Certik: Crypto Hack Losses Down 46.8% in H1 2026, but Attacks Hit Record 207 Incidents

Certik: Crypto Hack Losses Down 46.8% in H1 2026, but Attacks Hit Record 207 Incidents

N
News Editor 01
2026-07-23 07:15:14
CertiK reports H1 2026 crypto hack losses fell 46.8% YoY to $1.32B, but the number of attacks surged to 207 from 83, a new six-month record. Phishing and wallet takeovers dominate, with smart contract flaws accounting for 60% of incidents.
CertiKcrypto hackssecurity reportH1 2026attack trends

CertiK’s latest report reveals that total losses from crypto hacks in the first half of 2026 reached $1.32 billion, a 46.8% year-on-year decline from approximately $2.48 billion in H1 2025. However, the frequency and severity of attacks rose sharply: 207 security incidents were recorded in the period, up from 83 a year earlier, marking a new six-month high. The security firm stressed that the drop in absolute losses is largely due to the massive Bybit hack last year, which inflated the baseline, and cautioned against interpreting the decline as evidence of improved ecosystem security.

Phishing and Wallet Takeovers Lead Attack Vectors

In Q1, phishing attacks caused the largest share of losses at $508.2 million. By Q2, the dominant threat shifted to wallet compromise, accounting for $807.5 million in damages. CertiK noted that the shift in tactics demonstrates attackers continuously adapting to bypass defenses. Private key management and multisignature wallet security remain the most exploited weak points. Hardware wallet manufacturer Ledger continues to emphasize offline seed phrase storage as a core defense against phishing.

North Korea-linked Threats Prompt Multilateral Response

Blockchain intelligence firm TRM Labs estimates that North Korea-linked hacker groups have stolen over $6 billion in digital assets since 2017. Following recent incidents affecting KelpDAO and Drift Protocol, authorities from the United States, Japan, and South Korea convened late last month to discuss strategies to curb North Korea’s malicious cyber activities and illicit revenue generation. TRM Labs warned that the decline in stolen amounts “should not be mistaken for heightened security” given the marked rise in incident count.

Smart Contract Flaws Drive 60% of Incidents

Of the 207 total incidents, smart contract vulnerabilities were responsible for 125, or roughly 60%. Excluding the exceptional Bybit hack — which alone caused $1.4 billion in losses — CertiK argues the sector now faces a structurally higher attack pace, with each breach becoming more targeted and causing heavier financial damage. The Bybit incident remains one of the largest in crypto history, artificially depressing the year-on-year comparison.

Private Key Management Remains Weakest Link

CertiK maintains that protecting private keys and managing multisignature wallets are the most critical security surfaces. It urged protocols and institutions holding significant on-chain assets to reinforce security across hardware protection, multisig governance, and geographically distributed signers. TRM Labs data further confirms that the number of attacks in H1 2026 soared 150% year-on-year, setting a new half-year record.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.