Reference · updated as incidents are verified
Crypto Exploit Tracker 2026
A maintained record of the crypto exploits that actually moved money in 2026, with the cause of each one and how much came back.
The year so far
- 212 verified exploits and more than $1.1 billion lost in the first half of 2026.
- Past $1.2 billion across 276 incidents by the end of July.
- About $643 million, roughly 66 percent of first-half losses, attributed to North Korea linked groups.
- April was the worst month for value at about $631 million, close to 68 percent of the first half.
- August set a record for frequency, not size: 50 incidents, $136.3 million lost, down 49.5 percent from July's roughly $270 million.
Last updated 10 September 2026. Covers incidents from 1 January 2026. Figures are the loss reported at the time and are revised when better accounting appears.
What actually causes the losses
The most common cause is not the most expensive one
Smart contract vulnerabilities were the most common attack vector by count. They are also the risk that audits are built to find, and the losses tend to be smaller. The money went somewhere else. Roughly 76 percent of the value lost came from infrastructure and operational compromise: stolen keys, breached cloud accounts, a multisignature backup sitting on one laptop, an engineer talked into approving something.
That gap matters when you are judging a protocol. An audit report tells you about the contract. It tells you almost nothing about who can sign what, where those keys live, and how many people have to be wrong at once for the money to leave. Our guide to decentralised finance covers how to read those controls, and multi-party computation wallets explains one common way teams split them.
2026 incidents
Every major exploit, newest first
| Date | Target | Chain | Loss | Root cause | Outcome |
|---|---|---|---|---|---|
| 6 Sep | Liquid Network | Bitcoin sidechain | ~4,000 BTC (~$320M) | A range-proof verification caching bug in Elements let attackers create unbacked L-BTC, then redeem it through an authorised peg-out path. No keys were compromised. | 3,400 BTC returned on 7 September. About 598.5 BTC outstanding. Network paused. |
| 30 Aug | Tectonic | Cronos | ~$74M | The thinly traded TONIC governance token was pumped roughly 100-fold in about 20 minutes, then posted as inflated collateral to borrow real assets. | Validators halted the chain and rolled back state. About $6M reached Ethereum. |
| 12 Aug | Harmony | Harmony | >3 trillion ONE minted | A flaw in cross-shard receipt verification allowed valid receipts to be processed more than once, minting unauthorised tokens. | Chain rolled back to an 11 August checkpoint on 17 August, discarding 109,126 regular and 315 staking transactions. |
| 30 Jul | Coldcard (Coinkite) | Bitcoin | 1,816 BTC (~$116M) | A build configuration error in firmware 4.0.1, shipped in March 2021, used a weak software random number generator for seed generation, cutting effective entropy from 128 bits to as little as 40. | No recovery. More than 5,200 addresses affected across four waves to 4 August. |
| 9 Jun | Humanity Protocol | Ethereum, BNB Chain | ~$32M | Multisignature keys had been backed up to a single laptop, which was compromised. | None reported. |
| 18 May | Verus to Ethereum bridge | Ethereum | ~$11.6M | The bridge verified the state root but never validated transfer amounts against it. | None reported. |
| 15 May | THORChain | Multi-chain | ~$10.8M | A rogue validator exploited a weakness in the GG20 threshold-signature scheme. | Automatic solvency checks halted the drain. Protocol funds only. |
| 18 Apr | Kelp DAO | Cross-chain (LayerZero) | ~$292M | Two internal LayerZero RPC nodes were compromised and backup nodes hit with denial-of-service attacks, allowing a forged cross-chain message. | Partial. The protocol paused and blocked further attempts. |
| 16 Apr | Rhea Finance | NEAR | ~$18.4M | An oracle exploit combined with a margin logic flaw in swap output validation. | About $3.29M in USDT frozen by Tether. Roughly $9M frozen or recovered in total. |
| 1 Apr | Drift Protocol | Solana | ~$285M | Social engineering plus abuse of Solana durable nonces, which let pre-signed administrative transactions be replayed later. | None reported. |
| 22 Mar | Resolv Labs | Ethereum | ~$25M | An AWS Key Management Service breach enabled unauthorised minting. | Proceeds cashed out within 17 minutes. |
| 15 Mar | Venus Protocol | BNB Chain | ~$3.7M | A supply cap bypass on the THENA market via flash borrowing and price manipulation. | Market suspended. |
