Compromised keys surpassed smart-contract bugs as the leading DeFi attack vector, with $1.3B in losses recorded in 2026.
Security & Exploits ·
Compromised private keys have become the leading attack vector in decentralized finance, surpassing smart contract bugs for the first time on record, with $1.3 billion in losses recorded during the first eight months of 2026. The Drift Protocol and KelpDAO incidents, which together totaled $575 million, were attributed to North Korea's Lazarus Group, accounting for roughly 44 percent of the year's total DeFi losses. Social engineering and key theft have replaced technical vulnerabilities like reentrancy bugs as the dominant theft mechanism, with attackers finding it cheaper to compromise individuals than to exploit code flaws.