DeFi & NFT

Story: Crypto Hackers Drain $1.08 Billion in 68 Attacks as Social Engineering Surges

By James Thorp

1 / 15

Security Firms Under Fire. Security companies can't keep up with the wave. Alchemix, Trading Strategy, and Yearn Finance all…

2 / 15

Smaller Contracts Get Hit Hard. Older contracts and smaller projects are getting hammered.

3 / 15

Hackers took $1.08 billion from crypto platforms in 68 separate incidents through April 2026. April alone saw 30 of those thefts.

4 / 15

The pace hit more than one hack per day this month. Last week brought 13 separate losses worth over $11 million combined.

5 / 15

Security companies can't keep up with the wave. Alchemix, Trading Strategy, and Yearn Finance all went after Peckshield recently, saying the firm's security alerts made it look…

6 / 15

Even the security experts aren't safe. A business development manager at CertiK had his Telegram account hijacked. Hackers used it to spread malware through fake meeting links.

7 / 15

The visibility of these hacks has jumped partly because of AI. Hackers use AI tools to find weak spots faster.

8 / 15

Pigi Finance ran the numbers and found that 3.37% of DeFi assets get lost to protocol exploits every year. That's just protocol-level stuff—doesn't count bridge hacks or phishing.

9 / 15

Older contracts and smaller projects are getting hammered. They don't have the same security budgets as the big players.

10 / 15

Protocol security has actually gotten better. Smart contract exploits are down compared to a few years ago. But hackers adapted.

11 / 15

The two biggest April hacks prove the point. Drift Protocol and Kelp DAO lost $570 million combined. Neither hack came from a smart contract bug.

12 / 15

More context: Robinhood Users Hit by Phishing Scam That Fooled Gmails Security Filters

13 / 15

ImmuneFi tracks security breaches across crypto and sees the same pattern. Fewer attacks overall, but the ones that succeed are bigger and more complex.

14 / 15

The shift makes sense from the hacker's perspective. Why spend time looking for a smart contract vulnerability that might not exist when you can trick someone into giving you…

15 / 15

Security firms are caught between projects and reality. Projects want reassurance that their code is safe. Security firms want to warn users about risks.

The Currency Analytics

Want the full story?