Smart Contract Bugs Were 60% of 2026 Crypto Hacks, 17% of Losses

Smart contract exploits were 60% of 2026 crypto hacks but just 17% of the losses. Keys, custody and signing systems took 76% of the stolen value.

Jan Whitfield Analysis

Start with the split that almost no security roundup leads with. Of the 207 crypto hacks tracked in the first half of 2026, roughly 60 percent were smart contract exploits. Those 125 incidents accounted for 17 percent of the money. The far smaller pile of attacks that went after keys, custody accounts and signing systems, about 15 percent of the count, walked away with 76 percent of the stolen value. Audits are built to catch the first group. The money left through the second.

The figures come from a mid-year review of crypto hacks compiled with data from TRM Labs, which put total losses at about $972 million across those 207 events, down 57 percent from the $2.3 billion stolen in the same stretch of 2025. Fewer dollars, fewer of the old headline-grabbing protocol drains, and a quiet inversion underneath it all. As TRM Labs summed it up, three-quarters of all stolen value came from compromises of keys, custody systems and signing infrastructure, not from smart contract bugs.

CertiK's own eight-month tally reached roughly $1.3 billion and reads the trend the same way. Compromised keys have become the majority of losses by dollar value, the firm said, passing smart contract vulnerabilities for the first time on record. The two reports cover slightly different windows and land on different totals, but they do not disagree on the shape. The expensive crypto hacks in 2026 are not breaking code. They are stealing the ability to sign.

The audit covers the smaller pile of money

Here is what that inversion does to a familiar sales pitch. A protocol commissions an audit, publishes the report, and points to it as proof of safety. The audit examines the contract logic, the thing that produced 17 percent of this year's losses. It does not examine the laptop of the engineer holding an admin key, the multisig that three employees can approve, or the firmware inside the box a user bought specifically to hold a private key.

Attack typeShare of incidents (H1 2026)Share of stolen value
Key, custody and signing compromisesabout 15%about 76%
Smart contract exploitsabout 60%about 17%
Other, including phishing and manipulationthe remainderthe remainder

CertiK founder Ronghui Gu put the problem in one line: a protocol can pass a flawless code audit and still lose millions because of a compromised admin key. That is not a knock on auditing. It is a map of where the audit stops. We wrote in the spring that the industry's security problem had stopped being the code, and the mid-year numbers turned that read into the majority case.

A hardware wallet became the year's strangest theft

The clearest example is also the one that should not have been possible. Starting July 30, an attacker began draining Coldcard hardware wallets, the offline devices bought precisely so a key never touches an internet-connected machine. Galaxy Research put the preliminary tally near 1,816 BTC, close to $116 million, spread across more than 5,200 addresses in at least four waves.

No contract was exploited. No user was phished. The flaw sat in a 2021 firmware build that, on some devices, fell back to a weak software random number generator when it created a wallet seed. Effective key strength dropped from a designed 128 bits to as little as 40 bits on older units, low enough to brute force years later. The device sold as the safest place for a key had quietly been generating guessable ones. Coinliva has traced the on-chain movement, where one thief moved 1,083 BTC while everyone else moved 210.

That is the category the audit model misses entirely. A seed generator, a signing server, an operations account. None of it is in the contract.

Where the big money actually went

Among 2026's crypto hacks, the two largest DeFi losses both trace to keys, not code. Drift Protocol lost about $285 million on April 1 after an attacker socially engineered access to an admin key. KelpDAO lost close to $290 million weeks later through compromised developer credentials. Investigators including Mandiant and Elliptic tied both to North Korea's Lazarus Group, whose $575 million haul from those two incidents alone came to roughly 44 percent of everything stolen in 2026. A single state-backed unit, working the human and operational layer rather than the contract, out-stole the entire smart contract exploit category several times over.

Even the attacks that do not fit neatly into either box keep landing outside the code. A separate mid-year breakdown found that price manipulation was behind one in eight crypto hacks this year, oracle and market games that no contract audit is designed to price in. And custody failures reach well beyond DeFi natives. Last year a licensed European stablecoin issuer learned the same lesson when one stolen key was enough to drain it, license and compliance stack notwithstanding.

What this changes for anyone holding crypto

Audits still earn their keep. They cut down the 125-incident bucket, and a chain with no code review is a chain waiting for its turn. But the report a team waves around answers a shrinking share of the real risk. The question worth asking a protocol in late 2026 is not whether it was audited. It is who can sign, how many of them it takes, where those keys live, and what happens on the day one of those people is fooled or one of those devices was flawed from the factory.

The 57 percent drop in dollars lost is the good news, and it is real. The composition underneath it is the warning. Attackers have moved to the layer that no external review reads, and the two biggest reports of the year now agree that is where the value is going. Watch the next quarterly tally of crypto hacks for whether the key-compromise share climbs past 76 percent or the audit-covered category claws any of it back.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.