THE ANATOMY OF LOSS
- Blockchain Unmasked
- Jul 9
- 13 min read

Blockchain Exploits and Hacks from the Advent of Bitcoin to 2026
Research Report • 2026 | BlockchainUnmasked • Research & Intelligence • July 2026
1. Executive Summary
Since the launch of Bitcoin in January 2009, publicly disclosed hacks and exploits have drained more than US$37.88 billion from the cryptocurrency ecosystem across 2,173 recorded security incidents1 — a figure drawn from a live incident archive that continues to change as new events are logged and older ones revised. A narrower longitudinal study covering 2011 to mid-2025 places direct losses from hacks and scams at $22.7 billion across more than 1,000 major incidents2. These two counts use different scope and inclusion rules, and neither figure captures the full picture as consumer-facing fraud is tracked separately and now dwarfs hacks and exploits, with scam and fraud inflows of at least $9.9 billion in 2024 (later recalculated to $12B by Chainalysis) and a record of at least $14 billion on-chain in 2025, a figure Chainalysis projects will exceed $17 billion3.
Within service and protocol thefts specifically, six of the last nine calendar years have each seen more than $1 billion stolen. The record years remain 2022 ($3.8 billion, mostly driven by cross-chain bridge exploits) and 2025 ($3.4 billion, driven by the $1.5 billion Bybit compromise)4. The first half of 2026 inverted that pattern: a record 207 incidents produced a comparatively modest $972 million in losses, suggesting a year of frequent small-scale exploits interrupted by a few catastrophic breaches5.
This report classifies every major security incident through three root-cause categories — Human (phishing, social engineering, error, insider abuse, coercion), Code Exploit/Bug (smart-contract and protocol flaws), and Third Party/Supply Chain (compromise of trusted vendors, dependencies and infrastructure) — and then models incidents as attack chains rather than static categories. This report argues that the industry has not been defeated by broken cryptography but by failures of trust translation: interfaces that quietly convert user intent into opaque transactions, vendors who inherit custody risk, and workflows that can be socially engineered or coerced.
For law enforcement and regulators, the most consequential development of 2025–2026 is the professionalization of the adversary. North Korean state-linked groups stole a record $2.02 billion in 2025 and account for a cumulative $6.75 billion4 6; physical “wrench attacks” rose 75% in 2025 to 72 confirmed incidents7; and impersonation scams grew more than 1,400% year-over-year, while Chainalysis finds AI-enabled scams were roughly 4.5 times more profitable than traditional fraud.3
The Evolution of Crypto Exploitation Methods, 2009–2026
From stolen wallet files to state-directed supply-chain compromise — the migration of attack methods across three fault vectors

