Losses from Hacks of Crypto Projects Exceed $1.3 Billion

cryptonews.ruPubblicato 2026-07-27Pubblicato ultima volta 2026-07-27

Introduzione

According to a report by Onchain Lens, crypto project losses from hacks have exceeded $1.3 billion this year. The primary cause of damage was the compromise of access control mechanisms, where attackers obtained privileged rights or critical credentials. The biggest losers were Kelp DAO ($292M), Drift Protocol ($280M), Humanity Protocol ($31M), Step Finance ($30M), and Truebit ($26.5M). The second largest cause of loss was phishing and social engineering attacks, accounting for approximately $282 million. Attacks on oracles—services that feed external data into blockchains—also caused significant damage, with Ostium losing $24M, Blend Protocol $10.86M, and Bonzo $9M. The data indicates that the total damage stems from a limited number of highly effective attacks, rather than hundreds of small incidents. A shift in threat patterns is noted, with multi-million dollar losses increasingly resulting from compromised keys and access permissions rather than smart contract bugs. Security experts emphasize that the human factor remains a major industry risk, as phishing and social engineering remain as profitable as technical attacks. In a related incident, Blockaid reported a $24.15 million hack of the AFX Trade decentralized exchange's cross-chain bridge.

According to a report by Onchain Lens, the largest losses for crypto projects are related to the compromise of access control mechanisms. By obtaining privileged rights or access to critical credentials, attackers were able to carry out the most profitable attacks of the half-year. The greatest losses were incurred by:

  • Kelp DAO — $292 million;

  • Drift Protocol — $280 million;

  • Humanity Protocol — $31 million;

  • Step Finance — $30 million;

  • Truebit — $26.5 million.

The second largest cause of losses was phishing attacks and the use of social engineering methods. Approximately $282 million was stolen using this method. Another vulnerability turned out to be oracles—services that transmit external data to the blockchain. Due to attacks related to this infrastructure, the Ostium project lost $24 million, Blend Protocol — $10.86 million, and Bonzo — $9 million.

Onchain Lens statistics show: the total volume of damage was formed not by hundreds of separate incidents, but by a limited number of the most effective attacks. Simultaneously, the nature of threats is changing: increasingly, the cause of multi-million dollar losses is not errors in smart contracts, but the compromise of keys, permissions, and other access control mechanisms.

Security specialists stated that the human factor remains one of the main risks for the industry. Despite the development of protective measures, phishing and social engineering continue to bring attackers hundreds of millions of dollars, maintaining effectiveness on par with technical attacks.

Earlier, analysts from the company Blockaid reported a hack of the cross-chain bridge of the decentralized exchange AFX Trade. As a result of the attack, the attackers stole USDC stablecoins amounting to $24.15 million.

end-content

Domande pertinenti

QWhat was the total reported damage from hacks to crypto projects in the first half of the year, according to Onchain Lens?

AThe total reported damage exceeded $1.3 billion.

QWhat was identified as the primary cause of the largest losses for crypto projects in the Onchain Lens report?

AThe primary cause was the compromise of access control mechanisms, where attackers gained privileged rights or access to critical credentials.

QWhich crypto project suffered the single largest loss mentioned in the article, and what was the amount?

AKelp DAO suffered the single largest loss mentioned, amounting to $292 million.

QBesides compromised access controls, what were the other two major categories of attacks leading to significant losses?

AThe other two major categories were phishing/social engineering attacks (resulting in about $282 million in losses) and attacks targeting oracle infrastructure.

QWhat trend in the nature of security threats does the Onchain Lens report highlight?

AThe report highlights a shift where multi-million dollar losses are increasingly caused not by smart contract bugs, but by the compromise of keys, permissions, and other access management mechanisms, alongside the persistent risk of human factors like phishing.

