
Photo: Illustrative
Crypto Losses Drop 47% in First Half of 2026, But Security Risks Grow, CertiK Says
Crypto related losses fell 46.8% year on year to $1.32 billion in the first half of 2026, according to security firm CertiK, but the firm cautions that the decline does not reflect a safer industry. CertiK said the drop is largely explained by the absence of a repeat of last year's record-breaking $1.4 billion Bybit hack, the largest crypto exploit on record, rather than any real improvement in security.
.jpeg)
Crypto related losses fell 46.8% year on year to $1.32 billion in the first half of 2026, according to security firm CertiK, but the firm cautions that the decline does not reflect a safer industry. CertiK said the drop is largely explained by the absence of a repeat of last year’s record-breaking $1.4 billion Bybit hack, the largest crypto exploit on record, rather than any real improvement in security.
Attack Methods Shifted Between Quarters
Phishing attacks drove most losses in the first quarter, totaling $508.2 million. By the second quarter, wallet compromises took over as the leading attack method, contributing to $807.5 million in losses, a 59% increase from the previous quarter. More than 70% of that total came from two incidents, the KelpDAO and Drift Protocol exploits, both attributed to North Korean state-sponsored hackers.

North Korea Remains a Persistent Threat
North Korean hacking groups have stolen more than $6 billion in crypto since 2017, according to blockchain analytics firm TRM Labs. The KelpDAO and Drift Protocol attacks prompted a joint meeting between U.S., Japanese and South Korean officials last month to discuss ways to counter North Korea’s cyber operations and illicit revenue generation. Officials also noted that North Korean IT workers are increasingly relying on artificial intelligence to improve their tactics, a trend some cybersecurity experts believe has boosted the scale and speed of recent exploits.
Incident Count Hits Record High
TRM Labs reached a similar conclusion in its own first-half report, noting that a lower dollar total should not be mistaken for reduced attacker capability. The firm recorded 207 separate incidents in the first half of the year, more than double the 83 recorded during the same period last year and the highest six-month total TRM has tracked. Smart contract exploits made up 125 of those incidents, or about 60% of the total.

Private Key Security Remains the Weak Point
CertiK identified private key and multisignature wallet management as the most significant vulnerability attackers continue to target. The firm recommended that protocols and institutions holding substantial onchain assets strengthen every layer of key management, including hardware security, multisignature governance and geographically distributing signers, calling it an area where security spending delivers outsized protection.
Live market reaction
Disclaimer
This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.
Start trading
with BloFin today
Up to $500 sign-up bonus and zero-fee trading on your first 30 days.
Buy crypto nowⓘ You will be redirected to BloFin
About the author
.jpeg)
Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.


