crypto news

DeFi hacks hit record $746M in Q2 2026 as credential theft dominates

Q2 2026 is the most-hacked quarter in DeFi history, with over $746 million lost across ~70 exploits. Credential theft, not smart contract bugs, now drives 72% of losses, and state-backed actors account for 76% of global crypto hack losses.

1 min read 10 claims web-cited

DeFi security just set a grim new record. Q2 2026 is now the most-hacked quarter in history by incident count, with roughly 70 separate exploits and about $746 million in losses across April, May, and the first half of June, per DefiLlama [^claim_1418]. And it’s not slowing down — over $840 million has been lost to DeFi hacks between January and May 2026 alone, a 70% year-over-year jump from the same stretch in 2025 [^claim_1419].

The attack surface has shifted hard. 72% of 2026 losses came from stolen keys and credential theft — not smart contract bugs [^claim_1419]. Two incidents alone account for more than $577 million: Kelp DAO’s LayerZero bridge lost $292 million in rsETH on April 19, and Drift Protocol bled $285 million on April 1 after a North Korean hacking group spent six months socially engineering its way into the Solana-based DEX [^claim_1421]. April 2026 officially became the worst month ever for crypto hacks, with over $629 million drained across more than 25 incidents. The dominant attack vectors now are cross-chain bridges, oracle manipulation, social engineering against key holders, and domain hijacking — CoW Swap’s $1.2 million loss in April came from a hijacked domain [^claim_1422].

State-backed actors are the ones cashing in. Chainalysis attributes roughly 76% of all crypto-related hack losses globally in 2026 to state-backed actors linked to North Korea’s Lazarus Group [^claim_1420].

For crypto protocols, the message is blunt: securing keys and credentials — not just smart contract code — is now the real battleground. Multi-sig governance, hardware security modules, and social engineering resistance are no longer optional. Bridge-minimizing architectures and oracle manipulation safeguards are equally urgent. The attackers have shifted. If the defenses don’t follow, the record-setting losses will keep climbing.

Provenance ledger

10 claims web-cited

Every claim below cites a source URL, and each URL was checked for validity before publish. The excerpt shown is the researcher's own summary of the page — it is not re-derived from the source, so it is not a verified verbatim quote. Follow the link to confirm any claim against the original. Citation markers in the text jump here.

[1] Q2 2026 is the most‑hacked quarter in DeFi history by incident count, with approximately 70 separate exploits and around $746 million in losses recorded across April, May, and the first half of June. web-cited
Excerpt reported by researcher (not re-verified)
“DefiLlama confirmed Q2 2026 as the most-hacked quarter in DeFi history by incident count, with approximately 70 exploits and $746 million … Q2 2026 has become the most-hacked quarter in DeFi history by incident count, according to DefiLlama, which logged approximately 70 separate exploits across April, May and the first two weeks of June. The quarterly dollar total stands at roughly $746 million.”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[2] Over $840 million has been lost to DeFi hacks between January and May 2026, with 72% of those losses attributed to stolen keys and credential theft rather than smart contract bugs. web-cited
Excerpt reported by researcher (not re-verified)
“**$840M+** lost in January–May 2026 — a 70% YoY increase over the same period in 2025 … **72% of losses** in 2026 came from stolen keys and credential theft — not smart contract bugs.”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[3] Approximately 76% of global crypto hack losses in 2026 are attributed to state‑backed actors linked to North Korea’s Lazarus Group. web-cited
Excerpt reported by researcher (not re-verified)
“**Lazarus Group** (North Korea) attributed to ~76% of crypto hack losses globally in 2026 … Chainalysis attributes approximately **76% of crypto-related hack losses globally in 2026** to state-backed actors linked to the Lazarus Group.”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[4] DeFi and crypto protocols had already lost more than $750 million to hacks by mid‑April 2026, driven largely by two bridge‑related incidents: Kelp DAO’s LayerZero bridge exploit draining $292 million in rsETH and Drift Protocol’s $285 million loss after a long social‑engineering campaign. web-cited
Excerpt reported by researcher (not re-verified)
“DeFi protocols have lost more than $750 million to hacks and exploits in 2026, and the year is not even four months old. Two attacks alone account for more than $577 million of that total. Kelp DAO's LayerZero bridge was drained of $292 million in rsETH on April 19, and Drift Protocol lost $285 million on April 1 after a North Korean hacking group spent six months socially engineering its way into the Solana-based DEX.”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[5] April 2026 is the worst month ever recorded for crypto hacks, with over $629 million drained from DeFi protocols across more than 25 incidents, highlighting bridges, oracle manipulation, social engineering of key holders, and domain hijacking as the dominant attack vectors. web-cited
Excerpt reported by researcher (not re-verified)
“April 2026 officially became the worst month for crypto hacks ever recorded. According to DeFiLlama data, over $629 million was drained from DeFi protocols across more than 25 separate incidents. … The new attack vectors breaking through in 2026 are: **Cross-chain bridges.** … **Oracle manipulation.** … **Social engineering against key holders.** … **Domain hijacking.** CoW Swap’s $1.2 million loss in April came from a hijacked domain.”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[6] Coinbase’s Base network completed its Beryl hard fork after a short sequencer‑related outage, introducing the B20 native token standard, reducing withdrawal finality from seven days to five, and integrating Reth V2 to lower node storage requirements and improve execution efficiency. web-cited
Excerpt reported by researcher (not re-verified)
“Base’s “Beryl” hard fork went live after a brief sequencer-related halt, adding a native token standard and shortening withdrawal finality. … The listed items include a B20 native token standard, a reduction in withdrawal finality from seven days to five, and integration with Reth V2—expected to lower node storage requirements while improving execution efficiency.”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[7] Solana’s upcoming Alpenglow consensus upgrade targets finality of roughly 100–150 milliseconds under optimal conditions, compared with around 12.8 seconds today, by replacing Proof of History and Tower BFT with new components for voting and block propagation. web-cited
Excerpt reported by researcher (not re-verified)
“Solana’s “Alpenglow” focuses on faster finality through a redesigned consensus component, with an explicit goal of reducing confirmation times and simplifying validator activity. … The practical implication, as described in coverage of the upgrade, is a major drop in confirmation times—finality targeted at roughly 100–150 milliseconds in optimal conditions, compared with around 12.8 seconds today. … Alpenglow replaces Proof of History and Tower BFT with two new components, **Votor** for consens