Figure 1. Evolution of attack vectors across the crypto ecosystem, 2009–2026.
2. Scope, Methodology and Data Caveats
Scope. This review covers publicly documented thefts from cryptocurrency exchanges, protocols, bridges, custodians and individual holders from the advent of Bitcoin (2009) through 30 June 2026. “Hacks and exploits” are treated as thefts of funds from services, protocols, exchanges and wallets; consumer fraud (investment scams, pig butchering, romance fraud) is reported separately where relevant, because the leading analytics firms track the two categories under different methodologies.
Valuation. Unless stated otherwise, losses are expressed in U.S. dollars at the time of theft, consistent with the reporting of various data analytics firms.
Data-Source Reconciliation. Because this report draws on multiple analytics providers whose totals differ, reconciliation applies throughout. Divergence between firms is a matter of inclusion criteria and timing, not error: each firm counts different event types, attributes value at different moments, and revises estimates as attribution improves.
3. The Aggregate Record: What Has Been Lost Since Bitcoin’s Advent
The first era of crypto theft (2011–2018) was an era of exchange key compromise. The first widely publicized individual theft was 25,000 BTC taken from the user “allinvain” in June 2011, which was followed, within days, by the first Mt. Gox breach9. Mt. Gox’s terminal 2014 collapse revealed the loss of approximately 850,000 BTC (actual realized loss ~650,000 BTC, after some recovery, ≈$460 million at the time), attributed to long-running private-key compromise. Bitfinex lost 119,754 BTC in 2016 ($72 million then; the DOJ’s 2022 seizure of ≈94,000 of those coins, valued at $3.6 billion, remains a landmark of blockchain forensics)10, and Coincheck lost $534 million in NEM from an unprotected hot wallet in January 2018.
The second era (2020–2022) belonged to code. As decentralized finance locked tens of billions of dollars behind novel smart contracts, attackers industrialized the exploitation of contract logic, oracle feeds and, above all, cross-chain bridges. Stolen funds reached $3.3 billion in 2021 and a record $3.8 billion in 2022; in October 2022 alone, $718 million was taken in eleven DeFi incidents and bridges accounted for roughly 64% of the year’s losses to that point.11
The third era (2023–present) is the era of keys, people, and trusted third parties. Losses fell by more than half in 2023 (to ≈$1.7 billion) as protocol security matured, then rebounded to $2.2 billion in 2024 — with private- key compromise alone accounting for 43.8% of stolen value12 — and to $3.4 billion in 2025, when the Bybit incident became the largest publicly disclosed theft in cryptocurrency history and the top three hacks represented 69% of all service losses. The first half of 2026 recorded 207 incidents — more than any prior six-month period and more than double H1 2025’s 83 — yet losses of $972 million, with a median incident of roughly $219,00013.
LuBian precedent: In December 2020, the LuBian Bitcoin mining pool lost 127,426 BTC — approximately $3.5B at the time, and valued at more than $14B earlier this year.14 The loss reportedly stemmed from private keys compromised by a weak pseudo-random number generator with only 32 bits of entropy. We exclude LuBian from consideration because its five-year concealment falls outside our methodology, which relies on contemporaneous public reporting. Although often described as the largest cryptocurrency theft on record, the incident is methodologically distinct: neither the victim nor the apparent holder of the funds publicly disclosed it at the time, and it remained hidden until Arkham Intelligence surfaced the case in August 2025. The matter later culminated in an October 2025 U.S. DOJ indictment against Chen Zhi and the historic seizure of the funds. Because the original 2020 sweep has not been publicly resolved, attribution remains contested. The DOJ treats the coins as proceeds linked to Chen Zhi (Prince Group), but the identity of the party that executed the initial transfer is still unresolved in the public record. |

Figure 2. Annual value stolen from cryptocurrency services and protocols, 2021–2026 (H1). Earlier years exceeded, $1B in 2018; pre-2018 data is dominated by the Mt. Gox, Bitfinex and Coincheck events discussed above.
4. The Ten Largest Heists on Record
The ten largest incidents by value at the time of theft together account for approximately $5.70 billion — roughly 15% of all funds ever recorded stolen. Following the H1 2026 data, the tenth position is now held by the ~$292 million KelpDAO exploit of April 2026, which TRM Labs records as the single largest incident of the half, seventeen days after the ~$285 million Drift Protocol attack13; Drift is retained as an instructive near-top-ten case in the box below. Recent large infrastructure and third-party failures — Bybit, DMM Bitcoin, KelpDAO and Drift — all travelled through trusted signing, vendor or bridge channels rather than the victim's own core contract code. North Korea-linked actors are officially attributed (Ronin — OFAC; Bybit, DMM Bitcoin — FBI) or publicly assessed by forensic firms (KelpDAO — Mandiant/CrowdStrike/Chainalysis) as responsible for at least four of the ten — five including the near-top-ten Drift incident (TRM/Elliptic indicators).

