Crypto hacks set a record in the first half of 2026. Not for the money, for the count. TRM Labs logged 207 separate incidents, more than double the 83 it counted a year earlier, while the total stolen fell to roughly $972 million, less than half of the $2.3 billion lost in the first half of 2025. The figure that matters sits under those two. Most crypto hacks this year broke code, and almost none of the money walked out through a code flaw.
That gap is the story August keeps retelling.
Common break-ins are the cheap ones
Of the 207 incidents, 125 were smart contract exploits, close to 60 percent of the crypto hacks logged. Buggy code is still the everyday attack. It is also the least expensive. By value, TRM traced about 76 percent of all stolen funds to infrastructure and operational compromise, meaning leaked keys, spoofed interfaces, and staff tricked into signing a transaction they should not have. The contracts held. The people and the plumbing around them did not.
Two attacks tied to North Korea make the point at scale. The $285 million theft from Drift Protocol in April and a $292 million hit on KelpDAO moved $643 million between them, about two thirds of the entire half year. Neither turned on a clever bug in a contract. Both turned on access.
| Attack type | Share of the 207 hacks | Share of the $972M lost |
|---|---|---|
| Code and contract flaws | About 60 percent | A small share |
| Infrastructure and access | About 15 percent | About 76 percent |
The averages say the same thing from another angle. The mean loss per incident was $4.7 million, but the median came in at just $219,000, a spread that shows the tail is doing the damage. A pile of small crypto hacks sets the count. The access failures set the total.
August's biggest DeFi loss ran on a vote
On August 23 an attacker drained about $8.5 million from Term Finance, an Ethereum lending protocol. No contract was exploited. The wallet started with 2 ETH pulled through Tornado Cash, then bought up the project's thinly held governance token on the open market. Low float and light participation meant that a small position bought a controlling one. The attacker ended with 100 percent of the votes across four of the five USDC strategy vaults and roughly 91 percent of the Ethereum Meta Vault, then proposed sending the assets to a single address and voted the proposals through.
Out went 2,843 ETH, near $6.9 million, plus 1.68 million USDC later swapped into DAI. That ETH alone was about 68 percent of the Meta Vaults' holdings. Defimon, PeckShield, and CertiK all traced the same wallets. The two ETH that captured Term Finance's vaults did what a zero-day usually does, without touching a line of the code. Term said it is working with outside security teams to recover the assets and cover what it can.
Permissions and delegates did the rest
Term was the loudest case, not the only one. Two days earlier BounceBit lost about $3 million to an authorization flaw on its own layer-1, a failure serious enough that the team is winding the chain down and reissuing its BB token on BNB Chain. Around the same window, a delegate-permission hijack let an attacker mint an absurd nominal amount of SAND through a cross-chain messaging hook, though the real, sellable damage stayed tiny.
Each of these is a control failure wearing different clothes. Who can vote. Who is authorized. Who holds a delegate slot. The attacker never had to out-engineer the contract because the contract was told, through channels it trusted, to hand the money over. This is the same category that a single stolen key drained from a licensed stablecoin back in May, scaled up and dressed in DAO governance.
The code surface did not get safer
Read this the wrong way and you conclude that audits stopped mattering. They did not. Sixty percent of the year's crypto hacks were still contract bugs, and the record incident count means more code is under fire than ever, most of it in small protocols that never get a serious review. The typical hack is a $219,000 code slip on something few people watch.
The honest version is narrower. Code exploits win on frequency, control failures win on size, and the money follows control. That was true before August through leaked keys and social engineering, and Term Finance simply added a new door onto an old floor plan, buying the vote instead of stealing the signature. Governance was supposed to be the safeguard. Priced cheaply enough, it became the entry point.
For anyone holding funds in a protocol, the questions worth asking have shifted with it. How concentrated is the governance float, and how much would a majority actually cost to buy. Who controls the signing keys, the delegate slots, the upgrade switches. As licensing rules push more assets toward a handful of permitted issuers and custodians next year, those single points of control get larger, not smaller, and that is the surface to watch through the rest of 2026.