Cryptomarket Loses $14 Billion Due to Hacks. What Was Special About 2026?

cryptonews.ru2026-08-13 tarihinde yayınlandı2026-08-13 tarihinde güncellendi

Özet

The cryptocurrency market lost over $14 billion due to hacks and code exploits from 2016 to 2026, according to a CoinGecko report. The year 2026 has seen a significant spike, with 164 separate incidents recorded as of August—a 70% increase from all of 2025. Although the total financial loss for 2026 currently stands at about $1.2 billion, still below the peak of $2.77 billion in 2022, the number of attacks is unprecedented. Analysts attribute this rise to improved tracking methods and increased malicious activity, possibly fueled by advancements in artificial intelligence. Notable 2026 breaches include the April hacks of Drift and Kelp protocols, resulting in losses of $295 million and $293 million, respectively. The Kelp exploit, linked to North Korean hackers, involved minting unbacked tokens via a LayerZero bridge vulnerability, which were then used as collateral on Aave. This triggered a massive withdrawal of liquidity from Aave and the broader DeFi sector, leading to over $20 billion in sector-wide outflows by August, despite the eventual recovery of the stolen Kelp funds. The report also highlights that market reactions to hacks often inflict greater financial damage than the exploits themselves. For instance, following the BonkDAO hack, the token's market cap fell by nearly $140 million, far exceeding the $21 million direct loss. Other examples include the DRIFT token dropping 80% and Step Finance's token losing over 99% of its value, leading to the protocol's bankru...

"RBC-Crypto" does not provide investment advice, the material is published for informational purposes only. Cryptocurrency is a volatile asset that may lead to financial losses.

Over the period from 2016 to 2026, decentralized finance (DeFi) protocols and cryptocurrency exchanges collectively lost more than $14.27 billion due to hacker attacks and code errors, according to a report by the analytical platform CoinGecko. And in 2026, as of August, more incidents have already been recorded than in any previous period, although the total amount of losses still lags behind the peak year 2022.

According to CoinGecko, 164 separate incidents have already been recorded in 2026, which is approximately 70% more than the entire previous year—in 2025 there were 97 cases. The year with the highest total damage for the crypto industry remains 2022 at $2.77 billion, slightly ahead of the 2021 figure of $2.66 billion. As of early August 2026, the damage amounted to about $1.2 billion.

Experts attribute such a sharp spike not only to improved methods of tracking attacks but also to increased activity by malicious actors against the backdrop of the development of artificial intelligence.

When compiling the report, CoinGecko used data from the REKT Database (DeFiWatch) for 2018–2022 and the DeFiLlama hack tracker for 2023–2026. Protocols without their own tokens were excluded from the analysis—specifically, centralized exchanges, bridges without native assets, and hardware wallets.

The data for 2026 is preliminary and covers the period from January to early August. To assess the damage from the price drop of individual tokens this year, analysts used the average market capitalization for seven days before the hack and compared it with the figures as of early August 2026.

At the same time, as the authors of the study emphasize, the actual damage could be significantly higher, as this amount does not include hacks of individual wallets and other ecosystem losses.

Crypto Project Hacks of 2026

The greatest damage to the crypto industry in 2026 was inflicted in April, which accounted for nearly $645 million in losses. Key events were the hacks of the Drift and Kelp protocols for $295 million and $293 million respectively.

Both attacks, according to analysts, were carried out by different malicious actors, presumably linked to North Korean hackers. And the Kelp hack is also distinct from others in that it caused damage across the entire DeFi sector.

The attackers exploited a vulnerability in the LayerZero bridge and minted unbacked tokens of the wrapped version of Ethereum—rsETH. They then used them as collateral in the Aave protocol to obtain real assets.

The consequences for Aave were catastrophic—the situation led to users withdrawing billions of dollars in liquidity. Total deposits in the protocol fell by approximately $4 billion over two days, and by early August, the figure had dropped to $14.70 billion.

Although by the end of May, through the efforts of the crypto community, the user funds stolen from Kelp were returned and all assets were restored to the protocols affected by the incident, a huge portion of the deposits across the entire DeFi sector never returned. Sector losses by August amounted to over $20 billion.

Token Price Drops Bigger Than the Hacks Themselves

In addition to the hacks and thefts themselves, CoinGecko analysts highlighted another level of financial damage that falls on token holders of hacked protocols. They noted that the market reaction to incidents often inflicts greater damage.

Experts highlighted the case of BonkDAO, where the damage from the market reaction significantly exceeded the damage from the hack: losses amounted to $21 million in reserves, while the token BONK's market capitalization shrunk by almost $140 million. According to Coingecko, "this shows that the market reaction can be more costly than the hack itself."

The report also provides examples where the DRIFT token of the Drift protocol (renamed to Velocity) fell 80% since the hack on April 1. And Resolv (RESOLV) recorded a 70% drop since March 2026. And the worst example—Step Finance, where a vulnerability led to the protocol's bankruptcy, and their token STEP lost more than 99% of its value.

İlgili Sorular

QAccording to the article, how much has the crypto market lost due to hacks and code errors from 2016 to 2026, based on CoinGecko's report?

AOver $14.27 billion.

QWhy is 2026 a notable year in terms of security incidents, despite not having the highest total losses?

ABecause by August, 2026 had already recorded 164 separate incidents, which is about 70% more than the entire previous year (97 cases in 2025).

QWhat were the two largest hacks of 2026 mentioned, and what was their combined estimated impact?

AThe two largest hacks were on the Drift protocol ($295 million) and the Kelp protocol ($293 million) in April, with a combined impact of nearly $645 million for that month.

QHow did the exploit of the Kelp protocol uniquely affect the broader DeFi sector beyond the direct theft?