The ten largest cryptocurrency heists by value at time of theft (≈$5.70B combined).
Near-top-ten / instructive 2026 incident — Drift Protocol. The ~$285 million Drift Protocol theft (1 April 2026) narrowly sits below KelpDAO but is analytically important: DPRK proxies spent months building relationships with the Drift team (per Drift's post-mortem), while on-chain staging began March 11 — a Tornado Cash withdrawal funded a fictitious CarbonVote (CVT) token, seeded with ~$500 of liquidity and wash-traded into an oracle price. Days after Drift migrated to a 2-of-5 signing threshold with zero timelock, the attacker triggered two pre-signed durable-nonce transactions — executed four slots apart — that transferred admin control in seconds; using that captured authority, the attacker whitelisted the wash-traded CVT token as collateral and executed 31 rapid withdrawals against it, draining the vaults in roughly twelve minutes.17 It is the clearest illustration in this report of authorization-capture: legitimate signers approving an intent they did not understand. |

Figure 3. The ten largest heists colored by primary attack vector. Note the clustering of third-party/supply-chain incidents (teal) in 2024–2026.
Two caveats attach to any all-time ranking. First, valuation at the time of theft excludes incidents whose stolen assets later appreciated enormously — the 2016 Bitfinex theft ($72 million then, $3.6 billion at seizure) being the clearest example. Second, recoveries vary dramatically: Poly Network’s funds were returned almost in full, roughly $470 million of the BNB Bridge mint was frozen on-chain, and KuCoin (2020, $281 million) recovered about 84% — while Bybit, Ronin, Coincheck and DMM produced little or no recovery of principal. For investigators, the ranking is therefore a map of laundering caseloads as much as of losses.
5. The Five Dominant Causes of Loss
Across seventeen years of incident data, five root causes recur. They are ranked here by their combination of historical dollar impact and current prevalence. Note that the first, third, and fifth are close operational relatives —all target the custody and authorization layer rather than blockchain code— which is precisely the migration this report documents.

6. Three-Vector Fault Analysis: Human, Code, Third Party
The five causes collapse into three fault vectors — human, code, and third party — that BlockchainUnmasked applies across its casework. But modern heists are chains, not categories: the largest incidents traverse all three lenses in sequence.

Figure 4. The six-stage attack chain; the three fault vectors run as parallel analytical lenses.
6.1 Convergence: chains, not links
The practical consequence for investigators and supervisors is that response must map to the stage, not the label. In the Bybit case, a third-party vendor was breached (supply chain), the breach weaponized the signing interface against human review (human), and the payload manipulated delegatecall logic (code); in DMM Bitcoin, social engineering (human) compromised a wallet vendor (third party) whose access enabled transaction manipulation (code-adjacent). The correct evidentiary framing — the one this firm applies in casework — is that modern crypto heists are trust failures abused in sequence.

Figure 5. H1 2026: infrastructure and operational compromises were rare but catastrophic — 15% of incidents produced 76% of stolen value.
6.2 The investigative artifact matrix
Because responses must map to the stage of the attack chain, each stage of Figure 4 has a distinct evidentiary footprint. The following is a first-hour preservation checklist for responders, keyed to the six attack-chain stages.

