BTC…ETH…ETH gas…Fear & Greed…Live data · not advice

Reference · updated as incidents are verified

Crypto Exploit Tracker 2026

A maintained record of the crypto exploits that actually moved money in 2026, with the cause of each one and how much came back.

The year so far

Last updated 10 September 2026. Covers incidents from 1 January 2026. Figures are the loss reported at the time and are revised when better accounting appears.

What actually causes the losses

The most common cause is not the most expensive one

Chart showing that infrastructure and operational compromise accounted for about 76 percent of the value lost to crypto exploits in the first half of 2026, while smart contract vulnerabilities were the most common attack vector by count, and North Korea linked groups accounted for about 643 million dollars
Sources: Crypto Briefing and FinanceFeeds first-half reviews, 2026.

Smart contract vulnerabilities were the most common attack vector by count. They are also the risk that audits are built to find, and the losses tend to be smaller. The money went somewhere else. Roughly 76 percent of the value lost came from infrastructure and operational compromise: stolen keys, breached cloud accounts, a multisignature backup sitting on one laptop, an engineer talked into approving something.

That gap matters when you are judging a protocol. An audit report tells you about the contract. It tells you almost nothing about who can sign what, where those keys live, and how many people have to be wrong at once for the money to leave. Our guide to decentralised finance covers how to read those controls, and multi-party computation wallets explains one common way teams split them.

2026 incidents

Every major exploit, newest first

Major crypto exploits in 2026, newest first. Amounts are the loss reported at the time of the incident.
DateTargetChainLossRoot causeOutcome
6 SepLiquid NetworkBitcoin sidechain~4,000 BTC (~$320M)A range-proof verification caching bug in Elements let attackers create unbacked L-BTC, then redeem it through an authorised peg-out path. No keys were compromised.3,400 BTC returned on 7 September. About 598.5 BTC outstanding. Network paused.
30 AugTectonicCronos~$74MThe thinly traded TONIC governance token was pumped roughly 100-fold in about 20 minutes, then posted as inflated collateral to borrow real assets.Validators halted the chain and rolled back state. About $6M reached Ethereum.
12 AugHarmonyHarmony>3 trillion ONE mintedA flaw in cross-shard receipt verification allowed valid receipts to be processed more than once, minting unauthorised tokens.Chain rolled back to an 11 August checkpoint on 17 August, discarding 109,126 regular and 315 staking transactions.
30 JulColdcard (Coinkite)Bitcoin1,816 BTC (~$116M)A build configuration error in firmware 4.0.1, shipped in March 2021, used a weak software random number generator for seed generation, cutting effective entropy from 128 bits to as little as 40.No recovery. More than 5,200 addresses affected across four waves to 4 August.
9 JunHumanity ProtocolEthereum, BNB Chain~$32MMultisignature keys had been backed up to a single laptop, which was compromised.None reported.
18 MayVerus to Ethereum bridgeEthereum~$11.6MThe bridge verified the state root but never validated transfer amounts against it.None reported.
15 MayTHORChainMulti-chain~$10.8MA rogue validator exploited a weakness in the GG20 threshold-signature scheme.Automatic solvency checks halted the drain. Protocol funds only.
18 AprKelp DAOCross-chain (LayerZero)~$292MTwo internal LayerZero RPC nodes were compromised and backup nodes hit with denial-of-service attacks, allowing a forged cross-chain message.Partial. The protocol paused and blocked further attempts.
16 AprRhea FinanceNEAR~$18.4MAn oracle exploit combined with a margin logic flaw in swap output validation.About $3.29M in USDT frozen by Tether. Roughly $9M frozen or recovered in total.
1 AprDrift ProtocolSolana~$285MSocial engineering plus abuse of Solana durable nonces, which let pre-signed administrative transactions be replayed later.None reported.
22 MarResolv LabsEthereum~$25MAn AWS Key Management Service breach enabled unauthorised minting.Proceeds cashed out within 17 minutes.
15 MarVenus ProtocolBNB Chain~$3.7MA supply cap bypass on the THENA market via flash borrowing and price manipulation.Market suspended.
22 FebYieldBloxStellar~$10.2MMarket manipulation. The USTRY price was inflated through a single sell order.About $7.2M frozen by Stellar validators.
31 JanStep FinanceSolana~$40MPrivate keys compromised on executive devices.None. The project wound down.
25 JanSwapNetEthereum~$13.4MArbitrary external calls drained tokens that users had already approved to the contract.No funds recovered.
21 JanSagaEVMEthereum bridge~$7MA minting exploit used a helper contract and custom messages to bypass validation.A portion routed through Tornado Cash.
20 JanMakinaEthereum~$4.2MA Curve pool was targeted, with an MEV builder used to control transaction ordering.None reported.
8 JanTruebitEthereum~$26.6MAn integer overflow set the purchase price of TRU tokens to near zero.Routed through Tornado Cash.

Recovery

Recovery is rare, and the exceptions are revealing

Most of these losses were permanent. Funds reached a mixer within minutes and the trail stopped. But four of the recoveries in this table did not come from law enforcement or from clever tracing. They came from someone with the power to intervene deciding to use it.

Cronos validators halted a live chain and rolled back its state. Harmony rewrote seventeen blocks' worth of history, discarding more than 109,000 unrelated transactions in the process. Tether froze USDT at the issuer. Stellar validators froze roughly $7.2 million. Each of those is a genuine recovery, and each is also evidence that the system had a control point that could be used against a holder rather than for one.

That is the uncomfortable trade every reader should sit with. The property that saves you when the attacker is someone else is the same property that exposes you when the intervention is aimed your way. We worked through this in The Quiet Ledger on finality after a chain rollback.

How to use this

The questions worth asking before you deposit

Method and limits

Rows are added when an incident has a named target, a loss figure, and a cause stated by the affected project or a security firm rather than inferred from chain activity alone. Aggregate totals come from published first-half reviews and PeckShield's monthly counts; different trackers set different thresholds for what counts as an incident, so totals from different sources will not reconcile exactly, and we do not blend them into a single number.

Dollar amounts are the value at the time of the incident, which is why token-denominated losses such as Liquid's are given in both. Where a chain rolled back or an issuer froze funds, the outcome column reflects what was actually restored, not what was announced. If you have documentation that corrects a row, tell us and we will amend it with a note.

New incidents are covered as they happen in The Daily Ledger, and the structural questions behind them are taught in Academy School.

Sources

Disclaimer: This page is for education and information only. It is not financial, investment, legal, tax, or security advice. Incident details reflect public reporting at the time of writing and may be revised.

Reader reviews

Did you like what you just read?

Tell other readers what worked, what did not, and who you would recommend it to. Every review is read by a human before it is published, and critical reviews get the same treatment as glowing ones.

Leave a review →