Stolen Keys Cost More Than Code Bugs in DeFi's 2026 Loss Tally

Compromised keys, and not flawed code, produced most of what decentralized finance lost in 2026. On CertiK's half-year figures, infrastructure and operational failures account for about 76% of losses while making up roughly 15% of incidents; smart-contract bugs are about 60% of incidents and a far smaller share of the money. crypto.news set the pattern out again on Friday, counting more than 30 exploits above $3 million on rekt.news's leaderboard for the year. What the trackers do not agree on is how much has actually been lost.
Three tallies that will not line up
CertiK's own release for the first half says over $1.31 billion; ForkLog's account of the same report says $1.32 billion. TRM Labs counts $972 million across 207 incidents. SlowMist counts about $956 million across 182. The Crypto Times, citing CertiK, puts the incident count at 344. Same six months, three totals, and a spread of more than $360 million between the highest and the lowest. None of the three publishes a scope statement that would explain the gap, and the figures do not reconcile.
The direction of travel splits too. CertiK's total is 46.8% below the same period of 2025, though ForkLog notes that removing February 2025's $1.4 billion Bybit hack turns that comparison into a rise of about 28%. SlowMist has losses down 60% while its incident count is up 50%, with the average loss per incident falling 73% to $5.3 million from $19.6 million. That last series rests on one account.
An audit does not cover the signer
Both of the year's largest incidents were operational. KelpDAO lost about $290 million on 18 April and Drift Protocol about $285 million on 1 April, and together they made up more than 70% of a second quarter that ran to $807.5 million, up 59% on the first. CredShields, in its post-mortem on the Drift attack, said the attack surface had moved "up the stack to governance, to signers, and to the people." Every protocol involved had been audited.
"A protocol can pass a flawless code audit and still lose millions because of a compromised admin key," said Ronghui Gu, CertiK's co-founder.
August points the other way
One month cuts against the year. CertiK's August tally has $215 million in confirmed losses, $144.6 million of it in DeFi, and price manipulation accounts for $131.6 million of that against $11.8 million for wallet compromise. Phishing was $41.5 million and code vulnerabilities $20.6 million. About $110.7 million was frozen or returned, though how much reaches depositors is not established. This desk covered those totals when PeckShield and CertiK published counts $79 million apart. For that single month the vector ranking inverts, and no tracker has said whether August breaks the half-year pattern or sits inside its noise.
The hardware-wallet number is still moving
The biggest incident of the second half carries two figures. crypto.news puts losses from the Coldcard hardware-wallet compromise above $130 million; TRM Labs, in its own writeup, calls it a $116 million hack. Neither account acknowledges the other, and the case is not closed. The attacker behind the third wave moved coins for the first time in late August. Full-year reports from all three trackers are due in the new year. Until they arrive, the ranking of attack vectors rests on half-year documents that plainly count different things.
Read also: Term Labs Loses $8.5M to an Attacker Who Simply Won the Vote