April 2026 has officially become the most heavily hacked month in cryptocurrency history, with Defillama confirming 28 to 30 separate security incidents that resulted in total losses exceeding $625 million. The record was not driven by a single catastrophic event, but by two large-scale attacks that accounted for the bulk of the damage.
Two Attacks Dominate the Losses
On April 1, the Solana-based Drift Protocol was struck by a sophisticated social engineering attack linked to North Korea's Lazarus Group, losing approximately $285 million. Around April 18, KelpDAO suffered a Layerzero bridge message spoofing exploit that drained roughly $293 million. Together, these two incidents represented nearly 93% of April's total losses. The remaining 26 or more exploits were mostly below $5 million, with many under $1 million, targeting a wide range of DeFi components including lending pools, vaults, staking contracts, oracle configurations, and cross-chain bridges.
A New All-Time High in Incident Count
Defillama published a chart on April 30 showing monthly incident counts spiking to levels never seen since the platform began tracking. Previous monthly peaks rarely exceeded 12 to 15 incidents. April 2026 averaged close to one attack per day. On-chain researcher Stacy Muur shared a running tally on X on April 29, listing 24 confirmed hacks with losses exceeding $624 million, and noted the month still had days remaining. Final figures pushed the count higher before April ended.
In dollar terms, April ranks as the worst month since the February 2025 Bybit breach of approximately $1.4 billion. However, by incident count, April 2026 stands alone. Year-to-date through April, the industry recorded roughly 68 incidents and more than $1 billion stolen, already outpacing 2025's pace excluding the Bybit event. April alone was 3.7 times larger than all of Q1 2026, which saw approximately $165 million lost across 35 incidents.
Smaller Exploits Add Up
Notable smaller incidents in April included Rhea Finance ($18.4 million), Grinex ($15 million), Volo Vault ($3.5 million), Hyperbridge ($2.5 million), Sweat Foundation ($3.5 million), and Wasabi Protocol ($5 million on April 30). Dozens more ranged from $50,000 to $1.5 million. Following the KelpDAO hack, reports emerged that over $14 billion in total value locked (TVL) exited DeFi protocols within days, with withdrawals concentrated in bridge and lending platforms.
The community reacted with alarm and calls for structural change. Security researchers identified social engineering and access-control failures as the dominant attack vectors, moving beyond the smart-contract bugs that defined earlier years of DeFi exploits. Discussions across industry forums and social media called for multi-signature key management, AI-assisted monitoring, protocol security sprints, and user-level insurance products.
Long-Term Data and Warnings
Defillama's lifetime totals now show crypto hacks exceeding $16.5 billion, with DeFi-specific losses near $7.7 billion and bridge exploits accounting for approximately $2.9 billion. Private-key compromises and operational security failures remain the most common vectors across all categories. Blockchain analyst Wenzhao Dong observed that the Lazarus Group demonstrated a sophisticated grasp of market liquidity, rather than directly cashing out. Analysts warn that growing TVL during bull-market conditions attracts a higher volume of sophisticated attackers, pressuring protocols to prioritize defense over new features heading into Q2 2026. Additionally, advances in AI coding and cybersecurity appear to have paradoxically increased hacking incidents. Investigations into several April incidents remain open, and Defillama continues to track all confirmed exploits in real time, with figures subject to revision as recovery efforts proceed and attribution is finalized.

