Crypto security is getting better in some areas but hackers are still taking billions.
From January 1 to August 28, 2026, publicly tracked incidents show at least ~$1.26B in losses across 219+ incidents by Aug. 23 and more attacks were reported after that date. Different trackers use different definitions, so treat this as a conservative public-tracker figure, not a final audited total.
🔴 $1.26B+ worth of crypto has been reported stolen/lost in hacks & exploits
🔴 219+ incidents were publicly tracked by Aug. 23
🔴 H1 2026: ~$972M across 207 hack incidents (Immunefi)
🔴 July: ~$110M lost to hacks
🔴 August: more than $13M was confirmed across major Aug. 17–23 exploits; additional incidents were reported afterward, including Moonwell ($8.79M) and FH Token ($20K)
And these numbers are NOT a complete count of every wallet drain, phishing attack or smaller incident.

BIGGEST REPORTED INCIDENTS IN 2026:
▶️ KelpDAO → ~$290–292M
▶️ Drift Protocol → ~$280–285M
▶️ Coldcard → ~$112–116M currently tracked
▶️ Unknown user → ~$282M (NOT VERIFIED / attribution and incident details unclear)
▶️ Step Finance → ~$27–40M, depending on tracker methodology
▶️ AFX → ~$24M
▶️ Humanity Protocol → ~$36M
▶️ Resolv USR → ~$23M
▶️ BONK DAO → ~$21M
▶️ Ostium → ~$23.75M
▶️ Wanchain → ~$10M
▶️ Verus Bridge → ~$11.6M
▶️ Bonzo Lend → ~$9M
▶️ Syscoin Bridge → ~$9M
▶️ Moonwell → ~$8.79M
▶️ Term Labs → ~$8.5M
▶️ Coinsbuy → ~$7.9M
▶️ THORChain → ~$10.7M
▶️ SagaEVM → ~$7M
▶️ Trusted Volumes → ~$6.7M
▶️ SummerFi → ~$6M
▶️ Gravity Bridge → ~$5.4M
▶️ Makina → ~$5M
▶️ DxSale → ~$7.3M
IMPORTANT: Some incidents and amounts remain disputed, estimated, or based on security-firm tracking. I would label them “NOT VERIFIED” rather than present them as confirmed facts.
Examples:
➡️ Unknown user → ~$282M (NOT VERIFIED)
➡️ OneKey → reported security issue; “hack” characterization disputed/under investigation (NOT VERIFIED)
➡️ FOMO app incident → company denied a hack (NOT VERIFIED)
➡️ Zilliqa → incident reported, amount undisclosed (NOT VERIFIED)
This means the real number can move up or down as investigations finish and trackers reconcile duplicate or disputed incidents.
The scary part? Hackers don't always need to find a smart-contract bug.
⚠️ Private keys
⚠️ Developer devices
⚠️ Infrastructure
⚠️ Governance systems
⚠️ Bridges
⚠️ Supply-chain vulnerabilities
…are increasingly becoming attack targets.
2026 is proving one thing: Crypto security isn't only about auditing smart contracts anymore.
One compromised key or infrastructure component can put hundreds of millions of dollars at risk.
DATA NOTE: Immunefi reported ~$972M across 207 incidents in H1. Other trackers report higher H1 totals because they include different categories such as wallet compromises, infrastructure attacks and other security incidents. A separate tracker had 219+ incidents and more than $1.26B in losses by Aug. 23. So do NOT treat one number as the final 2026 total.

