Crypto hackers have fundamentally changed their playbook in 2026, and your wallet is now their favorite target. A new report from blockchain security firm CertiK reveals that wallet compromises have officially overtaken smart contract exploits as the single biggest source of stolen funds in the first half of this year — a shift that has profound implications for everyday investors who thought code audits were enough to keep them safe.
By Elena Kowalski | July 12, 2026
The Hook: A Record Number of Attacks, but a Different Kind of Threat
The Web3 industry recorded 344 security incidents in the first six months of 2026, resulting in approximately 1.31 billion in total losses, according to CertiK’s Hack3d report published on July 6. On the surface, that figure looks like an improvement — it represents a roughly 47 percent decline from the 2.47 billion stolen during the same period in 2025. But CertiK warned that the comparison is deeply misleading.
The reason? The first half of 2025 included the Bybit exploit, the largest single crypto hack ever recorded, which alone accounted for roughly 1.45 billion. Strip that one historic outlier out, and H1 2026 losses were actually about 28 percent higher than the comparable figure a year earlier. In other words, the security environment is not getting better. By several measures, it is getting worse.
“The underlying security environment has not improved; in several meaningful respects, it has deteriorated,” the CertiK report stated plainly.
A separate analysis from TRM Labs counted 207 incidents with losses totaling roughly 972 million, noting that North Korea-linked attacks accounted for about two-thirds of all stolen funds. While the two firms use different counting methodologies, they agree on the central trend: hackers are no longer primarily looking for bugs in smart contract code. They are coming for your private keys.
The Shift: Why Wallet Compromises Now Dominate
This is the most important takeaway for regular investors. For years, the standard security advice in crypto was: find protocols that have been audited, and you will probably be fine. Audits catch bugs in smart contract code — the automated programs that run on the blockchain. But CertiK’s data shows that code bugs are no longer where the money is being lost.
Here is how the numbers break down by attack type in H1 2026:
- Wallet compromises — 33 incidents resulting in approximately 444.5 million in losses, making it the single most expensive attack vector
- Phishing campaigns — 63 incidents accounting for roughly 366.3 million in stolen funds, with attackers targeting fewer but higher-value victims
- Code vulnerabilities — 204 incidents (the most common by count) but only about 151.6 million in losses
Think of it this way: hackers used to spend their time trying to pick the lock on the vault (the smart contract). Now they have realized it is far more profitable to trick the vault manager into handing over the keys. A wallet compromise means an attacker gains access to your private keys — the cryptographic passwords that control your crypto. Once they have those, no audit in the world can protect you.
The phishing numbers tell a similar story. While the number of phishing incidents dropped from 132 in H1 2025 to just 63 this year, the total amount stolen declined by only about 11 percent. That means each successful phishing attack is stealing significantly more on average — attackers are getting better at identifying and targeting high-net-worth individuals and project operators.
The Core Conflict: Old Code Is Now the Frontline
One of the most alarming findings in the CertiK report is that attackers are increasingly targeting legacy smart contracts — older codebases that have been running for months or even years without incident. In the past, the assumption was that if a contract survived its first few months without being exploited, it was probably safe. That assumption no longer holds.
According to CertiK, improved automated attack tools are enabling hackers to systematically scan and re-examine older code for vulnerabilities that were previously overlooked. This means protocols that passed security audits at launch may still be at risk if those audits are not updated regularly. The report underscores that continuous security reviews — not just one-time pre-launch audits — are now essential.
The two largest exploits of the year illustrate how attackers are diversifying their methods. The biggest was the Kelp DAO exploit in April, where attackers believed to be linked to North Korea’s Lazarus Group stole approximately 292 million by compromising the protocol’s internal RPC infrastructure — the behind-the-scenes servers that relay transactions to the blockchain. Rather than attacking a smart contract directly, they infiltrated the off-chain systems and used a DDoS attack to overwhelm external nodes, feeding false data to a single point of failure.
The second-largest was the Drift Protocol exploit, which resulted in roughly 285.3 million in losses from just seven incidents on Solana — again stemming from a wallet compromise rather than a code flaw. Together, these two attacks accounted for nearly 44 percent of all losses recorded in the first half of 2026.
