Crypto's 2026 security story runs against its own headline. Through the first half of the year, total losses to hacks and exploits fell below $1 billion — down sharply from prior cycles — even as the number of distinct incidents climbed to a record [1][2]. The money stolen shrank; the frequency of attacks did not. And the nature of the attacks shifted: the marquee incidents of 2026 have less to do with stolen private keys than with manipulated logic — oracles fed bad prices, vaults revalued mid-transaction, governance votes turned into withdrawal mechanisms, and software dependencies quietly weaponized. This tracker organizes the year's notable events by attack surface, drawn entirely from MoonWire's curated feed. It is a running, descriptive record of what happened and how — not a ranking, and not advice.
The macro frame
The Block counted 207 hack incidents in H1 2026 totaling $972M, with DeFi exploit losses down 74% from their 2022 peak, which it attributed to wider bug-bounty coverage and audits [1]. Cointelegraph put the year-to-date figure near $1 billion and noted that many affected projects had been audited before they were hit [2]. The monthly trend has been easing: June losses fell 7% to $75.9M across 40 incidents, down from $81.7M in May [3]. For context on how far the field has come, the year also marked the tenth anniversary of the Ethereum DAO hack — an incident that drained $50M in 2016 and seeded a security fund that has since grown to $130M [4].
1. Manipulated logic, not stolen keys
The defining pattern of 2026 is the economic exploit: no keys compromised, just the protocol's own accounting turned against it.
- Bonzo Lend (Hedera) — ~$9.05M. An attacker fed a manipulated SAUCE price through a faulty oracle verifier to borrow against inflated collateral; a second wallet withdrew a further $1M and later claimed to be a white-hat promising to return funds [5].
- SummerFi — ~$6M. The loss came from manipulating the NAV/share price of two USDC vaults rather than from hacked keys, in an attack the attacker appears to have prepared for at least three months; the Lazy Summer DAO opened a compensation discussion [6][7].
- Secret Network (Axelar bridge) — $4.67M. A cross-chain bridge exploit earlier in the cycle underscored that bridges remain a concentrated point of value [8].
2. Governance as an attack surface
Two 2026 incidents showed that a protocol's decision-making machinery can itself be the exploit path.
- BonkDAO — ~$20M. The Solana-based meme-coin treasury was drained through its own governance process, turning a voting mechanism into a withdrawal channel [9].
- Cardano "Pentad" — $2.4M across 374 wallets. After the exploit, EMURGO stepped down from the ecosystem's governance group, and SecondFi outlined a recovery plan targeting fund return [10][11].
3. Supply chain and key generation
- Injective npm package. Attackers compromised the widely used
@injectivelabs/sdk-tsdependency with malware built to steal wallet private keys — an attack on the software supply chain rather than the chain itself [12].
4. Bridges and layer-2s
- Taiko. The Ethereum layer-2 halted block production and urged users to withdraw funds after an exploit compromised its chain-state verification mechanism, then reopened its bridge and said the network was fully restored and every user made whole; a full post-mortem was still pending as of the reporting [13][14].
- MEV honeypot — $7.5M. The "jaredfromsubway" maximal-extractable-value bot was drained in a counter-MEV honeypot attack that tricked its automated system into approving attacker-controlled contracts [15].
- Solana whale — ~$14.2M. A wallet tied to the Genesis distribution was reportedly drained of roughly 180,900 SOL, with the proceeds bridged to Ethereum [16].
5. The quiet failures: shutdowns and wind-downs
Not every loss is an exploit. Several 2026 events cost users access through closure rather than theft.
- AscendEX. The exchange ceased operations on July 1, citing MiCA and a failed liquidity deal, leaving users unable to withdraw; on-chain data showed its tracked wallet falling from $2.12M in 2023 to about $1.9M by late June 2026 [17][18].
- Zapper. The seven-year-old DeFi dashboard announced an orderly wind-down [17815].
- Sophon shut down its layer-2 and shifted to Base [20]; Goldfinch retired its Prime product after a community vote [21].
6. Enforcement and laundering
The counter-pressure came from the state. INTERPOL's global financial-crime crackdown produced over 5,800 arrests and exposed a crypto money-laundering network using cross-chain swaps, including one wallet that processed $122.5M in ten months [22]. The US Department of Justice seized laundering infrastructure it linked to the Huione Group [23].
How to read this tracker
Every entry above traces to a dated item in MoonWire's curated feed and is described factually: the protocol or venue involved, the amount reported, and the attack vector as characterized by the reporting source. Figures are point-in-time as reported and may be revised as recoveries, reimbursements or white-hat returns are confirmed. This page is updated as the feed surfaces new incidents. It is a descriptive security record for research purposes and is not security guidance or investment advice.





