Cryptomarket Loses $14 Billion Due to Hacks. What Was Special About 2026?

cryptonews.ruPublicado a 2026-08-13Actualizado a 2026-08-13

Resumen

The cryptocurrency market lost over $14 billion due to hacks and code exploits from 2016 to 2026, according to a CoinGecko report. The year 2026 has seen a significant spike, with 164 separate incidents recorded as of August—a 70% increase from all of 2025. Although the total financial loss for 2026 currently stands at about $1.2 billion, still below the peak of $2.77 billion in 2022, the number of attacks is unprecedented. Analysts attribute this rise to improved tracking methods and increased malicious activity, possibly fueled by advancements in artificial intelligence. Notable 2026 breaches include the April hacks of Drift and Kelp protocols, resulting in losses of $295 million and $293 million, respectively. The Kelp exploit, linked to North Korean hackers, involved minting unbacked tokens via a LayerZero bridge vulnerability, which were then used as collateral on Aave. This triggered a massive withdrawal of liquidity from Aave and the broader DeFi sector, leading to over $20 billion in sector-wide outflows by August, despite the eventual recovery of the stolen Kelp funds. The report also highlights that market reactions to hacks often inflict greater financial damage than the exploits themselves. For instance, following the BonkDAO hack, the token's market cap fell by nearly $140 million, far exceeding the $21 million direct loss. Other examples include the DRIFT token dropping 80% and Step Finance's token losing over 99% of its value, leading to the protocol's bankru...

"RBC-Crypto" does not provide investment advice, the material is published for informational purposes only. Cryptocurrency is a volatile asset that may lead to financial losses.

Over the period from 2016 to 2026, decentralized finance (DeFi) protocols and cryptocurrency exchanges collectively lost more than $14.27 billion due to hacker attacks and code errors, according to a report by the analytical platform CoinGecko. And in 2026, as of August, more incidents have already been recorded than in any previous period, although the total amount of losses still lags behind the peak year 2022.

According to CoinGecko, 164 separate incidents have already been recorded in 2026, which is approximately 70% more than the entire previous year—in 2025 there were 97 cases. The year with the highest total damage for the crypto industry remains 2022 at $2.77 billion, slightly ahead of the 2021 figure of $2.66 billion. As of early August 2026, the damage amounted to about $1.2 billion.

Experts attribute such a sharp spike not only to improved methods of tracking attacks but also to increased activity by malicious actors against the backdrop of the development of artificial intelligence.

When compiling the report, CoinGecko used data from the REKT Database (DeFiWatch) for 2018–2022 and the DeFiLlama hack tracker for 2023–2026. Protocols without their own tokens were excluded from the analysis—specifically, centralized exchanges, bridges without native assets, and hardware wallets.

The data for 2026 is preliminary and covers the period from January to early August. To assess the damage from the price drop of individual tokens this year, analysts used the average market capitalization for seven days before the hack and compared it with the figures as of early August 2026.

At the same time, as the authors of the study emphasize, the actual damage could be significantly higher, as this amount does not include hacks of individual wallets and other ecosystem losses.

Crypto Project Hacks of 2026

The greatest damage to the crypto industry in 2026 was inflicted in April, which accounted for nearly $645 million in losses. Key events were the hacks of the Drift and Kelp protocols for $295 million and $293 million respectively.

Both attacks, according to analysts, were carried out by different malicious actors, presumably linked to North Korean hackers. And the Kelp hack is also distinct from others in that it caused damage across the entire DeFi sector.

The attackers exploited a vulnerability in the LayerZero bridge and minted unbacked tokens of the wrapped version of Ethereum—rsETH. They then used them as collateral in the Aave protocol to obtain real assets.

The consequences for Aave were catastrophic—the situation led to users withdrawing billions of dollars in liquidity. Total deposits in the protocol fell by approximately $4 billion over two days, and by early August, the figure had dropped to $14.70 billion.

Although by the end of May, through the efforts of the crypto community, the user funds stolen from Kelp were returned and all assets were restored to the protocols affected by the incident, a huge portion of the deposits across the entire DeFi sector never returned. Sector losses by August amounted to over $20 billion.

Token Price Drops Bigger Than the Hacks Themselves

In addition to the hacks and thefts themselves, CoinGecko analysts highlighted another level of financial damage that falls on token holders of hacked protocols. They noted that the market reaction to incidents often inflicts greater damage.

Experts highlighted the case of BonkDAO, where the damage from the market reaction significantly exceeded the damage from the hack: losses amounted to $21 million in reserves, while the token BONK's market capitalization shrunk by almost $140 million. According to Coingecko, "this shows that the market reaction can be more costly than the hack itself."

