
Main Takeaway: In the first half of 2026, security firm CertiK counted about $1.31 billion lost across 344 incidents, a record incident count even as the total fell year over year. Most of that money sat in infrastructure that individuals do not control, such as protocols and exchanges. Sorted by type, wallet compromise cost the most, phishing came close behind, and code bugs were the most frequent. The one variable you control is where your own keys live and where signing happens.
Quick Reference
| Term | What it means |
|---|---|
| Crypto hack | A theft of funds from a protocol, exchange, wallet, or user, counted by security firms per incident. |
| Wallet compromise | An attacker obtains the private keys or seed phrase, then moves the funds directly. |
| Phishing | Tricking a person into approving a transaction or revealing secrets through fake sites, messages, or apps. |
| Code vulnerability | A flaw in a smart contract or protocol that an attacker exploits, with no keys needed. |
| Wallet drainer | A kit that lures a user into signing a malicious approval, then spends within that approval on-chain. |
| Air-gapped | A device that does not connect to Wi-Fi, Bluetooth, USB data, or cellular. The ELLIPAL Titan 2.0 works this way. |
How Much Crypto Was Stolen in H1 2026?
About $1.31 billion was stolen across 344 incidents in the first half of 2026, according to the CertiK Hack3d H1 2026 report. The number that stands out is the incident count, which set a record even though the dollar total came down from the year before. In plain terms, attackers ran more operations for less money each, which points to a broad field of smaller attempts rather than a handful of giant ones.
Totals differ by who is counting, so treat any single figure as an estimate. Other firms such as TRM Labs and SlowMist land nearer $950 million for the same period, using different scopes and inclusion rules. The dollar line moves depending on the firm, yet the shape of the year is consistent across reports, which is a record number of incidents with losses concentrated in a few categories. That agreement on shape matters more than the exact total.
Where Did the $1.31 Billion Actually Go?
The losses sort into three layers, and reading them in order tells the real story of H1 2026. The most expensive layer is the keys, the second is people, and the most frequent is code. Much of the $1.31 billion also sat in shared infrastructure such as protocols, bridges, exchanges, and funds, which are systems an individual holder does not run or control.
The keys layer, tracked as wallet compromise, cost about $445 million across only 33 incidents. Few events, heavy damage. The people layer, tracked as phishing, cost about $366 million across 63 incidents. The code layer, meaning contract and protocol vulnerabilities, was the most frequent at 204 incidents, yet it produced roughly $152 million, the smallest average haul of the three. The pattern inverts what many expect, since the most common attack type was the least profitable, and the rarest key-theft events did the most financial harm.
One reading runs through all three layers. The underlying cryptography was not broken. What failed was the reachability of keys and the judgment of people under pressure, which is where the money moved.
Are Crypto Hacks Getting Worse in 2026?
Crypto hacks are getting more numerous but not more costly in aggregate, based on the H1 2026 figures. A record incident count sits alongside a lower dollar total than the prior year, so the frequency rose while the average payout fell. Reading that as safer would miss the detail underneath, because efficiency in some categories improved.
Phishing is the clearest example. Phishing incidents fell about 52.3 percent year over year, yet the dollars lost to phishing dropped only about 10.8 percent. Fewer campaigns extracted nearly as much money, which means the successful ones hit harder. So the honest answer is mixed, since the volume of attempts is up, the total is down, and the operators who remain are more effective per hit.
Wallet Compromise vs Phishing: Which Cost More?
Wallet compromise cost more than phishing in H1 2026, at about $445 million versus about $366 million. The gap is smaller than the incident counts suggest. Wallet compromise reached that total in just 33 incidents, while phishing needed 63 incidents to approach it, so each key-theft event was far more damaging on average.
The distinction is worth understanding because the defenses differ. Wallet compromise is about the keys themselves being exposed, often through leaked seed phrases, malware on a connected device, or a compromised signer. Phishing is about a person being steered into an action, usually approving a transaction that looks routine. One is a key-handling problem, and the other is a decision-making problem, and a full defense addresses both.
What Can You Actually Control?
You cannot patch a protocol or vouch for an exchange, so the parts of this report you can act on are narrow and specific. Your controllable variables are where your keys are generated and stored, and where a transaction is actually signed. Everything else in the $1.31 billion belongs to infrastructure and counterparties outside your hands, and no personal setup changes that.
Because the failures clustered around key reachability, moving keys off connected devices removes one whole path. A cold wallet keeps private keys offline between transactions, and an air-gapped cold wallet such as the ELLIPAL Titan 2.0 goes further by refusing Wi-Fi, Bluetooth, USB data, and cellular, communicating only through scanned QR codes. On the Titan 2.0, private keys are generated and stored offline, sit inside a CC EAL5+ certified secure element, and every transaction is confirmed on the device screen. That closes the malware and remote-signing routes, and the on-screen confirmation gives you a moment to catch a phishing approval before you sign. It does not stop a protocol exploit or an exchange failure, and it is not a claim to have prevented the wider losses. It addresses the one layer you own.
