According to a report by Onchain Lens, the largest losses for crypto projects are related to the compromise of access control mechanisms. By obtaining privileged rights or access to critical credentials, attackers were able to carry out the most profitable attacks of the half-year. The greatest losses were incurred by:
-
Kelp DAO — $292 million;
-
Drift Protocol — $280 million;
-
Humanity Protocol — $31 million;
-
Step Finance — $30 million;
-
Truebit — $26.5 million.
The second largest cause of losses was phishing attacks and the use of social engineering methods. Approximately $282 million was stolen using this method. Another vulnerability turned out to be oracles—services that transmit external data to the blockchain. Due to attacks related to this infrastructure, the Ostium project lost $24 million, Blend Protocol — $10.86 million, and Bonzo — $9 million.
Onchain Lens statistics show: the total volume of damage was formed not by hundreds of separate incidents, but by a limited number of the most effective attacks. Simultaneously, the nature of threats is changing: increasingly, the cause of multi-million dollar losses is not errors in smart contracts, but the compromise of keys, permissions, and other access control mechanisms.
Security specialists stated that the human factor remains one of the main risks for the industry. Despite the development of protective measures, phishing and social engineering continue to bring attackers hundreds of millions of dollars, maintaining effectiveness on par with technical attacks.
Earlier, analysts from the company Blockaid reported a hack of the cross-chain bridge of the decentralized exchange AFX Trade. As a result of the attack, the attackers stole USDC stablecoins amounting to $24.15 million.
end-content




