uMaHF0G5M1jYL9t88qHEEkQggU6GJ5wTZlhvItt7
Bookmark
coingecco

$100M Gone: The Biggest Crypto Hacks That Shook Web3 in 2026

More than $100 million has been lost in major crypto hacks throughout 2026 as attackers shift from exploiting smart contracts to targeting infrastruct

Top Crypto Hacks of 2026: How More Than $100 Million Disappeared in Blockchain Security Breaches

The cryptocurrency industry has spent years strengthening smart contracts through audits, bug bounty programs, and increasingly sophisticated security practices. Yet despite these improvements, 2026 has become another costly reminder that blockchain ecosystems remain vulnerable in places far beyond their code.

More than $100 million has vanished across a series of high-profile crypto attacks this year, according to blockchain security researchers. Unlike many of the largest exploits seen in previous years, the majority of recent incidents were not caused by flaws inside smart contracts themselves. Instead, attackers focused on weaker infrastructure surrounding decentralized applications, including bridge verification systems, compromised oracle keys, validator networks, and outdated contracts that had largely been forgotten.

Source: defillama.com data
Security analysts say this trend represents a major evolution in cybercrime targeting decentralized finance. Rather than searching for coding mistakes, hackers are increasingly looking for operational weaknesses that allow them to bypass otherwise secure protocols.

Below is a closer examination of five of the biggest crypto security incidents of 2026, including how each attack unfolded, how much was stolen, the response from project teams, and whether any of the missing assets have been recovered.

KelpDAO Bridge Exploit Becomes the Largest DeFi Attack of the Year

The most devastating incident occurred on April 18 when attackers successfully infiltrated infrastructure supporting KelpDAO's cross-chain bridge.

Cross-chain bridges allow users to transfer digital assets between different blockchain networks. To verify every transfer, bridge systems rely on validator or verifier nodes that confirm whether transactions are legitimate before assets are released on another chain.

In KelpDAO's case, investigators discovered that the bridge relied on a single verifier instead of multiple independent validators. That design decision created a critical single point of failure.

After compromising backend infrastructure connected to the verifier, attackers generated fraudulent bridge confirmations that appeared completely valid on-chain. As a result, they were able to authorize enormous asset withdrawals without triggering immediate security alarms.

The exploit resulted in the theft of approximately 116,500 rsETH, valued at roughly $292 million, making it one of the largest decentralized finance hacks ever recorded.

The project's emergency multisignature wallet quickly froze core protocol contracts approximately 46 minutes after suspicious activity began. That response prevented additional withdrawal attempts, limiting even greater losses.

Source for verification: KelpDAO official X post


Following the attack, disagreement emerged between KelpDAO and its bridge infrastructure provider regarding responsibility for the vulnerable architecture. Eventually, the infrastructure provider acknowledged that using only one verifier was inappropriate for a bridge responsible for securing assets worth hundreds of millions of dollars.

Despite extensive investigations, the stolen cryptocurrency has not been recovered. Blockchain tracking shows the assets have largely remained inactive, while KelpDAO has migrated to a more secure cross-chain messaging solution.

Ostium Oracle Attack Demonstrates the Risks of Compromised Price Feeds

Another major exploit occurred on July 15 when decentralized derivatives platform Ostium suffered an attack targeting its oracle infrastructure.

Unlike decentralized exchanges that depend solely on blockchain pricing, Ostium offers perpetual futures tied to traditional financial assets such as stocks and foreign exchange markets. To function correctly, the platform continuously receives external price updates through trusted oracle signers.

Investigators determined that an attacker obtained access to one of the authorized oracle signing keys.

Using the compromised credentials, the attacker submitted manipulated price reports that reflected future market values rather than current prices. These fabricated price feeds temporarily distorted trading conditions, allowing losing positions to appear highly profitable before funds were withdrawn.

Security firms estimate losses between $18 million and $24 million, with the precise amount varying depending on blockchain forensic analysis.

Source for verification: Ostium exploit
According to Ostium's founder, unusual trading activity was detected almost immediately, prompting the platform to suspend trading within approximately one hour. The company later confirmed that external cybersecurity specialists and law enforcement agencies had joined the investigation.

As of the latest available information, no public recovery effort has succeeded, and no reimbursement program has been formally announced.

Verus Bridge Exploit Ends With an Unusual Settlement

The Verus blockchain experienced its own bridge-related attack on May 17 after hackers exploited missing validation checks inside the Verus-Ethereum bridge.

The vulnerability allowed unauthorized withdrawals of wrapped Bitcoin, Ether, and USDC directly from bridge reserves.

Total losses reached approximately $11.58 million.

The Verus development team responded rapidly by shutting down block-producing nodes and deploying an emergency software update that closed the vulnerability before additional assets could be stolen.

However, the project's next decision attracted widespread attention throughout the cryptocurrency industry.

Instead of immediately threatening legal action alone, Verus publicly offered the attacker a settlement. If 75 percent of the stolen assets were returned within 24 hours, the remaining 25 percent would be treated as a legitimate white-hat bounty rather than criminal theft.

The strategy proved effective.

Within several days, approximately 4,052 ETH, valued at roughly $8.5 million, had been returned to the protocol. The attacker retained nearly $2.8 million under the proposed agreement.

