker to supply a carefully chosen large amount that caused intermediate calculations to wrap around to near-zero.

The outcome was free minting of TRU in massive quantities, which were immediately sold back into the bonding curve, draining about 8,535 ETH, worth $26 million-$27 million. A secondary opportunistic attacker extracted a further few hundred thousand dollars. The episode proved that unaudited code is always vulnerable, regardless of the time it has been functioning.

7. Resolv Labs: $25 million-$27 million (March 21-22)

Resolv’s USR stablecoin was designed to be fully collateralized one-to-one. A critical gap in its minting logic, tied to a privileged offchain signing key controlled by a single externally owned account, allowed an attacker to deposit about $200,000 in USDC and mint 80 million unbacked USR tokens.

The attacker rapidly swapped the newly minted tokens across decentralized exchanges, converting proceeds into roughly 11,400 ETH and extracting about $25 million before the peg collapsed. USR’s price crashed as much as 95%-98%. Resolv paused operations, neutralized tens of millions of the illicit supply, issued a white-hat recovery offer, and later published a detailed post-mortem confirming the offchain infrastructure compromise.

Resolv Labs. Source: Chainalysis

8. AFX Trade: $24.15 million (July 22)

AFX Trade’s Arbitrum-based custody bridge relied on a seven-validator multisig that required a two-thirds quorum to move funds. Attackers did not need to break the onchain math; they simply compromised the private keys of five of the seven validators, clearing the threshold outright, and drained $24.15 million in USDC. A 200-second challenge window expired with no intervention.

The stolen stablecoins were bridged to Ethereum and swapped for 12,467 ETH. Arbitrum’s native bridge remained unaffected. In a move that has become increasingly common, AFX publicly offered the attacker a 30% “bounty” to return the remainder, an implicit acknowledgment that partial recovery is often preferable to total loss.

9. Ostium: $24 million (mid-July)

Ostium is a real-world-asset perpetuals platform on Arbitrum offering synthetic exposure to stocks, commodities, forex, and crypto. It was hit around a week before the AFX incident. Attackers compromised offchain oracle-signing infrastructure rather than any smart contract logic. Holding a valid signer key and a registered forwarder role, they submitted fabricated price reports, then opened and instantly closed large positions to extract artificial profits from the OLP liquidity vault.

The attack, executed in a tight window of around five minutes across multiple transactions, drained $23.75 million-$24 million in USDC. Trader collateral remained isolated and untouched. The protocol paused trading, which was later resumed after hardening controls, and is still pursuing recovery for liquidity providers. The episode formed part of July’s brutal stretch that ranked as the second-worst month of the year for crypto theft.

10. BonkDAO: $21 million (July)

BonkDAO’s loss illustrated that even mid-size projects outside the marquee bridge and protocol hacks remain steady targets. An attacker spent $4.4 million-$8 million acquiring enough BONK (about 882 billion tokens) to meet the 1% quorum threshold. They then pushed through a malicious governance proposal (BIP-76) that transferred 4.426 trillion BONK, valued at $21 million-$21.2 million, from the treasury to a wallet they controlled.

The proposal passed with 99.9% approval amid minimal participation. Most of the tokens were later moved into a newly created “BONK 2.0” multisig and gradually liquidated, contributing to a sharp price decline. The incident, which fetched the attacker an estimated $13 million-$17 million, highlighted the risks of lightly contested, token-weighted governance.

The $1.3-billion blindspot: The pattern underneath the numbers

To comprehend why $1.3 billion vanished in just six months, you need to stop looking at the what and start looking at the how.

Audits no longer enough

A successful audit was once treated as a strong defense against protocol exploits. However, in 2026, attackers are taking a more direct route to protocol funds rather than finding vulnerabilities in smart contract code. They are using private keys, multisig signers, deployer accounts, and administrative controls to get through.

The distinction matters. A protocol’s contracts may withstand extensive security reviews, but those protections offer little defense if an attacker compromises the credentials capable of upgrading contracts or moving assets.

Attackers target the infrastructure

Validators, bridges, oracles, and other underlying services can become attractive targets because a single compromise can affect multiple applications.

Oracle manipulation is particularly risky for DeFi protocols that use external price feeds to calculate collateral values, borrowing limits, and liquidations. If manipulated data reaches a protocol, its smart contracts will execute exactly as designed but produce disastrous results.

Social engineering moves upstream

Social engineering has also become more sophisticated. Instead of relying primarily on mass phishing campaigns, attackers are targeting team members with access to critical systems. Fake recruitment, contributor accounts, and malicious software disguised as legitimate work tools can provide pathways into development environments.

Once credentials or devices are compromised, attackers may gain access to source code repositories, private keys, or administrative systems. They don’t have to discover or break the protocol’s technical vulnerabilities directly.

Institutional fallout and the security pivot

Crypto losses in 2026 are reshaping how institutions evaluate the sector. Beyond code audits, investors now scrutinize operational security — who controls private keys, how admin access is managed, and whether suspicious activity can be halted before funds exit.

This pressure is driving stronger security practices. Multi-party computation wallets reduce single points of failure, hardware-backed systems protect admin functions, and real-time monitoring shifts focus from post-attack investigations to detecting anomalies as they happen.

Rather than signaling a retreat of institutional capital, these targeted attacks are forcing protocols to professionalize security and treat privileged access as critical financial infrastructure.

For users and investors, risk assessment must extend past audits to include governance, multisigs, permissions, timelocks, and incident-response capabilities. Security is no longer a one-time check but an ongoing process that strengthens code, people, permissions, and surrounding infrastructure.

Share

Default avatar

Dilip Kumar Patairya

Dilip Kumar Patairya has a professional background in B2B technology journalism and focuses on blockchain, fintech, and related enterprise technologies. His work draws on more than 15 years of writing experience across corporate and media environments.

Table of content

Ad

Related Articles