DeFi Has Lost $1.3 Billion to Exploits in 2026 as Stolen Keys Overtake Code Bugs

Compromised private keys, not smart-contract flaws, are now the leading cause of DeFi losses for the first time on record, with two Lazarus-attributed hacks on Drift and KelpDAO accounting for roughly $575 million of this year's total.

Decentralized finance protocols have lost at least $1.3 billion to exploits in the first eight months of 2026, according to figures from security firm CertiK's Hack3d report cited by Forbes and crypto.news. The headline number is large, but the more important finding is what changed underneath it: for the first time on record, compromised private keys and infrastructure, rather than bugs in smart-contract code, are the leading cause of losses.

Two hacks, $575 million

Almost half of the year's damage traces to two incidents 17 days apart. On April 1, Drift Protocol lost about $285 million after attackers spent months social-engineering their way to an admin key and then drained the protocol in roughly two minutes. On April 18, KelpDAO lost about $290 million through a hijacked developer session tied to its LayerZero bridge verifier.

Investigators including Mandiant, CrowdStrike, Elliptic and LayerZero have attributed both attacks to North Korea's Lazarus Group, specifically its TraderTraitor subunit. That puts roughly $575 million, or about 44% of 2026 losses, on a single state actor. Counting the February 2025 Bybit theft, the group's 18-month tally exceeds $2 billion.

The rest of the list

  • Coldcard wallets, July 30: about $130 million linked to a firmware random-number-generator weakness.

  • AFX Trade, July 22: about $24 million after five validator signatures were compromised.

  • Cosmos EVM chains, August: about $21 million across three chains via a cross-shard receipt replay.

  • VerusCoin, May and July: about $19 million across two bridge-verification exploits.

Smaller key-compromise cases documented by Blockaid in the first half include Conduit (about $6.6 million via a compromised admin account), Wasabi Protocol (about $5 million across four chains) and StakeDAO (a compromised deployer key).

Why audits no longer cover the biggest risk

CertiK co-founder Ronghui Gu told Forbes that a protocol can pass a flawless code audit and still lose millions because of a compromised admin key. Security firm CredShields, in its Drift post-mortem, described the attack surface as having moved up the stack to governance, signers and the people building protocols. The pattern in 2026 is phished developer laptops, compromised executive devices, cloud key-store breaches and hijacked RPC nodes, not clever arithmetic in a contract.

What users and teams can do

  • Ask how a protocol's admin and upgrade keys are held: multisig thresholds, hardware isolation and timelocks matter more than the audit badge.

  • Treat bridges and cross-chain verifiers as the highest-risk component; both nine-figure losses this year went through them.

  • For teams, harden developer endpoints and CI pipelines as seriously as production infrastructure; that is where the year's largest thefts started.

Loss figures vary between trackers depending on what is counted (DeFi only versus all crypto, and whether recovered funds are netted out); TRM Labs, for example, put DeFi-only losses just under $1 billion for the same period. Nothing in this article is investment advice.

Featured image: "The gate's unlocked!!!" by Tripp via Flickr, licensed under CC BY 2.0.