---
title: "MoonWire Crypto Security Tracker (2026): Losses Fell Below $1 Billion Even as Incidents Hit a Record - and the Threat Moved From Stolen Keys to Manipulated Logic"
published: 2026-07-14T18:02:14.687078+00:00
type: entity_evergreen
scope: security
canonical: https://moonwire.org/insights/crypto-security-tracker-2026.html
tags: [evergreen, security, exploits, defi, oracle, governance, bridges, compliance, enforcement]
---

# MoonWire Crypto Security Tracker (2026): Losses Fell Below $1 Billion Even as Incidents Hit a Record - and the Threat Moved From Stolen Keys to Manipulated Logic

> A running, descriptive record of 2026's notable crypto exploits and failures, organized by attack surface. The year's paradox: total losses fell below $1B through H1 even as the count of distinct incidents hit a record, and the defining attacks shifted from stolen keys to manipulated logic - bad oracle prices, revalued vaults, and governance votes turned into withdrawal mechanisms.

## Key takeaways

- The 2026 paradox: losses to hacks and exploits fell below $1B through H1 (The Block counted 207 incidents totaling $972M) even as the number of distinct incidents hit a record [[1]](/s/GiX1pDOSRZC1kKVGhJKlJA)[[2]](/s/aRDASVCESBq3swLEZTqcIg).
- The threat moved from stolen keys to manipulated logic: Bonzo Lend lost ~$9.05M to oracle manipulation and SummerFi ~$6M to USDC-vault NAV manipulation the attacker prepared for months - no keys compromised [[5]](/s/WAl7bKRMTYKPFL5zlplSEQ)[[6]](/s/_WCmBOBfRru50FHmAkoIJQ).
- Governance itself became an attack surface: BonkDAO was drained of ~$20M through its own voting process, and a $2.4M Cardano exploit hit 374 wallets before EMURGO stepped down from governance [[9]](/s/UP95GekwRlqxGGC0lt7vtw)[[10]](/s/Lbe_NguNSoqrrmFvLIOK0Q).
- Not every loss is an exploit: AscendEX ceased operations citing MiCA and a failed liquidity deal, leaving users unable to withdraw, while Zapper, Sophon and Goldfinch's Prime product wound down [[17]](/s/L_EprlPVTtimOY4oy7l3-g)[17815][[20]](/s/URHl1KgqSTyDlG_xPOAtVw)[[21]](/s/2RNrQVPCRJWu8GbQlL_28Q).
- The counter-pressure is enforcement: INTERPOL's crackdown produced 5,800+ arrests and exposed a laundering network with one wallet moving $122.5M in ten months; the DOJ seized infrastructure it linked to the Huione Group [[22]](/s/050_1xMWStmmdPkwYbcdrg)[[23]](/s/vy98vsBbRRy0g_wtQhyLyQ).

Crypto's 2026 security story runs against its own headline. Through the first half of the year, total losses to hacks and exploits fell *below* $1 billion — down sharply from prior cycles — even as the number of distinct incidents climbed to a record [[1]](/s/GiX1pDOSRZC1kKVGhJKlJA)[[2]](/s/aRDASVCESBq3swLEZTqcIg). The money stolen shrank; the frequency of attacks did not. And the nature of the attacks shifted: the marquee incidents of 2026 have less to do with stolen private keys than with manipulated logic — oracles fed bad prices, vaults revalued mid-transaction, governance votes turned into withdrawal mechanisms, and software dependencies quietly weaponized. This tracker organizes the year's notable events by attack surface, drawn entirely from MoonWire's curated feed. It is a running, descriptive record of what happened and how — not a ranking, and not advice.

## The macro frame

The Block counted 207 hack incidents in H1 2026 totaling $972M, with DeFi exploit losses down 74% from their 2022 peak, which it attributed to wider bug-bounty coverage and audits [[1]](/s/GiX1pDOSRZC1kKVGhJKlJA). Cointelegraph put the year-to-date figure near $1 billion and noted that many affected projects had been audited before they were hit [[2]](/s/aRDASVCESBq3swLEZTqcIg). The monthly trend has been easing: June losses fell 7% to $75.9M across 40 incidents, down from $81.7M in May [[3]](/s/BcjAciCVSdOc0HxsCNgwtg). For context on how far the field has come, the year also marked the tenth anniversary of the Ethereum DAO hack — an incident that drained $50M in 2016 and seeded a security fund that has since grown to $130M [[4]](/s/OWRrid3wSz-CHfeLQmkZmQ).

## 1. Manipulated logic, not stolen keys

The defining pattern of 2026 is the economic exploit: no keys compromised, just the protocol's own accounting turned against it.

