Wrong Attack Surface

"A protocol can pass a flawless code audit and still lose millions because of a compromised admin key." - Ronghui Gu, CertiK
It took 128 seconds to drain $285 million from Solana's largest perpetuals exchange on April Fool's Day.
Drift Protocol's control plane was the target, not its code. Privileged key management was compromised, and the money moved out through a transaction that looked, from the outside, like an authorized action.
Seventeen days later, a different protocol named KelpDAO was exploited on a different chain and lost $290 million through a different mechanism, and the result was exactly the same: The system held, the money left.
Two of the year's biggest heists. Two audits that were technically correct.
So what, exactly, did those audits protect - the code, or the illusion that code was the whole attack surface?

Drift and KelpDAO weren't just the year's two biggest losses.
Together they became the clearest test of the thesis: when the failure sits outside the code, who was actually supposed to catch it?
Nobody involved agreed, and the two teams that lived through it had very different answers.
Drift's attackers didn't rush. The operation appears to have started at a conference in the fall of 2025, when a handful of people introduced themselves as a quantitative trading firm looking to integrate with the protocol.
Contributors met them again in other cities, other countries, over the following months.
Trust built exactly the way it's supposed to build in this industry, in person, over time, through the ordinary motions of doing business with someone.
By April 1, that trust paid off. The attackers used a durable nonce, a legitimate Solana feature, to get pre-signed authority from Drift's Security Council, authority that should have required more than a signature to hand over.
Once inside, they whitelisted a worthless token called CVT, deposited 500 million of it as collateral, and walked out with $285 million in USDC, SOL, and ETH.
Neodyme's 2024 audit flagged one issue that turned out to matter: Admin instructions like InitializeSpotMarket accept an oracle account with zero validation. The report rated it informational, reasoning that only the admin could call it, so the impact was limited.
Roughly two years later, that's the exact door the attackers walked through. Once they held the compromised admin key, they created a new collateral market for CVT, their fake token, pointed at an oracle they had built and controlled themselves for three weeks in advance.
The audit had already named the mechanism. It just assumed the key holding it would stay trustworthy.
The same 128-second window also saw the attackers raise withdrawal caps to 500 trillion across five markets, through an admin-only update instruction the report never itemized individually.
Investigators later linked the Drift attack, with medium-high confidence, to UNC4736, aka TraderTraitor, the same North Korea-linked group behind 2024's Radiant Capital hack.
KelpDAO's turn came 17 days later, and the setup looked nothing like Drift's. No conference, no fake trading desk.
Someone social-engineered a LayerZero Labs developer on March 6, lifted their session keys, and used that access to poison the RPC infrastructure feeding LayerZero's verifier network.
External nodes got DDoS'd into silence, leaving only the compromised ones to answer.
When a forged cross-chain message needed a signature, the compromised verifier gave it one.
The bridge minted 116,500 unbacked rsETH, about $290 million, and nothing upstream had reason to question it.
Mandiant, CrowdStrike, and LayerZero jointly attributed the attack to TraderTraitor, the Lazarus subgroup also tied to the Ronin Bridge and WazirX hacks.
Different chains. Different entry points. Same outcome twice: The system did exactly what it was built to do, and the money left anyway.
CredShields put it plainly in their Drift post-mortem: The attack surface has moved "up the stack to governance, to signers, and to the people building the protocols themselves."
Two firms had confirmed the code was fine. Neither had asked who was allowed to sign for it.
If the auditors did their jobs and the money still walked out the door, whose job was it to stop this?
The Blame Game
LayerZero published its post-mortem first, and it didn't flatter the protocol built on it.
The report said KelpDAO had ignored repeated recommendations to run a multi-verifier setup, choosing instead a single DVN, LayerZero Labs' own, as the sole signer on a bridge securing hundreds of millions of dollars.
KelpDAO didn't accept that framing for a day. The rebuttal came with receipts: Dune data showing that 47% of all LayerZero OApp contracts, more than 1,200 of them, run the exact same single-verifier configuration LayerZero was now calling reckless.
Screenshots followed: Over two and a half years and eight documented integration conversations, Kelp says LayerZero reviewed its configuration each time and raised no objections.
Kelp put it bluntly, early in its rebuttal: "LayerZero blamed their users for an issue that was caused by their own infrastructure failure."
LayerZero co-founder Bryan Pellegrino pushed back hours later, disputing Kelp’s account with on-chain records. He said Kelp originally used LayerZero’s defaults, which were MultiDVN or DeadDVN, and later manually migrated to a 1/1 configuration.
Take that with the obvious caveat: It's coming from the infrastructure provider being blamed.