Source for verification: Verus recovery
Although the recovery represented one of the industry's most successful negotiated settlements, Verus noted that accepting the returned funds did not eliminate the possibility of future legal action.

THORChain Suffers Insider Validator Security Breach

On May 15, decentralized liquidity protocol THORChain encountered another significant security incident involving its validator network.

Source: Yt THORChain

According to the project's investigation, an individual who had recently joined the network as a node operator exploited weaknesses within THORChain's distributed transaction signing process.

Validators in THORChain collectively authorize asset transfers using shared cryptographic signatures. By abusing flaws in this coordination mechanism, the attacker reconstructed sufficient signing authority to gain unauthorized access to one of the protocol's vaults.

Approximately $10.7 million in cryptocurrency was removed from the compromised vault.

Source for verification: THORChain exploit

THORChain's automated monitoring systems detected irregular fund movements within minutes, triggering an emergency suspension of trading and signature generation across the network.

Importantly, the underlying blockchain continued operating while protocol functions remained paused.

The network stayed partially suspended for nearly five weeks while developers conducted forensic investigations and coordinated security upgrades alongside node operators.

Rather than issuing additional RUNE tokens to compensate for losses, which would have diluted existing holders, THORChain absorbed the financial impact using protocol-owned treasury reserves.

The incident also renewed attention to THORChain's history of previous security challenges, reinforcing ongoing concerns regarding validator infrastructure and operational security.

DxSale Legacy Locker Exploit Exposes Forgotten Smart Contracts

The final major incident highlights a very different type of blockchain risk.

The theft itself occurred on May 29, but investigators later discovered that the underlying vulnerability had existed for nearly nine months.

Source for verification: DxSale exploit
Ownership of an older DxSale liquidity-locking contract on BNB Chain had quietly transferred to another wallet approximately 269 days before the exploit. No public announcement informed users that administrative control had changed.

Many projects continued storing liquidity inside the legacy contract under the assumption that it remained secure.

Once the new owner gained full control, the attacker used an updated BNB Chain transaction capability to execute coordinated withdrawals affecting roughly 1,400 separate liquidity positions, including assets locked as far back as 2021.

The exploit resulted in losses estimated at approximately $7.3 million.

DxSale later stated that its newer liquidity locker contracts had undergone independent security audits and remained unaffected by the attack.

However, critics argued that the company's explanation focused primarily on technical transaction mechanics while providing limited discussion regarding the undisclosed ownership transfer that ultimately enabled the exploit.

As of the latest reports, no comprehensive reimbursement plan has been announced for affected users.

Blockchain Security Is Entering a New Era

Taken together, these five attacks reveal an important shift in the evolving landscape of cryptocurrency security.

In previous years, many of the industry's largest exploits originated from vulnerabilities buried deep inside complex smart contract code. Today, attackers increasingly recognize that surrounding infrastructure often presents easier opportunities.

Bridge verification systems, validator networks, oracle signers, administrative permissions, and aging contracts have emerged as attractive targets because they frequently operate outside the visibility of traditional smart contract audits.

The KelpDAO breach demonstrated how a single infrastructure weakness could expose hundreds of millions of dollars. Ostium highlighted the enormous influence of trusted oracle keys. THORChain illustrated the risks associated with validator coordination, while DxSale underscored the long-term dangers posed by legacy contracts that receive little ongoing oversight.

Verus offered one of the few positive outcomes by recovering most of its stolen assets through negotiation, but such successful resolutions remain uncommon across the decentralized finance industry.

For investors, developers, and protocol operators alike, these incidents reinforce a critical lesson: blockchain security extends far beyond smart contracts. Every component surrounding a decentralized application, from infrastructure providers to validator architecture and operational procedures, now represents a potential attack surface.

As the cryptocurrency ecosystem continues expanding, experts believe future security efforts must focus just as heavily on operational resilience as they do on code quality. Without stronger protections across the broader blockchain infrastructure, sophisticated attackers will continue finding new ways to exploit the weakest links in decentralized finance.


hoka.news – Not Just Crypto News. It’s Crypto Culture.

Writer: Barland Vex

Crypto Market Analyst & Onchain Storyteller

Barland Vex is a veteran crypto writer who treats the chaos of digital markets as his playground. With a sharp instinct for reading Bitcoin's movements, DeFi waves, and the narratives that move millions of dollars in a matter of hours, Vex delivers analysis that's always one step ahead of the market itself.


From deep onchain reports to bold trend predictions, every piece is crafted to give readers one thing: an edge. Followed by traders, builders, and investors who refuse to miss a beat, Barland Vex is the name the market turns to when things start moving wild. 

Check out other news and articles on Google News

Disclaimer:


The articles published on hoka.news are intended to provide up-to-date information on various topics, including cryptocurrency and technology news. The content on our site is not intended as an invitation to buy, sell, or invest in any assets. We encourage readers to conduct their own research and evaluation before making any investment or financial decisions.
hoka.news is not responsible for any losses or damages that may arise from the use of information provided on this site. Investment decisions should be based on thorough research and advice from qualified financial advisors. Information on hoka.news may change without notice, and we do not guarantee the accuracy or completeness of the content published.