CertiK research finds wallet key compromises now exceed smart-contract bugs as DeFi's leading attack vector, with $444.5M lost to 33 compromises in H1 2026 versus $151.6M across 204 code bugs.
Security & Exploits ·
Research from CertiK has identified a shift in the leading attack vector threatening decentralized finance. Wallet key compromises now pose a larger financial threat than smart-contract code vulnerabilities, marking a change in the risk landscape for DeFi participants and platforms. Analysis covering H1 2026 shows that while smart-contract bugs remain numerous, the damage from compromised keys has surpassed them in total impact.
The data reveals a sharp contrast in scale: 204 incidents of code-bug exploits resulted in $151.6M in losses, whereas 33 wallet compromise events generated $444.5M in losses during the first half of the year. This disparity suggests that while code vulnerabilities remain frequent, each compromised key incident carries substantially higher financial consequences. Combined, these two attack vectors account for $1.3B in losses across the period examined.
The findings underscore a gap between the frequency and severity of attack types in DeFi. Questions remain about the specific mechanisms driving wallet compromise incidents—whether through social engineering, malware, phishing, or other vectors—and what preventive measures platforms and users might adopt to address this emerging priority.