The investigative artifact matrix, keyed to the stages in Figure 4.
6.3 Custody and signing-layer threat model
Because the signing layer is now the primary loss surface, it warrants its own threat model across four control planes. Key generation and custody: weak entropy, seed exposure, hot-wallet leakage, HSM/MPC compromise, privileged cloud identity, recovery-share compromise. Transaction construction: frontend poisoning, RPC substitution, address replacement, proxy-upgrade payloads, call data ambiguity, hardware-wallet display limits. Policy enforcement: velocity limits, asset and destination allowlists, approval thresholds, per-wallet transfer limits, time-locks, emergency revocation. Intent verification: pre-execution simulation, human-readable payload rendering, deterministic decoding, signer out-of-band confirmation, an independent policy engine. Controls must move from “who signed?” to “what did the organization intend to authorize?”16
7. Emerging Vectors and Future Concerns (2026–2028)
The next phase of crypto exploitation is unlikely to be defined by broken elliptic-curve cryptography or a return to simple hot-wallet theft. The probable direction is a continued migration toward the authorization layer—the systems, vendors, employees, devices and interfaces that translate human intent into on-chain state changes.
Bybit was not a failure of Safe's contract code in isolation; it was an attack on the pathway by which trusted signers were shown one transaction while authorizing another. DMM was a vendor-mediated social-engineering operation. Drift and KelpDAO show the same principle now reaching DeFi governance, bridge verifiers, and protocol operations.
7.1 Infrastructure compromise becomes the default mega-heist pattern
The largest losses now come from a handful of infrastructure and operational compromises rather than many code bugs. In H1 2026, about 15% of incidents — chiefly private-key, seed-phrase and signing-system compromises — produced roughly 76% of all stolen value, while the biggest single incident (KelpDAO) alone represented just under 30% of the half13. Expect the mega-heist to remain an infrastructure event, not a Solidity event.
7.2 Signing-layer deception and transaction-intent manipulation
For years, the industry treated cold storage and multisig as the high-water mark of custody. Bybit shows the limit: a quorum of legitimate signers is still unsafe if the transaction-construction environment is compromised, the hardware-wallet display is too opaque for complex calldata, or the policy layer cannot evaluate economic intent. Baseline defenses will need independent transaction simulation, human-readable payload rendering, destination and method allowlists, timelocks for upgrades, signer-device separation, immutable frontend delivery, and policy engines that reject transactions whose economic effect differs from approved intent.16
7.3 Bridge and message-layer failures after the bridge-audit era
The 2021–2022 bridge era was dominated by proof, signature, and validation flaws (Poly Network, BNB Token Hub, Wormhole). That risk persists, but the newer pattern is broader: single-verifier assumptions, compromised internal RPC nodes, relayer-governance weaknesses, and opaque message routing. KelpDAO is the warning case for the whole ecosystem—the weakness was not a classic Solidity bug but a single-verifier LayerZero configuration undermined by RPC infrastructure compromised inside LayerZero's own DVN environment, not KelpDAO's20. Bridges should be evaluated like miniature consensus systems, with explicit assumptions about verifier independence, finality, failure domains, withdrawal limits, challenge windows, and emergency freezes.
7.4 AI-industrialized social engineering, recruiter personas and support impersonation
Generative AI reduces the cost of maintaining believable personas across language, time zone, platform and media format. Chainalysis reports a greater-than-1,400% year-over-year rise in impersonation scams and finds AI-enabled scams roughly 4.5 times more profitable than traditional fraud. Sumsub reports deepfakes accounting for about 11% of global fraudulent activity in its identity-fraud telemetry18. The most severe publicly reported single case saw an investor lose 783 BTC (approximately $91.4 million) to an attacker impersonating hardware-wallet support, per on-chain investigator ZachXBT19. Voice, video, and document checks are no longer sufficient for high-risk actions; high-value withdrawals, signer changes and vendor-access approvals should require out-of-band verification through pre-registered channels.
7.5 State-actor embedded access and contractor/IT-worker infiltration
DPRK-linked operations increasingly combine recruiter impersonation, fake technical screens, contractor placement and long-runway relationship-building—turning the insider model inside out: the attacker may not be an employee when reconnaissance begins, but the campaign is designed to become internal before the theft. The Drift operation involved months of relationship-building with the Drift team (per Drift's post-mortem), with on-chain staging beginning March 11, before signers were induced to pre-authorize the durable-nonce transactions that handed over admin control. HR, contractor onboarding, device management, and source-code access are now asset-protection functions: identity-proofing for remote workers, device attestation, privileged-access segmentation, repository controls and rapid revocation.

