DropsTab logo - blue line depicting the shape of a water drop with Christmas decoration
M. Cap$2.93 T −0.11%24h Vol$187.37 B −16.13%BTC$85,807.00 −0.11%ETH$2,719.13 −1.13%S&P 500$7,741.60 −0.38%Gold$4,285.50 −1.22%BTC Dominance58.73%

Analytics

Crypto Hacks 2026: Record Attacks and Where AI Fits In

Crypto hacks hit a record in H1 2026, yet stolen value fell. Will AI break the new bull market with mass hacks? We break down the numbers, AI's real role, and the token fallout.

AIMarket
23 Sep, 202612 min read
Join Our Socials

Key Takeaways

  • A record number of hacks, but less money stolen than a year earlier. H1 2026 logged 207 incidents by TRM Labs' count, up from about 83 a year earlier, yet stolen value fell to $972M, from $2.3B a year earlier.
  • Vendors disagree on the trend. TRM reads H1 2026 losses as down 57% year-over-year. CertiK reads the same window as losses up 28% once the 2025 Bybit theft is stripped out.
  • North Korea drove most of the losses. Roughly 66% (~$643M) of TRM's total traced to DPRK-linked groups, with about 90% of that from two April attacks.
  • AI mostly scales scams so far. The only named AI-agent hack losses are small — about $216K (Bankr) and $100K (Zerion).
  • A mint hack is a supply event. KelpDAO re-backed its rsETH in about five weeks; Syscoin burned ~5B minted SYS; Harmony absorbed ~26% inflation.
  • Price rarely bounces back fast. Immunefi found 83.9% of hacked tokens still trading below their pre-hack price six months later.

How Many Crypto Hacks in 2026, and How Much Was Stolen

Crypto hacks hit a record in H1 2026: 207 incidents by TRM Labs' count, the highest-incident six-month period on record. The stolen totals diverge: TRM logged $972M, down 57% from 2025, while CertiK counted $1.31B under a broader taxonomy. North Korea-linked groups drove roughly two-thirds of the losses.

Every major vendor agrees on frequency: the latest crypto hacks put the first half of 2026 on record as the busiest six-month stretch they have measured. TRM Labs put the count at 207 incidents (as of Sept 22, 2026), up from about 83 in H1 2025. Blockaid counted 212, and CertiK 344 under a wider definition that folds in phishing and wallet compromise.

Dollar value is where they part ways. The table below reconciles the main tallies.

VendorIncidentsValue stolen (H1 2026)DPRK shareNote
TRM Labs207$972M (−57% vs $2.3B)~$643M ≈ 66%Infrastructure and key compromises were ~15% of incidents but ~76% of all money stolen
Immunefi207$972M (<½ of H1'25)not specifiedCounts DeFi only ($680.3M), averaging ~$24.5M per attack (March interim)
Blockaid212~$1.1B~$609M ≈ 55%3.4x more large exploits than in all of 2025
CertiK (Hack3D)344$1.31B (net ~$1.2B)not specifiedBroader definition (adds phishing and wallet theft); +28% YoY once Bybit is excluded
Quill Audits~$935.3MSecondary estimate, not a primary source
Finbold~$955MMedia estimate

Source: TRM Labs, Blockaid, CertiK, Immunefi reports, as of 2026-09-22.

The −57% headline and the +28% counter-reading both hold up, and they are not a contradiction: TRM keeps the $1.5B Bybit theft in its 2025 base, so 2026 looks like a sharp drop. CertiK strips that single outlier out and finds losses actually rose 28% year-over-year. The gap between the two numbers is a methodology choice, so both estimates are worth weighing.

TRM Labs laid out the split directly in its mid-year summary:

@trmlabs — more hacks, less money: the lower total reflects the absence of another Bybit-scale theft, not weaker attackers, with DPRK-linked infrastructure attacks doing most of the damage.

