April 2026 has closed as the most hacked month in crypto history by number of incidents, according to data tracked by DefiLlama. The platform said the industry recorded 28 to 30 separate exploits during the month, with total losses exceeding $625 million. While previous monthly peaks generally stayed in the 12 to 15 incident range, April’s final tally pushed attack frequency to nearly one exploit per day, underlining how broad and persistent the threat environment has become across digital asset markets.
Two major exploits drove most of the losses
The month was not defined by a single catastrophic event alone, but by two outsized attacks that absorbed nearly all of the dollar damage. On April 1, Drift Protocol on Solana lost about $285 million in what was described as a social engineering attack linked to North Korea’s Lazarus Group. Later in the month, around April 18, KelpDAO suffered an estimated $293 million loss tied to a LayerZero bridge message forgery exploit. Combined, the two incidents accounted for roughly 93% of April’s total losses.
That concentration in dollar terms, however, should not obscure the broader pattern. More than 26 additional incidents were recorded during the month, and most of them were below $5 million, with many under $1 million. The spread of these smaller exploits points to an ecosystem-wide attack surface affecting lending pools, vaults, staking contracts, oracle configurations, and cross-chain bridges. In other words, even though the month’s headline losses were dominated by two large breaches, the underlying issue was one of widespread vulnerability.
April’s pace sharply exceeded earlier 2026 losses
DefiLlama’s figures suggest that April alone was dramatically worse than the start of the year. By the end of the month, the crypto industry had logged roughly 68 incidents and more than $1 billion in stolen funds since the beginning of 2026. Excluding the singular impact of the Bybit breach in February 2025, which totaled about $1.4 billion, the current year is already running ahead of 2025 in both pace and intensity.
One of the most striking comparisons is against the first quarter of 2026. During Q1, the sector lost about $165 million across 35 incidents. April by itself was therefore about 3.7 times larger than the entire first quarter in dollar losses. That jump has raised fresh questions about whether rising total value locked during bullish market conditions is attracting more sophisticated attackers, especially at moments when teams may be focused on growth and product expansion rather than hardening infrastructure.
Smaller attacks still reveal systemic pressure points
Beyond Drift and KelpDAO, a series of smaller but still meaningful incidents added to the month’s record count. Reported cases included Rhea Finance with losses of $18.4 million, Grinex at $15 million, Volo Vault at $3.5 million, Hyperbridge at $2.5 million, Sweat Foundation at $3.5 million, and Wasabi Protocol at roughly $5 million on April 30. Dozens of additional exploits reportedly ranged from $50,000 to $1.5 million.
Individually, many of these incidents may appear manageable compared with the month’s largest breaches. Collectively, however, they suggest that crypto security risks are not isolated to one chain, one exploit class, or one type of protocol. Instead, the data points to a broad deterioration in operational resilience across DeFi and adjacent infrastructure.
Bridges and operational security are under renewed scrutiny
The aftermath of the KelpDAO exploit appears to have intensified concerns around cross-chain risk. Reports cited in the source material indicate that more than $14 billion in TVL left DeFi protocols within days of that attack, with withdrawals concentrated in bridge-related systems and lending platforms. That reaction shows how rapidly trust can evaporate when key infrastructure is compromised, and how exploit fallout can spread well beyond the directly affected protocol.
Security researchers increasingly argue that the dominant attack vectors are evolving. Rather than being driven only by the smart contract bugs that defined many earlier DeFi exploits, recent incidents are highlighting the role of social engineering, private key compromise, access control failures, and weaknesses in cross-chain messaging systems. These forms of attack often blend technical and human vulnerabilities, making them harder to prevent through code audits alone.
Industry response centers on defense, monitoring, and controls
In response, community discussion has shifted toward more structural security measures. Among the ideas gaining attention are multisig key management, AI-assisted monitoring, dedicated protocol security sprints, and user-level insurance products. While these proposals vary in practicality and maturity, they reflect a broader view that reactive patching is no longer enough in a market where incidents can emerge almost daily.
DefiLlama’s cumulative data now shows that total crypto hack losses have surpassed $16.5 billion, with DeFi-specific losses approaching $7.7 billion. Bridge exploits account for around $2.9 billion of that sum, reinforcing why cross-chain infrastructure remains one of the most sensitive parts of the ecosystem. Across categories, private key compromises and operational security failures continue to rank among the most common attack vectors.
Investigations remain open as Q2 risk builds
Several of April’s incidents are still under investigation, and DefiLlama continues to update its exploit tracker in real time, meaning some figures could still be revised as attribution is finalized and recovery efforts progress. Even so, the broad message is already clear: April 2026 marked a turning point in the scale and frequency of crypto security failures.
For market participants, the month’s record is a reminder that rising TVL and renewed market optimism can cut both ways. More capital in DeFi can support growth, but it also increases the incentive for increasingly sophisticated attackers. As the second quarter unfolds, protocols may face growing pressure to prioritize defense, tighten access controls, and reassess cross-chain dependencies before another record month arrives.

