← MoonWire

Three Firms Counted Crypto's H1 Thefts and Got Three Different Answers

Aug 16, 2026 · security

Immunefi put the first half of 2026 at $972 million across a record 207 incidents; Blockaid put it above $1 billion with North Korean groups taking nearly $600 million; CertiK reported April alone above $650 million in DeFi losses. The spread is a disclosure problem rather than an arithmetic one - July showed why, when a $47 million exchange loss from 2021 entered the record only because a regulator filed over it. The one series with a stated year-over-year multiple was attacks on people.

July produced three published tallies of what crypto lost to theft in the first half of 2026, and they do not compose into a single number.

Cointelegraph framed the same period on 9 July as nearly $1 billion stolen in 2026 so far, noting that many of the victims had already passed audits [4].

Each firm states a different scope — hack incidents and losses, funds stolen, DeFi dollar losses — so these figures are not directly comparable, and none of them is offered here as the correct one. That is the finding. There is no settled number for what crypto lost in the first half of 2026, and July showed precisely why.

The totals cannot settle, because the record is assembled from disclosures

Three July events, each of which moves a half-year total after the fact.

A five-year-old loss entered the record because a regulator filed. On 27 July, Thailand's Securities and Exchange Commission lodged a criminal complaint against the exchange Bitkub and two former directors, accusing them of submitting false reports following a 2021 hack that resulted in a $47 million loss [5]. The complaint is an allegation and the coverage reports no finding against them. The point here is mechanical rather than moral: that loss is five years old, and it reached the public record in July because a regulator alleged it had not been reported properly — not because anyone tallying H1 2026 went looking for it.

A number entered the tape and left it the same day. On 15 July a LayerZero executor wallet was reported compromised, with $2.1 million said to have been taken across multiple chains [6]. LayerZero then denied any theft had occurred, stating the transfers were routine inventory consolidation [7].

A single incident's count was still climbing at the window's close. On 31 July, the last day of the month, The Block reported that Galaxy Research put the bitcoin drained through the Coldcard wallet exploit at $70 million — climbed, in the firm's words — across nearly 1,200 addresses and more than 1,000 BTC [8]. The vulnerability had been under discussion earlier that same day [9].

A half-year theft total is a snapshot of what had been disclosed, corrected and attributed by the day someone chose to publish it. July moved all three of those inputs.

One series carries an explicit multiple, and it points at people

Set the aggregate aside and one category in July's coverage arrives with a stated year-over-year multiple.

CertiK counted 52 crypto "wrench attacks" — physical coercion of holders — in the first half of 2026, with recorded financial exposure at $124.1 million, a more than 1,000% increase on the prior year. France accounted for nearly two-thirds of incidents, and home invasions rose to 20 from just one a year earlier [10] [11].

Four more of the month's incidents point at the holder rather than the contract:

Protocol exploits did not stop, and it would be wrong to imply they did. SummerFi lost $6 million to a flash-loan attack [16], BonkDAO $20 million [17], Bonzo Lend $9.05 million to oracle manipulation on Hedera [18], Ostium $18 million from an Arbitrum vault [19] and AFX Trade $24.15 million in drained USDC [20]; Cointelegraph put the Verus-Ethereum bridge exploit at $7.54 million and combined bridge losses across two incidents at $31.6 million [21]. The contract layer remained a live target all month.

What separates the two groups is not size. It is that the coercion series is the one reported with a year-over-year multiplier attached.

Three responses, all addressed to platforms

Three of the month's regulatory and industry responses, and each one lands on an intermediary:

Custody reviews, login mandates and reserve attestations are obligations on venues. None of the three reaches a person holding their own keys — which is the setting for the one series that carries a four-figure percentage increase.

The split, and both sides are attributable

One disagreement runs underneath the month's security coverage, and it is about direction rather than arithmetic.

Immunefi's reading is that the defensive side is gaining on code: DeFi exploit losses down 74% from the 2022 peak, with a record incident count producing a smaller dollar total [1]. Read alongside The Block's June figure — hacks down 7% month-over-month to $75.9 million across 40 incidents, from $81.7 million in May [26] — the trend line is more attacks for less money.

CertiK's April data cuts the other way: a single month above $650 million in DeFi dollar losses on flat incident counts, sourced from legacy smart contracts rather than from any new technique [3].

Both can hold simultaneously, and the mechanism is unremarkable once stated. A maturing audit layer catches what is new and shallow while leaving what is old and deep, which produces exactly this signature — rising incident counts, a falling typical loss, and occasional months that blow the average out on contracts written years earlier. That is also why a half-year average is a poor summary of the risk, and why three firms measuring three things arrived at three answers without any of them having to be wrong.

What would settle it

  1. Convergence. If H2 tallies from these firms land on a common scope and a comparable number, July's spread was a reporting artifact and the aggregate becomes usable again.
  2. Compounding coercion. If the wrench-attack count keeps rising into H2 while protocol losses keep falling, the shift from contract to holder is structural — and a regulatory response aimed entirely at platforms is aimed at the shrinking half of the problem.
  3. A first address to holders. If any jurisdiction issues guidance directed at individual holders rather than at licensed platforms, that is a sign a supervisor has priced the second reading.

Watch which of the three prints first. The order matters more than the totals do.

Sources & assets

Sources

Assets

Join MoonWire Early Access →

Real-time signal intel — AI-read crypto news, importance-scored and de-noised.