The North Korea attribution is not abstract. Most of these losses trace to the Lazarus Group, and DropsTab Research keeps a dedicated public portfolio of its attacks that you can follow.

DropsTab Research tracks Lazarus Group-linked wallets in a public portfolio — ~$1.21B, BTC-dominant, as of 2026-09-23.

The vector split matters more than the total. By TRM's count, smart-contract exploits made up 125 of 207 incidents but only about 17% of stolen value. Infrastructure and key compromise ran the opposite way: roughly 15% of incidents, about 76% of the money.

Blockaid attributes about 74% of losses to operational and key theft. CertiK's own breakdown puts Wallet Compromise at $445M across 33 events, Phishing at $366M across 63, and Code Vulnerability at just $152M across 204.

How AI Is Lowering the Attack Barrier

AI is measurably scaling crypto scams and fraud, but its role in hack losses stays largely a forecast. Chainalysis and TRM Labs document AI-driven scam growth in hard numbers. On the hack side, only two named 2026 losses — Bankr and Zerion — carry a direct AI-agent attribution, and both are small.

On the scam side, the data is concrete: Chainalysis found that AI-enabled scams extract $3.2M per operation against $719K without AI (as of 2026) — about 4.5 times more profitable — and move roughly nine times the transfer volume.

Impersonation scams rose 1,400% year-over-year, inside a broader ~$17B crypto-fraud figure for 2025. TRM's AI-in-crime index climbed to 54 out of 100 in 2026, from about 28 in 2024, with scams the only category it rates "Mature." CertiK reports phishing as the leading vector, up 200% year-over-year.

Hack losses are a different question, and the evidence there is thin. The only forensically-attributed AI-agent hack loss of 2026 is Blockaid's Bankr case — about $216K (Blockaid's estimate) via prompt injection in May. Bankr is exactly the kind of agent that on-chain payment rails such as x402 are built to serve, and every new agent that holds or moves funds becomes a fresh target.

CertiK ties a $100K Zerion loss to North Korea-linked AI social engineering. Against that, Blockaid pins about 74% of H1 2026 losses on plain infrastructure and operational compromise. Google's Mandiant flagged a deepfake campaign by the group UNC1069 but stated it could not verify that AI was actually used.

The intersection runs the other way too: the AI-token projects themselves are targets. In September 2026, one attacker used stolen keys to mint unauthorized supply across the Fetch.ai, SingularityNET and NuNet ecosystem (the ASI Alliance) — inflating NTX, AGIX and WMTx while draining FET, with roughly $2.25M cashed out before the teams paused the affected bridges. The root cause was compromised keys, not any AI weakness — the same operational failure that drives most 2026 losses.

PeckShield traced the coordinated mint on-chain as it unfolded:

@PeckShieldAlert — the same exploiter minted 260M AGIX and 53.8M WMTx on Ethereum after hitting Fetch.ai and NuNet, holding ~$16.77M at the time of the alert.

Agents that move money through on-chain payment rails are grouped on DropsTab in the x402 ecosystem category — Bankr among them. It is a convenient way to watch these assets in one place, and to stay doubly cautious with any that move funds on their own.

DropsTab’s x402 ecosystem category groups the protocols and agents built on on-chain payment rails — as of 2026-09-23.

The AI projects themselves sit in a separate AI agents category, from FET (ASI Alliance) to hundreds of smaller tokens. It is worth keeping on your radar so you can factor these risks into your risk-management strategy.

DropsTab’s AI agents category collects AI-token projects, from FET (ASI Alliance) to hundreds of smaller ones — as of 2026-09-23.

Code-generation risk is real but unrealized in crypto so far. Veracode found 45% of AI-generated code samples carried an OWASP Top-10 vulnerability, and a CSA/Georgia Tech review logged 74 CVEs in AI tooling by early 2026. Yet no named 2026 crypto loss traces to AI-written contract code.