FBI wanted poster for DPRK IT workers (fbi.gov/wanted/cyber/dprk-it-workers).
7.6 Physical coercion and the data-breach-to-violence pipeline
A customer-database breach is no longer only a privacy or fraud event; it can become a target list for kidnapping, home invasion and extortion. CertiK verified 72 physical-coercion (“wrench”) incidents in 2025, up about 75% year-over-year, with confirmed losses above $40.9 million, and its 2026 tracking shows a steep early-year trajectory (34 verified incidents January–April, on a path toward roughly 130 for the year)22. National law-enforcement datasets (for example, French prosecutors' counts) use different inclusion criteria and should not be merged with CertiK's global verified figures. Data minimization, executive privacy, home-address suppression where legally possible, duress procedures and wallet compartmentalization now belong in the same risk register as phishing and contract audits.

Figure 6. Confirmed wrench attacks by year. 2026 figure is CertiK’s full-year projection from 34 verified incidents through April.
7.7 Long-tail exploit industrialisation and AI-assisted code discovery
H1 2026 showed a structural inversion: record incident counts but lower total losses than the Bybit-dominated 2025 period—207 hacks, 125 of them smart-contract exploits, at approximately $219K median. Code risk is not solved; it is becoming more industrialised and granular, with attackers automating the discovery of stale code, weak access controls, oracle edge cases, and composability assumptions. The response is continuous assurance: invariant monitoring, on-chain anomaly detection, emergency-pause playbooks, attack simulation, formal verification for critical modules, and bug bounties that reward economically meaningful discoveries.
7.8 Laundering infrastructure and the shortening freeze window
The investigative window is compressing because attackers normalize assets quickly across chains and services. Chainalysis describes a recurring approximately 45-day DPRK laundering cycle, while TRM notes the largest 2026 attacks moved through bridges, THORChain and no-KYC swap paths before off-ramp attempts—with KelpDAO proceeds routed into Bitcoin via THORChain and handled largely by Chinese-language intermediaries. Recovery is a time-to-action problem: incident-response plans should pre-authorize exchange notices, preserve vendor evidence immediately, identify freeze-capable jurisdictions and use multi-hop monitoring rather than first-hop screening alone.
8. Conclusion
Across seventeen years, the locus of loss has migrated from wallet files to exchange keys, to contract code, to bridges, and finally to the signing, vendor and human infrastructure that authorizes movement of funds. Attackers no longer need to break cryptography or, increasingly, even the victim's own code; they inherit trust through a vendor, borrow it through a stolen credential or session, manufacture it through AI-assisted impersonation, or extract it through physical coercion. The controls that matter most in 2026–2028 are therefore those that verify intent rather than identity, that treat vendors and interfaces as part of the custody perimeter, and that compress response time to match a shortening laundering window. BlockchainUnmasked will continue to update this dataset as attribution matures; fast-moving incidents are added to the primary count only once a reliable public source establishes the initial-access path.
9. Methodology and Limitations
This review covers publicly documented thefts from cryptocurrency exchanges, protocols, custodians, and wallets from 2009 through 30 June 2026. Losses are stated in USD at the time of theft unless noted, consistent with Chainalysis and TRM practice; this understates present-day value for early incidents. Each incident is assigned one primary fault lens to avoid double-counting, with secondary contributors noted. Aggregate figures are lower bounds subject to upward revision—Chainalysis notes its annual illicit-volume estimates have historically grown by an average of about 24% between reporting periods. Undisclosed events such as LuBian are excluded from time-of-theft rankings and flagged separately in Section 3. Live databases such as SlowMist and DefiLlama were accessed on 6–7 July 2026, and their counts may since have changed1 8.
