Smart Contract Exploits Are Down 89% — So Why Did Hackers Still Steal $450M in Q1?

Smart Contract Exploits Are Down 89% — So Why Did Hackers Still Steal $450M in Q1?

N
News Editor 01
2026-07-23 21:50:16
Q1 2026 saw $450M stolen in 145 crypto incidents despite a 89% drop in smart contract exploits. Social engineering accounted for two-thirds of losses, including a 6-month DPRK operation against Drift Protocol.
smart contract securityhacksocial engineeringDrift ProtocolDeFi security

Crypto lost $450 million to hackers in Q1 2026 across 145 incidents. The headline number is alarming, but the real story lies beneath the surface—security threats have migrated from code to people.

According to DefiLlama, smart contract exploit losses fell 89% year-over-year in Q1. Audits are working; protocol architecture is improving. Yet hackers still walked away with $450 million by shifting their targets from code to the people who write it.

Hacken's quarterly security report shows that phishing and social engineering accounted for $306 million of Q1 losses—nearly two-thirds of the total. A single social engineering attack in January drained $282 million without touching a line of code: a fake support call and a user handing over credentials. Six audited protocols were breached in the same quarter; one had passed 18 prior audits before being compromised.

The Drift Hack: Six Months of Human Manipulation

The largest DeFi exploit of the year illustrates the shift perfectly. On April 1, Drift Protocol lost $285 million. TRM Labs confirmed the attackers were DPRK-linked operatives (UNC4736) who spent six months systematically targeting contributors. One contributor was compromised via a malicious code repository; another downloaded a weaponized wallet app through Apple's TestFlight. No code vulnerability—just six months of human targeting.

Twelve Protocols, Every Attack Vector in Two Weeks

In the two weeks following the Drift exploit, twelve protocols fell across all attack vectors. CoW Swap was taken down by a DNS hijack. Hyperbridge lost nearly $237,000 after forged cross-chain state proofs allowed attackers to mint approximately one billion DOT tokens. Zerion lost $100,000 to another DPRK social engineering operation. Silo V2 fell to oracle manipulation. Dango lost $410,000 through a logic flaw in its insurance fund contract. KuCoin's deposit infrastructure was used to launder $9.5 million. Kraken was extorted—systems held, funds never at risk, but the attempt was real.

The diversity matters: this is not a single technique proliferating, but every technique running in parallel.

First AI-Authored Contract Exploit, DPRK Fake VC Scams

Sherlock's Q1 2026 report documented the first known exploit of an AI-authored smart contract. Hacken confirmed DPRK operatives extracted over $40 million through fake venture capital outreach alone. The industry spent years asking whether protocols had been audited. The question now is whether every person with access to those protocols has been targeted—and whether anyone would know if they had.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.