On AI, the takeaway holds: it accelerates scams, not hacks. The more fundamental threat is the cryptography itself. Quantum computers will eventually derive private keys from public ones, and every wallet rests on those keys. That is a risk on a longer horizon — the subject of our quantum-resistant blockchains breakdown.

What Happens to the Token After a Hack

A mint hack inflates a token's supply from nothing, and the outcome depends on how fast the team contains it. Two patterns recur: burn-and-restore, where minted tokens are recovered and destroyed, and sunset-and-reissue, where the old token is retired for a new one. Speed of response decides the damage more than the headline dollar figure.

The dollar amount stolen tells you little about what happens to the token. A mint exploit creates fresh supply that either gets unwound or hangs over the market. The table tracks that supply outcome for the year's mint-driven events — no prices, just what happened to the tokens.

IncidentDateAmountChainToken / supply outcome
KelpDAO rsETHApr 18, 2026~$292M (116,500 rsETH ≈ 18% supply)EthereumUnbacked mint of ~116,500 rsETH, fully re-backed by ~May 25, 2026 (~5 weeks); rsETH markets paused across DeFi; peg held on mainnet
Syscoin SYS~Jun 8, 2026~$9–10MSyscoin~5B unauthorized SYS minted; team recovered and burned all ~5B; supply restored
Harmony ONEAug 12, 2026mint-drivenHarmony L1~4B ONE minted ≈ 26% inflation; ~97% cashed onto exchanges; durable hit; a proposed L1 sunset and ETH migration followed in Sept 2026
Humanity $HJun 8, 2026~$32–36MBNB Chain~100M $H minted; token fell ~80–90% intraday; old $H sunsetted, replaced by a new audited ERC-20 plus recovery airdrop
The Sandbox SANDAug 21–22, 2026~$675K realizedEthereum/Base/BSC~14.9B unbacked SAND minted (~5x legit supply) but only ~14.75M extracted before bridging halted; no lasting supply change
Hyperbridge bridged-DOTApr 13, 2026~$237K–$240KEthereum (bridge)~1B fake bridged DOT minted; native Polkadot DOT supply unaffected
WEMIX$Jul 26, 2026~$724K moved (media)WEMIX L1Minted 5,225,525 WEMIX$, a USDC-backed stablecoin; native WEMIX supply stayed flat; the 2025 Korean delisting was a regulatory action
Echo ProtocolMay 18, 2026~$76.7M minted / ~$816K realizedMonad1,000 eBTC minted from an uncapped admin key; thin liquidity capped the actual theft; 955 eBTC burned and the mint authority revoked; Echo Protocol and its ECHO token stay active
ASI AllianceSep 19–21, 2026~$2.25M cashed (≈$16.8M held)EthereumOne attacker used stolen keys to mint ~408.5M NTX, ~260M AGIX and ~53.8M WMTx and drain ~8.7M FET across the Fetch.ai / SingularityNET / NuNet ecosystem; AGIX→FET conversion and the ETH bridge were paused

Source: incident post-mortems and on-chain data; token supply confirmed against DropsTab, as of 2026-09-22.

Uncapped supply is the risk multiplier. Syscoin, Harmony and Humanity all run without a max-supply cap, so a mint exploit expands total supply directly, while The Sandbox's fixed 3B cap meant its ~14.9B minted tokens never became durable supply. DropsTab data, as of 2026-09-22.

That gives a clean supply-recovery test few trackers apply. By it, Syscoin, KelpDAO and The Sandbox all returned to their pre-hack supply — burned, re-backed or contained — while Harmony's total remains roughly 26% inflated and Humanity retired its token entirely for a fresh one. The dollar figure fades from view faster than the supply record does.

A mint hack is a supply event; the completeness of containment, not the dollar figure, decides the damage.

Two big thefts belong beside the table as counter-examples. Drift lost ~$285–295M on April 1 through fake "CVT" collateral and a Solana durable-nonce trick, but no DRIFT was minted — supply stayed intact, and about $147.5M was rescued.

