$840M Lost to DeFi Exploits in Six Months
212 Exploits, $840 Million Gone, and the Year Is Not Over
DeFi protocols lost over $840 million to exploits in the first half of 2026 across 212 separate incidents. April alone accounted for $635 million, roughly quadrupling the $167 million stolen during the entire first quarter. These proved to be structural failures that recur because the incentives to attack still outweigh the cost of prevention.
The two largest incidents, KelpDAO at $292 million and Drift Protocol at $285 million, together represent more than two thirds of the year's total losses. A similar pattern that neither was a traditional smart contract bug. Both exploited infrastructure and governance weaknesses that audits were never designed to catch. The nature of DeFi security risk is shifting, and the defences have failed to keep up.
KelpDAO: $292 Million Through the Infrastructure
On April 18, attackers drained approximately $292 million from KelpDAO by compromising the protocol's cross-chain bridge infrastructure. The attack targeted off-chain RPC nodes rather than smart contract logic.
Attackers compromised internal nodes and launched distributed denial of service attacks against external ones, feeding false data to a single verifier network that operated on a 1-of-1 configuration.
The 1-of-1 DVN (Decentralized Verifier Network) setup meant there was no redundancy. A single point of failure controlled the verification of cross-chain messages, and once that point was compromised, the attackers minted 116,500 unbacked rsETH tokens across 20 chains. The exploit was a result of architecture that placed critical infrastructure behind a single gate with no fallback.
This type of attack is harder to prevent because it does not show up in a smart contract audit. Auditors review Solidity code for reentrancy bugs, integer overflows and access control flaws. They do not typically evaluate the operational security of the RPC infrastructure, the DVN configuration, or the social engineering resilience of the team running the nodes.
Drift Protocol: $285 Million and Months of Preparation
The Drift Protocol exploit on April 1 was attributed to North Korean operatives who spent months embedding themselves within the project's operations. This was social engineering at an institutional level: attackers infiltrated the team, gained access to internal systems, and executed a $285 million drain from the Solana based perpetual futures protocol.
The Drift attack emphasizes a category of risk that technical security measures cannot fully address. No amount of smart contract auditing protects against a compromised insider with legitimate access.
The attack vector was human, not computational, and the scale of the loss shows how much value sits behind access controls that assume good faith from authorised personnel.
North Korea Accounts for 76% of Losses
Chainalysis and TRM Labs attribute approximately 76% of all crypto related hack losses in 2026 to state backed actors linked to North Korea's Lazarus Group. That figure represents nearly $600 million of the $840 million total, concentrated across a small number of high value targets.
The Lazarus Group has industrialised crypto theft. Their operations involve months of reconnaissance, social engineering campaigns that target specific employees at specific protocols, and sophisticated laundering infrastructure that moves stolen funds through mixing services and cross-chain bridges within hours of an exploit. These are a state funded operation with the resources of a national intelligence service.
The concentration of losses in state backed attacks creates a paradox for the DeFi security industry. The most common vulnerability categories, smart contract bugs and oracle manipulation, account for a minority of actual dollar losses.
The majority of value is lost through operational security failures and social engineering that target the humans operating the protocol rather than the code running it.
AI Is Accelerating Attack Speed
A concerning development in 2026 is the role of artificial intelligence in exploit discovery. AI coding agents can now scan codebases, identify vulnerability patterns, and generate exploit payloads at speeds that human auditors cannot match.
The asymmetry between attack and defence has always favoured attackers in software security, but AI tools are widening that gap.
The same AI capabilities that help developers write and audit code also help attackers find flaws faster. A vulnerability scanner that takes a human auditor days to run manually can now execute in minutes.
The implication for DeFi protocols is that the window between deploying code and having it probed for weaknesses is shrinking. Protocols that rely on pre-deployment audits as their primary security measure are operating on assumptions about attacker timelines that are no longer valid.
What the Numbers Mean for Users
The $840 million in H1 2026 losses is a tax on the DeFi ecosystem that every user pays through reduced trust, higher insurance costs and the opportunity cost of capital that stays on the sidelines because the security track record is not convincing.
The figure also understates the total impact because it excludes rug pulls, governance attacks that do not trigger exploit classifications, and losses from protocols that shut down quietly without public incident reports.
For users evaluating where to deploy capital, the data suggests three practical considerations.
First, bridge infrastructure remains the highest risk category by dollar amount. Cross-chain protocols that rely on small validator sets or single point verification networks carry disproportionate risk relative to protocols operating on a single chain.
Second, the team behind a protocol matters as much as the code. Operational security practices, insider threat policies and access control hygiene are not visible to users but determine whether a $200 million treasury can be drained by a compromised employee.
Third, audits are necessary but not sufficient. A protocol can be audited by four firms and still lose everything through an infrastructure attack that no audit scope would have covered.
Explore DeFi Safely with Portals
Portals.fi is a DeFi aggregation platform that lets users swap tokens, discover yields and manage positions across major blockchains from a single interface.
Whether you are evaluating new protocols or managing an existing portfolio, Portals searches across hundreds of liquidity sources to find the optimal route for every transaction.
Visit portals.fi to get started.
This article is for informational purposes only and does not constitute financial advice. DeFi protocols carry inherent risks including smart contract vulnerabilities, bridge exploits and operational security failures.
Always conduct your own research before interacting with any protocol. For our full disclaimer, please visit disclaimer.
Portals.fi Blog Newsletter
Join the newsletter to receive the latest updates in your inbox.