guideAugust 1, 2026

Top 10 DeFi Hacks of 2026 (So Far)

The ten biggest DeFi hacks of January through July 2026, ranked by amount lost: KelpDAO's $292M bridge exploit, Drift's $285M key compromise, and eight more, with the root cause of each and the operational-failure pattern behind nearly half the year's losses.

Top 10 DeFi Hacks of 2026 (So Far)

TLDR

The first seven months of 2026 were the most hacked stretch in DeFi history by incident count, with security firms placing first-half losses between $970 million and $1.3 billion depending on methodology. Two April incidents, KelpDAO ($292M) and Drift Protocol ($285M), account for nearly half of everything stolen, and both were operational failures rather than smart contract bugs: compromised infrastructure and stolen keys, not broken math. This list ranks the ten biggest DeFi hacks of 2026 so far by amount lost, with the root cause of each and the pattern that connects them.

1. KelpDAO — $292M

The largest DeFi loss of 2026 was a bridge that got lied to. On April 18, attackers who had compromised KelpDAO's internal RPC nodes fed false data to its LayerZero bridge configuration, so a phantom burn on one chain released 116,500 rsETH on another. No signature was forged and no contract was buggy in isolation; the bridge simply trusted infrastructure that had been taken over. Blockchain investigators attributed the attack to North Korea-linked actors. It is a textbook false-deposit exploit, the third of the four ways bridges get drained, and a reminder that a bridge's solvency is defined by whatever its verifier says.

2. Drift Protocol — $285M

On April 1, attackers drained roughly $285 million from Drift, the largest exploit ever recorded on Solana, in under 12 minutes. The entry point was not the protocol's code but its administration: a compromise of privileged keys, reportedly the product of a months-long social engineering campaign, let the attackers fabricate collateral pricing and walk the funds out. Investigators attributed this one to North Korea-linked actors as well; together with KelpDAO it made April a record month, with more than $625 million lost across roughly 30 incidents.

3. Humanity Protocol — $30M+

On June 9, attackers drained H tokens reported at between $30 million and $36 million from Humanity Protocol, the palm-scan proof-of-humanity project. A phishing email compromised a developer's laptop that held enough key material to control both a hot wallet and two multisig accounts. The attacker dumped the tokens on-chain and the H token fell more than 80% within hours. The stated explanation, accidental key backups on one machine, drew public skepticism from independent on-chain investigators, who suggested insider involvement. Either way, the failure was custody, not code.

4. Step Finance — $27M

On January 31, attackers took 261,854 SOL, about $27 million, from Step Finance's treasury and fee wallets after compromising devices belonging to the project's executive team. The team recovered about $4.7 million with partner help, but the damage was terminal: on February 23 Step Finance announced it was winding down entirely, taking SolanaFloor and Remora Markets with it. It is the clearest 2026 example of a treasury hack killing the company that suffered it.

5. Truebit — $26.4M

The year's first major exploit hit Truebit on January 8. An unaudited Purchase contract deployed in 2021 contained an unchecked integer addition; the overflow drove the computed mint price of TRU to effectively zero, letting the attacker mint tokens for nothing and drain 8,535 ETH, about $26.4 million. TRU collapsed 99.9% in a day. The lesson is uncomfortable for every mature protocol: old, unaudited code with mint authority is an exploit with a delay timer, and attackers are systematically re-auditing DeFi's back catalog.

6. Resolv — $25M

In March, an attacker who had compromised the AWS KMS environment holding a critical Resolv key exploited the protocol's two-step mint design, in which the amount of USR stablecoin to mint arrived as an unchecked parameter from an off-chain service the contract implicitly trusted. Roughly 80 million unbacked USR were minted against a few hundred thousand dollars of collateral and swapped out for approximately $25 million. USR depegged as low as fractions of a cent before partially recovering, and downstream lending markets absorbed eight figures of bad debt. One compromised key, one trusting contract.

7. Ostium — $23.75M

On July 15, an attacker with price-submission authority on Ostium, a perpetuals DEX on Arbitrum, opened BTC longs at $5,000 and closed them near $60,000, prices the market never traded, and drained $23.75 million from the vault backing every position. Ostium's pull-based oracle delivered a signed price only at settlement, with no independent cross-check on what an authorized submitter provided. It is 2026's cleanest example of oracle manipulation as a category: the attacker didn't move a market, just the number the contract believed.

8. Verus Bridge — $19.1M across two hacks

The Verus-Ethereum bridge earns its spot by getting drained twice through the same door. In May, a forged cross-chain import whose proof passed verification despite no matching export took $11.58 million; the attacker returned most of it after negotiations. The recovered funds were moved back into the bridge on July 8, and on July 23 a different wallet drained $7.54 million through the same import path. Whether the second hit was a new attacker or something worse remains unproven, but the operational lesson stands: refilling a bridge before the vulnerability class is provably closed is re-arming the trap.

