Hacken said accessibility failures drove most losses, while DPRK-linked actors accounted for 75.5% of drained funds and MiCA licensing pressure reshaped the European market.
Crypto hacks drained $763,971,791 across 67 incidents in Q2 2026, up 58.3% from Q1's $482.7 million and marking the highest losses since Q2 2025, according to a report from blockchain security and compliance firm Hacken. Drift Protocol and KelpDAO recorded the largest losses at about $290 million each. The report said smart contract bugs (self-executing blockchain code flaws) caused most incidents by count, but represented only 11% of total losses, while operational and infrastructure breakdowns such as compromised keys and signers made up 88.3%. Hacken also attributed 75.5% of drained funds to Democratic People's Republic of Korea actors. The quarter included what Hacken described as the first AI malicious prompt injection case to cause fund exfiltration, resulting in a $174,000 loss tied to “inadequate review, missing variants and weak testing.” On regulation, the report said U.S. crypto rules under the GENIUS Act will take effect in early 2027, while the European Union's MiCA (crypto rulebook for the EU) grace period ended on July 1 with only about 215 Crypto-Asset Service Providers licensed despite 1,200 expressing interest. Binance, MEXC and HTX were among exchanges forced to shut down under the rule, and Circle's USDC was the only MiCA-compliant stablecoin among the top 10 by market cap. Hacken said the most trusted counterparties going forward will be those that can prove safety first, regardless of age, audits or total value locked.