The first half of 2026 was marked by high hacker, scammer, and cybercriminal activity. We break down how much they made from crypto industry crimes.
From January to June 2026, the crypto industry lost about $1.32 billion across 224 publicly disclosed hacking incidents, according to Onchain Lens analysts.
Hot topic: Strategy Adds $525M to Cover Dividends Into 2028
The bulk of the damage came from a limited number of large-scale exploits. Attackers are increasingly targeting access control mechanisms, phishing, and oracle manipulation rather than code vulnerabilities. Experts warn that human factors and access management are becoming the industry’s main risks.
Contents
Access Control and Phishing Are the Top Attack Vectors
The largest losses came from compromised access control mechanisms. By gaining privileged rights or critical credentials, attackers executed the most profitable attacks of the half-year. These included hacks of:
- Kelp DAO — $292 million
- Drift Protocol — $280 million
- Humanity Protocol — $31 million
- Step Finance — $30 million
- Truebit — $26.5 million
- Resolv Labs — $25 million
- AFX — $24.15 million
- BonkDAO — $21 million
Phishing and social engineering were the second-largest cause of losses, accounting for about $282 million.
Oracle attacks were another key vulnerability. Related incidents include:
- Ostium — $24 million
- Blend Protocol — $10.86 million
- Bonzo — $9 million
Analysts emphasize that total damages were driven by a limited number of highly effective attacks, not hundreds of separate incidents.
Read more: RootData 2026 Crypto Project Closures — 99 Projects Have Already Died This Year
Shift in Threats: From Code to Access Control
Onchain Lens data shows a structural shift in the threat landscape. The largest losses came not from smart contract bugs but from compromised keys, permissions, and privileged rights. Humans and access control–not the code itself–are increasingly the entry point for attackers.
Phishing and social engineering netted attackers $282 million, showing that tricking employees and users is as effective as technical exploits. Oracle manipulation cost the market significantly less than the first two categories, but the vector can’t be dismissed entirely.
The bottom line: code security still matters, but access control and social engineering protection have become the critical priorities. The focus should shift to access management, privileged account monitoring, and employee phishing awareness training.
Learn more: What Is the BIP-110 Upgrade? Why Bitcoin Developers Can’t Agree
