Crypto hacks in 2026 have seen over $972 million stolen from platforms in the first half of the year.
This year’s wave of crypto hacks highlights a pronounced shift in attack vectors, moving away from inherent smart contract bugs towards vulnerabilities in operational systems, such as compromised private keys, insecure signers, and flawed governance mechanisms.
Shifting targets in crypto security
Mitchell Amador, founder and CEO of Immunefi, observes that the majority of stolen funds in 2026 haven’t departed through code flaws but through these more systemic weaknesses. It’s a concerning trend for an industry still grappling with its security foundations, despite a decrease from the $2.3 billion lost during the first half of 2025.
The nature of successful crypto exploits has undeniably changed. Rather than sophisticated attacks on smart contract code, hackers are increasingly exploiting human and procedural weaknesses. Amador noted that the number of incidents continues to climb, with funds increasingly disappearing due to stolen signing keys, misconfigured verifiers, or governance systems that can be manipulated.
Consider the BonkDAO incident this month, where an attacker spent approximately $4 million to drain about $20 million from the treasury. This wasn’t a smart contract failing; it was a clever exploit of the governance rules themselves.
The attacker simply acquired enough tokens to pass a malicious proposal during a low-turnout vote, and the system executed it exactly as designed, demonstrating that the rules, not just the code, can be a vulnerability.
Beyond the code: operational vulnerabilities
The problem extends beyond governance exploits. June saw Humanity Protocol lose over $30 million when a private key on a team member’s machine was compromised, leaving the underlying smart contract untouched. This kind of attack underscores how critical the security of off-chain elements, human processes, and individual device security have become.
Data from CertiK further reinforces this point, identifying wallet compromise as the single costliest vector. Such incidents led to $444.5 million in losses across just 33 events in the first half of the year.
Blockaid’s analysis also attributed nearly $600 million to operations linked to the Democratic People’s Republic of Korea (DPRK), including two significant April incidents involving KelpDAO and Drift that accounted for almost 44% of CertiK’s total H1 losses.
The audit dilemma: why “audited” doesn’t mean “safe”
For many years, smart contract audits have been touted as the gold standard for blockchain project security. Yet, recent events demonstrate that an audit, while essential, offers only a snapshot of security at a particular moment. Mitchell Amador aptly points out that “we were audited” was never the same as “we are safe.”
An audit meticulously scrutinizes code for bugs, but it doesn’t address the broader attack surface of a protocol. It can’t account for how private keys are stored, who holds signing authority, or what happens if an individual’s laptop is compromised. One notable protocol, for instance, underwent 11 audits and still suffered a $128 million loss, illustrating the limitations of code-centric security assessments.
Continuous pressure over one-time checks
To truly harden contract code, continuous and incentivized review is proving more effective than periodic audits. Bug bounty programs, coupled with robust monitoring and rapid response systems, empower security researchers to identify vulnerabilities before malicious actors do. The economics of this approach are compelling: a median bounty of roughly $20,000 routinely averts hacks that average around $25 million.
This model, driven by ongoing incentives, maintains its efficacy because it doesn’t cease when organizational structures change or key personnel depart. It creates an always-on defense mechanism, constantly testing the system in a way that static audits simply cannot replicate.
While smart contract bugs still exist—with 93.9% of programs running five years or more eventually surfacing a confirmed critical vulnerability—this continuous vigilance helps keep pace with attackers on the code layer.
The evolving threat landscape for digital assets
The sheer number of incidents in H1 2026 — 207 hacks reported by TRM Labs, the highest in any six-month period, and 344 by CertiK — underscores the relentless nature of threats to digital assets.
While the total value lost is down year-over-year, the increased frequency of attacks suggests a more distributed, perhaps less coordinated, but equally persistent effort by exploiters. The average loss per incident was $4.7 million, with a median of approximately $219,000.
The industry’s initial focus on securing smart contracts was a necessary first step. Now, the emphasis must broaden to encompass the entire operational stack. Securing digital assets involves a multi-faceted approach, recognizing that the weakest link can often be found outside the immutable code — in the mechanisms that control access, transfer value, and govern decisions within a decentralized ecosystem.
Implications for institutional adoption
This shift in the vulnerability landscape carries significant implications for institutional adoption of crypto. Larger institutions, with their stringent compliance and risk management frameworks, demand comprehensive security that extends beyond code integrity. The prospect of losses due to compromised keys or governance failures introduces a new layer of complexity to due diligence.
For crypto to achieve broader mainstream acceptance and institutional integration, it needs to demonstrate not just technological robustness but also operational resilience. These 2026 crypto hacks serve as a stark reminder that security is a continuous process, demanding constant adaptation and a holistic view of potential weak points across the entire digital asset ecosystem. This includes everything from developer workstations to complex multi-signature schemes.
Moving forward: a holistic security approach
The cryptocurrency industry can no longer afford to view security as a singular technical challenge solvable by auditing code alone. Mitchell Amador contends that a protocol is genuinely secure only when its code, keys, people, governance structures, and monitoring systems are all treated as live attack surfaces.
This means implementing robust security practices across every layer of operation. It involves not just external audits but also internal security protocols, ongoing penetration testing, comprehensive bug bounty programs that cover more than just smart contracts, and rigorous training for all personnel.
As the digital asset space matures, a truly secure environment will depend on continuous, multi-pronged efforts to identify and mitigate risks wherever they may arise.