AIt triggered a catastrophic withdrawal of user liquidity, particularly from the Aave protocol. Total deposits in Aave dropped by about $4 billion in two days, and the broader DeFi sector lost over $20 billion in deposits by August.

QAccording to CoinGecko's analysis, what type of damage often causes more financial loss to token holders than the hack itself?

AThe market reaction and the subsequent fall in token prices often cause more financial damage than the direct losses from the hack.

İlgili Okumalar

Google and Meta Called Out for Benchmark Gaming

Recently, analysis firm SemiAnalysis accused tech giants Google and Meta of "benchmark gaming" with their AI models Gemini 3.8 Flash and Muse Spark 1.3. The accusation stems from a dramatic performance drop between two versions of the Terminal-Bench evaluation for AI agents. On the older, public Terminal-Bench 2.1, Gemini 3.8 Flash scored 89.4, ranking second and beating GPT-6 Astra, while Muse Spark 1.3 scored 88.8. However, on the newly released, more secure Terminal-Bench 4.0, their scores plummeted to 19.1 and approximately 33.3 respectively, far behind competitors. SemiAnalysis argues this indicates "benchmark contamination," where companies train models not on the public test questions themselves, but on expensive, privately purchased training data specifically designed to mimic the benchmark's style. This has evolved into a lucrative industry, with specialized firms selling tailored training tasks for thousands to hundreds of thousands of dollars. The article specifically points to Datacurve, a company that both sells expert coding data and runs its own benchmark (DeepSWE), where the accused models also performed well. Meta's Chief AI Officer, Alexandr Wang, dismissed the claims as a "silly argument," pointing out similar performance drops for other models like GPT-5.6 Sol. He stated Meta never claimed Muse Spark 1.3 was as powerful as top-tier models, only that it offered better value. The report concludes that this is the inevitable fate of all high-quality public benchmarks—they become "gamed" over time. The proposed solution of private, high-quality benchmarks comes with a significant downside: it would erode public transparency, turning open rankings into marketing tools and leaving developers without a common, fair measure to compare AI models.

marsbit3 saat önce

Google and Meta Called Out for Benchmark Gaming

marsbit3 saat önce

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

Coinbase co-founder Fred Ehrsam is venturing into the oil fields of Venezuela, a surprising shift for a prominent figure in the digital asset space. Through his company Primavera Infinita, he recently secured a production contract for the Budare-Elotes block with Venezuela's state oil firm PDVSA. This move into a politically volatile, sanction-scarred country highlights a bet on high returns from its reopening under new leadership and shifting U.S. foreign policy. Ehrsam’s investment reflects a venture capital-style appetite for risk, targeting assets deeply discounted by political uncertainty. He is not alone; smaller, politically connected U.S. firms like Aspect Holdings and Hunt Oil are also entering, while established giants like ExxonMobil remain cautious due to past expropriations. To manage the complex, capital-intensive nature of oil, Ehrsam is assembling a professional team. This trend extends beyond Ehrsam. Other crypto wealth, like BitMEX's Arthur Hayes and Tether, is diversifying into traditional hard assets—energy, metals, and agriculture—seeking physical scarcity as a long-term anchor. Tether, for instance, took a controlling stake in agricultural giant Adecoagro. These moves signify crypto capital's evolving interest: not just tokenizing real-world assets (RWA), but directly acquiring and operating them. Ultimately, Ehrsam's gamble is less on oil geology and more on the duration of Venezuela's current political window. It underscores a broader narrative where digital-era wealth seeks stability and scale in the physical world's most traditional, immovable resources.

marsbit3 saat önce

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

marsbit3 saat önce

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

Title: Refuting the "Ethereum Abandoning ETH" Argument: What Does Paying Gas Without ETH Really Mean? The debate sparked by Vitalik Buterin's discussion of EIP-8141 (Frame Transactions), which suggests users could pay transaction fees without holding ETH, has led to extreme claims that ETH will lose its value. However, this perspective misunderstands the proposal. Currently, an Ethereum user initiating a transaction must also pay the network's Gas fee in ETH. EIP-8141 aims to decouple these actions. It allows a transaction to be split into separate "frames." A user could sign a transaction to, for example, send USDC, while a separate Paymaster account pays the required ETH Gas fee on their behalf. The user would then settle the cost with the Paymaster using USDC or another token. From the user's perspective, they pay in a stablecoin without interacting with ETH. Crucially, from the Ethereum protocol's perspective, the Gas is still paid in ETH; only the settlement layer between the user and Paymaster changes. This concept isn't entirely new; ERC-4337's Account Abstraction already allows similar Gas sponsorship. EIP-8141 seeks to integrate this capability more natively. The core goal is to drastically improve user experience by abstracting away the complexity of Gas, similar to how one pays with a credit card abroad without handling the local currency. It also enables atomic operations, like bundling token approval with a swap, which would revert together if the swap fails. Regarding ETH's value, the argument that "no ETH is needed" is incorrect. While users may not hold ETH, Paymasters and services must still acquire and spend ETH to pay network fees on the backend. The demand for ETH shifts from being distributed across millions of user wallets to being concentrated in the balances of these service providers. The key variable is whether this improved usability attracts significant new users and increases overall network activity. If it does, total ETH burned in fees could rise substantially. If it doesn't, the change merely reshuffles who holds the ETH needed for Gas. In summary, EIP-8141 aims to lower the entry barrier by hiding Gas complexity, betting that this will drive broader adoption and increase the fundamental utility—and thus demand—for the Ethereum network and ETH itself.

marsbit3 saat önce

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

marsbit3 saat önce

İşlemler

Spot
活动图片