Losses from Hacks of Crypto Projects Exceed $1.3 Billion

cryptonews.ru2026-07-27 tarihinde yayınlandı2026-07-27 tarihinde güncellendi

Özet

According to a report by Onchain Lens, crypto project losses from hacks have exceeded $1.3 billion this year. The primary cause of damage was the compromise of access control mechanisms, where attackers obtained privileged rights or critical credentials. The biggest losers were Kelp DAO ($292M), Drift Protocol ($280M), Humanity Protocol ($31M), Step Finance ($30M), and Truebit ($26.5M). The second largest cause of loss was phishing and social engineering attacks, accounting for approximately $282 million. Attacks on oracles—services that feed external data into blockchains—also caused significant damage, with Ostium losing $24M, Blend Protocol $10.86M, and Bonzo $9M. The data indicates that the total damage stems from a limited number of highly effective attacks, rather than hundreds of small incidents. A shift in threat patterns is noted, with multi-million dollar losses increasingly resulting from compromised keys and access permissions rather than smart contract bugs. Security experts emphasize that the human factor remains a major industry risk, as phishing and social engineering remain as profitable as technical attacks. In a related incident, Blockaid reported a $24.15 million hack of the AFX Trade decentralized exchange's cross-chain bridge.

According to a report by Onchain Lens, the largest losses for crypto projects are related to the compromise of access control mechanisms. By obtaining privileged rights or access to critical credentials, attackers were able to carry out the most profitable attacks of the half-year. The greatest losses were incurred by:

  • Kelp DAO — $292 million;

  • Drift Protocol — $280 million;

  • Humanity Protocol — $31 million;

  • Step Finance — $30 million;

  • Truebit — $26.5 million.

The second largest cause of losses was phishing attacks and the use of social engineering methods. Approximately $282 million was stolen using this method. Another vulnerability turned out to be oracles—services that transmit external data to the blockchain. Due to attacks related to this infrastructure, the Ostium project lost $24 million, Blend Protocol — $10.86 million, and Bonzo — $9 million.

Onchain Lens statistics show: the total volume of damage was formed not by hundreds of separate incidents, but by a limited number of the most effective attacks. Simultaneously, the nature of threats is changing: increasingly, the cause of multi-million dollar losses is not errors in smart contracts, but the compromise of keys, permissions, and other access control mechanisms.

Security specialists stated that the human factor remains one of the main risks for the industry. Despite the development of protective measures, phishing and social engineering continue to bring attackers hundreds of millions of dollars, maintaining effectiveness on par with technical attacks.

Earlier, analysts from the company Blockaid reported a hack of the cross-chain bridge of the decentralized exchange AFX Trade. As a result of the attack, the attackers stole USDC stablecoins amounting to $24.15 million.

end-content

İlgili Sorular

QWhat was the total reported damage from hacks to crypto projects in the first half of the year, according to Onchain Lens?

AThe total reported damage exceeded $1.3 billion.

QWhat was identified as the primary cause of the largest losses for crypto projects in the Onchain Lens report?

AThe primary cause was the compromise of access control mechanisms, where attackers gained privileged rights or access to critical credentials.

QWhich crypto project suffered the single largest loss mentioned in the article, and what was the amount?

AKelp DAO suffered the single largest loss mentioned, amounting to $292 million.

QBesides compromised access controls, what were the other two major categories of attacks leading to significant losses?

AThe other two major categories were phishing/social engineering attacks (resulting in about $282 million in losses) and attacks targeting oracle infrastructure.

QWhat trend in the nature of security threats does the Onchain Lens report highlight?

AThe report highlights a shift where multi-million dollar losses are increasingly caused not by smart contract bugs, but by the compromise of keys, permissions, and other access management mechanisms, alongside the persistent risk of human factors like phishing.

İlgili Okumalar

A sales director consulted DeepSeek and lost her job and 5 million rubles

Moscow's Babushkinsky District Court upheld the lawful dismissal of Ekaterina Remizova, sales director at GC Energroprof, for disclosing trade secrets. The court found she forwarded tender documents and colleagues' salary data to her personal email, and uploaded protected company reports—including PowerBI analytics on deals and finances—to the AI service DeepSeek. This act alone was deemed disclosure of confidential information. Additional grounds for dismissal included revealing strategic plans, such as launching a new brand and direct generator imports from China, to a supplier. The company also cited her systematic failure to meet sales targets. Following her dismissal in 2025, Remizova sued, seeking to have the firing deemed illegal, changed to "by mutual agreement," and to receive a 5-million-ruble "golden parachute." The court rejected the main claims, ruling her actions a gross violation of duties. The parachute payment was denied as it only applied to mutual agreement or layoff scenarios. The company was ordered to pay 10,000 rubles in moral damages for one unjustified disciplinary penalty. The ruling can still be appealed. The case highlights broader data security risks: experts note that DeepSeek's "Share" function creates temporary links that can be indexed by search engines like Google, potentially exposing corporate data without malicious intent.

cryptonews.ru3 dk önce

A sales director consulted DeepSeek and lost her job and 5 million rubles

cryptonews.ru3 dk önce

Wall Street Traders Shift Crypto Market Activity to Weekdays

For decades, Wall Street adhered to a strict Monday-Friday schedule, a rhythm initially challenged but not fully overturned by the 24/7 nature of cryptocurrencies. However, institutional adoption is now fundamentally reshaping crypto market dynamics, shifting most price discovery and trading activity to traditional U.S. market hours (9:30 AM - 4:00 PM ET). According to Kaiko Research, weekend trading volume has fallen from roughly 25% to about 16% of the total. This concentration creates a significant "liquidity vacuum" on weekends when institutional support withdraws. Analysis by BridgePort shows the market becomes more vulnerable: trading costs rise by an average of 11% due to wider spreads, market depth for $100k trades worsens by nearly 9%, and displayed liquidity drops over 5%. Consequently, smaller trades can trigger sharper price swings. The massive success of U.S. spot Bitcoin ETFs has been a key driver of this structural shift. While providing steady weekday demand, their complete inactivity on weekends exacerbates the liquidity gap. Large capital movements, like the over $0.5 billion withdrawn from U.S. spot ETFs since October 2023, are easily absorbed on weekdays but can cause significant turbulence on thinner weekends. Ultimately, weekend trading now requires heightened caution due to a "thin" market, absent major market makers, and multiplied risks of sudden price jumps and slippage. Understanding these hidden liquidity mechanisms has become crucial for navigating the new financial reality.

cryptonews.ru1 saat önce

Wall Street Traders Shift Crypto Market Activity to Weekdays

cryptonews.ru1 saat önce

İşlemler

Spot
活动图片