The report also provides examples where the DRIFT token of the Drift protocol (renamed to Velocity) fell 80% since the hack on April 1. And Resolv (RESOLV) recorded a 70% drop since March 2026. And the worst example—Step Finance, where a vulnerability led to the protocol's bankruptcy, and their token STEP lost more than 99% of its value.

Preguntas relacionadas

QAccording to the article, how much has the crypto market lost due to hacks and code errors from 2016 to 2026, based on CoinGecko's report?

AOver $14.27 billion.

QWhy is 2026 a notable year in terms of security incidents, despite not having the highest total losses?

ABecause by August, 2026 had already recorded 164 separate incidents, which is about 70% more than the entire previous year (97 cases in 2025).

QWhat were the two largest hacks of 2026 mentioned, and what was their combined estimated impact?

AThe two largest hacks were on the Drift protocol ($295 million) and the Kelp protocol ($293 million) in April, with a combined impact of nearly $645 million for that month.

QHow did the exploit of the Kelp protocol uniquely affect the broader DeFi sector beyond the direct theft?

AIt triggered a catastrophic withdrawal of user liquidity, particularly from the Aave protocol. Total deposits in Aave dropped by about $4 billion in two days, and the broader DeFi sector lost over $20 billion in deposits by August.

QAccording to CoinGecko's analysis, what type of damage often causes more financial loss to token holders than the hack itself?

AThe market reaction and the subsequent fall in token prices often cause more financial damage than the direct losses from the hack.

Lecturas Relacionadas

Token Buyback Volumes Continue to Rise, But Price Lows Keep Falling

The volume of token buybacks continues to grow, but the minimum price level is constantly declining, according to an internal memo by Bitwise CIO Matt Hogan. He argues that most crypto tokens, except Bitcoin, are undervalued as investors are unaware of the revenue now being returned to holders. He highlights the example of Hyperliquid, which has bought back and burned $1.3 billion worth of its $HYPE token. Hogan posits that tokens are beginning to trade based on revenue, similar to stocks and bonds, marking the end of an era where scaling networks provided little token utility. He links token valuation to strengthening protocol revenue, noting that Hyperliquid has earned over $800 million in the past year and spends nearly all fees on $HYPE buybacks. Following this model, protocols like Uniswap and Aave have implemented fee mechanisms to buy back and burn their own tokens. The trend has also affected base chains like Solana and Aptos, which have proposed or enacted higher fee burns. However, the memo acknowledges that reducing token supply has not reliably boosted prices. A Cryptopolitan report found many tokens with regular buybacks still underperformed the market. Even Hyperliquid's upward trend broke, and Pump.fun conducted significant buybacks near token lows. Hogan cautions that token buybacks differ from stock buybacks due to the lack of contractual claims on profits or assets, as governance rules can always be rewritten.

cryptonews.ruHace 42 min(s)

Token Buyback Volumes Continue to Rise, But Price Lows Keep Falling

cryptonews.ruHace 42 min(s)

NullReceiver abandons the recording address that made EtherHiding easy to detect

**Sonatype Research Labs has uncovered six malicious npm packages that retrieve command-and-control server addresses from an attacker's Ethereum wallet.** Three of the packages are legitimate, popular libraries that were compromised: `@kolbo/mcp`, `agentgui`, and `godot-kit`. The other three are purely malicious packages: `envpack-conf`, `postcss-initial-provider`, and `tailwindcss-motion-advanced`. All six deploy the same payload. The malware loader queries the Ethereum blockchain for the latest outgoing transaction from a specific wallet. It extracts bytes from the recipient field of that transaction, converts them into two IPv4 addresses, and uses these as primary and backup command-and-control servers. After connecting, it fetches, decodes, and executes a second-stage payload using `eval()` or by spawning a child process. This method, dubbed **"NullReceiver,"** is an evolution of the earlier "EtherHiding" technique. While EtherHiding hid data in transaction fields and sent funds to a fixed "burner" address (creating a monitoring point), NullReceiver sends no funds and generates unique, dynamic receiver addresses, making detection harder. OpenSourceMalware has linked this activity to the North Korean Lazarus group's "Contagious Interview" campaign. Sonatype advises developers to remove the affected package versions immediately and check their systems for signs of secondary payload execution.

cryptonews.ruHace 44 min(s)

NullReceiver abandons the recording address that made EtherHiding easy to detect

cryptonews.ruHace 44 min(s)

Trading

Spot
活动图片