Crypto lost $764M to hackers last quarter, and code wasn't the problem
Hacken's Q2 2026 Security and Compliance Report found $763.9M stolen across 67 incidents, with 88.3% of losses traced to compromised keys and infrastructure rather than smart contract bugs. Two North Korea-linked attacks on Drift Protocol and KelpDAO accounted for the bulk of the damage.
The crypto industry lost nearly $764 million to hackers in the second quarter of 2026, but the bigger finding from security firm @hackenclub is where the money actually went, and why.
Keys, Not Code
Hacken's Q2 2026 Security and Compliance Report counted $763.9 million stolen across 67 incidents, making it the worst quarter since Q2 2025. The firm found that compromised keys, signers, and infrastructure accounted for 88.3% of losses, a finding that challenges the industry's heavy focus on smart contract audits. Smart contract flaws appeared in 44 of the 67 incidents but drove only around 11% of the total damage.
Hacken tracked 1,427 projects with market capitalizations above $1 million and found that only 9% had third-party monitoring in place. Just 4% combined monitoring with an active bug bounty and an audit. Fourteen projects exploited during the quarter had previously been audited, with most losses originating outside the scope of traditional smart contract reviews. The report identified the most affected attack surfaces as signer devices, bridge validators, backend infrastructure, and admin keys. The pattern points to a structural gap: the industry audits code rigorously but leaves operational security, key management, and human access controls largely unguarded.
Two Attacks, Three-Quarters of the Damage
Two North Korea-attributed incidents dominated the quarter. On April 1, 2026, Solana's Drift Protocol lost approximately $285 million in roughly twelve minutes. No smart contract bug was involved. TRM Labs traced a six-month social engineering campaign in which Lazarus Group operators posed as a legitimate trading firm, attended crypto conferences in person, and ultimately compromised the signing keys used by the protocol's multisig Security Council.
On April 18, KelpDAO suffered a separate $292 million breach via a LayerZero bridge compromise. North Korea's TraderTraitor subunit hacked two RPC nodes feeding data to LayerZero's verifier network, injected false transaction data, and then knocked the legitimate nodes offline to force a failover to the compromised ones. The bridge had been configured with a single-verifier design, creating one critical point of failure. Together, the two attacks account for roughly three-quarters of everything stolen in Q2.
Hacken's report is a clear signal that operational security, not just cleaner code, needs to become a first-order priority. The firm concluded that security must cover code, operations, and infrastructure throughout a project's life, not end when an audit report is published.
Sources:
Hacken: Q2 2026 Security and Compliance Report
TRM Labs: North Korea Stole 76% of All Crypto Hack Value in 2026 With Just Two Attacks
Crypto.news: Crypto Security Audits Lose Trust as Institutions Demand Live Monitoring
Latest News
Read More...
Author
Crypto RichRich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.













