April 2026 was the worst month on record for crypto theft. Data cited from DeFiLlama shows that at least 13 DeFi protocols were attacked within 30 days, with combined losses exceeding $630 million. Two incidents alone, Drift Protocol and KelpDAO, accounted for $578 million, or 92% of the monthly total. On-chain investigations by TRM Labs and Chainalysis linked both cases to North Korea's Lazarus Group.
Two major exploits dominated the month
On April 1, Solana-based Drift Protocol suffered a $285 million exploit. The attacker stole an admin key, forged CVT tokens as collateral, and drained more than half of the protocol's TVL in 12 minutes. The report described it as the largest single hack of 2026 so far.
On April 18, KelpDAO was hit for an even larger $293 million loss across Ethereum and LayerZero. The attacker compromised an RPC node and used a 1-of-1 validator setup to inject false messages, stealing 116,500 rsETH, equal to 18% of circulating supply. The source also said the incident wiped $10 billion from AAVE's TVL in a single day.
Thirteen incidents in one month
Beyond those two outsized cases, April saw a steady stream of smaller but still serious attacks. Hyperbridge lost $2.5 million on April 12 after a cross-chain bridge contract flaw was exploited. On April 16, Rhea Finance saw $18.4 million withdrawn without authorization, while Grinex lost $15 million the same day. On April 21, Sui-based protocol Volo was drained for $3.5 million. Purrlend, a lending protocol, lost $1.52 million on April 25.
Other affected projects included ThetanutsFi, JuiceboxETH, Scallop.io, ZetaChain, and AftermathFi, with losses ranging from $50,000 to $1.14 million. The pace was relentless. On average, one attack landed in less than three days.
Wasabi exploit closed the month
On April 30, Wasabi Protocol lost more than $5 million. After an admin key was compromised, the attacker granted themselves management privileges and replaced contracts with malicious versions, draining funds across ETH, Base, Blast, and Berachain. Wasabi had deployed an access-control framework with timelock support, but the delay was set to zero, leaving the protection ineffective.
The report said the two Lazarus-linked attacks triggered roughly $13 billion in DeFi capital outflows. Ledger CTO Charles Guillemet warned that single-signature architecture in DeFi has created a systemic risk, and that 2026 could become the most severe year yet for hacking activity.

