Crypto news report · source clearly identified
DeFi Hacks in 2026: $1.3 B Lost as Compromised Keys Eclipse Code Bugs
Compromised private keys have become the leading cause of DeFi theft in 2026, accounting for the majority of the $1.3 billion lost so far, with North Korea’s Lazarus Group responsible for roughly 44 % of the total.

DeFi protocols have suffered at least $1.3 billion in losses during the first eight months of 2026, according to Forbes and CertiK. For the first time, compromised private keys have overtaken smart‑contract bugs as the primary attack vector.
Key incidents and their impact
- Drift Protocol – $285 million drained on April 1 after attackers obtained an admin key through months of social engineering.
- KelpDAO – $290 million lost on April 18 via a single compromised verifier on its LayerZero bridge.
- Coldcard hardware wallet – $130 million stolen on July 30 after a firmware flaw made seed phrases guessable, enabling brute‑force attacks on thousands of wallets.
- Bridge exploits – AFX Trade ($24.15 million), VerusCoin ($19.14 million across two attacks), and the Cosmos EVM underflow chain ($20.8 million across MANTRA, TAC, and KiiChain) all suffered cross‑chain verification failures.
State‑backed actor dominates the losses
North Korea’s Lazarus Group, operating under the alias TraderTraitor, has been linked to at least $575 million of the 2026 losses, covering both the Drift and KelpDAO hacks. This represents roughly 44 % of the year’s total DeFi thefts.
Why compromised keys matter more than code bugs
Audits continue to confirm that the affected smart contracts were free of critical vulnerabilities. The breaches instead stemmed from human‑focused attacks: social engineering, session hijacking, validator key theft, and governance capture. Attackers found it cheaper to compromise a trusted individual or key than to break a contract’s code.
Recurring bridge weaknesses
Bridge infrastructure remains the soft underbelly of DeFi. Exploits repeatedly rely on a small set of signers or validators. When enough of these nodes are compromised, bridges release funds on the destination chain as if the request were legitimate. Multi‑verifier configurations that require independent confirmations could have prevented the KelpDAO and AFX Trade attacks, yet they are rarely deployed.
Industry response
Security councils have taken emergency actions, such as Arbitrum’s seizure of 30,766 ETH from the attacker’s wallet, but opinions differ on the adequacy of these measures. The recurring pattern has prompted calls for auditors to shift focus from code to governance and signer security.
Source & attribution
News Source
- Publisher
- crypto.news
- Original date
- September 4, 2026, 7:36 AM
- Original headline
- DeFi has lost $1.3 billion to hacks in 2026 and the same attack keeps working