April was the costliest month, with the Drift Protocol and KelpDAO attacks causing about $577 million; CertiK and TRM Labs both flagged DPRK-linked Lazarus Group activity as a major driver.
Web3 security incidents caused $1.3 billion in losses across 344 cases in the first half of 2026, with adjusted net losses of about $1.2 billion after frozen and recovered funds, according to CertiK’s Hack3D: H1 2026 Report. CertiK said April was the costliest month at roughly $651 million across 61 incidents, driven largely by the April 1 Drift Protocol exploit and the April 18 KelpDAO attack, which together accounted for about $576 million to $577 million in losses. TRM Labs separately said those two incidents were linked to separate Lazarus Group subgroups and that North Korean operations accounted for 66% of all crypto losses in H1 2026 and 76% of hack value recorded through April. CertiK said wallet compromise was the most damaging attack type by value, phishing ranked second, and code vulnerability led by incident count.