DeFiLlama reported 83 security breaches across the crypto sector in Q2 2026, with roughly $775 million stolen. The incident count set a quarterly record, though the dollar value stayed below the historical peak of $3.56 billion recorded in Q4 2020. Market intelligence provider Unfolded said the quarter was shaped less by a few outsized hacks and more by a steady stream of smaller incidents that kept pressure on the sector throughout the period.
Two hacks dominated the quarter’s losses
Most of the damage came from two attacks. KelpDAO lost $293 million and Drift Protocol lost $280 million, together accounting for more than three-quarters of all funds stolen during the quarter. Both incidents took place in April. CertiK said the month produced record damage for the industry, with $651 million stolen across 28 to 30 separate attacks.
By attack type, cross-chain bridge exploits caused about $351 million in losses, making bridges the costliest category in Q2. The LayerZero OFT bridge exploit tied to the KelpDAO case alone represented more than 38% of the quarter’s losses. Compromised admin credentials and fake token price manipulation made up about 37% of the damage, while private key theft accounted for around 5.7%.
Attack frequency stayed high across all three months
CertiK’s monthly data showed 58 incidents in April, 60 in May, and 25 in June so far. June was still ongoing when the data was compiled, yet the attacks had not slowed. May posted the highest number of cases, but total losses for that month were only $68.3 million, pointing to a pattern of more frequent attacks with smaller individual financial impact.
June still included several notable cases. On June 8, Humanity Protocol lost $32 million after a private key compromise. Aztec Connect’s deprecated smart contracts were hit twice in one week, with $2.19 million stolen on June 14 and another $2 million on June 17. Taiko said on June 22 that its bridge validation mechanism had been exploited for $1.7 million. On June 10, decentralized exchange Raydium lost $1.34 million in a counterfeit LP mint attack.
Deprecated contracts are drawing fresh attacks
One of the clearer shifts this quarter was the return of abandoned contracts as viable targets. Aztec Labs said administrative privileges on the affected products had already been renounced on-chain after those products were retired in 2022 and 2023, leaving no emergency patch option. The code was no longer active in development, but any assets and unresolved weaknesses remained exposed.
A similar case appeared at Thetanuts Finance. On June 15, an old vault linked to the project was drained for $2.1 million. Security researcher Blockful.eth said several attacks have focused on dormant contracts still holding stagnant funds. CertiK data showed that cumulative crypto losses from January through the end of May 2026 had already reached about $1.3 billion, with June incidents adding to that total.

