A recent report from blockchain security and compliance company Hacken shows that the crypto industry experienced 67 security incidents in the second quarter of 2026, with a total loss of approximately $764 million, a 58.3% increase from $482.7 million in the first quarter, marking the highest single-quarter loss since the second quarter of 2025.
Operational errors account for the majority of the losses.
The report states that while smart contract vulnerabilities remain the most common type of attack, they account for a relatively small percentage in terms of monetary value. The majority of losses in the second quarter stemmed from operational and infrastructure issues, including breaches of private keys and signer permissions, representing 88.3% of total losses.
Hacken listed "accessibility vulnerabilities" as the most significant single point of failure, indicating that many losses did not originate from the on-chain code itself, but rather from issues related to account permissions, internal processes, and system management.

Drift and KelpDAO suffered the largest losses.
In terms of individual losses, Drift Protocol and KelpDAO were the two largest losses in the second quarter, with each outflowing nearly $290 million. The report did not provide further details in the summary, but these two incidents accounted for a significant proportion of the total losses for the quarter.
The report also mentioned that the second quarter saw its first case of funds being injected due to malicious AI prompts, resulting in losses of approximately $174,000. Hacken believes that such issues expose gaps in oversight, incomplete testing coverage, and weak variant protection.
North Korea-related funds account for over 75%.
Hacken estimates that approximately 75.5% of the stolen funds in the second quarter were attributed to North Korean-related actors. The report also mentions that MetaMask's parent company, Consensys, recently admitted to mistakenly hiring a software developer with ties to North Korea.
According to the disclosure, the company discovered the problem a month later, subsequently dismissing the employee and revoking their system access, while also reporting the incident to law enforcement. Consensys stated that the incident did not result in any financial loss to users, nor did it involve any data breaches or malicious code deployment.
EU MiCA transition period ends
In addition to security incidents, the report also reviewed compliance progress in the second quarter. In the EU, the transition period for crypto service providers to apply for full licenses ended on July 1st. Approximately 1200 institutions had expressed their intention to apply, but as of that time, only about 215 crypto asset service providers had received MiCA authorization.
Hacken noted that exchanges such as Binance, MEXC, and HTX have ceased operations in their respective markets as a result. Regarding stablecoins, among the top ten by market capitalization, only USDC has been reported as compliant with MiCA requirements.
Overall, this report reflects a shift in industry risks from simple contract vulnerabilities to areas more focused on access control, personnel vetting, and infrastructure protection. As compliance thresholds tighten in Europe, security capabilities and licensing qualifications are simultaneously becoming key competitive indicators for platforms.