| 22 Feb | YieldBlox | Stellar | ~$10.2M | Market manipulation. The USTRY price was inflated through a single sell order. | About $7.2M frozen by Stellar validators. |
| 31 Jan | Step Finance | Solana | ~$40M | Private keys compromised on executive devices. | None. The project wound down. |
| 25 Jan | SwapNet | Ethereum | ~$13.4M | Arbitrary external calls drained tokens that users had already approved to the contract. | No funds recovered. |
| 21 Jan | SagaEVM | Ethereum bridge | ~$7M | A minting exploit used a helper contract and custom messages to bypass validation. | A portion routed through Tornado Cash. |
| 20 Jan | Makina | Ethereum | ~$4.2M | A Curve pool was targeted, with an MEV builder used to control transaction ordering. | None reported. |
| 8 Jan | Truebit | Ethereum | ~$26.6M | An integer overflow set the purchase price of TRU tokens to near zero. | Routed through Tornado Cash. |
Recovery
Recovery is rare, and the exceptions are revealing
Most of these losses were permanent. Funds reached a mixer within minutes and the trail stopped. But four of the recoveries in this table did not come from law enforcement or from clever tracing. They came from someone with the power to intervene deciding to use it.
Cronos validators halted a live chain and rolled back its state. Harmony rewrote seventeen blocks' worth of history, discarding more than 109,000 unrelated transactions in the process. Tether froze USDT at the issuer. Stellar validators froze roughly $7.2 million. Each of those is a genuine recovery, and each is also evidence that the system had a control point that could be used against a holder rather than for one.
That is the uncomfortable trade every reader should sit with. The property that saves you when the attacker is someone else is the same property that exposes you when the intervention is aimed your way. We worked through this in The Quiet Ledger on finality after a chain rollback.
How to use this
The questions worth asking before you deposit
- Who can move the money? Name the signers, the threshold, and where the keys are held. If nobody can answer, that is the answer.
- What is the price of my collateral, and who says so? Tectonic, YieldBlox and Venus were all price manipulation on a thin market, not contract bugs.
- What does the bridge actually verify? The Verus bridge checked a state root but never the amounts inside it. Kelp DAO's attacker forged a message by taking out the nodes that would have disputed it.
- Does the vendor's supply chain reach my keys? Coldcard's loss came from firmware shipped five years before anyone noticed. Read our cold storage guide for what you can verify yourself.
- Is there an intervention point? If yes, decide whether you want it. Do not discover it during an incident.
Method and limits
Rows are added when an incident has a named target, a loss figure, and a cause stated by the affected project or a security firm rather than inferred from chain activity alone. Aggregate totals come from published first-half reviews and PeckShield's monthly counts; different trackers set different thresholds for what counts as an incident, so totals from different sources will not reconcile exactly, and we do not blend them into a single number.
Dollar amounts are the value at the time of the incident, which is why token-denominated losses such as Liquid's are given in both. Where a chain rolled back or an issuer froze funds, the outcome column reflects what was actually restored, not what was announced. If you have documentation that corrects a row, tell us and we will amend it with a note.
New incidents are covered as they happen in The Daily Ledger, and the structural questions behind them are taught in Academy School.
Sources
- Crypto Briefing: 212 exploits and $1.1 billion stolen in the first half of 2026
- FinanceFeeds: the 15 biggest crypto exploits of the first half of 2026
- TRM Labs: inside the $116 million Coldcard hack
- PeckShield via CryptoRank: August 2026 set a record for incident count
- Crypto.news: August 2026 losses of $136.3 million
- Blockstream: Liquid security incident status page
- CoinOtag: the Tectonic exploit and Cronos rollback
- Blockonomi: Harmony's August exploit and rollback
Disclaimer: This page is for education and information only. It is not financial, investment, legal, tax, or security advice. Incident details reflect public reporting at the time of writing and may be revised.
Reader reviews
Did you like what you just read?
Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.
Leave a review →