Skip to content
Saturday, August 29, 2026 · Global Edition
BITCOIN TRADER
CRYPTO · MARKETS · TRADING
Loading market quotes…
BTC · ETH · SOL · XRP · ADA · DOGE · AAPL · MSFT · NVDA · AMZN · GOOGL · TSLA
Market data by TradingView
Home / Crypto News

Crypto Hacks Hit a Record 207 Incidents in H1 2026 While Losses Fell Below $1 Billion

Attack count reached an all-time high in the first half of 2026 even as dollar losses dropped to 972 million — a quarter of 2025's haul — per TRM Labs.

Two security analysts working at a dark monitoring wall
Frequency up, severity down: the hardened core holds while the long tail takes the hits.

Crypto hacks reached a record 207 incidents in the first half of 2026, though total losses fell to roughly 972 million dollars — below the billion-dollar mark and far under 2025's record 2.1-billion-dollar haul — per TRM Labs' half-year analysis. North Korea-linked actors remained a major factor, the blockchain-analytics firm reported, while June alone saw 40 hacks totaling 75.87 million dollars, with Humanity Protocol's exploit the month's largest.

Bitcoin Trader publishes information, not investment advice. This report describes security incidents as documented by their sources; allegations against named parties remain with the authorities pursuing them.

What did the half-year show?

Frequency up, severity down. The 207 incidents are the most on record for a half-year, yet 972 million dollars in losses is under half the comparable 2025 figure — 2025 set the all-time annual record of 2.1 billion across 75 exploits, led by the 1.46-billion-dollar Bybit theft attributed to North Korea's Lazarus Group. The divergence means the average incident shrank sharply: more attacks against smaller pools of vulnerable value, and none in H1 2026 approached the catastrophic single-event scale of prior years.

June fits the pattern at monthly grain: 40 incidents — more than one a day — totaling 75.87 million dollars, an average under two million per event, with Humanity Protocol heading the leaderboard, per market reporting of the period.

Where is the security frontier moving?

Two documented shifts stand out. First, the perimeter hardened where money concentrated: after the large-exchange and bridge exploits of 2022-2025, the biggest custodial surfaces invested in monitoring, multisignature controls and withdrawal friction — so attackers moved to softer targets: smaller protocols, newly launched platforms, and processes rather than code. Second, the human layer became the attack surface: TRM's analysis highlighted roughly 30 million dollars stolen from holders through physical 'wrench' attacks in the half-year — coercion and kidnapping targeting known holders — a category no smart-contract audit addresses.

The Treasury Department's sanctions architecture remains the main state response to the North Korea-linked share, with OFAC designations of mixer services and laundering networks cutting the exit ramps for stolen funds. Enforcement recovers little; denial of cash-out is the operative strategy.

What is the angle other coverage skipped?

The denominator. Record incident count against falling losses reverses the metric most coverage anchors on — dollar damage — and the two together describe a maturing threat economy: automated, commoditized attack tooling hitting a long tail of small targets, while the hardened core holds. For infrastructure operators the half-year's lesson is that security investment visibly moved the loss curve; for individuals the parallel lesson is that the fastest-growing loss category is now physical, not cryptographic.

The second angle is what the record count implies about reporting itself: a hack census at 207 incidents in six months means near-daily incident news, which selects for coverage fatigue — each individual exploit now competes for attention against three others that week. The aggregate data is the defense against that distortion, which is why the half-year figures matter more than any single headline exploit of the period.

What should readers and operators take from it?

For operators, the standard checklist against the period's incident classes: key-management governance (the Ronin-class failure mode), oracle and dependency review, incident-response drills with pause authority, and continuous monitoring. For holders, the wrench-attack trend argues for operational privacy — holdings invisibility — alongside the usual custody hygiene. For everyone, the pattern to track into the second half is whether the shrinking-average thesis holds: another record count with sub-billion losses would confirm the long-tail shift; a return of single-billion events would not.

The TRM Labs half-year report and the Treasury sanctions record linked below are the primary sources; both are updated as incidents develop.

Tomás Ferreira

Tomás Ferreira came to crypto through payments infrastructure, and still finds the plumbing more interesting than the price.

More about Tomás Ferreira

Frequently Asked Questions

How many crypto hacks happened in the first half of 2026?
A record 207 incidents, per TRM Labs — the highest count on record for a half-year — with total losses of roughly 972 million dollars, less than half the comparable period of 2025.
Why are losses lower if hacks are more frequent?
The average incident shrank: hardened custodial surfaces and better monitoring moved attackers toward smaller protocols and processes, while the largest venues held. More attacks against a long tail of smaller targets produced record count with reduced dollar damage.
What are wrench attacks in crypto?
Physical coercion — kidnapping or threatening holders to force transfers. TRM's H1 2026 analysis flagged roughly 30 million dollars stolen this way, a category no technical security measure addresses directly; operational privacy is the main defense.
How does 2026 compare with 2025's record losses?
2025 set the all-time record: 2.1 billion dollars across 75 exploits, led by the 1.46-billion-dollar Bybit theft attributed to Lazarus Group. H1 2026's 972 million across 207 incidents marks far lower severity per event.

Sources

  1. Record 207 incidents and ~$972 million losses in H1 2026; North Korea-linked actors major factor; ~$30 million physical wrench-attack theftsTRM Labs, H1 2026 report
  2. 2025 record $2.1 billion across 75 exploits; Bybit $1.46 billion attributed to Lazarus Group; sanctions-based responseTRM Labs prior reporting; U.S. Department of the Treasury sanctions record