DeFi hacks have already topped $840 million in losses in 2026
DeFi hacking losses have surged in 2026, with more than $840 million drained in the first five months alone, according to CoinDesk. April accounted for the bulk of the damage: over $600 million was stolen, including two of the year's biggest incidents—the KelpDAO exploit tied to about $292 million in losses and a separate $285 million exploit at Drift Protocol. Losses extended into May, and Thunder Chain security researchers flagged a suspected crosschain vulnerability impacting more than $10 million that prompted a trading halt.
A growing list of affected projects includes Trusted Volume, Echo Protocol, Step Finance, Truebit, Resolv Labs, Wolo Protocol, Rhea Finance, and the VerusEthereum Bridge, among others. DeFiLlama data cited in the report underscores the breadth of the damage, which analysts described as a stress test for the trust assumptions embedded across DeFi infrastructure.
Security specialists told Decrypt that recent incidents point to structural weaknesses, especially in bridges and management systems, and that advances in artificial intelligence may be helping attackers find vulnerabilities faster. Natalie Newson, a senior blockchain investigator at CertiK, said April stood out for its intensity—only three days passed without an exploit, and at least $10,000 was stolen each day. Even so, she said the overall pace of incidents (excluding phishing) has remained relatively stable and below the 2023 peak. Newson added that April's severity was driven by 14 attacks exceeding $1 million in losses, second only to the 16 such incidents recorded in September 2025.
TRM Labs' Head of Global Policy and Government Affairs, Ari Redbord, attributed much of the surge to state-linked activity, describing North Korea as the main driver of an increasingly targeted campaign. He said 76% of global cryptocurrency hacking losses in the first four months of 2026 were linked to this activity, up from 64% in 2025 and less than 10% in 2020, and noted that attackers combine technical intrusions with carefully planned social engineering.
The largest DeFi hack of the year so far occurred on April 18, when attackers stole roughly 116,500 rsETH from a crosschain bridge, valued at about $292 million. LayerZero provides the messaging infrastructure used by the bridging protocol. LayerZero said the compromise traces back to March 6, when a developer was targeted in a social engineering attack and a session key was stolen. The firm said an incident investigation report prepared by Mandiant and CrowdStrike would be shared, and it cited attributions from Mandiant, CrowdStrike and independent researchers linking the attack to the North Korea-associated threat actor TraderTraitor (also known as UNC4899).
Redbord said DeFi's recurring security issues are rooted in where funds are stored and how they move, arguing that crosschain complexity creates abundant attack surfaces. He added that bridges continue to drive the largest single-event losses and that similar failure modes keep reappearing because the underlying issues are architectural.
Raz Niv, co-founder and CTO of Blockaid, said three technical patterns show up repeatedly in major 2026 incidents: failures in privileged access controls, malicious proxy upgrades (where attackers swap in a backdoored implementation contract), and weaknesses in crosschain message validation. On privileged access, he said Blockaid watches for anomalous role-assignment events and unauthorized privilege escalation, pointing to the Echo Protocol exploit as an example that can stem from leaked admin keys or misconfigurations. Niv said attackers often obtain keys through social engineering or exploit weak multisig thresholds. He argued the deeper issue is that each additional layer—agents, admin roles, crosschain messaging—introduces trust assumptions that adversaries systematically probe.
On AI, Niv said current models are increasingly capable of identifying known vulnerabilities at scale, effectively automating parts of skilled auditing. He said the bigger risk is not AI replacing human attackers, but amplifying their effectiveness by automating reconnaissance and freeing them to focus on more advanced techniques. He added that defenders can adopt the same tools, with AI-assisted monitoring and simulation becoming increasingly important.
Newson said AI progress may be one factor behind the recent wave, citing CertiK's observations of more exploitation of outdated and unverified contracts. Redbord said malicious actors are deploying AI at scale for reconnaissance, social engineering and exploit design, and that the sophistication seen in attacks such as Drift appears consistent with AI-assisted workflows. TRM analysts said North Korean operators are increasingly integrating AI tools, arguing that defensive AI needs to be deployed as aggressively as attackers use it offensively.
Redbord called DeFi hacking a "solvable problem" but said the industry needs greater transparency about where failures occur. He said audits can reduce code vulnerabilities but cannot fully protect against advanced social engineering such as the Drift incident, where North Korean-linked actors were reported to have spent months gaining access. He advocated for real-time public-private collaboration.
Newson said 2026 could mark an "evolutionary turning point" as the industry increasingly treats cybersecurity as a full-stack issue spanning AI, state-linked threats, infrastructure and people. She said weaknesses in offchain manual processes can undermine even well-designed onchain systems, and she expects a shift toward practical structural measures to address infrastructure and social engineering risk.
The confidence impact is hard to measure but visible, the report said. The KelpDAO vulnerability triggered an estimated $6.2 billion outflow. A rescue effort led by Aave CEO Stani Kulechov included an initiative called "DeFi United," which raised about $303 million in 132,650 ETH to backstop bad debt. The response highlighted the industry's ability to mobilize while underscoring the scale of capital required to absorb or mask bridge-related losses.
Newson said fallout depends on who is hit. Industry veterans may see the past six weeks as part of a painful but familiar learning cycle, she said. For newer participants facing major losses, she warned the consequences can raise existential doubts about the long-term viability and security of crypto—and technical fixes often arrive too late to recover stolen funds.