2026 年 DeFi 因黑客攻击损失了 13 亿美元,而同样的攻击仍在继续
核心要点
- The Coldcard incident is not a DeFi hack in the traditional sense.What is the Coldcard hack and how does it relate to DeFi security?
- The Coldcard hack

Compromised keys, not broken code, now drive the majority of crypto theft, and North Korea is cashing the checks.
Summary DeFi protocols have lost at least $1.3 billion to exploits in the first eight months of 2026, according to Forbes and CertiK, with compromised private keys overtaking smart contract bugs as the leading attack vector for the first time on record.
Drift Protocol lost $285 million on April 1 after attackers spent months social engineering their way to an admin key, then drained the protocol in 128 seconds. KelpDAO lost $290 million 17 days later through a single compromised verifier on its LayerZero bridge.
North Korea’s Lazarus Group (operating as TraderTraitor) has been attributed to at least $575 million of 2026 losses across the Drift and KelpDAO hacks alone, meaning a single state actor accounts for roughly 44% of the year’s total.
Bridge infrastructure remains the dominant failure point. AFX Trade ($24.15 million), VerusCoin ($19.14 million across two exploits), and the Cosmos EVM underflow chain ($20.8 million across MANTRA, TAC, and KiiChain) all involved cross-chain verification layers that broke in the same predictable way.
The Coldcard hardware wallet exploit ($130 million, July 30) proved that the compromised key problem extends beyond DeFi protocols. A firmware bug made seeds guessable, and attackers brute-forced their way into thousands of wallets without touching a single network.
Eight months into the year, and the crypto industry has already replayed the same failure mode enough times to fill a textbook. The attack surface has not changed. Protocols keep trusting a small number of keys, signers, and verification nodes, and attackers keep finding that it is cheaper to compromise one person than to break one smart contract.
The numbers are stark. CertiK’s Hack3d H1 2026 report and Forbes both put total crypto hack losses at $1.3 billion through the first half of the year. TRM Labs arrived at a similar figure, noting that losses were trending just below the $1 billion mark for DeFi alone. The rekt.news leaderboard, which tracks individual exploits above $3 million, lists more than 30 incidents from 2026 so far, with the top two alone accounting for $575 million.
What separates 2026 from prior years is not the dollar amount. It is the attack taxonomy. The year’s biggest thefts did not exploit reentrancy bugs, flash loan loops, or oracle manipulation. They exploited people. Social engineering, session hijacking, validator key theft, and governance capture now drive the majority of losses by dollar value. The code passed every audit. The humans around it did not.
Two hacks, one playbook, $575 million gone
The year’s defining moment happened in an 18-day window between April 1 and April 18.
On April 1, attackers drained Drift Protocol of $285 million in 128 seconds. Drift was Solana’s largest perpetuals exchange. The exploit did not touch a single line of smart contract logic. The attackers had spent months posing as a quantitative trading firm, attending conferences, meeting Drift contributors in person across multiple countries, and building the kind of trust that this industry runs on.
JUST IN: The Sandbox hit by major exploit as attackers mint 49B unbacked $SAND
The team isolated liquidity on BSC and Base, disabled bridging, and is preparing a compensation plan for affected LPs pic.twitter.com/zEktGZJbNG — crypto.news (@cryptodotnews) August 23, 2026
By the time they struck, they had obtained pre-signed authority from Drift’s Security Council using a durable nonce, a legitimate Solana feature. They whitelisted a worthless token called CVT, deposited 500 million of it as collateral against a fake oracle they had controlled for three weeks, and withdrew $285 million in USDC, SOL, and ETH.
Neodyme’s 2024 audit had flagged the exact mechanism. The report noted that admin instructions like InitializeSpotMarket accepted an oracle account with zero validation. It was rated informational, reasoning that only the admin could call it. Two years later, the admin key was in the wrong hands, and the informational finding became a nine-figure exit.
Seventeen days later, on April 18, KelpDAO lost $290 million through its LayerZero bridge. The method was entirely different. No conference circuit, no fake trading desk. Someone social-engineered a LayerZero Labs developer on March 6, lifted their session keys, and used that access to poison the RPC infrastructure feeding LayerZero’s verifier network. External nodes were DDoS-ed into silence. The remaining compromised nodes signed off on a forged cross-chain message, and the bridge minted 116,500 unbacked rsETH.
The stolen rsETH went straight into Aave as collateral, borrowed real WETH against itself, and moved out before the emergency multisig had assembled enough signatures to pause. Aave’s total value locked dropped $6.28 billion in 48 hours. Nine protocols froze markets. Arbitrum’s Security Council used emergency powers to seize 30,766 ETH from the attacker’s wallet on-chain, a move that split opinion almost as much as the exploit itself.