Bybit is the largest theft of all, yet it was a CEX cold-wallet drain with no token aftermath to track. One structural thread runs through the biggest mint events: compromised LayerZero infrastructure, and how quickly each team froze it decided the supply result.

KelpDAO shows the good outcome — it re-backed every minted token:

@KelpDAO — the final tranche of 20,373.72 rsETH closed the recovery plan; rsETH has been fully backed since the unpause.

The Biggest Incidents of 2026 and Their Attack Vectors

  • Bybit — ~$1.5B (Feb 21, 2025, the largest crypto theft on record). Attackers compromised a Safe{Wallet} developer machine and injected JavaScript on the signing interface; "blind signing" defeated the multisig. The FBI attributed it to DPRK's TraderTraitor. Laundering ran ETH into BTC through THORChain — about $1.4B, roughly 83% converted across 6,954 wallets, with about 20% gone dark. In August 2026, Bybit won a preliminary injunction freezing assets (~$48.4M recovered, over $30.5M frozen across 28+ custodians), enforceable against John Doe holders but largely symbolic against a sovereign attacker. This is the H1 2025 outlier behind TRM's −57%.
  • KelpDAO — ~$292M (Apr 18, 2026), the largest DeFi hack of 2026. A 1-of-1 LayerZero DVN, poisoned RPC nodes, and a DDoS failover did the work; no contract was exploited. The breach began March 6 through a social-engineered LayerZero developer.
  • Drift — ~$285–295M (Apr 1, 2026). Attackers whitelisted fake CVT collateral after months of social engineering, then used Solana durable nonces to pre-sign an admin handover.
  • Liquid Network — ~4,000 BTC (~$320M, Sep 6, 2026). This one is a Bitcoin sidechain rather than a DeFi protocol, so it sits outside the "largest DeFi hack" ranking above. A cryptographic flaw in Blockstream's Elements code — a range-proof cache-key collision, not a stolen key — let the attacker mint about 4,000 unbacked L-BTC and drain nearly all of the sidechain's reserves. Self-declared white hats returned 3,400 BTC and kept 598.5 BTC (~$48M) as a bounty; the white-hat label is disputed, and Blockstream did not publicly pay.

The video below shows how the KelpDAO exploit's blast radius reached past its own token. Aave founder Stani Kulechov breaks down how a single bridge failure left the lending protocol carrying roughly $200M in bad debt.

In most incidents the vector is the same — infrastructure, key, and social-engineering compromises move the real money, while smart-contract exploits are frequent but small. Liquid is the rare exception, where the flaw sat in the cryptography itself rather than with the operators.

Blockstream made the same point on X:

@Liquid_BTC — a range-proof caching bug in the Elements software minted ~4,000 unbacked LBTC; the team stressed no keys were compromised and that ~598.5 BTC remains outstanding.

A Hack's Blast Radius Beyond the Token

The stolen token is only the first-order loss. A 2026 exploit's real damage often lands on the lending protocols around it and on the venture money that funded the project. DropsTab and DefiLlama data show second-order hits that can dwarf the headline theft by an order of magnitude.

KelpDAO is the clearest case: its own vaults barely flinched (re-backing held total value locked near $1.6B through the incident), but Aave, left holding the bad debt, shed about $12 billion in TVL over six days, from roughly $26.4B to $14.3B (DefiLlama, April 2026). A $292M theft triggered a value exodus roughly forty times its size. Drift shows the other pattern: its own TVL halved overnight, from about $550M to $252M on April 2, and never recovered.

ProtocolHackOwn TVLSecond-order damage
Drift~$290M (Apr 1)~$550M → ~$252M overnight (−54%), no recovery
KelpDAO~$292M (Apr 18)~$1.64B → ~$1.52B (−7%), recovered within days
Aave— (held the bad debt)~$26.4B → ~$14.3B in six days (−46%, ~$12.1B)

Source: DefiLlama protocol TVL, April 2026.