- **Bonzo Lend (Hedera) — ~$9.05M.** An attacker fed a manipulated SAUCE price through a faulty oracle verifier to borrow against inflated collateral; a second wallet withdrew a further $1M and later claimed to be a white-hat promising to return funds [[5]](/s/WAl7bKRMTYKPFL5zlplSEQ).
- **SummerFi — ~$6M.** The loss came from manipulating the NAV/share price of two USDC vaults rather than from hacked keys, in an attack the attacker appears to have prepared for at least three months; the Lazy Summer DAO opened a compensation discussion [[6]](/s/_WCmBOBfRru50FHmAkoIJQ)[[7]](/s/dL5pUKwxQ6qgn1AVPUv_cw).
- **Secret Network (Axelar bridge) — $4.67M.** A cross-chain bridge exploit earlier in the cycle underscored that bridges remain a concentrated point of value [[8]](/s/ZV9DBfOXTLqwhCNsCR_I3w).

## 2. Governance as an attack surface

Two 2026 incidents showed that a protocol's decision-making machinery can itself be the exploit path.

- **BonkDAO — ~$20M.** The Solana-based meme-coin treasury was drained through its own governance process, turning a voting mechanism into a withdrawal channel [[9]](/s/UP95GekwRlqxGGC0lt7vtw).
- **Cardano "Pentad" — $2.4M across 374 wallets.** After the exploit, EMURGO stepped down from the ecosystem's governance group, and SecondFi outlined a recovery plan targeting fund return [[10]](/s/Lbe_NguNSoqrrmFvLIOK0Q)[[11]](/s/MJYqOSPgSB-EDofZ8n6YVA).

## 3. Supply chain and key generation

- **Injective npm package.** Attackers compromised the widely used `@injectivelabs/sdk-ts` dependency with malware built to steal wallet private keys — an attack on the software supply chain rather than the chain itself [[12]](/s/OHceXdcZTJW9n_K2aTJHCw).

## 4. Bridges and layer-2s

- **Taiko.** The Ethereum layer-2 halted block production and urged users to withdraw funds after an exploit compromised its chain-state verification mechanism, then reopened its bridge and said the network was fully restored and every user made whole; a full post-mortem was still pending as of the reporting [[13]](/s/TJN_u3OaQZW1CJ1qzZiYbg)[[14]](/s/LMRYKq_aQ8e_Q_ebDVBWpQ).
- **MEV honeypot — $7.5M.** The "jaredfromsubway" maximal-extractable-value bot was drained in a counter-MEV honeypot attack that tricked its automated system into approving attacker-controlled contracts [[15]](/s/EW6lLLJzRm6pQYyZQIZBdQ).
- **Solana whale — ~$14.2M.** A wallet tied to the Genesis distribution was reportedly drained of roughly 180,900 SOL, with the proceeds bridged to Ethereum [[16]](/s/c7hqXhquSuenFNjdwVEtEQ).

## 5. The quiet failures: shutdowns and wind-downs

Not every loss is an exploit. Several 2026 events cost users access through closure rather than theft.

- **AscendEX.** The exchange ceased operations on July 1, citing MiCA and a failed liquidity deal, leaving users unable to withdraw; on-chain data showed its tracked wallet falling from $2.12M in 2023 to about $1.9M by late June 2026 [[17]](/s/L_EprlPVTtimOY4oy7l3-g)[[18]](/s/GOvBKiHmRgeFUwa12idq5g).
- **Zapper.** The seven-year-old DeFi dashboard announced an orderly wind-down [17815].
- **Sophon** shut down its layer-2 and shifted to Base [[20]](/s/URHl1KgqSTyDlG_xPOAtVw); **Goldfinch** retired its Prime product after a community vote [[21]](/s/2RNrQVPCRJWu8GbQlL_28Q).

## 6. Enforcement and laundering

The counter-pressure came from the state. INTERPOL's global financial-crime crackdown produced over 5,800 arrests and exposed a crypto money-laundering network using cross-chain swaps, including one wallet that processed $122.5M in ten months [[22]](/s/050_1xMWStmmdPkwYbcdrg). The US Department of Justice seized laundering infrastructure it linked to the Huione Group [[23]](/s/vy98vsBbRRy0g_wtQhyLyQ).

## How to read this tracker

Every entry above traces to a dated item in MoonWire's curated feed and is described factually: the protocol or venue involved, the amount reported, and the attack vector as characterized by the reporting source. Figures are point-in-time as reported and may be revised as recoveries, reimbursements or white-hat returns are confirmed. This page is updated as the feed surfaces new incidents. It is a descriptive security record for research purposes and is not security guidance or investment advice.

---

*MoonWire surfaces and summarizes public crypto news.*

**General information only — not financial advice.** MoonWire Ltd. is not licensed by ASIC and holds no AFSL. This content does not consider your objectives, financial situation, or needs, and is not a recommendation to buy, sell, or hold any asset.

*This analysis is generated by artificial intelligence and may be inaccurate, incomplete, or fabricated. Independently verify before acting.*

© 2026 MoonWire Ltd. · [Terms](https://moonwire.org/legal/TOS) · [Risk Disclosure](https://moonwire.org/legal/RISK_DISCLOSURE)
