April 2026 has officially become the most hacked month in the history of the cryptocurrency industry by number of incidents. According to data compiled by Defillama, the month saw between 28 and 30 separate exploits, resulting in total losses of over $625 million. This record surpasses all previous monthly highs, which rarely exceeded 12 to 15 incidents.
Key Metrics
Defillama published a chart on April 30 showing that the incident count more than doubled the prior record. On average, nearly one attack occurred per day throughout the month. For the year to date (January–April 2026), the industry has experienced approximately 68 incidents with total losses exceeding $1 billion. Excluding the Bybit breach in February 2025 (which alone accounted for ~$1.4 billion), the 2026 pace is already ahead of 2025's timeline.
April's dollar losses were 3.7 times larger than the entire first quarter of 2026, which saw about $165 million stolen across 35 incidents.
Two Dominant Exploits
Two large-scale attacks accounted for nearly 93% of April's total losses:
- Drift Protocol (Solana): On April 1, a social engineering attack linked to the North Korean Lazarus Group siphoned approximately $285 million.
- KelpDAO: Around April 18, an exploit exploiting a Layerzero bridge message forgery vulnerability resulted in losses of roughly $293 million.
The remaining 26+ incidents were mostly under $5 million, with many under $1 million. Targets included lending pools, vaults, staking contracts, oracle configurations, and cross-chain bridges.
Notable Smaller Incidents
Other significant events in April included Rhea Finance ($18.4M), Grinex ($15M), Volo Vault ($3.5M), Hyperbridge ($2.5M), Sweat Foundation ($3.5M), and Wasabi Protocol (~$5M on April 30). Dozens of additional exploits ranged from $50,000 to $1.5 million.
Following the KelpDAO hack, reports indicated that over $14 billion in total value locked (TVL) exited DeFi protocols within days, concentrated in bridge and lending platforms.
Shift in Attack Vectors and Industry Response
Security researchers note that April's incidents show a clear shift from smart contract bugs to social engineering and access control failures. Private key compromises and operational security lapses remain the dominant attack vectors across all categories. Certik analyst Wenzhao Dong broke down the KelpDAO exploit in detail, illustrating how bridge vulnerabilities can cascade into broader DeFi markets.
The community has called for multi-signature key management, AI-assisted monitoring, protocol security sprints, and user-level insurance products. Analysts warn that bull market TVL growth attracts sophisticated attackers, urging protocols to prioritize defense over feature development heading into Q2 2026.
Defillama's cumulative data now shows total crypto hacking losses exceeding $16.5 billion, with DeFi-specific losses near $7.7 billion and bridge exploits accounting for approximately $2.9 billion.
Investigations into several April incidents remain ongoing. Defillama continues to track all confirmed exploits in real time, with figures subject to revision as recovery efforts progress and attribution is finalized.