3 days after that, LayerZero reversed course entirely: “We made a mistake by allowing our DVN to act as a 1/1 DVN for high-value transactions,” the company wrote. “We didn’t police what our DVN was securing, which created a risk we simply didn’t see. We own that.”
The same company that had spent weeks pointing at Kelp's configuration chose to take the blame instead.
The technical argument never fully closed, though.
LayerZero’s own forensic report, published weeks later with Mandiant, CrowdStrike, and zeroShadow, said the rsETH bridge had been downgraded from a 2-of-2 configuration to a 1-of-1 before the attack.
The report said the impact was made possible by the affected OApp’s single-verifier configuration and added that LayerZero’s DVN would no longer sign as the sole required attestor on any channel.
Three days after the exploit, something rarer happened. The Arbitrum Security Council froze roughly 30,766 ETH, about $71 million, tied to the stolen funds, acting on identifying information law enforcement had supplied.
SEAL founder samczsun called it a huge day for victims of the Kelp DAO hack, saying he hoped “that we can look back on today as the day our industry realized that we can simultaneously build useful products while also protecting users rather than be a consequence-free infinite money glitch for hackers.”
That's the exception, not the pattern. Most of the money moved before anyone with the power to freeze it agreed on who should have stopped it.
Two teams, two audits, two post-mortems, and neither one answers the question that actually mattered going into the exploit.
Who was responsible for the part nobody thought to audit?
A Moving Target
Ask five security firms how bad the first half of 2026 was, and you get five different answers.
Security firms don't all track the same thing, and that's not a strike against any of them.
Some scope to verified on-chain exploits only. Others count rug pulls and smaller token-level incidents, or narrow the field to DeFi specifically.
Every one of these teams does careful work, they're just building different rulers.
Run the numbers across the major trackers this half.
TRM Labs counted 207 hacks, $972 million.
Immunefi's own June Ecosystem Update repeats that same $972 million figure, attributing it directly to TRM Labs rather than reporting an independently tallied total, which illustrates that apparent agreement can sometimes reflect shared sourcing rather than independent tallies.
Blockaid counted 212 incidents, $1.1 billion.
CertiK's Hack3D put it at 344 incidents, $1.315 billion.
SlowMist logged 182 incidents, $956 million.
QuillAudits, working from a narrower DeFi-only dataset, found 87 incidents, $935.3 million. They also highlighted there was an average of one hack every two days.
Across those six trackers, incident counts span from 87 to 344, and total losses range from $935.3 million to $1.315 billion.
Averaged out, that points to roughly 206 incidents and just over a billion dollars stolen, a rough center of gravity for the half, even if no two firms agree on the exact figure.
One number holds regardless of who's counting: The incident count is the highest ever recorded for a six-month period, according to TRM Labs.
Losses look lower than 2025 only because 2025 had a single $1.5 billion outlier, the Bybit hack, and 2026 didn't repeat it.
CertiK's own analysis makes that point directly: Strip Bybit out of the 2025 baseline, and its 2026 figures come in roughly 28% higher, not lower.
The median hack cost about $219,000, the midpoint if you ranked every H1 2026 incident by size.
The mean, the total divided evenly across every incident, came to $4.7 million, twenty times higher.
That gap is the whole industry in one statistic: Thousands of small, forgettable exploits pulling the median down, and a handful of nine-figure operations pulling the mean somewhere the typical incident never goes.
That split isn't just a quirk of the math. It's proof that frequency and severity are two separate problems wearing the same headline number.
Zoom into DeFi specifically, and the picture shifts again, in a different direction.
ack3's evidence-graded incident ledger, built specifically to track audit coverage rather than headline totals, counted 135 verified incidents in H1 2026 worth $939.86 million.
Of those, 68 had an audited party involved, 46 sat entirely outside any audit's scope, and 20 were in-scope misses, incidents the relevant audit should have caught and didn't.
Their ledger also caught something this piece hadn't touched yet: Supply-chain compromise, sitting at three different scales across the half.
Holdstation lost $462,000 after a stolen developer session token let an attacker inject malicious code into an app update.
Resolv Labs lost $24.5 million after a compromised signing key traced back to a software supply-chain breach.
Polymarket's front end lost $3.1 million after a third-party vendor's script was compromised.
Different sizes, same root cause, and none of it a line of exploited contract code.
Even the question of what counts as audited turns out to be nearly as contested as the question of what counts as a hack.
None of that is a knock on the people doing the counting. This year has genuinely been a rollercoaster, and a hard one to measure.
But if the industry's best trackers still can't settle on the shape of what already happened, what confidence should anyone have in spotting what's coming next?
No Bug Required
The easiest wins in this entire dataset were never the smart contracts.
