BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Crypto lost $764M to hackers last quarter, and code wasn't the problem

The crypto industry lost nearly $764 million to hackers in the second quarter of 2026, but the bigger finding from security firm @hackenclub is where the money actually went, and why. Keys, N

AnonymousCryptoCompass newsroom
July 23, 2026
3 min read
NEWS
Crypto lost $764M to hackers last quarter, and code wasn't the problem
CryptoCompass editorial visual for defi coverage.

The crypto industry lost nearly $764 million to hackers in the second quarter of 2026, but the bigger finding from security firm @hackenclub is where the money actually went, and why.

Keys, Not Code

Hacken's Q2 2026 Security and Compliance Report counted $763.9 million stolen across 67 incidents, making it the worst quarter since Q2 2025. The firm found that compromised keys, signers, and infrastructure accounted for 88.3% of losses, a finding that challenges the industry's heavy focus on smart contract audits. Smart contract flaws appeared in 44 of the 67 incidents but drove only around 11% of the total damage.

Hacken tracked 1,427 projects with market capitalizations above $1 million and found that only 9% had third-party monitoring in place. Just 4% combined monitoring with an active bug bounty and an audit. Fourteen projects exploited during the quarter had previously been audited, with most losses originating outside the scope of traditional smart contract reviews. The report identified the most affected attack surfaces as signer devices, bridge validators, backend infrastructure, and admin keys. The pattern points to a structural gap: the industry audits code rigorously but leaves operational security, key management, and human access controls largely unguarded.

Two Attacks, Three-Quarters of the Damage

Two North Korea-attributed incidents dominated the quarter. On April 1, 2026, Solana's Drift Protocol lost approximately $285 million in roughly twelve minutes. No smart contract bug was involved. TRM Labs traced a six-month social engineering campaign in which Lazarus Group operators posed as a legitimate trading firm, attended crypto conferences in person, and ultimately compromised the signing keys used by the protocol's multisig Security Council.

On April 18, KelpDAO suffered a separate $292 million breach via a LayerZero bridge compromise. North Korea's TraderTraitor subunit hacked two RPC nodes feeding data to LayerZero's verifier network, injected false transaction data, and then knocked the legitimate nodes offline to force a failover to the compromised ones. The bridge had been configured with a single-verifier design, creating one critical point of failure. Together, the two attacks account for roughly three-quarters of everything stolen in Q2.

Hacken's report is a clear signal that operational security, not just cleaner code, needs to become a first-order priority. The firm concluded that security must cover code, operations, and infrastructure throughout a project's life, not end when an audit report is published.

Sources:Hacken: Q2 2026 Security and Compliance ReportTRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026 With Just Two AttacksCrypto.news: Crypto Security Audits Lose Trust as Institutions Demand Live Monitoring