Ethereum remained the most targeted blockchain overall, with 153 incidents and approximately 522.8 million in losses. Binance Smart Chain saw over 100 incidents but with smaller average losses.
Market Implications: What This Means for Your Portfolio
For everyday investors, the CertiK report carries several uncomfortable truths. The most important one is this: the security of your crypto holdings depends far less on the protocols you choose and far more on how you store your keys.
If you keep your crypto on an exchange, you are trusting that exchange’s operational security — their ability to protect private keys from hackers, rogue employees, and social engineering attacks. If you hold your own keys in a software wallet (like MetaMask or Phantom), you are trusting your own ability to avoid phishing links and malicious downloads. If you use a hardware wallet (like a Ledger or Trezor), you are significantly safer — but only if you verify every transaction on the device screen before signing.
The report also suggests that investors should pay closer attention to how a protocol manages its infrastructure, not just whether its smart contracts have been audited. The Kelp DAO hack demonstrated that even a protocol with solid on-chain code can be devastated by weaknesses in its off-chain systems. Ask whether the protocol uses multi-signature wallets (which require multiple people to approve transactions), whether it has decentralized its infrastructure to avoid single points of failure, and whether it conducts regular post-launch security reviews.
There is a sliver of good news. CertiK reported that approximately 115.3 million in stolen assets were frozen or recovered during H1 2026, bringing adjusted losses down to about 1.20 billion. Blockchain analytics firms and law enforcement are getting faster at tracing and freezing stolen funds, particularly when attackers attempt to move them through major exchanges. But a significant portion of stolen funds remains inactive in attacker wallets, meaning future recoveries are possible but not guaranteed.
The Verdict: Stop Relying on Audits Alone
The central lesson from H1 2026 is that the crypto security model needs to evolve. Audits remain important — they catch the code bugs that still account for the majority of individual incidents. But audits are necessary, not sufficient. The most damaging attacks are now happening at the intersection of human error, infrastructure compromise, and social engineering — areas that a smart contract audit simply cannot address.
For protocols, this means investing in operational security: multi-signature controls, hardware security modules, regular penetration testing of off-chain infrastructure, and continuous monitoring for suspicious activity. For investors, it means recognizing that the biggest risk to your portfolio may not be a market crash or a protocol bug — it may be a convincing phishing email or a compromised private key.
The hackers have adapted. The question now is whether the rest of the crypto ecosystem will adapt fast enough to keep up.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry risk; always do your own research.
33 wallet drains for 444.5m vs 204 code bugs only hitting 151.6m. the math is brutal, they get way more per wallet compromise than per contract exploit now
phish_resistant_ 33 wallet drains for 444m vs 204 code bugs for 151m. the per-incident haul for wallet compromises is 3x higher. attackers follow the money and the money is in your browser extension
seed_phrase_rat 3x higher per incident haul on wallet compromises vs contract bugs. attackers are rational actors, they go where the money is easiest to take
Been saying this for months. Everyone obsessing over audit scores while their seed phrase sits in a notes app. The Kelp DAO RPC compromise proved social engineering beats code bugs every time
exactly. 292m from kelp dao alone because they went after internal RPC infra not the contract itself. hardware wallet wouldnt have saved them but at least its a start
Henrik S. the Kelp DAO RPC compromise proved social engineering beats code bugs every time. auditors check smart contracts but nobody audits your Slack
Sora K. nobody audits your slack is the perfect summary. 292M from Kelp DAO because they went after internal RPC not the contract. perimeter security is theater if the humans are the attack surface
33 wallet drains averaging 13M per incident. thats not hacking thats grand theft with extra steps. the per-incident payout is insane compared to contract exploits
33 wallet drains for 444M vs 204 contract bugs for 151M. the per incident haul on wallet compromises is insane. one good phish nets you more than a month of hunting smart contract bugs
Henrikke S. Kelp DAO lost 292M because the attackers went after RPC infra not the contract. audits are useless when your attack surface is the teams slack channel. perimeter security is the real gap
CertiK saying the security environment deteriorated once you strip out the Bybit outlier. 1.31B stolen and the industry is calling it an improvement because 2025 was worse. the baseline is cooked