DeFi suffered $1.3B in hacks during 2026, with stolen keys overtaking code vulnerabilities as the primary attack vector; Lazarus Group attributed to $575M of losses across KelpDAO and Drift.
Security & Exploits ·
DeFi protocols have sustained $1.3 billion in security breaches during 2026, marking a structural shift in attack methodology. Stolen cryptographic keys have displaced code vulnerabilities as the dominant threat vector for the first time on record. The year's largest individual incidents include a $290 million breach at KelpDAO stemming from a single compromised verifier, a $285 million drainage of Drift executed in 128 seconds, and $130 million stolen from Coldcard wallets via guessable seed phrases.
North Korea's Lazarus Group has been attributed to $575 million of these losses—nearly half the year's total—through attacks on Drift and KelpDAO alone. Other notable breaches involved AFX Trade ($24 million from five stolen validator keys) and VerusCoin ($19 million from a bridge exploited twice). The recurrence of key-theft attacks across multiple protocols suggests a persistent vulnerability class that remains difficult to defend against even at scale.
A critical gap remains in understanding why formal security audits, which most of these protocols completed before compromise, failed to detect or mitigate key-management weaknesses. The shift toward credential theft as the primary attack vector implies that traditional code-focused audit methodologies may not adequately address operational security practices or infrastructure hardening.