LIVE MARKET DATA SUN 12 JUL 2026 UTC [ VIEW ALL COINS ]
// DeFi

Five Exploits, $955.9M: H1 2026 DeFi Losses Concentrate in Two April Hits

$955.86M lost across five protocols in H1 2026, with Kelp DAO and Drift Protocol alone accounting for roughly 60% of the total.

James Corrigan · ·upd ·3 min read
Five Exploits, $955.9M: H1 2026 DeFi Losses Concentrate in Two April Hits

Five DeFi exploits between January and June 2026 produced a combined $955,864,608 in stolen assets, per data compiled by Finbold. The figure is notable less for its size than for its concentration: two incidents alone account for close to 60% of the total, meaning H1 security losses were driven by a handful of high-value breaches rather than a broad spread of smaller ones.

The two nine-figure outliers

The largest single loss hit Kelp DAO, an Ethereum-based liquid restaking protocol, on April 18. A supply chain attack drained 116,500 rsETH, valued at approximately $293 million at the time. Seventeen days earlier, on April 1, Drift Protocol — a Solana-based DeFi trading platform — lost roughly $285 million to attackers using social engineering tactics rather than a direct contract exploit.

Between them, Kelp DAO and Drift Protocol represent close to $578 million of the $955.9 million H1 total. For desks tracking exposure, that puts the bulk of tail risk squarely on liquid restaking tokens and Solana DEX/perp infrastructure rather than on Ethereum smart contract layers broadly.

Attack vectors split across four categories

The remaining three protocols on the list — Step Finance, Humanity Protocol and Truebit — were compromised through different mechanisms. Step Finance and Humanity Protocol were both hit via private key leakage, while Truebit’s loss originated from a smart contract vulnerability.

That gives four distinct attack vectors — supply chain compromise, social engineering, private key leakage, and contract-level bugs — each producing nine-figure or near-nine-figure losses independently across just five incidents. Two of the five largest exploits originated entirely outside the smart contract layer, in operational security and human-facing attack surfaces, which suggests contract audits alone are not closing the exposure gap for treasury managers and liquidity providers.

Losses run parallel to institutional inflows

Finbold’s report sets the $955.9 million loss figure against a market backdrop where regulatory clarity — the Clarity Act in the US and MiCA in Europe — is cited as a tailwind for institutional capital allocation and a broader crypto market reversal. The data implies these two trends are running in parallel rather than in conflict: capital inflows tied to regulatory certainty have continued alongside, not despite, ongoing protocol-level security failures.

The report also flags that Ethereum is weighing a security-focused upgrade, and that broader adoption of AI-driven coding agents is expected to cut smart contract vulnerabilities in web3 over coming months. Neither development shows up in the H1 numbers yet, which remain dominated by the April cluster of Kelp DAO and Drift Protocol losses. Finbold’s data does not disclose any recovery or reimbursement figures for the five protocols, leaving $955.9 million as gross loss rather than net investor impact.

Read more: Ethereum’s USDT Float Falls Below Tron as Aave TVL Halves to $13B

Sources

More DeFi

Leave a Reply

Your email address will not be published. Required fields are marked *