TRM Labs counted 207 crypto attack incidents in the first half of 2026, the highest total ever recorded for a six-month period. In the first half of 2025, the firm had identified only 83 cases. Even with that sharp rise in incident count, the value stolen moved the other way: total losses came to about $972 million, down from $2.3 billion a year earlier.
The increase was not driven by one outsized exploit. TRM Labs said the jump came from a steady build-up of smaller and more scattered breaches through the year, with 123 incidents logged in the second quarter alone. The median loss for the 2026 period was $219,000, which points to a heavier concentration of lower-value attacks.
Smart contract exploits led by count
Smart contract vulnerabilities remained the most common attack category. Out of 207 incidents, 125 fell into that group, largely affecting DeFi applications, decentralized exchanges, and token projects. TRM Labs also said attackers are increasingly combining several code-level interventions within a single exploit instead of relying on one technique.
These attacks typically stem from logic flaws or weak authorization controls in blockchain-based code. They happened often, but they did not account for the largest share of stolen funds.
North Korea-linked activity made up nearly 66% of losses
TRM Labs traced roughly $643 million of the stolen funds to activity linked to North Korea. That represented nearly 66% of total losses during the period. Most of the damage came from two major April incidents.
Those attacks targeted Drift Protocol and KelpDAO. According to the report, the Drift Protocol breach caused about $285 million in losses, while the KelpDAO incident led to about $292 million being siphoned away. Together, the two cases accounted for $577 million.
Infrastructure breaches caused most of the financial damage
Incidents tied to infrastructure or operational failures made up only 15% of all recorded attacks, yet they were responsible for about 76% of total losses. TRM Labs said these breaches were aimed less at on-chain code and more at signature systems, access credentials, and the infrastructure used to control assets.
That split helps explain why incident numbers climbed while overall losses fell. Smaller smart contract exploits became more common, but the largest losses still came from a limited number of infrastructure failures. The report also referenced a “wrench attack,” involving physical coercion, which resulted in about $24 million in losses.
TRM Labs said organizations should continue auditing smart contracts while also tightening key management and transaction approval procedures. The report’s core pattern is clear: minor vulnerabilities are surfacing more often, but major infrastructure breaches still shape the total loss figures.