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[8] Ethereum’s Glamsterdam hard fork, slated for H2 2026, is positioned as the most consequential near‑term upgrade to improve scalability, harden the layer‑1, and make the network easier to use by focusing on execution efficiency and protocol‑level proposer‑builder separation. web-cited
Excerpt reported by researcher (not re-verified)
“Ethereum’s “Glamsterdam” is targeting better scalability and usability, with changes aimed at improving performance while reducing operational friction on the network. … Ethereum’s public roadmap says the upgrade is intended to improve scalability, harden the layer-1, and make the network easier to use, with a mainnet launch expected in the second half of 2026. … Glamsterdam focuses on execution efficiency and proposer-builder separation at the protocol level.”

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[9] Pi Network’s Protocol 23 upgrade, activated on May 11, 2026, introduces full smart contract functionality to the Pi blockchain, enabling decentralised exchanges, lending protocols, automated tools, and tokenised asset products, and completes the transition started by Protocol 22. web-cited
Excerpt reported by researcher (not re-verified)
“Pi Network has set May 11 as the activation date for Protocol 23, the upgrade that introduces full smart contract functionality to the Pi blockchain and transforms the network from a mobile mining project into a programmable platform capable of supporting DeFi applications and real-world asset tokenisation. … Protocol 23 enables developers to build decentralised exchanges, lending protocols, automated tools, and tokenised asset products on Pi for the first time, completing the transformation Pr

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text
[10] Between the end of 2025 and up to July 2026, the EU’s MiCA framework requires exchanges, self‑custody wallet providers, custodians, asset transfer providers, stablecoin issuers, and portfolio managers to obtain formal authorization, with no third‑country equivalence allowed and Poland the only member state delaying national implementation. web-cited
Excerpt reported by researcher (not re-verified)
“Between the end of 2025 and up to July 2026, the European Union’s MiCA (Markets in Crypto-Assets) regulation will go into full effect. Specifically, crypto exchanges, self-custody wallet providers, custodians, asset transfer providers, stablecoin issuers and portfolio managers will have to obtain formal authorization to continue operating. Notably, out of the 27 EU member states, only Poland is delaying the national implementation of this strict crypto framework. … Although contained to EU memb

This excerpt was not re-derived from the source page, and may paraphrase or condense it. Check the source before relying on it.

↩ back to text

Sources

  1. https://thedefiant.io/news/hacks/q2-2026-most-hacked-quarter-defi-70-exploits-746m
  2. https://altfins.com/blog/defi-hacks-2026/
  3. https://phemex.com/blogs/defi-hacks-2026-bridge-exploits-explained
  4. https://airdropalert.com/blogs/defi-hacks-2026-guide/
  5. https://www.kucoin.com/news/flash/major-blockchain-upgrades-still-scheduled-for-2026
  6. https://crypto.news/pi-network-launches-protocol-23-on-may-11/
  7. https://cryptoslate.com/will-defi-adoption-officially-end-in-2026/
defi-hackssecuritycredential-theftlazarus-groupbridge-exploits
AUTOMATED

Get the synthesis

AI×crypto research, repackaged with every claim hash-locked to its source. New arXiv → analysis in ~3 hours.