Crypto lost $450 million to hackers in Q1 2026 across 145 incidents. The headline number is alarming, but the real story lies beneath the surface—security threats have migrated from code to people.
According to DefiLlama, smart contract exploit losses fell 89% year-over-year in Q1. Audits are working; protocol architecture is improving. Yet hackers still walked away with $450 million by shifting their targets from code to the people who write it.
Hacken's quarterly security report shows that phishing and social engineering accounted for $306 million of Q1 losses—nearly two-thirds of the total. A single social engineering attack in January drained $282 million without touching a line of code: a fake support call and a user handing over credentials. Six audited protocols were breached in the same quarter; one had passed 18 prior audits before being compromised.
The Drift Hack: Six Months of Human Manipulation
The largest DeFi exploit of the year illustrates the shift perfectly. On April 1, Drift Protocol lost $285 million. TRM Labs confirmed the attackers were DPRK-linked operatives (UNC4736) who spent six months systematically targeting contributors. One contributor was compromised via a malicious code repository; another downloaded a weaponized wallet app through Apple's TestFlight. No code vulnerability—just six months of human targeting.
Twelve Protocols, Every Attack Vector in Two Weeks
In the two weeks following the Drift exploit, twelve protocols fell across all attack vectors. CoW Swap was taken down by a DNS hijack. Hyperbridge lost nearly $237,000 after forged cross-chain state proofs allowed attackers to mint approximately one billion DOT tokens. Zerion lost $100,000 to another DPRK social engineering operation. Silo V2 fell to oracle manipulation. Dango lost $410,000 through a logic flaw in its insurance fund contract. KuCoin's deposit infrastructure was used to launder $9.5 million. Kraken was extorted—systems held, funds never at risk, but the attempt was real.
The diversity matters: this is not a single technique proliferating, but every technique running in parallel.
First AI-Authored Contract Exploit, DPRK Fake VC Scams
Sherlock's Q1 2026 report documented the first known exploit of an AI-authored smart contract. Hacken confirmed DPRK operatives extracted over $40 million through fake venture capital outreach alone. The industry spent years asking whether protocols had been audited. The question now is whether every person with access to those protocols has been targeted—and whether anyone would know if they had.

