DeFi attacks in 2026 have resulted in huge crypto losses, but, according to the recent data, hackers start exploiting the weakness of the infrastructure, not only the weaknesses in the smart contracts.
TRM Labs registered 207 crypto attacks in the first six months of 2026, resulting in a total loss of $972 million, along with over 100 smart contract exploits.

Source: TRM Labs
This tendency does not mean that there is an overall increase in DeFi insecurity. Six-year analysis by Immunefi revealed that the amount of losses in DeFi protocols dropped almost 80% from $2.62 billion in 2022 to $534 million in 2024 and grew to $680 million in 2025. The loss per incident also decreased from $6 million in 2022 to $1.5 million in 2025.
However, the composition of attacks has changed. DeFi applications increasingly depend on oracles, bridges, cross-chain messaging systems, governance mechanisms, privileged wallets, and third-party infrastructure. A failure in one component can therefore expose assets held by another.
DeFi exploits increasingly involve infrastructure.
TRM Labs reported on July 1 that infrastructure attacks represented about 15% of incidents during the first half of 2026 but generated roughly 76% of total losses. The figures show how a relatively smaller number of infrastructure-related attacks can account for a disproportionate share of stolen funds.
The same pattern appeared in 2025. TRM Labs said infrastructure attacks involving private keys, wallets, privileged access, and front-end surfaces caused $2.2 billion of the $2.87 billion stolen during the year. Code exploits accounted for $350 million, or 12.1%, across 52 incidents.
The February 2025 Bybit breach further demonstrated the importance of infrastructure security. Bybit said a forensic investigation found that credentials belonging to a Safe developer had been compromised.
Attackers then accessed Safe’s infrastructure and deceived signers into approving a malicious transaction. The incident was not a conventional smart contract exploit, but it showed how compromised credentials and transaction-signing systems can produce significant losses without directly attacking a DeFi contract.
Cross-chain systems add another layer of risk
Cross-chain infrastructure has become another important component of DeFi security. Ethereum’s security documentation identifies bridges among the largest sources of DeFi hacks and notes their smart contract, systemic financial, and counterparty risks.
The April 2026 KelpDAO rsETH incident illustrated those risks. LayerZero’s May 20 report said attackers stole 116,500 rsETH worth approximately $292 million after exploiting the configuration of KelpDAO’s cross-chain rsETH route.
According to LayerZero, the attack involved social engineering, compromised session keys, and poisoned internal RPC infrastructure. The attacker manipulated information used by the verification system to generate an attestation for a forged cross-chain message.
Aave said the attacker exploited a Kelp LayerZero V2 route between Unichain and Ethereum that relied on a one-of-one decentralized verifier network configuration.
The forged inbound packet was accepted without a corresponding source-side burn, releasing rsETH on Ethereum. Aave subsequently froze rsETH and wrsETH markets where the assets were listed.
| Metric | Reported figure |
| Crypto hacks in H1 2026 | 207 |
| H1 2026 losses | $972 million |
| DeFi losses in 2022 | $2.62 billion |
| DeFi losses in 2024 | $534 million |
| DeFi losses in 2025 | $680 million |
| Median DeFi loss in 2022 | $6 million |
| Median DeFi loss in 2025 | $1.5 million |
| KelpDAO rsETH incident | $292 million |
Audits cannot cover every DeFi security risk.
Audits remain an important security measure, but Ethereum’s documentation warns that they should not be treated as a guarantee against vulnerabilities. Protocols can introduce new risks when contracts are upgraded, parameters change, new collateral is added, or external integrations are introduced.
Economic design can also create vulnerabilities even when contracts operate according to their programmed rules. Oracle manipulation, for example, can become dangerous when lending protocols rely on vulnerable spot prices to value collateral. Flash loans can be combined with price manipulation under those conditions.
Governance systems are an additional potential attack vector due to the ability to use voting power in changing protocol parameters or making treasury decisions. These risks suggest that security analysis should go beyond single lines of code and cover economic assumptions, privileges, oracles, and external systems.
Key takeaways
- Infrastructural attacks represented around 76% of cryptocurrency-related thefts in H1 2026 revealed by TRM Labs.
- Losses from DeFi attacks fell significantly after reaching the 2022 peak to grow back to $680 million in 2025.
- Cross-chain configurations, credentials, oracles, and privileged systems can create major attack paths.
Conclusion
DeFi exploits continue to produce substantial losses, but the available data shows that the security challenge extends beyond smart contract code. Infrastructure, credentials, cross-chain configurations, oracles, and governance can all influence the safety of decentralized applications.
While median losses and overall DeFi losses have declined from earlier peaks, major incidents such as the KelpDAO breach demonstrate why security requires broader controls across the full protocol ecosystem.
FAQs
What are DeFi exploits?
DeFi exploits are any exploits that exploit vulnerabilities in the DeFi system.
What was the level of DeFi losses for 2025?
Immunefi estimated that the losses for DeFi protocols in 2025 were $680 million.
What is the reason behind most crypto losses in 2025?
TRM Labs reported that infrastructure attacks involving private keys, wallets, privileged access, and front-end surfaces caused $2.2 billion of the $2.87 billion stolen in 2025.
Did the KelpDAO incident involve an Aave vulnerability?
No. Aave said the incident did not originate from an Aave protocol vulnerability, although Aave froze affected rsETH and wrsETH markets.





