Crypto thefts reach $2.7 billion in 2026 as North Korea-linked hackers dominate losses
Crypto security incidents have cost the industry nearly $2.7 billion in 2026, with a handful of mega-breaches at exchanges and protocols driving most of the damage. North Korea-linked hackers account for more than a third of that total, a concentration that is reshaping how firms assess and insure against theft.
- CertiK recorded 658 security incidents through September, with $420.4 million later frozen or returned
- Bitget’s $387.5 million breach and the $318.7 million Liquid Network incident together exceeded $700 million
- Elliptic says suspected North Korean hackers stole more than $1 billion across over 51 incidents in 2026
- $2.7B total 2026 crypto losses, down to $2.26B after recoveries
- $1B+ North Korea-linked thefts, over 37% of CertiK’s tally
- $766.5M September losses, topping April’s prior high of $651.3M
- $1.46B Bybit theft in February 2025, the largest confirmed crypto heist on record
Crypto firms and users have lost roughly $2.7 billion to hacks, exploits and fraud so far this year, according to CryptoSlate reported, citing data from blockchain security firm CertiK. Blockchain analytics firm Elliptic separately puts the share tied to North Korea above $1 billion, a threshold it says underscores how dependent the industry’s annual loss figures have become on a small number of state-linked attacks.
CertiK’s dashboard logged 658 security incidents through September. About $420.4 million of stolen funds have since been frozen or returned, cutting the adjusted loss figure to roughly $2.26 billion, or an average of $4.1 million per incident.
September becomes 2026’s costliest month at $766.5 million
Losses spiked sharply last month, reaching about $766.5 million and surpassing April’s prior high of $651.3 million as the year’s most damaging stretch. Two incidents did most of the work: the $387.5 million Bitget breach and the $318.7 million Liquid Network exploit, which together accounted for more than $700 million, equivalent to over a quarter of all gross losses CertiK has tracked in 2026.
Bitget’s breach alone represents about 14.4% of CertiK’s year-to-date losses and now ranks as 2026’s single largest reported crypto incident. It is followed by Liquid Network, then KelpDAO at $291.3 million, Drift Protocol at $285.3 million, and an unidentified victim at $284.8 million. Those five incidents total roughly $1.57 billion, or almost 59% of the $2.68 billion CertiK has recorded this year.
Recoveries have softened some of the blow. Liquid Network clawed back a large share of the stolen assets, and other incidents produced partial or full returns, which is why CertiK’s adjusted total runs about $420 million below the gross figure. That recovery, however, does not erase the operational cost: affected platforms still had to suspend services, replenish customer balances and rebuild systems before any funds came back.
North Korea’s crypto theft crosses $1 billion for the year
Elliptic says the Bitget breach pushed thefts it attributes to North Korea past $1 billion in 2026, spread across more than 51 suspected incidents, according to the firm’s analysis. Measured against CertiK’s $2.68 billion industrywide gross-loss figure, that tally equals more than 37% of this year’s total security losses. Elliptic assessed the Bitget attack as highly likely linked to the Democratic People’s Republic of Korea, citing laundering behavior and infrastructure shared with earlier operations.
Elliptic previously linked the roughly $286 million Drift Protocol exploit to North Korean actors, putting suspected DPRK operations behind more than one of 2026’s five largest crypto thefts.
The campaign extends a pattern stretching back nearly a decade. Elliptic estimated last year that DPRK-linked hackers have stolen more than $6 billion in crypto since 2017, with governments saying the proceeds help fund North Korea’s nuclear weapons and ballistic missile programs, a concern the US Treasury has flagged in designating Lazarus Group and related units as operations controlled by North Korea’s Reconnaissance General Bureau. US authorities previously tied Lazarus to the roughly $620 million Ronin Bridge theft in 2022 and to laundering proceeds from the $100 million Atomic Wallet attack.
Wrench attacks and the shadow of a $1.46 billion record
The escalation of state-linked hacking peaked in February 2025, when attackers stole about $1.46 billion from Bybit, the largest confirmed crypto theft on record. The FBI formally attributed that breach to North Korea, and Elliptic tracked the subsequent laundering of funds through thousands of addresses and cross-chain services.
Physical theft has grown too. CertiK recorded 52 so-called wrench attacks in the first half of 2026, up from 39 a year earlier, with exposure climbing to $124.2 million from $10.5 million and the average loss per incident rising to about $2.4 million from roughly $270,000.
CertiK’s annual data also show incidents spanning multiple blockchains have produced the largest dollar losses, while Ethereum has logged the greatest number of discrete security events. North Korean operators, Elliptic says, are increasingly relying on repeated cross-chain transfers and mixers to break the transaction trail as exchanges and analytics firms get faster at freezing stolen assets.
The BlockWest read. The concentration in these numbers matters more for insurers and exchange treasuries than for headline totals. When five incidents drive 59% of a year’s losses, underwriting and custody decisions should price for tail risk at a handful of large venues rather than for an average breach, and boards should treat state-linked actors as a distinct, higher-severity category requiring separate controls and capital buffers.
Elliptic’s North Korea tally and CertiK’s loss dashboard are both live counts that will keep moving as 2026 closes, and neither firm has indicated the pace of attacks is slowing. The open question for exchanges and protocols is whether faster freezing and recovery, which has already clawed back $420.4 million this year, can keep up with the size of individual breaches before the next nine-figure incident resets the annual tally again.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