The people layer needs a habit rather than hardware. Verify what you are signing, get software only from official sources, and slow down when a message adds urgency. If you want the mechanics of the most common trap, see our explainer on what approval phishing is and how it works.
The Three Layers at a Glance
| Layer | How it attacks | H1 2026 shape | What you control |
|---|---|---|---|
| Code | Exploits a smart contract or protocol flaw, no keys needed | 204 incidents, about $152M (most frequent) | Little. Favor audited protocols and limit how much you expose |
| Keys | Obtains the private keys or seed phrase, then moves funds | About $445M across 33 incidents (most costly) | A lot. Where keys are generated and stored, offline or online |
| People | Steers a person into signing or revealing something | About $366M across 63 incidents | A lot. Verify every transaction and slow down on approvals |
Which Risks Apply to You?
- You keep funds on an exchange. The main exposure is infrastructure you do not control, so the balance is only as secure as the platform holding it.
- You use a hot wallet every day. Phishing and drainer approvals are the likely path, so read what you sign and be wary of surprise prompts.
- You use DeFi regularly. Malicious approval signing is the risk, so review token approvals and revoke stale ones you no longer need.
- You were prompted to update or install a wallet app. Poisoned software updates and fake apps are a real vector, so download only from official sources and verify the developer.
- You hold long-term savings. Key reachability is your variable, so offline key generation and offline signing keep the keys off connected devices between the rare times you transact.
- You manage funds for an organization. Signing discipline and independent verification of each transaction matter as much as the device, since the people layer scales with the number of approvers.
Frequently Asked Questions
How much crypto was stolen in the first half of 2026?
About $1.31 billion was stolen across 344 incidents in H1 2026, according to CertiK. That incident count set a record, while the dollar total fell from the previous year. Other firms report different totals, with TRM Labs and SlowMist nearer $950 million, because each uses its own scope. The figures vary by firm, though all agree the year featured more incidents with losses concentrated in wallet compromise, phishing, and code exploits.
Are crypto hacks getting worse?
Crypto hacks are getting more frequent but not more costly overall, based on H1 2026 data. The incident count reached a record, yet the aggregate dollars fell year over year, so more attempts produced less total theft. The detail to watch is efficiency, since phishing incidents dropped about 52.3 percent while phishing dollars fell only about 10.8 percent. Fewer campaigns took nearly as much money, which means the successful attacks became more damaging per hit.
What was the biggest category of loss?
Wallet compromise was the most expensive category in H1 2026, at about $445 million, even though it came from only 33 incidents. Phishing followed at about $366 million across 63 incidents, and code vulnerabilities were the most frequent at 204 incidents but the least costly at roughly $152 million. The takeaway is that the rarest attack type, direct key theft, did the heaviest financial damage per event.
How do I protect myself from these attacks?
Protecting yourself starts with the layers you actually control, which are your keys and your approvals. Keep long-term holdings on a wallet that stores keys offline, get software only from official sources, and verify every transaction on a screen you trust before you sign. Review and revoke old token approvals in DeFi, and treat urgency in any message as a reason to slow down. These habits address wallet compromise and phishing directly, which together accounted for the largest share of individual-facing losses.
Is a cold wallet worth it after reading this?
A cold wallet is worth it to the degree that it addresses your controllable layer, which is where your keys live. A cold wallet keeps private keys offline, closing the malware and remote-signing routes behind wallet compromise, and on-device confirmation helps you catch a phishing approval. A cold wallet does not stop a protocol exploit or an exchange failure, so it is not a fix for the whole $1.31 billion. The value scales with how much you hold and how long you plan to keep it.
What is a wallet drainer, and does it steal my seed phrase?
A wallet drainer does not steal your seed phrase, according to security firm Group-IB. A drainer tricks you into signing a malicious approval, and then the funds leave under what the blockchain reads as a legitimate authorization you granted. That is why verifying the details of every signature request matters more than guarding against someone typing your seed, since the drainer does not need the seed at all. You can read Group-IB's breakdown of how crypto wallet drainers work.
Trust Layer
Sources for this article are the CertiK Hack3d H1 2026 report for loss figures and Group-IB for the drainer mechanism, with a note that totals vary by firm. ELLIPAL has been on the market since 2018, with more than 1 million users across 140+ countries, support for 10,000+ tokens across 45+ blockchains, and BIP39 and BIP44 compatibility. The ELLIPAL Titan 2.0 is an air-gapped cold wallet that generates and stores keys offline inside a CC EAL5+ certified secure element and confirms every transaction on its own screen. Independent reviews are available from Coin Bureau, 99Bitcoins, and CryptoNews.
Own it. Then use it.
Security note: No self-custody setup removes every risk. Offline key storage and anti-tamper hardware close significant categories of remote attack, but they do not eliminate physical, supply-chain, firmware, social-engineering, or user-error risks, and they do not affect losses at protocols or exchanges you do not control. Buy from an official source, store your recovery phrase on a durable offline backup kept separately from the device, do not share or digitally enter it, and verify every transaction on the device screen. This article is general educational information about wallet security. It is not financial, investment, or custodial advice.