The money behind the hacked projects tells its own story, and it is one only a data platform with both a funding cap-table and token supply can join. DropsTab's funding records show Drift had raised about $52M — seeded by Multicoin, Polychain, Jump and Alameda — before losing roughly $292M, then took a $145M debt lifeline from Tether to plug the hole.

Humanity had raised more than it lost. And Ronin, the field's long-running cautionary tale, pulled in $150M from a16z alone before its bridge was drained.

ProjectRaisedLost to hackLead backers
Drift~$52M (+ $145M Tether debt after)~$290MMulticoin, Polychain, Jump, Alameda
Humanity~$50M~$32–36MAnimoca, Shima, Kingsway
The Sandbox~$120M~$675K (contained)Animoca, Galaxy
Ronin (context)~$159M ($150M a16z)2022 bridge, $625Ma16z

Source: DropsTab funding data, as of 2026-09-22.

How to Check a Token's Post-Hack Health

Recovery in 2026 followed a few archetypes:

  • Burn-and-restore. Syscoin recovered and burned all ~5B minted SYS.
  • Full re-backing. KelpDAO's rsETH was restored in about five weeks.
  • Sunset-and-reissue. Humanity retired its old token for a new audited ERC-20 plus an airdrop, Harmony proposed an ETH migration, and Drift switched to a recovery token backed by a ~$147.5M rescue.
  • Negotiated return. On Liquid Network, self-declared white hats sent back 3,400 of the ~4,000 BTC they drained and kept the rest as a bounty — a partial recovery that hinges entirely on the attacker's goodwill.

Keep expectations modest: Immunefi's data says most hacked tokens stay underwater for months, so a fast price rebound is the exception. Delisting is a weak signal for 2026 — no hack-triggered delisting was confirmed, and WEMIX's 2025 Korean delisting was a regulatory action unrelated to any exploit.

To read a token's post-hack health yourself, work through four checks:

  • Compare the current total and max supply against the pre-hack figure for any mint event.
  • Confirm whether the minted supply was burned or still sits outstanding.
  • Check whether the token still trades on major exchanges or was quietly removed.
  • Watch for a token replacement or reissue, which resets the supply picture entirely.

To make that check practical, the DropsTab Research team built a dedicated Hacked & Exploited Tokens tab — the eight survivors from this article in one live table. It puts three of the four checks in adjacent columns: circulating supply and its share of the total, the exchanges still listing each token, and the CertiK audit score. SAND and FET still hold AA-grade audits, Drift sits at BBB after falling about −85%, and WEMIX has no CertiK coverage. Sort it by any column, or clone it and add your own.

Eight tokens that survived a 2026 hack, side by side: CertiK audit grade, supply and listings — as of 2026-09-23.

But even these checks do not always work. In privacy-preserving chains, supply integrity can be impossible to even verify — from 2022 to 2026, Zcash holders could not prove that no counterfeit ZEC had been minted inside its shielded pool, even though the hard 21M cap still held. We cover how that works in Zcash vs Bitcoin.

Both coins cap at 21 million; only Bitcoin's supply is node-verifiable. Zcash's in-pool integrity was unprovable 2022–2026 until Ironwood. Source: DropsTab, Shielded Labs, as of September 15, 2026.

How to Track a Hacked Token's Supply and Delisting on DropsTab

According to DropsTab data (as of Sept 22, 2026), several of the hacked tokens here — Syscoin, Harmony and Humanity — carry an uncapped max supply, which is exactly the condition that lets a mint exploit move total supply so fast.

Check each hacked token's live supply and where it trades on DropsTab to see whether a mint was burned or is still outstanding, and check whether any venue has dropped it.

AI is not a threat to crypto in its own right yet, but it speeds up how fast attackers find weaknesses. Will it break the bull run with a wave of hacks? Not yet. Still, vetting the projects you put money into deserves more care now — so you are not among those whose funds an automated exploit walked off with. DYOR.

Latest Articles