July produced three published tallies of what crypto lost to theft in the first half of 2026, and they do not compose into a single number.
- Immunefi, via The Block on 9 July: a record 207 hack incidents in H1 2026, with losses staying below $1 billion at $972 million, and DeFi exploit losses down 74% from their 2022 peak as bug bounties and audits mature faster than attackers [1].
- Blockaid, via The Block on 28 July: hackers stole over $1 billion in the first half, with Ethereum and Solana projects hit hardest and North Korean state-linked groups responsible for the largest single share at nearly $600 million [2].
- CertiK, via Cointelegraph on 23 July: April alone exceeded $650 million in DeFi dollar losses while incident counts stayed flat, attributed to legacy smart-contract exploits rather than to new AI-driven attack tooling [3].
Cointelegraph framed the same period on 9 July as nearly $1 billion stolen in 2026 so far, noting that many of the victims had already passed audits [4].
Each firm states a different scope — hack incidents and losses, funds stolen, DeFi dollar losses — so these figures are not directly comparable, and none of them is offered here as the correct one. That is the finding. There is no settled number for what crypto lost in the first half of 2026, and July showed precisely why.
The totals cannot settle, because the record is assembled from disclosures
Three July events, each of which moves a half-year total after the fact.
A five-year-old loss entered the record because a regulator filed. On 27 July, Thailand's Securities and Exchange Commission lodged a criminal complaint against the exchange Bitkub and two former directors, accusing them of submitting false reports following a 2021 hack that resulted in a $47 million loss [5]. The complaint is an allegation and the coverage reports no finding against them. The point here is mechanical rather than moral: that loss is five years old, and it reached the public record in July because a regulator alleged it had not been reported properly — not because anyone tallying H1 2026 went looking for it.
A number entered the tape and left it the same day. On 15 July a LayerZero executor wallet was reported compromised, with $2.1 million said to have been taken across multiple chains [6]. LayerZero then denied any theft had occurred, stating the transfers were routine inventory consolidation [7].
A single incident's count was still climbing at the window's close. On 31 July, the last day of the month, The Block reported that Galaxy Research put the bitcoin drained through the Coldcard wallet exploit at $70 million — climbed, in the firm's words — across nearly 1,200 addresses and more than 1,000 BTC [8]. The vulnerability had been under discussion earlier that same day [9].
A half-year theft total is a snapshot of what had been disclosed, corrected and attributed by the day someone chose to publish it. July moved all three of those inputs.
One series carries an explicit multiple, and it points at people
Set the aggregate aside and one category in July's coverage arrives with a stated year-over-year multiple.
CertiK counted 52 crypto "wrench attacks" — physical coercion of holders — in the first half of 2026, with recorded financial exposure at $124.1 million, a more than 1,000% increase on the prior year. France accounted for nearly two-thirds of incidents, and home invasions rose to 20 from just one a year earlier [10] [11].
Four more of the month's incidents point at the holder rather than the contract:
- A randomness flaw named Ill Bloom exposed more than 2,114 wallet seeds across Bitcoin, Ethereum, Solana and other chains, with more than $5 million drained since 27 May [12].
- SparkKitty malware, distributed through mainstream app stores, scans photos on compromised devices to harvest wallet recovery phrases and other sensitive data [13] [14].
- Two separate campaigns targeted the people who build and hold: fake LinkedIn recruitment posts delivering a remote-access trojan to Web3 developers, and, per Kaspersky, counterfeit GitHub applications aimed at investors [15].
- The Coldcard failure was a firmware entropy bug — a defect in how a device generated a secret, exploitable without touching a chain or a contract at all [8] [9].
Protocol exploits did not stop, and it would be wrong to imply they did. SummerFi lost $6 million to a flash-loan attack [16], BonkDAO $20 million [17], Bonzo Lend $9.05 million to oracle manipulation on Hedera [18], Ostium $18 million from an Arbitrum vault [19] and AFX Trade $24.15 million in drained USDC [20]; Cointelegraph put the Verus-Ethereum bridge exploit at $7.54 million and combined bridge losses across two incidents at $31.6 million [21]. The contract layer remained a live target all month.
What separates the two groups is not size. It is that the coercion series is the one reported with a year-over-year multiplier attached.
Three responses, all addressed to platforms
Three of the month's regulatory and industry responses, and each one lands on an intermediary:
- ESMA opened a dedicated review of crypto custody providers, assessing operational resilience and compliance with EU frameworks [22].
- Hong Kong's SFC ordered licensed virtual-asset trading platforms to replace one-time passwords with phishing-resistant authentication within 12 months, pushing them toward biometric or hardware-based login [23] [24].
- Proof of reserves was presented as the post-FTX credibility standard in a Binance-commissioned primer, pairing proof of assets and liabilities through Merkle trees and zero-knowledge proofs [25].
Custody reviews, login mandates and reserve attestations are obligations on venues. None of the three reaches a person holding their own keys — which is the setting for the one series that carries a four-figure percentage increase.
The split, and both sides are attributable
One disagreement runs underneath the month's security coverage, and it is about direction rather than arithmetic.
Immunefi's reading is that the defensive side is gaining on code: DeFi exploit losses down 74% from the 2022 peak, with a record incident count producing a smaller dollar total [1]. Read alongside The Block's June figure — hacks down 7% month-over-month to $75.9 million across 40 incidents, from $81.7 million in May [26] — the trend line is more attacks for less money.
CertiK's April data cuts the other way: a single month above $650 million in DeFi dollar losses on flat incident counts, sourced from legacy smart contracts rather than from any new technique [3].
Both can hold simultaneously, and the mechanism is unremarkable once stated. A maturing audit layer catches what is new and shallow while leaving what is old and deep, which produces exactly this signature — rising incident counts, a falling typical loss, and occasional months that blow the average out on contracts written years earlier. That is also why a half-year average is a poor summary of the risk, and why three firms measuring three things arrived at three answers without any of them having to be wrong.
What would settle it
- Convergence. If H2 tallies from these firms land on a common scope and a comparable number, July's spread was a reporting artifact and the aggregate becomes usable again.
- Compounding coercion. If the wrench-attack count keeps rising into H2 while protocol losses keep falling, the shift from contract to holder is structural — and a regulatory response aimed entirely at platforms is aimed at the shrinking half of the problem.
- A first address to holders. If any jurisdiction issues guidance directed at individual holders rather than at licensed platforms, that is a sign a supervisor has priced the second reading.
Watch which of the three prints first. The order matters more than the totals do.




