← MoonWire

MoonWire Crypto Security Tracker (2026): Losses Fell Below $1 Billion Even as Incidents Hit a Record - and the Threat Moved From Stolen Keys to Manipulated Logic

Jul 14, 2026 · security

A running, descriptive record of 2026's notable crypto exploits and failures, organized by attack surface. The year's paradox: total losses fell below $1B through H1 even as the count of distinct incidents hit a record, and the defining attacks shifted from stolen keys to manipulated logic - bad oracle prices, revalued vaults, and governance votes turned into withdrawal mechanisms.

Crypto's 2026 security story runs against its own headline. Through the first half of the year, total losses to hacks and exploits fell below $1 billion — down sharply from prior cycles — even as the number of distinct incidents climbed to a record [1][2]. The money stolen shrank; the frequency of attacks did not. And the nature of the attacks shifted: the marquee incidents of 2026 have less to do with stolen private keys than with manipulated logic — oracles fed bad prices, vaults revalued mid-transaction, governance votes turned into withdrawal mechanisms, and software dependencies quietly weaponized. This tracker organizes the year's notable events by attack surface, drawn entirely from MoonWire's curated feed. It is a running, descriptive record of what happened and how — not a ranking, and not advice.

The macro frame

The Block counted 207 hack incidents in H1 2026 totaling $972M, with DeFi exploit losses down 74% from their 2022 peak, which it attributed to wider bug-bounty coverage and audits [1]. Cointelegraph put the year-to-date figure near $1 billion and noted that many affected projects had been audited before they were hit [2]. The monthly trend has been easing: June losses fell 7% to $75.9M across 40 incidents, down from $81.7M in May [3]. For context on how far the field has come, the year also marked the tenth anniversary of the Ethereum DAO hack — an incident that drained $50M in 2016 and seeded a security fund that has since grown to $130M [4].

1. Manipulated logic, not stolen keys

The defining pattern of 2026 is the economic exploit: no keys compromised, just the protocol's own accounting turned against it.

2. Governance as an attack surface

Two 2026 incidents showed that a protocol's decision-making machinery can itself be the exploit path.

3. Supply chain and key generation

4. Bridges and layer-2s

5. The quiet failures: shutdowns and wind-downs

Not every loss is an exploit. Several 2026 events cost users access through closure rather than theft.

6. Enforcement and laundering

The counter-pressure came from the state. INTERPOL's global financial-crime crackdown produced over 5,800 arrests and exposed a crypto money-laundering network using cross-chain swaps, including one wallet that processed $122.5M in ten months [22]. The US Department of Justice seized laundering infrastructure it linked to the Huione Group [23].

How to read this tracker

Every entry above traces to a dated item in MoonWire's curated feed and is described factually: the protocol or venue involved, the amount reported, and the attack vector as characterized by the reporting source. Figures are point-in-time as reported and may be revised as recoveries, reimbursements or white-hat returns are confirmed. This page is updated as the feed surfaces new incidents. It is a descriptive security record for research purposes and is not security guidance or investment advice.

Sources & assets

Sources

Assets

Join MoonWire Early Access →

Real-time signal intel — AI-read crypto news, importance-scored and de-noised.