Crypto investors were fleeced of almost a billion dollars in the first half of 2026, and the industry’s favorite comfort blanket did little to stop it.
Security research house ack3 has verified 135 exploits between January and June, with $939.86m in attributed losses, averaging $6.96m each time the alarm sounded. The firm has published its full incident dataset openly, so every number can be checked line by line.
Here’s the stat that should chill every retail holder: of the money stolen from audited projects, 94.4% walked out through code or infrastructure the auditors never examined. The green tick covered the front door. The thieves came through the loading bay.
The Mega Heists Major Crypto Audits Missed
Two mega-heists account for the bulk of the carnage, and neither was a bug that an auditor missed.
Kelp DAO’s rsETH hemorrhaged $292m in April after attackers forged a LayerZero cross-chain message by compromising the protocol’s single message verifier – one checkpoint, no backup.
Two weeks earlier, Solana perps giant Drift lost $285m when operatives – linked by researchers to North Korea – spent months socially engineering their way to admin keys. Between them: $577m, roughly 61% of everything stolen all half. Not broken maths. Broken keys and broken trust.
The pattern repeats down the ledger. Step Finance ($40m), Humanity Protocol ($32m), and Resolv’s USR stablecoin ($24.5m) were all drained through compromised private keys and signing infrastructure, the humans, not the smart contracts. Cross-chain bridges were the other killing field, from Verus ($11.5m) to Syscoin ($8m) to Taiko ($1.7m).
Nowhere was safe, not even the blue chips. Polymarket was hit twice: a $700k internal wallet drain in May, then a $3.1m front-end supply-chain attack in June that turned its own website into a wallet drainer.
CoW Swap had its domain hijacked from under it. And in the half’s most poetic entry, feared MEV bot jaredfromsubway.eth, which spent years farming retail traders, was itself fleeced for $7.5m by a honeypot token.
The unaudited crowd fared no better. Truebit coughed up $26.4m to a schoolboy integer-overflow error in its mint pricing.
DISCOVER: The Biggest Crypto Hacks of 2025
One Crypto Audit Isn’t Enough: Good Projects Are Checked Regularly
And on the rare occasions, had auditors reviewed the exploited code? The reports were mostly stale; 17 of the 20 nearest relevant audits were at least six months old by the time the hackers struck.
In a worrying prediction about the rise of AI tooling, Ack3 CEO and Founder Josef Gattermayer said:
Our research shows that audited projects lost $681 million through attack paths outside the identified audit scope, representing 94% of their losses. Smart contract reviews remain essential, but AI makes it easier to find weaknesses across integrations and combine them into cross-component attacks, so security reviews must now cover the whole system.
Josef Gattermayer, Founder and CEO Ack3
The takeaway is brutal in its simplicity. “Audited” is a marketing word until you ask three questions: what exactly was reviewed, how long ago, and who controls the keys today. In H1 2026, the honest answers were too often: not this bit, over a year ago, and one compromised key from a catastrophe.
The auditors can read every line of the code. They can’t read the developer’s mind when clicking a link from “HR”.
Discover: The Best Crypto to Diversify Your Portfolio