Disclaimer: Information found on CryptoreNews is those of writers quoted. It does not represent the opinions of CryptoreNews on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoreNews covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.
Hackers Burn $940M in Six Months; Security Audits Overlooked 94% of Losses
Crypto investors lost nearly $1 billion in the first half of 2026, and the industry’s primary safety net—security audits—did little to prevent the losses.
Security research firm Ack3 verified 135 exploits between January and June, attributing $939.86 million in losses to them, with an average loss of $6.96 million per incident. The firm has published its full incident dataset openly, allowing every figure to be verified line by line.
Here is the statistic that should concern every retail investor: of the funds stolen from audited projects, 94.4% exited through code or infrastructure that auditors had not examined. The green tick covered the front door, but the thieves entered through the loading bay.
The Mega Heists Major Crypto Audits Missed
Two mega-heists account for the bulk of the damage, and neither was caused by a bug that an auditor missed.
Kelp DAO’s rsETH lost $292 million in April after attackers forged a LayerZero cross-chain message by compromising the protocol’s single message verifier—one checkpoint with no backup.
Two weeks earlier, Solana perpetuals platform Drift lost $285 million when operatives, linked by researchers to North Korea, spent months socially engineering their way to admin keys. Together, these two incidents totaled $577 million, roughly 61% of all funds stolen in the half-year. This is not a mathematical error; it is broken keys and broken trust.
The pattern repeats throughout the ledger. Step Finance ($40 million), Humanity Protocol ($32 million), and Resolv’s USR stablecoin ($24.5 million) were all drained through compromised private keys and signing infrastructure—the humans, not the smart contracts, were the vulnerability. Cross-chain bridges were another major point of failure, with losses from Verus ($11.5 million), Syscoin ($8 million), and Taiko ($1.7 million).
No platform was safe, not even blue-chip projects. Polymarket was hit twice: a $700,000 internal wallet drain in May, followed by a $3.1 million front-end supply-chain attack in June that turned its own website into a wallet drainer.
CoW Swap had its domain hijacked. In the half-year’s most ironic incident, the feared MEV bot jaredfromsubway.eth, which had spent years extracting value from retail traders, was itself fleeced for $7.5 million by a honeypot token.
The unaudited sector fared no better. Truebit lost $26.4 million to a schoolboy integer-overflow error in its mint pricing.
DISCOVER: The Biggest Crypto Hacks of 2025
One Crypto Audit Isn’t Enough: Good Projects Are Checked Regularly
On the rare occasions when auditors had reviewed the exploited code, the reports were mostly stale; 17 of the 20 nearest relevant audits were at least six months old by the time the hackers struck.
In a warning about the rise of AI tooling, Ack3 CEO and Founder Josef Gattermayer stated:
The takeaway is brutal in its simplicity. “Audited” is a marketing word until you ask three questions: what exactly was reviewed, how long ago, and who controls the keys today. In H1 2026, the honest answers were too often: not this bit, over a year ago, and one compromised key from a catastrophe.
Auditors can read every line of code. They cannot read the developer’s mind when clicking a link from “HR.”
Discover: The Best Crypto to Diversify Your Portfolio
The post Hackers Burn $940M in Six Months; Security Audits Overlooked 94% of Losses appeared first on Cryptonews.