9. Rhea Finance — $18.4M

In mid-April, an attacker hit Rhea Finance, NEAR's largest DeFi hub, using fake token contracts and manipulated liquidity pools to distort pricing and exploit a slippage-protection flaw in its margin trading feature, draining the reserve pool. Initial estimates of $7.6 million were revised to about $18.4 million after investigation. Recovery was unusually substantial: the attacker returned roughly $3.3 million in USDC plus 1.56 million NEAR, and around $4.34 million in USDT was frozen with issuer cooperation.

10. SwapNet — $13.4M

On January 25, an arbitrary-call vulnerability in SwapNet, a DEX aggregator integrated into Matcha Meta, let an attacker route calls through the contract to any address, including token contracts, and drain wallets that had granted SwapNet unlimited approvals. Confirmed losses were $13.43 million, almost all from a single user, in what researchers called the largest approval attack recorded outside phishing. The aggregator should have rejected calls to anything but whitelisted routers; every user's standing approval became the attacker's allowance.

The Pattern: Keys, Not Code

Rank the list by root cause and 2026's story writes itself. Seven of the ten entries trace to operational failure, compromised keys, devices, infrastructure, or trusted off-chain services, and by loss value the skew is stronger: industry analyses attribute roughly 70% of 2026 losses to key and credential theft, with the two largest incidents alone making up nearly half the half-year total. Smart contract auditing has matured; attacker tradecraft has shifted to laptops, cloud key stores, RPC nodes, and the people who hold admin rights. The exceptions, Truebit's integer overflow, SwapNet's arbitrary call, Ostium's trusting oracle, cluster in old unaudited code and designs that trust a single input nobody double-checks.

The other constant is speed of consequence. Drift was empty in under 12 minutes. Truebit's token lost essentially all its value in a day. Step Finance, the company, was gone within a month. The window between first malicious transaction and irreversible damage is now minutes, which is why every one of these incidents was visible on-chain before it was announced anywhere.

Watching the Next One Happen

Every hack on this list produced a loud on-chain signature: mints with no matching burns, vault balances collapsing, settlement prices orders of magnitude off market. Detection is not the hard part; being early enough to act is. Defimon detects anomalous profit extraction across major chains in under a second and streams structured alerts, including victim protocol and per-address balance changes, over a real-time WebSocket feed, with a confirmed stream that names the victim so integrators can auto-pause or unwind exposure. Our own coverage of Ostium and Verus started from those alerts, and in February the same detection let us rescue $1.84 million from Foom.cash before an attacker got there. For how the wider tooling landscape divides up, see our comparison of DeFi security monitoring platforms.

This list covers January through July 2026 and will be updated as the year produces new entries. Given the run rate, with the first half setting an all-time record for incident count, it will.

Frequently Asked Questions

What is the biggest DeFi hack of 2026?

The biggest DeFi hack of 2026 so far is the KelpDAO exploit of April 18, which lost about $292 million when compromised internal RPC nodes fed false data to the protocol's LayerZero bridge, releasing 116,500 rsETH against a phantom burn. The second largest is Drift Protocol's roughly $285 million loss on Solana on April 1 via compromised administrative keys. Both were attributed to North Korea-linked actors by blockchain analytics firms.

How much money has been lost to DeFi hacks in 2026?

Security firms tracking on-chain incidents place first-half 2026 losses between roughly $970 million and $1.3 billion, across more than 200 recorded attacks. Estimates differ because each tracker counts incidents and recoveries differently, but every major one agrees 2026 set an all-time record for the number of attacks.

What causes most DeFi hacks in 2026?

Key and credential theft, not smart contract bugs. Industry analyses attribute roughly 70% of 2026 losses to compromised private keys, devices, and infrastructure, spanning phished developer laptops (Humanity Protocol), compromised executive devices (Step Finance), cloud key-store breaches (Resolv), and hijacked RPC nodes (KelpDAO). The two largest incidents, KelpDAO and Drift, were both operational compromises and together account for nearly half of first-half losses.

How do you find out about a DeFi hack in real time?

Every major 2026 hack was visible on-chain minutes to hours before any official announcement, as anomalous mints, drains, or settlement prices far off market. Real-time monitoring services detect these signatures as they execute: Defimon, for example, flags anomalous profit extraction across major chains in under a second and streams structured alerts over WebSocket and a free public Telegram channel, so protocols, funds, and traders can react before the news cycle does.

Put the feed in your stack

Connect in minutes. Every attack across major chains, as JSON, in under a second.

@DefimonAlerts

© 2026 Defimon by Decurity

Powered by QuickNode