PeckShield said on its official X account that 16 crypto hacking incidents were recorded in January 2026, with combined losses of $86 million. The figure was down 1.42% from the $87.25 million reported in January 2025, but it increased from December 2025, when losses stood at $75.95 million. At the same time, phishing losses passed $300 million, far exceeding the damage tied to reported exploit cases and showing that user-targeted fraud remains a major source of losses.
The five largest cases listed for January
PeckShield’s breakdown put Step Finance at $28.9 million, Truebit Protocol at $26.4 million, SwapNet at $13.3 million, Saga at $7 million, and Makina Finance at $4.13 million. In Makina Finance’s case, $2.7 million was recovered. The incidents were spread across different parts of the crypto stack, from analytics-related tools to protocol infrastructure, which suggests attackers are not concentrating on one narrow segment.
Security losses are landing in a weak market
The source material describes a market already under pressure from falling token prices, lower trading activity, and fragile sentiment. Fresh exploit disclosures add another layer of stress. In a down cycle, loss reports do not stay isolated inside security circles; they feed into broader risk pricing and can weigh on recovery expectations already struggling to take hold.
Why attacks keep showing up
The report points to phishing, social engineering, compromised private keys, and rushed integrations as recurring causes. It also notes that smart-contract systems are becoming more complex faster than audits and testing can keep up. A separate concern is behavioral risk: attackers are increasingly going after users through fake links, wallet approvals, and misleading interfaces rather than relying only on code-level weaknesses.
Security is being framed as an ongoing infrastructure issue
According to the source, exchange operators and blockchain founders have repeatedly argued that decentralization does not remove responsibility. Risk shifts instead to users, developers, and validators. The responses most often cited include stronger wallet warnings, transaction simulation tools, continued audits, and slower rollouts backed by tighter testing. Repeated losses during a weak market can delay capital returning and make it harder for new users to enter.

