CertiK says Web3 lost $1.3 billion in 344 H1 2026 incidents

April was the costliest month, with the Drift Protocol and KelpDAO attacks causing about $577 million; CertiK and TRM Labs both flagged DPRK-linked Lazarus Group activity as a major driver.

RSETH

Summary

Web3 security incidents caused $1.3 billion in losses across 344 cases in the first half of 2026, with adjusted net losses of about $1.2 billion after frozen and recovered funds, according to CertiK’s Hack3D: H1 2026 Report. CertiK said April was the costliest month at roughly $651 million across 61 incidents, driven largely by the April 1 Drift Protocol exploit and the April 18 KelpDAO attack, which together accounted for about $576 million to $577 million in losses. TRM Labs separately said those two incidents were linked to separate Lazarus Group subgroups and that North Korean operations accounted for 66% of all crypto losses in H1 2026 and 76% of hack value recorded through April. CertiK said wallet compromise was the most damaging attack type by value, phishing ranked second, and code vulnerability led by incident count.

Terms & Concepts
  • Lazarus Group: North Korea’s state-sponsored hacking operation, which CertiK and TRM Labs associated with major 2026 crypto theft patterns.
  • RPC compromise: Attack targeting remote procedure call infrastructure; CertiK said this was central to the KelpDAO incident.
  • social engineering: Manipulating people to gain access or information; TRM Labs said the Drift Protocol exploit reportedly involved months of it.