Web3: Report: Crypto industry Q2 attack losses rise to $764 million
Coinpedia
07-23 08:27
Ai Focus
Hacken reports that the crypto industry suffered $764 million in losses from attacks in the second quarter of 2026, with operational errors accounting for the majority and approximately three-quarters of the stolen funds flowing to North Korean-related actors.
Helpful
No.Help

A recent report from blockchain security and compliance company Hacken shows that the crypto industry experienced 67 security incidents in the second quarter of 2026, with a total loss of approximately $764 million, a 58.3% increase from $482.7 million in the first quarter, marking the highest single-quarter loss since the second quarter of 2025.

Operational errors account for the majority of the losses.

The report states that while smart contract vulnerabilities remain the most common type of attack, they account for a relatively small percentage in terms of monetary value. The majority of losses in the second quarter stemmed from operational and infrastructure issues, including breaches of private keys and signer permissions, representing 88.3% of total losses.

Hacken listed "accessibility vulnerabilities" as the most significant single point of failure, indicating that many losses did not originate from the on-chain code itself, but rather from issues related to account permissions, internal processes, and system management.

Drift and KelpDAO suffered the largest losses.

In terms of individual losses, Drift Protocol and KelpDAO were the two largest losses in the second quarter, with each outflowing nearly $290 million. The report did not provide further details in the summary, but these two incidents accounted for a significant proportion of the total losses for the quarter.

The report also mentioned that the second quarter saw its first case of funds being injected due to malicious AI prompts, resulting in losses of approximately $174,000. Hacken believes that such issues expose gaps in oversight, incomplete testing coverage, and weak variant protection.

North Korea-related funds account for over 75%.

Hacken estimates that approximately 75.5% of the stolen funds in the second quarter were attributed to North Korean-related actors. The report also mentions that MetaMask's parent company, Consensys, recently admitted to mistakenly hiring a software developer with ties to North Korea.

According to the disclosure, the company discovered the problem a month later, subsequently dismissing the employee and revoking their system access, while also reporting the incident to law enforcement. Consensys stated that the incident did not result in any financial loss to users, nor did it involve any data breaches or malicious code deployment.

EU MiCA transition period ends

In addition to security incidents, the report also reviewed compliance progress in the second quarter. In the EU, the transition period for crypto service providers to apply for full licenses ended on July 1st. Approximately 1200 institutions had expressed their intention to apply, but as of that time, only about 215 crypto asset service providers had received MiCA authorization.

Hacken noted that exchanges such as Binance, MEXC, and HTX have ceased operations in their respective markets as a result. Regarding stablecoins, among the top ten by market capitalization, only USDC has been reported as compliant with MiCA requirements.

Overall, this report reflects a shift in industry risks from simple contract vulnerabilities to areas more focused on access control, personnel vetting, and infrastructure protection. As compliance thresholds tighten in Europe, security capabilities and licensing qualifications are simultaneously becoming key competitive indicators for platforms.

Tip
$0
Like
0
Save
0
Views 248
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Web3: Across discloses attack on Solana repeaters, resulting in approximately $4.5 million in losses.
Risk Labs, the operator of Across, stated that the Solana repeater was attacked due to a lack of off-chain event verification, resulting in a loss of approximately $4.5 million, but user funds were not affected.
The Cryptonomist
·2026-07-25 03:19:19
712
web3: Wall Street lowers its Q2 forecast for Coinbase
Coinbase's Q2 earnings forecast has been lowered, with market focus shifting to second-half guidance and progress on US crypto legislation.
CoinDesk
·2026-07-29 23:23:02
504
Web3: Report says the crypto industry added $55 billion to the US economy.
The report states that the crypto industry has contributed $55 billion to the U.S. economy and created hundreds of thousands of jobs.
crypto.news
·2026-07-28 20:03:08
536
Web3: Report says the US crypto industry supports 232,000 jobs
The report states that the U.S. crypto industry will directly provide approximately 34,000 jobs by 2026 and support approximately 232,000 jobs nationwide, contributing over $55 billion to GDP.
crypto.news
·2026-07-23 11:48:53
869
Web3: Report says US crypto scams may cause $80.7 billion in losses annually.
The report states that actual losses from crypto scams in the United States could reach $80.7 billion by 2025, with investment scams accounting for the largest share, and the elderly being particularly vulnerable.
Decrypt
·2026-07-29 20:23:59
81