Cryptocurrency platforms lost $764 million to hackers in the second quarter of 2026, the worst quarter since the same period last year, according to Hacken's latest security report. Infrastructure compromises including stolen keys, compromised signers, and operational failures accounted for 88.3% of the total damage across incidents, while smart contract vulnerabilities played a secondary role.

Two state-attributed breaches dominated the quarter's losses. Drift Protocol suffered a $285 million multisig takeover attributed to North Korea, while KelpDAO's bridge breach cost $292 million and was also attributed to North Korean actors. The two incidents together represent roughly 75% of all second-quarter theft across the sector.

Smart contract flaws appeared in 44 of the incidents but drove only 11% of the damage, according to the report. Development teams and protocols have invested heavily in code audits and formal verification over the past three years. Operational security, key management, infrastructure hardening, and signer protection, caused the majority of losses.

Drift's compromise involved the takeover of its multisig wallet, a governance mechanism meant to require multiple approvals before moving funds. KelpDAO's loss stemmed from a bridge contract breach, an infrastructure component that custodies assets across blockchains. Both stem from failures in operational controls rather than flaws discovered by static code analysis.

MSB Intel

Attacker targeting has moved upstream toward administrative keys, deployment infrastructure, and cross-chain bridges. As protocols mature and code audits become standard, the operational layer where human trust and centralized key storage create exploitable concentrations of risk has become the primary target.

Hacken's findings place Q2 2026 among the costliest quarters in crypto security history. The $764 million loss exceeds most full-year totals from the early 2020s. Q2 2025 remains the only comparable recent quarter, with operational breaches persisting at a high level.

The data point that decides whether this becomes a policy inflection: whether major institutions and protocols begin segregating key management and signer controls from their core development teams and infrastructure audits by the end of 2026.