Hackers Torch $940M In 6 Months, and Security Audits Missed 94% of It
Crypto traders had been fleeced of virtually a billion {dollars} within the first half of 2026, and the trade’s favourite consolation blanket did little to cease it.
Security analysis home ack3 has verified 135 exploits between January and June, with $939.86m in attributed losses, averaging $6.96m every time the alarm sounded. The agency has printed its full incident dataset overtly, so each quantity could be checked line by line.
Here’s the stat that ought to chill each retail holder: of the cash stolen from audited initiatives, 94.4% walked out by means of code or infrastructure the auditors by no means examined. The inexperienced tick coated the entrance door. The thieves got here by means of the loading bay.
The Mega Heists Major Crypto Audits Missed
Two mega-heists account for the majority of the carnage, and neither was a bug that an auditor missed.
Kelp DAO’s rsETH hemorrhaged $292m in April after attackers solid a LayerZero cross-chain message by compromising the protocol’s single message verifier – one checkpoint, no backup.
Two weeks earlier, Solana perps big Drift misplaced $285m when operatives – linked by researchers to North Korea – spent months socially engineering their approach to admin keys. Between them: $577m, roughly 61% of every thing stolen all half. Not damaged maths. Broken keys and damaged belief.
The sample repeats down the ledger. Step Finance ($40m), Humanity Protocol ($32m), and Resolv’s USR stablecoin ($24.5m) had been all drained by means of compromised non-public keys and signing infrastructure, the people, not the sensible contracts. Cross-chain bridges had been the opposite killing subject, from Verus ($11.5m) to Syscoin ($8m) to Taiko ($1.7m).
Nowhere was protected, not even the blue chips. Polymarket was hit twice: a $700k inner pockets drain in May, then a $3.1m front-end supply-chain assault in June that turned its personal web site right into a pockets drainer.
CoW Swap had its area hijacked from beneath it. And within the half’s most poetic entry, feared MEV bot jaredfromsubway.eth, which spent years farming retail merchants, was itself fleeced for $7.5m by a honeypot token.
The unaudited crowd fared no higher. Truebit coughed up $26.4m to a schoolboy integer-overflow error in its mint pricing.
DISCOVER: The Biggest Crypto Hacks of 2025
One Crypto Audit Isn’t Enough: Good Projects Are Checked Regularly
And on the uncommon events, had auditors reviewed the exploited code? The experiences had been principally stale; 17 of the 20 nearest related audits had been at the least six months previous by the point the hackers struck.
In a worrying prediction in regards to the rise of AI tooling, Ack3 CEO and Founder Josef Gattermayer stated:
The takeaway is brutal in its simplicity. “Audited” is a advertising and marketing phrase till you ask three questions: what precisely was reviewed, how way back, and who controls the keys at this time. In H1 2026, the sincere solutions had been too usually: not this bit, over a 12 months in the past, and one compromised key from a disaster.
The auditors can learn each line of the code. They can’t learn the developer’s thoughts when clicking a hyperlink from “HR”.
Discover: The Best Crypto to Diversify Your Portfolio
The publish Hackers Torch $940M In 6 Months, and Security Audits Missed 94% of It appeared first on Cryptonews.
