Three incidents wiped out nearly two-thirds of everything stolen from crypto in the first six months of 2026. Kelp DAO, Drift Protocol, and a single targeted phishing attack that cost one victim $284 million together account for roughly 65% of the $1.316 billion in gross losses recorded across 344 incidents, according to CertiK's H1 2026 security report. About $115.3 million was frozen or returned, bringing the adjusted figure closer to $1.2 billion.

On the surface, that looks like progress. The first half of 2025 ended worse, at $1.45 billion. But that number was almost entirely driven by the Bybit breach, a single catastrophic event. Strip Bybit out of the 2025 comparison and CertiK estimates that like-for-like losses actually grew by around 28% this year.

A handful of failures, not hundreds of small ones

The math inside those 344 incidents tells a sharper story. The average loss per incident came to $3.82 million. The median was $138,703. That gap, more than 27 to 1, means the aggregate is almost entirely a product of a few catastrophic outliers rather than a broad wave of small thefts. For most projects that got hit, the damage was painful but manageable. For the ones at the top of the list, it was existential.

What the largest incidents had in common was also notable. None of the headline cases exploited a bug in public smart contract code. The attack surfaces were RPC infrastructure, administrative permissions, signing systems, and compromised personal devices belonging to people with privileged access. That pattern has been consistent for several years now: the protocol logic holds, but the humans and the infrastructure around it do not.

Comparing incident reports across the industry requires some care, because the numbers being cited often measure different things. Gross loss captures what left a protocol before any recovery. Net loss is what remained missing after freezes and repayments. Realized extraction reflects what an attacker actually converted into usable value, which can be far below the headline figure when the stolen assets are illiquid. A thief who mints $100 million of a thin token and exits with $1 million of real collateral should not be ranked alongside someone who walked away with $100 million in stablecoins, even if headline figures suggest otherwise.

This ranking was compiled on July 17, with 167 days left in the year. That is 45.8% of 2026 still to run, enough time for new incidents, partial recoveries, and revised attributions to move these numbers significantly in either direction.

This article is for informational purposes only and does not constitute financial advice or an investment recommendation.