Letture associate

Sales Director Consulted with DeepSeek, Lost Job and 5 Million Rubles

Babuskinsky District Court of Moscow upheld the lawful dismissal of Ekaterina Remizova, sales director at GK Energoprof, for disclosing trade secrets. The employee was found to have forwarded company documents, including tender participation details and colleagues' salary data, to her personal email. Furthermore, she uploaded confidential reports with sales statistics, financial metrics, and cash flow data from the company's internal PowerBI resources into the external AI service DeepSeek. The court ruled that uploading such protected information into the DeepSeek AI system itself constitutes disclosure. An additional ground for dismissal was her disclosure of strategic company plans to a supplier, after which the counterparty ceased communication. The employer also cited systematic failure to meet sales targets. Following her dismissal, Remizova sued, demanding the termination be declared illegal, changed to "by mutual agreement," and seeking a contractual "golden parachute" of 5 million rubles. The court rejected the 5 million ruble claim, as such payment was only stipulated for mutual agreement or redundancy. While one disciplinary penalty was deemed unjustified, ordering the company to pay 10,000 rubles in moral compensation, the court largely sided with the employer, refusing to recognize the dismissal as unlawful. The case highlights risks associated with using external AI services. A security expert noted that DeepSeek's "Share" function creates links that can be indexed by search engines like Google, potentially turning temporary shares into permanent, publicly accessible digital traces containing corporate data.

cryptonews.ru1 min fa

Sales Director Consulted with DeepSeek, Lost Job and 5 Million Rubles

cryptonews.ru1 min fa

A Serious Threat is Looming for Bitcoin (BTC) and Cryptocurrencies: They Could Be the First Target!

The rapid advancement of quantum computing poses a serious threat not only to cryptocurrencies but to the entire encryption system, including banking. However, experts warn that the cryptocurrency market might be the first sector to suffer from this transformation. As predictions of a 'Q-Day' approach, the slow governance processes of cryptocurrencies, rather than their cryptography, could become the biggest obstacle to defending against quantum attacks. Quantum Xchange CEO Eddy Zervigon has compared cryptocurrencies to "canaries in the coal mine," stating that the first successful quantum-powered cyberattack is likely to target decentralized blockchain networks. While a cryptographically relevant quantum computer capable of breaking the elliptic curve cryptography underlying Bitcoin's signatures and banking security does not yet exist, work by giants like Microsoft, IBM, and Google suggests the threat is nearer than previously thought. The industry consensus estimates such a computer could emerge around 2029. Supporting this view, recent Google research indicates the number of physical qubits needed to break the cryptographic systems protecting Bitcoin and Ethereum has decreased by about 20 times compared to prior estimates, highlighting the accelerated danger. Zervigon concludes that Bitcoin's greatest risk lies not in its current cryptographic system, but in the slow pace of implementing major network upgrades.

cryptonews.ru47 min fa

A Serious Threat is Looming for Bitcoin (BTC) and Cryptocurrencies: They Could Be the First Target!

cryptonews.ru47 min fa

Crypto Outperforming Stocks: How Digital Assets Are Withstanding Macroeconomic Pressure

Crypto Outperforms Stocks Amid Macro Pressure Trading firm QCP Capital's report analyzes the divergent performance of crypto and stock markets ahead of the July 29 FOMC meeting. While major US stock indexes showed mixed results, with tech weakness pressuring the Nasdaq, crypto assets like Bitcoin (up ~11.6% in July) and Ethereum (up ~24.6%) have outperformed despite a challenging macro backdrop, including rising Treasury yields and risk-off sentiment. Key focus points include the upcoming Fed decision and commentary from Chair Kevin Warsh, which could signal the regulator's stance on inflation and growth. Spot Bitcoin and Ethereum ETFs saw a net outflow of ~$311 million on July 24, ending a seven-day inflow streak, highlighting shifting institutional sentiment. Option market data reveals increased demand for downside protection, indicating caution, though constructive long-term positioning remains. Implied volatility for Ethereum trades at a premium to Bitcoin, and perpetual funding rates stay positive. The week's key events are the FOMC decision, Treasury yield movements, ETF flow trends, and US regulatory developments like the CLARITY Act. The market balances crypto's resilience against growing option market caution, with the Fed's decision poised to tip the scales. Analysis compares the current Fed pause to historical rate-cutting cycles, questioning whether crypto's strength can persist if monetary policy tightening persists.

cryptonews.ru57 min fa

Crypto Outperforming Stocks: How Digital Assets Are Withstanding Macroeconomic Pressure

cryptonews.ru57 min fa

Trading

Spot
活动图片