Stolen Keys Drove 2026's Crypto Hacks and One Crew Took 44%
The biggest crypto hacks of 2026 skipped the code and stole the keys. Losses fell below 2025, yet one state-linked crew still took nearly half the total.
The biggest crypto hacks of 2026 skipped the code and stole the keys. Losses fell below 2025, yet one state-linked crew still took nearly half the total.
DefiLlama data shows $17 billion stolen across 518 incidents in a decade, and more than half of the losses came from stolen keys or phished humans. The…
North Korea's TraderTraitor subgroup hit Drift on April 1 and KelpDAO on April 18. One attack used a fake quant firm. The other poisoned bridge infrastructure. Different tactics, same wallet.
ZachXBT flagged six attacker wallets funded through Tornado Cash. A minting flaw in KelpDAO's rsETH token left Aave V3 holding bad debt, sending the AAVE token down 10-13%.
The attacker funded the node through Monero and Hyperliquid weeks before the theft. Chainalysis mapped the entire trail. THORChain paused all trading.
The Senate passed it unanimously on April 3. Ringleaders whose operations kill victims face life in prison. The government has set an April 2026 deadline to shut down every illegal scam compound inside its borders.
A pre-signed transaction feature designed for convenience became the entry point for the largest DeFi hack of 2026. Elliptic has flagged North Korean state actors. Circle faces fresh scrutiny.
A researcher says over 40 DeFi platforms have employed DPRK state-linked developers. Their seven years of blockchain experience is, as she notes, not a lie. The Drift Protocol exploit was not a code bug. It was a six-month intelligence operation conducted by a North Korean state-affiliated group that attended conferences, deposited real capital, and waited.
One of the world's largest Bitcoin ATM operators filed an SEC Form 8-K on April 8, 2026, disclosing that an unauthorized party accessed its corporate IT systems and drained 50.903 BTC from settlement accounts. Customer platforms and user data were not affected.
North Korean group UNC4736 stole $270 million from Drift Protocol on April 1, converting part of it into USDC via Circle's own bridge. Circle's formal response clarifies when and why it can freeze assets — and calls for legislative action.
Investors allege Circle let $230 million in stolen USDC cross from Solana to Ethereum without intervention. The lawsuit lands as Tether steps in with a $127.5 million recovery package.
The six-month ETH Rangers program recovered $5.8 million and flagged 785 vulnerabilities. Investigators say DPRK workers used fake identities and normal hiring channels to embed inside Web3 teams.
A forged message bypassed the Polkadot token contract's admin controls on Ethereum, allowing unlimited minting. Hyperbridge paused operations after the attack — notable because the protocol markets itself as a "full node security" bridge.
The $150 million recovery plan will fund user reimbursements as Drift relaunches with USDt as its settlement asset. Circle faced heavy criticism for not freezing $232 million in USDC that the North Korea-linked attacker moved through its own bridge.
Tether's USDT dominates with $185 billion in market cap but faces ongoing transparency questions. Circle's USDC is smaller at $78 billion but audited monthly by Deloitte, MiCA-compliant, and now leads in transaction volume. Here is what the data says about which one to trust with long-term holdings.
NEAR's largest DeFi protocol revises hack damage upward after post-mortem reveals margin trading flaw. About $11.2 million has been returned or frozen so far.
Drift Protocol is a Solana-based perpetuals DEX that became the center of one of the largest exploits in DeFi history when a $285M attack drained the protocol in April 2026, and the post-mortem traced the breach back to North Korean operatives who had been embedded in DeFi development teams since 2020. The coverage here tracks the full incident and what came after: the $285M exploit and the on-chain trail across mixers and bridges, Circle’s response on USDC freezes and the class action lawsuit that followed over freeze failures, Tether’s $127.5M commitment to the recovery effort, the North Korean IT worker investigation that exposed how deep state-sponsored infiltration of DeFi protocols actually runs, and the Solana ecosystem response from major protocols and validators. Drift continues to operate, and the technical questions are not the most interesting part of the story anymore. The interesting part is what the case revealed about who actually builds DeFi protocols, how due diligence on contributors actually works, and how stablecoin issuers respond when stolen funds move across chains faster than legal compulsion can travel. Coinliva covers the recovery effort, the legal proceedings, the regulatory response, and the broader implications for every protocol relying on anonymous or pseudonymous contributors.