Crypto security losses did not top $1 billion in H1 2026, but the number of hacks and exploits did hit a new high. That distinction matters, because in crypto, sloppy headlines are almost as annoying as sloppy security.
- Record incident count: 207 hacks and exploits in H1 2026
- Losses reported: $972 million, according to TRM Labs
- Main pressure points: smart contract bugs, key thefts, and infrastructure compromises
- Biggest source of stolen value: North Korea-linked activity
TRM Labs, a blockchain intelligence and compliance firm, says crypto hacks and exploits reached a record 207 separate incidents in the first half of 2026. Q2 alone saw 123 incidents, the highest quarterly count TRM has recorded. The total value stolen came to $972 million though, a brutal number, sure, but still below $1 billion.
So what actually hit the record? The number of attacks, not the dollar losses. That’s a real difference, and it’s worth keeping straight. A period can be packed with smaller breaches and still lose less money than a period with only a few massive thefts.
TRM’s breakdown makes that clear. Smart contract exploits accounted for 125 of the 207 incidents. Smart contracts are pieces of code that run on a blockchain and automatically move funds or execute rules. When they’re poorly designed, weakly audited, or built with bad assumptions, attackers can abuse them fast.
But the biggest losses came from somewhere else: infrastructure and operational compromises. In plain English, that means thefts involving keys, signing systems, custody workflows, or similar control failures. These made up only about 15% of incidents, yet they were responsible for roughly 76% of total losses.
That’s the part the industry keeps relearning the hard way. Many teams obsess over code audits while leaving the door open on the operational side. A protocol can have polished on-chain logic and still get smoked if the people or systems approving transactions are compromised. Security is not one shiny checkbox. It’s a stack, and the stack keeps breaking at the weak link.
The losses were also heavily concentrated. TRM says two April thefts linked to North Korea did much of the damage: the Drift breach at about $285 million and the KelpDAO theft at about $292 million. Combined, that’s roughly $577 million from just two incidents.
TRM attributes about $643 million, or 66% of all funds stolen in H1 2026, to North Korea-linked activity. That’s not random opportunism. It’s a persistent, organized threat that keeps targeting high-value crypto infrastructure because that’s where the money is. And unlike retail phishing crews, state-linked operators tend to be patient, disciplined, and annoyingly effective.
TRM’s data also shows why incident count and loss amount can tell very different stories. If a half-year includes many smaller smart contract exploits, the hack count can spike even while total losses stay lower than in a year dominated by one or two monster thefts. That appears to be the pattern here: more attacks overall, but not another H1 2025-style blowout. TRM says losses in H1 2025 reached $2.3 billion.
That wider context matters. Crypto security is still a mess, but the threat picture is not just “bad code on chain.” It includes:
- Key management, who controls private keys and how
- Signing infrastructure, how transactions get approved
- Custody controls, where assets are stored and how they move
- Incident response, how fast teams can react when something breaks
- Multisig design and segmentation, how many approvals are needed, and whether one compromised device can wreck everything
TRM also notes that stolen funds are often moved through cross-chain bridges, tools that transfer assets between blockchains, and no-KYC swap services, which let users exchange assets without identity checks. From there, attackers often try to route funds through centralized exchanges. The hack is only half the job. Laundering the loot is the other half.
The takeaway for builders is pretty blunt: if your security model stops at audits, you do not have a security model. The takeaway for users is just as blunt: if a platform’s operations are sloppy, “decentralized” won’t save you from a bad signature, a stolen key, or a compromised workflow. Blockchains are unforgiving in that way. There is no polite undo button.
Key takeaways
-
Did crypto breaches surpass $1 billion in H1 2026?
According to TRM Labs, no. Reported losses came to $972 million, which is below $1 billion. -
What hit a record high?
The number of hacks and exploits. TRM says H1 2026 saw 207 incidents, the highest six-month total it has recorded. -
What caused most of the losses?
A small number of infrastructure and operational compromises, especially two North Korea-linked thefts in April. For more context, see Crypto security breaches surpass $1B in H1 2026, hit record and H1 2026 Crypto Hacks Reach Record High as Losses Fall Below. -
Why did smart contract exploits matter so much?
They made up the majority of incidents, 125 of 207, but usually caused smaller losses than wallet, key, and signing-system breaches. -
What’s the main security lesson?
Audits are not enough. Good crypto security also depends on key management, custody, transaction approvals, and fast incident response.
Crypto keeps proving two things at once: the attack surface is real, and the weakest defenses still get punished first. The sector can build world-changing financial rails, but it cannot keep pretending that code alone will save it. It won’t. Bad ops, weak keys, and careless trust models are still handing attackers the easiest money in the room.
For deeper reporting, TRM Labs has also detailed Illicit Crypto Activity Trends and Enforcement in 2025, while Chainalysis has its own take in The Chainalysis 2026 Crypto Crime Report. If you want a sharper read on the industry’s biggest blind spots, Crypto hacks hit a record count but the biggest threat isn't smart contracts gets to the point without the usual PR foam.
Recent coverage from Adbytes.Media has also tracked the same pattern from different angles: TRM Labs Says H1 2026 Set Record for Crypto Hacks as Losses, North Korea-Linked Crypto Hacks Stole $643M in H1 2026, and TRM Labs: North Korea-Linked Hackers Behind 76% of Early. TRM’s own data also puts the spotlight on the state-linked threat itself: North Korea Stole 76% of All Crypto Hack Value in 2026.
And if you really want to appreciate how messy the numbers are, the broader estimates don’t always line up neatly either, which is why analysts keep comparing releases like North Korea Stole 76% of All Crypto Hack Value in 2026 with the still-stinging North Korea-Linked Crypto Hacks Stole $643M in H1 2026 figures.