Losses from Hacks of Crypto Projects Exceed $1.3 Billion

cryptonews.ruОпубліковано о 2026-07-27Востаннє оновлено о 2026-07-27

Анотація

According to a report by Onchain Lens, crypto project losses from hacks have exceeded $1.3 billion this year. The primary cause of damage was the compromise of access control mechanisms, where attackers obtained privileged rights or critical credentials. The biggest losers were Kelp DAO ($292M), Drift Protocol ($280M), Humanity Protocol ($31M), Step Finance ($30M), and Truebit ($26.5M). The second largest cause of loss was phishing and social engineering attacks, accounting for approximately $282 million. Attacks on oracles—services that feed external data into blockchains—also caused significant damage, with Ostium losing $24M, Blend Protocol $10.86M, and Bonzo $9M. The data indicates that the total damage stems from a limited number of highly effective attacks, rather than hundreds of small incidents. A shift in threat patterns is noted, with multi-million dollar losses increasingly resulting from compromised keys and access permissions rather than smart contract bugs. Security experts emphasize that the human factor remains a major industry risk, as phishing and social engineering remain as profitable as technical attacks. In a related incident, Blockaid reported a $24.15 million hack of the AFX Trade decentralized exchange's cross-chain bridge.

According to a report by Onchain Lens, the largest losses for crypto projects are related to the compromise of access control mechanisms. By obtaining privileged rights or access to critical credentials, attackers were able to carry out the most profitable attacks of the half-year. The greatest losses were incurred by:

  • Kelp DAO — $292 million;

  • Drift Protocol — $280 million;

  • Humanity Protocol — $31 million;

  • Step Finance — $30 million;

  • Truebit — $26.5 million.

The second largest cause of losses was phishing attacks and the use of social engineering methods. Approximately $282 million was stolen using this method. Another vulnerability turned out to be oracles—services that transmit external data to the blockchain. Due to attacks related to this infrastructure, the Ostium project lost $24 million, Blend Protocol — $10.86 million, and Bonzo — $9 million.

Onchain Lens statistics show: the total volume of damage was formed not by hundreds of separate incidents, but by a limited number of the most effective attacks. Simultaneously, the nature of threats is changing: increasingly, the cause of multi-million dollar losses is not errors in smart contracts, but the compromise of keys, permissions, and other access control mechanisms.

Security specialists stated that the human factor remains one of the main risks for the industry. Despite the development of protective measures, phishing and social engineering continue to bring attackers hundreds of millions of dollars, maintaining effectiveness on par with technical attacks.

Earlier, analysts from the company Blockaid reported a hack of the cross-chain bridge of the decentralized exchange AFX Trade. As a result of the attack, the attackers stole USDC stablecoins amounting to $24.15 million.

end-content

Пов'язані питання

QWhat was the total reported damage from hacks to crypto projects in the first half of the year, according to Onchain Lens?

AThe total reported damage exceeded $1.3 billion.

QWhat was identified as the primary cause of the largest losses for crypto projects in the Onchain Lens report?

AThe primary cause was the compromise of access control mechanisms, where attackers gained privileged rights or access to critical credentials.

QWhich crypto project suffered the single largest loss mentioned in the article, and what was the amount?

AKelp DAO suffered the single largest loss mentioned, amounting to $292 million.

QBesides compromised access controls, what were the other two major categories of attacks leading to significant losses?

AThe other two major categories were phishing/social engineering attacks (resulting in about $282 million in losses) and attacks targeting oracle infrastructure.

QWhat trend in the nature of security threats does the Onchain Lens report highlight?

AThe report highlights a shift where multi-million dollar losses are increasingly caused not by smart contract bugs, but by the compromise of keys, permissions, and other access management mechanisms, alongside the persistent risk of human factors like phishing.

