Losses from Hacks of Crypto Projects Exceed $1.3 Billion

cryptonews.ruОпубліковано о 2026-07-27Востаннє оновлено о 2026-07-27

Анотація

According to a report by Onchain Lens, crypto project losses from hacks have exceeded $1.3 billion this year. The primary cause of damage was the compromise of access control mechanisms, where attackers obtained privileged rights or critical credentials. The biggest losers were Kelp DAO ($292M), Drift Protocol ($280M), Humanity Protocol ($31M), Step Finance ($30M), and Truebit ($26.5M). The second largest cause of loss was phishing and social engineering attacks, accounting for approximately $282 million. Attacks on oracles—services that feed external data into blockchains—also caused significant damage, with Ostium losing $24M, Blend Protocol $10.86M, and Bonzo $9M. The data indicates that the total damage stems from a limited number of highly effective attacks, rather than hundreds of small incidents. A shift in threat patterns is noted, with multi-million dollar losses increasingly resulting from compromised keys and access permissions rather than smart contract bugs. Security experts emphasize that the human factor remains a major industry risk, as phishing and social engineering remain as profitable as technical attacks. In a related incident, Blockaid reported a $24.15 million hack of the AFX Trade decentralized exchange's cross-chain bridge.

According to a report by Onchain Lens, the largest losses for crypto projects are related to the compromise of access control mechanisms. By obtaining privileged rights or access to critical credentials, attackers were able to carry out the most profitable attacks of the half-year. The greatest losses were incurred by:

  • Kelp DAO — $292 million;

  • Drift Protocol — $280 million;

  • Humanity Protocol — $31 million;

  • Step Finance — $30 million;

  • Truebit — $26.5 million.

The second largest cause of losses was phishing attacks and the use of social engineering methods. Approximately $282 million was stolen using this method. Another vulnerability turned out to be oracles—services that transmit external data to the blockchain. Due to attacks related to this infrastructure, the Ostium project lost $24 million, Blend Protocol — $10.86 million, and Bonzo — $9 million.

Onchain Lens statistics show: the total volume of damage was formed not by hundreds of separate incidents, but by a limited number of the most effective attacks. Simultaneously, the nature of threats is changing: increasingly, the cause of multi-million dollar losses is not errors in smart contracts, but the compromise of keys, permissions, and other access control mechanisms.

Security specialists stated that the human factor remains one of the main risks for the industry. Despite the development of protective measures, phishing and social engineering continue to bring attackers hundreds of millions of dollars, maintaining effectiveness on par with technical attacks.

Earlier, analysts from the company Blockaid reported a hack of the cross-chain bridge of the decentralized exchange AFX Trade. As a result of the attack, the attackers stole USDC stablecoins amounting to $24.15 million.

end-content

Пов'язані питання

QWhat was the total reported damage from hacks to crypto projects in the first half of the year, according to Onchain Lens?

AThe total reported damage exceeded $1.3 billion.

QWhat was identified as the primary cause of the largest losses for crypto projects in the Onchain Lens report?

AThe primary cause was the compromise of access control mechanisms, where attackers gained privileged rights or access to critical credentials.

QWhich crypto project suffered the single largest loss mentioned in the article, and what was the amount?

AKelp DAO suffered the single largest loss mentioned, amounting to $292 million.

QBesides compromised access controls, what were the other two major categories of attacks leading to significant losses?

AThe other two major categories were phishing/social engineering attacks (resulting in about $282 million in losses) and attacks targeting oracle infrastructure.

QWhat trend in the nature of security threats does the Onchain Lens report highlight?

AThe report highlights a shift where multi-million dollar losses are increasingly caused not by smart contract bugs, but by the compromise of keys, permissions, and other access management mechanisms, alongside the persistent risk of human factors like phishing.

Пов'язані матеріали

Huang Xiaoming, Li Bin, Lei Jun, Liang Wenfeng... Changxin IPO Feast, Who's the Biggest Winner?

Changxin Technology's IPO on the Shanghai STAR Market created significant wealth for its stakeholders. Founder Zhu Yiming and his family saw their wealth surge nearly 300%, with his stake in Changxin alone valued at approximately 80 billion RMB. Over 6700 employees benefited, creating at least 237 new millionaires. Several prominent figures also profited. Liang Wenfeng, founder of Deepseek, saw a paper gain of 827 million RMB through his funds' participation. Kong Jianping, founder of Nano Labs, holds an indirect stake worth around 940 million RMB, representing a roughly 44x return on his 2020 investment. Former Midea executive Huang Xiaoming gained approximately 503 million RMB. Strategic investors included industry partners. Nio, represented by founder William Li, pledged 158 million RMB for shares now showing a paper gain of about 740 million RMB. Similarly, a Xiaomi subsidiary acquired shares resulting in an over 736 million RMB gain, though the company clarified this is a corporate investment, not directly attributable to founder Lei Jun's personal wealth. Founder Zhu Yiming further plans to donate shares worth over 37.6 billion RMB for future employee incentives. The IPO solidified Changxin's position as a leading domestic memory chip maker, triggering a widespread wealth creation event for its network of founders, employees, and investors.

Odaily星球日报9 хв тому

Huang Xiaoming, Li Bin, Lei Jun, Liang Wenfeng... Changxin IPO Feast, Who's the Biggest Winner?

Odaily星球日报9 хв тому

Aave's Stable Vault

This article explores Aave's recently launched "Stable Vaults," a product designed to bridge the gap between traditional finance users and DeFi yield. It argues that while DeFi offers transparency and potentially higher returns, its complexity and volatility are major barriers for mainstream adoption. The core problem is that users pay for convenience and simplicity, often accepting lower returns to avoid decision-making and technical hurdles. Stable Vaults allow fintech apps, neobanks, or payment platforms (operators) to integrate with Aave's lending markets once and offer their users a "savings account" with a fixed, predictable yield (e.g., 4%). The operator absorbs the underlying market volatility; if Aave's pool pays 6%, the operator pockets the 2% difference, but if it pays only 2%, the operator covers the shortfall to maintain the promised 4% for users. The piece analyzes this model from three perspectives: 1. **The User:** Gains simplicity, a fixed rate, and familiar app features (customer support, account recovery). However, they lose potential upside, accept a lower fixed yield, and take on new counterparty risks from the operator and its proprietary backend systems. 2. **The Operator (e.g., a neobank):** Can monetize idle user balances easily, generating significant fee income (the spread between the fixed rate and the actual yield) with minimal integration effort, turning a cost center into revenue. 3. **Aave:** Gains "sticky," loyalty-based deposits that are less likely to flee during minor yield fluctuations, securing a stable revenue stream crucial for its tokenomics (like buybacks). It becomes a back-end infrastructure provider for the broader consumer finance ecosystem. The author acknowledges that while sophisticated users can access higher yields directly on Aave, most people prefer convenience and security over optimization. They reference behavioral studies showing that too many choices lead to inaction. Therefore, Stable Vaults represent an acceptance of human nature—prioritizing safety, predictability, and ease—and a strategic move for Aave to capture stable, large-scale deposits from mainstream finance applications. Examples like Rise (payroll) and Kraken are already using similar embedded yield models.

marsbit14 хв тому

Aave's Stable Vault

marsbit14 хв тому

Торгівля

Спот
活动图片