DeFiLlama Says Crypto Saw 83 Security Breaches and $775 Million Stolen in Q2 2026

DeFiLlama Says Crypto Saw 83 Security Breaches and $775 Million Stolen in Q2 2026

N
News Editor 01
2026-07-22 17:50:14
DeFiLlama reported 83 crypto security incidents in Q2 2026, with total losses reaching about $775 million. KelpDAO and Drift Protocol accounted for most of the damage, while cross-chain bridges remained the costliest attack vector.
DeFiLlamasecurity breachescross-chain bridgescrypto hackson-chain security

DeFiLlama reported 83 security breaches across the crypto sector in Q2 2026, with roughly $775 million stolen. The incident count set a quarterly record, though the dollar value stayed below the historical peak of $3.56 billion recorded in Q4 2020. Market intelligence provider Unfolded said the quarter was shaped less by a few outsized hacks and more by a steady stream of smaller incidents that kept pressure on the sector throughout the period.

Two hacks dominated the quarter’s losses

Most of the damage came from two attacks. KelpDAO lost $293 million and Drift Protocol lost $280 million, together accounting for more than three-quarters of all funds stolen during the quarter. Both incidents took place in April. CertiK said the month produced record damage for the industry, with $651 million stolen across 28 to 30 separate attacks.

By attack type, cross-chain bridge exploits caused about $351 million in losses, making bridges the costliest category in Q2. The LayerZero OFT bridge exploit tied to the KelpDAO case alone represented more than 38% of the quarter’s losses. Compromised admin credentials and fake token price manipulation made up about 37% of the damage, while private key theft accounted for around 5.7%.

Attack frequency stayed high across all three months

CertiK’s monthly data showed 58 incidents in April, 60 in May, and 25 in June so far. June was still ongoing when the data was compiled, yet the attacks had not slowed. May posted the highest number of cases, but total losses for that month were only $68.3 million, pointing to a pattern of more frequent attacks with smaller individual financial impact.

June still included several notable cases. On June 8, Humanity Protocol lost $32 million after a private key compromise. Aztec Connect’s deprecated smart contracts were hit twice in one week, with $2.19 million stolen on June 14 and another $2 million on June 17. Taiko said on June 22 that its bridge validation mechanism had been exploited for $1.7 million. On June 10, decentralized exchange Raydium lost $1.34 million in a counterfeit LP mint attack.

Deprecated contracts are drawing fresh attacks

One of the clearer shifts this quarter was the return of abandoned contracts as viable targets. Aztec Labs said administrative privileges on the affected products had already been renounced on-chain after those products were retired in 2022 and 2023, leaving no emergency patch option. The code was no longer active in development, but any assets and unresolved weaknesses remained exposed.

A similar case appeared at Thetanuts Finance. On June 15, an old vault linked to the project was drained for $2.1 million. Security researcher Blockful.eth said several attacks have focused on dormant contracts still holding stagnant funds. CertiK data showed that cumulative crypto losses from January through the end of May 2026 had already reached about $1.3 billion, with June incidents adding to that total.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.