Пов'язані матеріали

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

Ray Dalio, founder of Bridgewater Associates, warns in an interview that the current AI boom shows classic bubble characteristics, which could lead to significant economic downturns as seen in past cycles like 1929 or 2000. He explains that speculative enthusiasm, fueled by debt and overvaluation, often precedes a crash when rising rates or taxation force asset sales, causing widespread losses and recession. Dalio also outlines his "Big Cycle" theory, describing an approximate 80-year pattern where widening wealth gaps, massive government deficits, and shifting geopolitical power (like China's rise) create internal conflict and global instability. He emphasizes that we are in a late-cycle, transitional phase where traditional powers like the US and UK face decline. For personal wealth protection, Dalio advises diversification beyond cash into assets like stocks, bonds, real estate, and particularly gold, which he prefers over Bitcoin. While he holds about 1% of his portfolio in Bitcoin as a non-printable hard asset, he views gold as more secure from technological or governmental threats. Regarding AI's impact, Dalio believes it will disproportionately benefit capital owners, worsening inequality by replacing both physical and cognitive labor. He suggests that human intuition and emotional intelligence, combined with AI, will be key for future workers. On taxation, Dalio argues that wealth taxes are impractical and risk triggering asset sell-offs, reducing productive investment. He points to the UK as a cautionary example of debt, low productivity, and political strife. Geopolitically, Dalio foresees a more regionalized world, with the US showing weakness in prolonged conflicts like with Iran, akin to past imperial declines. The ideal outcome, he suggests, is coexisting powerful blocs (e.g., Americas, China-Asia Pacific) without major war.

marsbit46 хв тому

In Conversation with Ray Dalio: We Are Currently in an AI Bubble, with 1% of My Portfolio in Bitcoin

marsbit46 хв тому

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

South Korean stock market sees a dramatic shift in fund flows. On July 31, foreign investors made a record net purchase of approximately KRW 7.2 trillion in KOSPI stocks, marking a fundamental reversal from the persistent large-scale net outflows seen in previous months. This contributed to a significant narrowing of foreign net selling in July to KRW 9.8 trillion, down sharply from KRW 48.4 trillion in June and KRW 44.5 trillion in May. Simultaneously, domestic institutional pressure eased. South Korean pension funds and asset managers turned to a net buying position in July, purchasing KRW 1.0 trillion worth of KOSPI shares, contrasting with net sales in May and June. Market volatility is expected to be dampened by new financial regulations. Effective July 31, the Financial Services Commission tightened access for retail investors to single-stock leveraged ETFs by raising the minimum cash deposit requirement. Trading volumes for these products subsequently dropped to about 50% of their monthly average. Citigroup Research maintains its year-end KOSPI target of 10,000 points. The firm cites several supportive factors: the substantial easing of headwinds from capital outflows, a robust fundamental outlook for the semiconductor sector, historically low market valuations, strong economic fundamentals, and the potential for policy support from financial authorities if needed.

marsbit46 хв тому

Daily 7.2 Trillion KRW: Foreign Capital's Record Net Buying on Friday! Wall Street Says Headwinds for Korean Stock Fund Flows Have Subsided

marsbit46 хв тому

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

The article discusses using dice rolls to generate secure Bitcoin wallet seeds, providing entropy independent of potentially flawed hardware random number generators. It explains that each fair dice roll offers about 2.585 bits of entropy, with around 50 rolls needed for a standard 12-word seed phrase and 99+ recommended for higher security. This method gained attention after a vulnerability was revealed in some Coldcard hardware wallets, where a faulty firmware RNG (dating back to 2021) compromised generated keys. The analysis notes that while a dice-generated main seed was safe from this specific flaw, other Coldcard functions (like creating paper wallets, backup keys, or passwords) could still be vulnerable if they used the defective RNG. The piece argues that while dice-based entropy is technically robust, the manual process is error-prone, tedious, and unrealistic for most new users, who might make mistakes in recording or inputting rolls. It concludes that while manual entropy generation should remain an option for advanced users, the long-term goal is to develop reliable, user-friendly hardware and software that securely generates randomness without requiring specialized knowledge. Coldcard users are advised to check their firmware version and replace any secondary secrets (like paper wallet keys) created with vulnerable devices, while also considering multi-signature setups with devices from different manufacturers for added security.

cryptonews.ru6 год тому

Thanks to Dice Rolls, Bitcoin Keys Are Stored Offline, But Not Everyone Will Do It

cryptonews.ru6 год тому

Торгівля

Спот
活动图片