Wrong Attack Surface
The numbers may differ, but the signal holds. The biggest crypto losses of H1 2026 passed every audit. The real attack surface was the keys, signers, and people around the code, not the code itself.
The numbers may differ, but the signal holds. The biggest crypto losses of H1 2026 passed every audit. The real attack surface was the keys, signers, and people around the code, not the code itself.
A second exploit drained VerusCoin's Ethereum Bridge for $7.54 million, following a similar $11.6 million hack in May - same bridge, a different gap in the same broken trust boundary. This time there was no statement, no bounty, just silence.
Five compromised validator signatures cleared the two-thirds threshold guarding a bridge, draining $24.15 million from AFX Trade's USDC custody bridge contract on Arbitrum and moving it out through the same public rails everyone else uses.
AI keeps getting trusted before anyone checks if it should be. The bill is landing. Essays nobody can quote, wrongful arrests, insurance denials reversed 90% of the time, and data centers draining local water. The tool isn't the failure. Trusting it blind is.
An attacker used a trusted price forwarder to feed the vault a fake $60K Bitcoin quote to drain $23.75 million from Ostium on Arbitrum, then collected the payout on trades that were never real.
Four exploits, $2.97 million gone, and a deployer wallet that shouldn't have known the attacker existed. Three years later, a forensic investigator pulled the thread on Zunami Protocol. Five exchanges, an FBI filing, and wallets still moving in 2026.
Zero equals zero. Supra’s oracle verifier accepted a zeroed signature against a zeroed key, and Bonzo Finance on Hedera lost $9.05 million because the math checked out and nobody questioned the premise.
$19.3 million drained from BonkDAO in a pure governance attack. An attacker bought 1% of BONK, buried a treasury transfer inside a boring proposal, and passed it with 2.9% turnout. No code broke., no keys leaked, just crooked token-weighted governance voting math.
$6.04 million stolen from Summer Finance's Lazy Summer depositors when a capped-for-removal Ark was still counted in the vault’s value, letting a donated stale asset inflate the share price and drain real liquidity.
Multi-strategy yield protocol Altura, raised $39 million for a gold-backed strategy, moved funds through Tron, relied on a verifier tied to the COO's own project, ran a dashboard that admitted it verified nothing, closed the vault, and left depositors waiting.
A single missing secret in SecondFi's signing code made every on-chain transaction a private key disclosure. Attackers drained $2.4 million from 374 wallets on Cardano. One line of missing code, nothing more. Just reading what was already there.
$4.67 million lost from Secret Network’s bridge connection to Axelar Network after a forked Secret-side IBC contract minted unbacked tokens from thin air. 2 missing validation checks let an attacker forge deposits with a fake Cosmos chain. Drain went undetected for 7 days.