0x1153dd861153…1153dd83

ConfirmedSecurity671 vB114 sat/vB3 min decode

Crypto Hacks Hit Record 207 Incidents in H1 2026, Losses Under $1B: TRM

TRM Labs recorded 207 crypto hacks in H1 2026 — a record — but losses fell to $972M, with two North Korea-linked April thefts driving 66% of stolen value.

H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion - TRM Labs
WitnessH1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion - TRM LabsAI-generated

Outputs

  1. 207 crypto hacks recorded in H1 2026, a record six-month count, versus 83 in H1 2025

  2. Total losses fell to USD 972 million, less than half of H1 2025's USD 2.3 billion

  3. North Korea-linked activity accounted for about USD 643 million, or 66% of stolen funds

  4. Drift Protocol (USD 285M) and KelpDAO (USD 292M) April thefts totaled roughly USD 577 million

  5. Infrastructure compromises were ~15% of incidents but ~76% of losses; median hack cost USD 219,000

Attackers carried out 207 separate crypto hacks in the first half of 2026 — the highest six-month incident count TRM Labs has ever recorded — yet total losses fell to USD 972 million, less than half the USD 2.3 billion stolen in the same period of 2025, according to the blockchain intelligence firm's latest analysis.

The divergence between incident frequency and stolen value defines the half. The number of incidents more than doubled from 83 in H1 2025, while the median hack now costs only about USD 219,000. The mean loss, skewed by two enormous April thefts, sits at USD 4.7 million — more than twenty times the median.

Q2 2026 set a quarterly record with 123 incidents, following a record first quarter. The rise was steady across the half rather than concentrated in a single month.

What drove the money, versus the incident count?

Two distinct threat patterns emerged. Smart contract exploits accounted for 125 of the 207 incidents, increasingly chaining multiple contract manipulations into a single attack rather than relying on a single coding flaw. Most stolen funds came from financial services and crypto-native platforms.

Infrastructure and operational compromises told the opposite story: roughly 15% of incidents, but approximately 76% of total losses. These attacks targeted the systems, credentials and signing infrastructure that control assets, rather than vulnerabilities in on-chain code.

The remaining losses came from other attack types, including a USD 24 million physical coercion — or "wrench" — attack.

How much did North Korea-linked actors steal?

TRM assesses that approximately USD 643 million, about 66% of all funds stolen in H1 2026, is attributable to North Korea-linked activity — down from roughly USD 1.7 billion in H1 2025, though North Korea remained by far the largest single source of stolen value.

Nearly all of those losses came from two April operations:

  • The Drift Protocol breach, at approximately USD 285 million
  • The KelpDAO exploit, at approximately USD 292 million — the single largest incident of the half, just under 30% of all funds stolen

Together the two attacks totaled roughly USD 577 million. TRM had assessed these incidents at 71% of all crypto hack losses through April; by end of June that share declined to about 66% as non-state incidents accumulated while North Korea's total stayed largely unchanged.

TRM characterizes these operations as state-directed financial activity involving sophisticated infrastructure compromises, not opportunistic code exploits. The firm notes its figures cover only hacks and exploits — North Korea also generates crypto revenue through phishing, social engineering, fraud, scams and covert IT-worker operations.

Why the lower total does not mean lower risk

The decline in total losses reflects the absence of a theft on the scale of 2025's largest attacks, not a reduction in attacker capability. The attack surface keeps expanding: thousands of DeFi protocols, tokens and smart contracts create more opportunities for attackers to exploit vulnerabilities at scale. A single successful operation against a major target can still outweigh months of losses from every other attacker combined.

For security teams, TRM's data points to a rebalancing of priorities. Smart contract audits remain essential because code exploits are the most common attack, but key management, signing infrastructure, approval workflows and custody now represent the greatest source of catastrophic losses. Incident response planning, insurance coverage and treasury reserves should be sized against a major infrastructure compromise rather than an average loss.

For exchanges and financial institutions, the laundering patterns behind the largest thefts are well understood: stolen assets typically move through cross-chain bridges and no-KYC swap services before reaching exchanges. Detection requires multi-hop transaction monitoring beyond first-hop screening. TRM's Beacon Network, now more than 70 members strong, shares attacker wallet information to cut response times from days to minutes.

With the conditions that produced 2025's record losses still in place, TRM expects both threat patterns — rare infrastructure mega-thefts and a growing stream of smaller code exploits — to continue shaping the ecosystem through the remainder of 2026.

via cdn.prod.website-files.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles