April 2026 marked DeFi's worst month with $635M lost across 28 exploits, highlighting systemic security culture failures.
Security & Exploits ·
April 2026 saw $635 million in losses across 28 separate exploits, making it the worst month in DeFi history. Two incidents—Drift Protocol and Kelp DAO—accounted for nearly 90 percent of total losses, while the remaining 26 smaller incidents targeted protocols not typically associated with security breaches, suggesting a broader vulnerability across the ecosystem rather than isolated failures.
The largest losses stemmed from preventable architectural and operational failures rather than novel attack vectors. Drift's breach involved months of social engineering that compromised multisig signers through in-person relationship building at industry conferences. Kelp DAO's vulnerability centered on a single-verifier configuration in cross-chain messaging that created a single point of failure. Wasabi Protocol's attacker exploited an unprotected deployer admin key lacking timelock or multisig safeguards. Each attack followed patterns the industry has encountered before.
The concentration of these incidents within 30 days raises questions about whether a coordinated campaign or widespread shift in attacker sophistication is occurring. However, the specific attack surfaces—compromised keys, misconfigured access controls, and social engineering—point instead to gaps in security practices and governance rather than breakthrough exploits. Whether this represents a structural change in DeFi's risk profile or a temporary convergence of execution failures remains unclear.