Cryptorank Crypto Hacks in 2026: $2.2B Lost Amid Rising Threats
Article Content
- •Crypto security losses in 2026 total $2.21 billion across 288 incidents.
- •4% of attacks accounted for 75% of the total stolen funds.
- •Operational vulnerabilities are now the most common attack vector.
In 2026, cryptocurrency security losses have reached approximately $2.21 billion across 288 reported incidents. The first half of the year saw 207 hacks, a significant increase from 83 in the same period of 2025. Major losses were driven by infrastructure and operational failures, with 4% of attacks accounting for 75% of stolen funds. Notable incidents include breaches at Liquid Network, Bitget, KelpDAO, and Drift Protocol, which collectively resulted in hundreds of millions lost. The median loss per incident was around $219,000, while the mean loss was approximately $4.7 million. Smart-contract exploits were the most common attack vector, although operational vulnerabilities accounted for the majority of losses. The rise in attacks coincides with increased AI-enabled social engineering risks. The current state of crypto security highlights the urgent need for improved risk management and security practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track 0x8B84 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Exaforce Launches AI Security Tool to Combat Rogue Agents Exaforce has introduced Exaforce AI Security, a platform designed to monitor and control AI agents within enterprise environments. The tool addresses vulnerabilities in enterprise logging that attackers exploit to hide malicious activities under legitimate user actions. Recent incidents have shown how compromised AI…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…