Crypto Hacks Cost the Industry $1.32 Billion in the First Half of 2026

Last Updated on 25 July 2026 by CryptoTips.eu

Crypto hackers struck hard during the first half of 2026, with approximately $1.32 billion in digital assets lost across 224 publicly disclosed incidents. Although the number of attacks was significant, most of the financial damage came from a relatively small number of major exploits. Access control failures, phishing attacks, and oracle vulnerabilities accounted for the largest losses.

Access control failures caused the biggest losses

Access control failures were by far the most damaging category. In these attacks, hackers gained unauthorized access to systems or accounts with elevated privileges, allowing them to steal substantial amounts of funds.

Kelp DAO recorded the largest loss at approximately $292 million, followed by Drift Protocol with $280 million. Humanity Protocol lost $31 million, while Step Finance suffered losses of around $30 million. Truebit, Resolv Labs, AFX, and BonkDAO also experienced significant exploits, losing $26.5 million, $25 million, $24.15 million, and $21 million respectively.

The available data shows that these access-related breaches accounted for a large share of the total losses reported during the first six months of the year.

Phishing and oracle vulnerabilities remain major threats

Beyond access control failures, phishing continued to be one of the most effective attack methods. A single large-scale social engineering attack resulted in losses of approximately $282 million, highlighting how attackers continue to exploit human error to gain access to sensitive information and crypto assets.

Oracle vulnerabilities also contributed to the overall damage. Ostium lost approximately $24 million, Blend Protocol suffered losses of $10.86 million, and Bonzo lost around $9 million due to oracle-related exploits.

A handful of incidents drove most of the damage

The figures show that only a small number of incidents were responsible for the majority of the $1.32 billion in losses during the first half of 2026. Compromised permissions and privileged accounts remained some of the most attractive targets for attackers.

The data underscores the importance of strengthening access controls and improving defenses against phishing attacks as key priorities for crypto projects. More information about the reported incidents was shared by OnchainLens:


Jeroen Kok

Jeroen is one of the lead copywriters on Cryptotips.eu and discusses all recent events in the crypto market. This includes news updates, but also price analyzes and more. He developed his passion for cryptocurrency during the bull run in 2017. He has learned a lot since then. The combination of cryptocurrency and creative writing is perfect for Jeroen and an excellent way to share his knowledge with a wide audience. Find me on LinkedIn / jeroen@cryptotips.eu