In the second quarter of 2026, the crypto industry faced a record number of hacks. According to DeFiLlama, as of June 22, about 83 incidents had been recorded. This is almost twice the previous quarterly high for number of attacks.
However, in terms of total losses, this period has not yet become the worst in history. During the quarter, hackers withdrew about $775 million. The amount is large, but still far from previous anti-records.
As Unfolded described the situation quite simply: the market suffered not from a couple of giant hacks, but from a constant series of smaller attacks. It was these that created the sense of almost continuous pressure on the industry.
The record for stolen funds is still held by the fourth quarter of 2020. At that time, crypto projects lost about $3.56 billion.
Which Hacks Caused the Most Damage in the Second Quarter
The largest incidents of the quarter were the KelpDAO hack for $293 million and the attack on Drift Protocol for $280 million. Together, they accounted for more than three-quarters of all stolen funds in Q2.
See also: Dash Explores the Philippines for Crypto Payments Launch
Both attacks occurred in April. According to CertiK, this month set a record for the industry: total losses amounted to about $651 million, and the number of individual attacks reached about 28–30.
The greatest damage was caused by cross-chain bridge vulnerabilities. Such exploits resulted in about $351 million in losses for the quarter.
The LayerZero OFT bridge vulnerability, associated with the KelpDAO incident, alone accounted for more than 38% of all stolen funds in Q2.
Another 37% of losses were due to compromised admin rights and price manipulation of fake tokens.
Theft of private keys accounted for about 5.7% of total damage.
How Often Crypto Project Attacks Occurred by Month
Statistics from CertiK show that malicious activity remained high throughout the second quarter. In April, 58 incidents were recorded, in May — 60, and as of now in June DeFiLlama counted another 25 attacks. With more than a week left in the month, the final figure could be significantly higher.
Interestingly, a large number of hacks did not always mean record losses. For example, in May, the damage from 60 incidents amounted to about $68.3 million. This confirms the trend where the market faces a large number of relatively small attacks.
Several notable incidents also occurred in June. One of the largest was the Humanity Protocol hack, which lost about $32 million after a private key was compromised on June 8.
In addition, abandoned Aztec Connect smart contracts were attacked twice in one week. The first attack on June 14 led to losses of about $2.19 million, and on June 17, attackers withdrew another $2 million.
See also: Secret Bridge Bug Led to $4.7 Million Loss
Another affected project was Taiko. On June 22, the team confirmed the exploitation of a vulnerability in its bridge verification mechanism. According to PeckShield, the damage was about $1.7 million. Analysts from Lookonchain also recorded a transfer of 1.99 million TAIKO tokens to the MEXC exchange.
The decentralized exchange Raydium lost about $1.34 million as a result of an attack using a fake LP token, which occurred on June 10.
Outdated Smart Contracts Are Becoming a New Target for Hackers
More and more often, attackers are paying attention to projects that have long ceased development of certain products and no longer support them. It is these forgotten smart contracts that have begun to appear in a number of recent attacks.
A good example was the two Aztec Connect hacks, which occurred just a few days apart. As explained by Aztec Labs, the attacked products had been decommissioned back in 2022 and 2023. At the same time, admin rights for these contracts had been permanently disabled on the blockchain, so developers could no longer make emergency fixes after the problem was discovered.
A similar situation happened with Thetanuts Finance. On June 15, attackers withdrew about $2.1 million from an old vault associated with the project and no longer used in the platform’s main operations.
Security researcher Blockful.eth drew attention to this trend on X. According to him, several attacks on old contracts have occurred recently, in which significant amounts of funds still remained.
See also: STRC Drop Tests Strategy Model for Resilience
Such projects are often seen as low-priority from a security perspective, but the presence of locked liquidity makes them an attractive target for attackers, especially if the code has not been updated or re-audited for a long time.
What This Trend Means for the Rest of 2026
According to CertiK, from January through the end of May, the crypto industry had already lost about $1.3 billion due to hacks. The June attacks continue to increase this amount, and the second quarter is not yet over.
The main change is that attacks have become more frequent, but the average damage per attack is lower. In previous years, a single major bridge or exchange hack could immediately result in losses of billions of dollars. Now the market faces a different scenario: a constant stream of small and medium-sized incidents.
Most often, attackers target admin rights, bridge infrastructure, and old code that has not been supported by teams for a long time. These are no longer rare catastrophic hacks, but a more regular threat for projects of all sizes.
At the same time, the industry has become faster at responding to attacks. One example is the KelpDAO incident in April. Then the Arbitrum Security Council used emergency powers and froze $71 million in funds linked to the attacker.