10. Sources
S1. SlowMist — Hacked incident archive (cumulative all-time theft; live database). https://hacked.slowmist.io
S2. Crystal Intelligence — “$22.7B in stolen digital assets since 2011” (>1,000 incidents, Jun 2011–Apr 2025). https://crystalintelligence.com/thought-leadership/22-7b-in-stolen-digital-assets-since-2011/
S3. Chainalysis — 2026 Crypto Crime Report: Scams (2025 scams ≥$14B; impersonation +1,400%; AI 4.5×; 2024 recalculated $9.9B→$12B). https://www.chainalysis.com/blog/crypto-scams-2026/
S4. Chainalysis — “2025 Crypto Theft Reaches $3.4 Billion” (2025 total; Bybit impact; DPRK $2.02B / $6.75B; personal-wallet 20% / $713M; 45-day laundering). https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/
S5. BlockchainUnmasked — LinkedIn post, Q2 2026 crypto loss data (branded chart and analysis). https://www.linkedin.com/feed/update/urn:li:activity:7478192037557858305
S6. The Record (Chainalysis data) — $2.17 billion in crypto stolen in first half of 2025, driven by North Korean hacks. https://therecord.media/chainalysis-crypto-stolen-billions
S7. CoinDesk — wrench attacks jumped 75% in 2026 (physical-coercion trend coverage). https://www.coindesk.com/markets/2026/02/02/crypto-crime-is-getting-violent-wrench-attacks-jumped-75-in-2026
S8. DefiLlama — hacks tracker (protocol-level incident values; April 2026 monthly record; live dashboard). https://defillama.com/hacks
S9. Wired — coverage of the Mt. Gox collapse (~$460M loss at the time). https://www.wired.com/2014/03/bitcoin-exchange/
S10. U.S. Department of Justice — two arrested for alleged conspiracy to launder $4.5 billion in stolen cryptocurrency (Bitfinex theft laundering case). https://www.justice.gov/archives/opa/pr/two-arrested-alleged-conspiracy-launder-45-billion-stolen-cryptocurrency
S11. Chainalysis — “2022 Biggest Year Ever for Crypto Hacking, With $3.8 Billion Stolen.” https://www.chainalysis.com/blog/2022-biggest-year-ever-for-crypto-hacking/
S12. Chainalysis — “$2.2 Billion Stolen from Crypto Platforms in 2024.” https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/
S13. TRM Labs — “H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion” (207 incidents; $972M; median $219K; 125 contract exploits; 76%/15% infra split; KelpDAO/Drift values). https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion
S14. Elliptic — “$15 Billion US Seizure Reveals Prince Group's Connection to Iran/China Bitcoin Mining Theft.” https://www.elliptic.co/blog/15-billion-us-seizure-reveals-prince-groups-connection-to-iran-china-bitcoin-mining-theft
S15. The Block — “North Korea Accounts for 76% of 2026 Crypto Hack Losses…” (KelpDAO/Drift mechanics; DPRK share trajectory). https://www.theblock.co/post/399569/north-korea-accounts-for-76-of-2026-crypto-hack-losses-with-theft-since-2017-topping-6-billion-trm-labs
S16. BlockSec — Bybit incident technical analysis (frontend/S3 injection; UI-payload mismatch; proxy masterCopy replacement; delegatecall drain). https://blocksec.com/blog/bybit-incident-a-web2-breach-enables-the-largest-crypto-hack-in-history
S17. TRM — North Korean Hackers Attack Drift Protocol In USD 285 Million Heist. https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist
S18. Sumsub — Fraud Trends 2026. https://sumsub.com/blog/fraud-trends/
S19. CoinDesk — Victim Loses $91M in Bitcoin in Social Engineering Scam. https://www.coindesk.com/business/2025/08/21/victim-loses-usd91m-in-bitcoin-after-social-engineering-scam-zachxbt
S20. KelpDAO — Setting the Record Straight Around the LayerZero Bridge Hack. https://x.com/KelpDAO/status/2051754226351771772
S21. Incrypted — Hacken: Crypto Industry Losses Exceed $3 Billion in the First Half of 2025. https://incrypted.com/en/hacken-crypto-industry-losses-exceed-3-billion-in-the-first-half-of-2025/
S22. CertiK — Skynet Wrench Attacks Report. https://www.certik.com/skynet-report/skynet-wrench-attacks-report

BlockchainUnmasked • Research & Intelligence • July 2026