LIVE MARKET DATA SAT 11 JUL 2026 UTC [ VIEW ALL COINS ]
// DeFi

On-Chain Losses: $955M Drained From Five DeFi Protocols in H1 2026

Finbold data shows five exploits — led by Kelp DAO and Drift Protocol — accounted for nearly $955.9M in stolen crypto in H1 2026.

James Corrigan · ·3 min read
On-Chain Losses: $955M Drained From Five DeFi Protocols in H1 2026

Five DeFi exploits accounted for $955,864,608 in stolen assets between January 1 and June 2026, according to a Finbold report tracking the largest crypto hacks of the first half of the year. The concentration of losses in just five incidents underscores how a small number of high-value exploits — rather than a broad wave of smaller breaches — drove H1 security losses across the sector.

The single largest hit came on April 18, when Kelp DAO, an Ethereum-based liquid restaking protocol, lost 116,500 rsETH — valued at roughly $293 million — in a supply chain attack. Finbold’s data identifies this as the top exploit of the period, ahead of an April 1 breach at Drift Protocol, a Solana-based DeFi trading platform, where attackers used social engineering tactics to extract approximately $285 million.

Attack vectors diverge across the top five

The remaining three protocols on Finbold’s list — Step Finance, Humanity Protocol and Truebit — were compromised through distinct methods. Step Finance and Humanity Protocol were both hit via private key leakage, while Truebit’s loss stemmed from a smart contract vulnerability, according to the report.

For traders and on-chain analysts, the spread of attack vectors is the notable data point: supply chain compromise, social engineering, key leakage and contract-level bugs each produced nine-figure or near-nine-figure losses independently. That distribution suggests protocol-level audits alone are not closing the exposure gap, since two of the five largest exploits originated outside the smart contract layer entirely — in operational security and human-facing attack surfaces.

Losses land against a backdrop of institutional inflows

Finbold frames the $955.9 million total against a market environment where institutional capital allocation and regulatory clarity — including the Clarity Act in the United States and MiCA in Europe — are cited as tailwinds for a broader crypto market reversal. The juxtaposition matters for positioning: capital inflows tied to regulatory certainty are occurring in parallel with, not despite, continued protocol-level security failures.

Finbold also reports that Ethereum is considering a security-focused upgrade, and notes that wider adoption of AI-driven coding agents is expected to reduce smart contract vulnerabilities in the web3 space over coming months. Neither development has yet been reflected in the H1 loss data, which remains dominated by the April cluster of Kelp DAO and Drift Protocol incidents.

What the data implies for risk desks

With restaking (Kelp DAO) and trading infrastructure (Drift Protocol) accounting for roughly 60% of the H1 total between them, liquidity providers and treasury managers monitoring exposure to liquid restaking tokens and DEX/perp infrastructure on Solana carry the largest tail-risk weighting from this dataset. Private key management failures at Step Finance and Humanity Protocol add a second cluster of operational-security risk that sits outside standard smart contract audit scope.

Finbold’s report does not disclose recovery or reimbursement figures for any of the five protocols, leaving the $955.9 million figure as gross loss rather than net investor impact.

Read more: Ethereum’s USDT Float Falls Below Tron as Aave TVL Halves to $13B

More DeFi

Leave a Reply

Your email address will not be published. Required fields are marked *