100-Day Trade Challenge: trade on our AI predictions, up to 2 trade ideas a day. Free · educational · unregulated & risky Create free account
Cryptos: 21,667 Exchanges: 1,501 Market Cap: $2.85T 3.72% 24h Vol: $134.78B Dominance: BTC: 58.3% ETH: 11.4% Fear & Greed: 74/100 USD/INR: ₹95.98
Security

DeFi hacks pass $1.3 billion in 2026 as stolen keys lead

Stolen keys and admin credentials, not smart-contract bugs, now cause the most DeFi losses, with North Korea's Lazarus Group linked to about $575 million.

DeFi hacks pass $1.3 billion in 2026 as stolen keys lead
Photo: CC0, via rawpixel

At least $1.3 billion has been taken from decentralised finance (DeFi) protocols in the first eight months of 2026, CertiK's Hack3d data shows. The bigger shift is in how attackers are getting in.

Keys, not code

For the first time on record, the leading attack vector is compromised private keys and admin credentials, ahead of smart-contract bugs. The year's largest thefts relied on social engineering, session hijacking and validator-key theft rather than weaknesses in the code itself.

In plain terms, social engineering means tricking a person into handing over access, for example through a fake job offer or a message that seems to come from a colleague. Session hijacking means taking over a logged-in session, often through malware, so the attacker does not even need a password. Validator-key theft targets the keys that approve transactions on a network or bridge.

Two incidents stand out:

  • Drift Protocol, 1 April: about $285 million was drained in 128 seconds after attackers used social engineering to get hold of admin keys.
  • KelpDAO, 18 April: about $290 million was lost, traced back to a single compromised bridge verifier.

A bridge moves tokens between blockchains. A verifier checks that a transfer on one chain is genuine before tokens are released on the other. If one verifier alone can approve transfers, stealing its key can be enough to drain the bridge.

Links to North Korea

North Korea's Lazarus Group, operating as TraderTraitor, has been tied to roughly $575 million of this year's losses through those two attacks alone. That is about 44% of the 2026 total. Add the $1.5 billion Bybit hack of February 2025, and the group's rolling 18-month tally now exceeds $2 billion.

Recommended defences

Security experts are focusing on people and key management rather than code alone. Their suggestions include:

  • multi-party computation wallets with threshold signing, so no single key can move funds
  • timelocks that delay admin actions and leave time to spot abuse
  • bridge set-ups that rely on several verifiers rather than one
  • treating social engineering as a primary threat, not an afterthought

Threshold signing splits control of a wallet so that several key holders out of a group must approve a transaction. One stolen key is then not enough on its own.

What it means for Indian users

If well-funded protocols are losing money to stolen keys rather than clever exploits, individual users are an even easier target. Keep any crypto you are not actively trading in a hardware wallet. Be wary of any "support" or "partnership" message that ends with a request to sign a transaction. Most of 2026's losses began with a person being deceived, not a contract being broken.

A few practical habits help:

  • Never share your seed phrase with anyone, and never type it into a website. Our guide on storing a seed phrase safely explains why.
  • Check what a transaction will do before you sign it, and be especially careful with token approvals that give a contract unlimited access to your coins.
  • Use a separate wallet with a small balance for trying new DeFi apps.
  • Treat unexpected job offers, airdrops and "urgent" security alerts as possible scams. See our guide to avoiding crypto scams in India.

Stolen crypto is rarely recovered. In India, VDA losses also cannot be set off against gains on other crypto, so prevention is the only reliable protection.


This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.

Put it into practice

Run the 100-trade challenge: cap every loss, log every trade, and find out honestly whether you have an edge.