Cryptomarket Loses $14 Billion Due to Hacks. What Was Special About 2026?

cryptonews.ruPublished on 2026-08-13Last updated on 2026-08-13

Abstract

The cryptocurrency market lost over $14 billion due to hacks and code exploits from 2016 to 2026, according to a CoinGecko report. The year 2026 has seen a significant spike, with 164 separate incidents recorded as of August—a 70% increase from all of 2025. Although the total financial loss for 2026 currently stands at about $1.2 billion, still below the peak of $2.77 billion in 2022, the number of attacks is unprecedented. Analysts attribute this rise to improved tracking methods and increased malicious activity, possibly fueled by advancements in artificial intelligence. Notable 2026 breaches include the April hacks of Drift and Kelp protocols, resulting in losses of $295 million and $293 million, respectively. The Kelp exploit, linked to North Korean hackers, involved minting unbacked tokens via a LayerZero bridge vulnerability, which were then used as collateral on Aave. This triggered a massive withdrawal of liquidity from Aave and the broader DeFi sector, leading to over $20 billion in sector-wide outflows by August, despite the eventual recovery of the stolen Kelp funds. The report also highlights that market reactions to hacks often inflict greater financial damage than the exploits themselves. For instance, following the BonkDAO hack, the token's market cap fell by nearly $140 million, far exceeding the $21 million direct loss. Other examples include the DRIFT token dropping 80% and Step Finance's token losing over 99% of its value, leading to the protocol's bankru...

"RBC-Crypto" does not provide investment advice, the material is published for informational purposes only. Cryptocurrency is a volatile asset that may lead to financial losses.

Over the period from 2016 to 2026, decentralized finance (DeFi) protocols and cryptocurrency exchanges collectively lost more than $14.27 billion due to hacker attacks and code errors, according to a report by the analytical platform CoinGecko. And in 2026, as of August, more incidents have already been recorded than in any previous period, although the total amount of losses still lags behind the peak year 2022.

According to CoinGecko, 164 separate incidents have already been recorded in 2026, which is approximately 70% more than the entire previous year—in 2025 there were 97 cases. The year with the highest total damage for the crypto industry remains 2022 at $2.77 billion, slightly ahead of the 2021 figure of $2.66 billion. As of early August 2026, the damage amounted to about $1.2 billion.

Experts attribute such a sharp spike not only to improved methods of tracking attacks but also to increased activity by malicious actors against the backdrop of the development of artificial intelligence.

When compiling the report, CoinGecko used data from the REKT Database (DeFiWatch) for 2018–2022 and the DeFiLlama hack tracker for 2023–2026. Protocols without their own tokens were excluded from the analysis—specifically, centralized exchanges, bridges without native assets, and hardware wallets.

The data for 2026 is preliminary and covers the period from January to early August. To assess the damage from the price drop of individual tokens this year, analysts used the average market capitalization for seven days before the hack and compared it with the figures as of early August 2026.

At the same time, as the authors of the study emphasize, the actual damage could be significantly higher, as this amount does not include hacks of individual wallets and other ecosystem losses.

Crypto Project Hacks of 2026

The greatest damage to the crypto industry in 2026 was inflicted in April, which accounted for nearly $645 million in losses. Key events were the hacks of the Drift and Kelp protocols for $295 million and $293 million respectively.

Both attacks, according to analysts, were carried out by different malicious actors, presumably linked to North Korean hackers. And the Kelp hack is also distinct from others in that it caused damage across the entire DeFi sector.

The attackers exploited a vulnerability in the LayerZero bridge and minted unbacked tokens of the wrapped version of Ethereum—rsETH. They then used them as collateral in the Aave protocol to obtain real assets.

The consequences for Aave were catastrophic—the situation led to users withdrawing billions of dollars in liquidity. Total deposits in the protocol fell by approximately $4 billion over two days, and by early August, the figure had dropped to $14.70 billion.

Although by the end of May, through the efforts of the crypto community, the user funds stolen from Kelp were returned and all assets were restored to the protocols affected by the incident, a huge portion of the deposits across the entire DeFi sector never returned. Sector losses by August amounted to over $20 billion.

Token Price Drops Bigger Than the Hacks Themselves

In addition to the hacks and thefts themselves, CoinGecko analysts highlighted another level of financial damage that falls on token holders of hacked protocols. They noted that the market reaction to incidents often inflicts greater damage.

Experts highlighted the case of BonkDAO, where the damage from the market reaction significantly exceeded the damage from the hack: losses amounted to $21 million in reserves, while the token BONK's market capitalization shrunk by almost $140 million. According to Coingecko, "this shows that the market reaction can be more costly than the hack itself."

The report also provides examples where the DRIFT token of the Drift protocol (renamed to Velocity) fell 80% since the hack on April 1. And Resolv (RESOLV) recorded a 70% drop since March 2026. And the worst example—Step Finance, where a vulnerability led to the protocol's bankruptcy, and their token STEP lost more than 99% of its value.

Related Questions

QAccording to the article, how much has the crypto market lost due to hacks and code errors from 2016 to 2026, based on CoinGecko's report?

AOver $14.27 billion.

QWhy is 2026 a notable year in terms of security incidents, despite not having the highest total losses?

ABecause by August, 2026 had already recorded 164 separate incidents, which is about 70% more than the entire previous year (97 cases in 2025).

QWhat were the two largest hacks of 2026 mentioned, and what was their combined estimated impact?

AThe two largest hacks were on the Drift protocol ($295 million) and the Kelp protocol ($293 million) in April, with a combined impact of nearly $645 million for that month.

QHow did the exploit of the Kelp protocol uniquely affect the broader DeFi sector beyond the direct theft?

AIt triggered a catastrophic withdrawal of user liquidity, particularly from the Aave protocol. Total deposits in Aave dropped by about $4 billion in two days, and the broader DeFi sector lost over $20 billion in deposits by August.

QAccording to CoinGecko's analysis, what type of damage often causes more financial loss to token holders than the hack itself?

AThe market reaction and the subsequent fall in token prices often cause more financial damage than the direct losses from the hack.

Related Reads

Trezor Customer Data Leak: Coins Are Safe, But Phishing Is Inevitable

Trezor, a hardware cryptocurrency wallet manufacturer, reported a data breach at its logistics partner, ShipMonk, affecting around 13,689 customers. The incident, confirmed on August 13, 2026, involved unauthorized access to ShipMonk's systems, which stored order information from May 10 to August 8, 2026. Trezor's own systems and user crypto assets were not compromised. The leaked data varies: for 11,742 customers, full names, email addresses, phone numbers, and delivery addresses were exposed. For 1,947 others, only name, city, and email were leaked. The breach was limited to customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal. Trezor warns affected users of an increased risk of phishing attacks, where malicious actors may use the stolen contact details to impersonate Trezor, banks, or exchanges to steal wallet recovery phrases. All impacted customers have been notified via email. In response, Trezor announced a planned "Anonymous Delivery" feature for the EU (September 2026) and the US (end of 2026), aiming to anonymize logistics data. ShipMonk has not yet issued a public statement on its official website. The analysis highlights this as a recurring industry pattern where third-party logistics vendors become weak links in the supply chain, storing data longer than necessary. Similar incidents, like the 2020 Ledger breach, led to prolonged phishing campaigns. A key question remains whether hardware wallets can ever fully decouple from external logistics risks.

cryptonews.ru1h ago

Trezor Customer Data Leak: Coins Are Safe, But Phishing Is Inevitable

cryptonews.ru1h ago

Trading

Spot
活动图片