Both hacks passed their audits. Both teams had followed standard security practices. Both lost everything to a single compromised key.
The Lazarus assembly line
Investigators linked both Drift and KelpDAO to TraderTraitor, a subgroup of North Korea’s Lazarus Group. Mandiant, CrowdStrike, Elliptic, and LayerZero jointly confirmed the KelpDAO attribution. Elliptic tied Drift to the same unit with medium-high confidence.
This is not new. Lazarus was behind the $1.5 billion Bybit hack in February 2025, identified by on-chain investigator ZachXBT within hours. Before that, the same group hit Radiant Capital, the Ronin Bridge, WazirX, and Harmony’s Horizon Bridge across 2022 through 2024. The U.S. Treasury, FBI, and CISA have all published joint advisories naming the group and its tactics.
LATEST: Moonwell loses about $9 million in a Base oracle attack
The exploiter pumped illiquid MAMO from $0.01 to nearly $0.47 and used it as inflated collateral to borrow cbBTC and USDC pic.twitter.com/Q6T41JOlS3 — crypto.news (@cryptodotnews) August 27, 2026
What changed in 2026 is the sophistication of the social engineering layer. The Drift attackers built relationships over months. The KelpDAO attackers targeted a specific developer’s session credentials. In both cases, the initial breach happened through trust, not technology. The technical exploitation only began after the human layer was already compromised.
CertiK’s Ronghui Gu put it plainly in an interview with Forbes: “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key.” That quote now reads more like a warning label than an observation.
Bybit has since sued North Korea, its intelligence agency, and the Lazarus Group in U.S. federal court, trying to recover assets from the $1.5 billion hack. The legal theory is novel, but it underscores how few options victims have when the attacker is a sovereign state.
The math is uncomfortable. Drift ($285 million) plus KelpDAO ($290 million) equals $575 million from a single threat actor in 18 days. Against a total 2026 loss figure of $1.3 billion, Lazarus accounts for at least 44% of all stolen funds. If you include the Bybit hack from late February 2025, the group’s rolling 18-month tally exceeds $2 billion.
Bridges keep breaking the same way
Bridges are crypto’s soft underbelly. They have been since the Ronin Bridge hack in 2022 ($624 million), the Wormhole hack ($326 million), and the Nomad hack ($190 million). Four years later, the pattern has not changed.
In 2026, bridge exploits include KelpDAO ($290 million, single-verifier compromise), AFX Trade ($24.15 million, five compromised validator signatures on an Arbitrum USDC bridge), and VerusCoin ($19.14 million across two separate exploits of the same Ethereum bridge in May and July). The Cosmos EVM underflow bug hit three chains in quick succession: MANTRA ($3.6 million), TAC ($7.5 million), and KiiChain ($9.7 million), all through the same cross-shard receipt replay vulnerability.
The common thread is verification. Bridges must confirm that a message or transaction on one chain is valid before executing it on another. That confirmation almost always relies on a small set of signers, validators, or oracle nodes. Compromise enough of them, and the bridge does exactly what it was designed to do: release funds on the destination chain against what it believes is a legitimate request from the source chain.
AFX Trade is a case study in how thin the margins are. On July 22, five compromised validator signatures cleared the two-thirds quorum on its Arbitrum bridge, draining $24.15 million in USDC. The attacker moved the funds to Ethereum, swapped for 12,467.5 ETH, and consolidated into a single wallet. All of this happened 49 days after AFX had proudly promoted a security audit from Zellic. That audit documented zero test coverage and left acknowledgments unfixed. The dispute window on the bridge was 200 seconds. It disputed nothing.
The VerusCoin Bridge was hit twice: $11.6 million in May, then $7.54 million in July. Same bridge, different gap in the same broken trust boundary. The second time, there was no statement, no bounty offer, no communication at all.
The fix is known but rarely applied. Multi-verifier configurations, where a bridge requires confirmation from multiple independent verification networks before releasing funds, would have stopped both the KelpDAO and AFX Trade exploits. LayerZero publicly blamed KelpDAO for running a single-verifier setup. KelpDAO fired back with Dune data showing 47% of all LayerZero OApp contracts, more than 1,200 of them, use the exact same configuration. Over two and a half years and eight documented integration conversations, KelpDAO says LayerZero reviewed its setup each time and raised no objections.
This is the real scandal. The fix exists. The infrastructure supports it. Almost nobody uses it.
Audits are checking the wrong surface
Rekt.news published an editorial in July 2026 titled “Wrong Attack Surface” that crystallized what the year’s exploits had been screaming: the biggest losses all passed their audits because auditors were checking the code, and the code was fine.
CredShields put it directly in their Drift post-mortem: the attack surface has moved “up the stack to governance, to signers, and to the people building the protocols themselves.”
JUST IN: Governance attack on Term Labs causes $8.5M loss