They were the people who work on them, the vendors they trust, and the keys nobody made hard enough to steal.
Opsec, supply chain, identity, all of it is low-hanging fruit, whether the target is a person or the system they log into every day.
North Korea is just the sharpest, most concentrated version of that same pattern.
One answer to that doesn't depend on whose spreadsheet you trust.
North Korea-linked actors were responsible for most of the loss total in H1 2026. TRM Labs puts that figure at roughly 66%, about $643 million.
Blockaid's number is lower but points in the same direction: 55%, about $609 million, traced to a single DPRK cluster. Different tallies, same concentration of losses.
Hacks and exploits are only part of that revenue stream.
TRM has also tied North Korea to covert IT worker placements, phishing, and fraud that never touch a smart contract at all.
In March, the US Department of Treasury sanctioned six individuals and two entities tied to one such scheme, operatives placed inside crypto and tech firms using stolen identities, laundering an estimated $800 million in 2024 alone.
It's similar to the broader infiltration pattern seen before Drift, built on patience and a fabricated professional identity rather than a single technical exploit.
Sodot co-founder and CEO, Ido Sofer, who builds key management infrastructure for a living, put it plainly on the On The Margin podcast: "There will be hacks. The question is, is it going to be in your company or not. North Korea, they spend a significant amount of resources, and they're going to be successful one way or another. If a nation state is after you, it's going to be very hard."
What's realistic is raising the cost.
"You think about attackers. They're organizations," Sofer said. "They calculate the ROI. If you put enough constraints and enough security rails, the cost is going to be higher than my neighbor and the other company, so probably they're going to go there because the ROI is lower."
None of that requires a smart contract bug. It requires months of patience and a convincing cover story.
That's the wrong attack surface working exactly as intended, long before anyone signs anything.
It's been a long time since Rekt News had to flag an audit as in scope for one of these bigger exploits.
Those are the memorable ones, since they mean contacting auditors with actual questions. It's been a while and they are great at providing receipts.
So when a state actor doesn't need to write a single line of exploit code to get in, what exactly is a security audit defending against?

The vault held. The money still walked out the front door.
Pete and Repeat walk into a store, Pete walks out and who is left?
Repeat.
2026, and stretching back into 2025, these operational failures have been stuck on repeat.
Feels like we are living through the defi version of the movie Groundhog Day.
Drift and KelpDAO had passed the audits that covered their code and integration paths, and together they still lost $577 million to attacks that never touched a line of code. LayerZero and KelpDAO couldn't agree on whose job it was to prevent it.
Five different security firms couldn't even agree on how big the damage was in the first place.
The numbers disagree because the methods disagree, but the signal doesn't.
TRM called it two distinct threat patterns.
Ronghui Gu, CertiK's co-founder, called it the shape of the losses.
Either way: More attacks, and more of the damage concentrated in a handful of nine-figure operations, and more of it happening outside the contract entirely.
Underneath all of it sat one threat actor who didn't need any of those disputes settled to keep winning: Patient enough to spend six months building a relationship before it ever needed a keyboard.
Audits reduce code risk. They don't cover the keys, the signers, or the trust assumptions built around the code, and that's where the money left.
Multi-party computation, multi-verifier bridges, and withdrawal delays are all being proposed as fixes, and each one helps.
None of them stop a six-month friendship built one meeting at a time.
When the wall is reinforced and the door is watched and the money still walks out through the person holding the key, what exactly was being protected?

REKT, anonim yazarlar için halka açık bir platform olarak hizmet eder, REKT'te bulunan görüşler veya içerik için hiçbir sorumluluk kabul etmiyoruz.
bağış yap (ETH / ERC20): 0x3C5c2F4bCeC51a36494682f91Dbc6cA7c63B514C
sorumluluk reddi:
REKT, Web Sitemizde veya hizmetlerimizle bağlantılı olarak web sitemizin ANON yazarı veya REKT tarafından gönderilen, yayınlanan veya neden olunan hiçbir içerikten hiçbir şekilde sorumlu veya yükümlü değildir. Anon yazarın davranışları ve gönderileri için kurallar sağlamamıza rağmen, onun web sitemizde veya hizmetlerimizde yayınladığı, ilettiği veya paylaştığı şeylerden sorumlu değiliz veya web sitemizde ve hizmetlerimizde karşılaşabileceğiniz herhangi bir saldırgan, uygunsuz, müstehcen, yasa dışı veya başka şekilde sakıncalı olan içerikten sorumlu değiliz. REKT, Web Sitemizin veya Hizmetlerimizin herhangi bir kullanıcısının çevrimiçi veya çevrimdışı davranışlarından sorumlu değildir.