Crypto hacks fell in H1 2026, but the security problem did not
CertiK’s H1 2026 data showed a sharp drop in reported crypto losses, but the mix of attacks shifted toward wallet compromises and more sophisticated actors. The takeaway for operators is simple: lower headline losses do not mean safer treasury or payout workflows.

CertiK’s H1 2026 data suggests crypto losses were lower than a year earlier, but the risk picture did not improve in a straightforward way. The main change was in the type of attack, not a clean reduction in attacker capability, which matters for exchanges, treasury teams, and any business moving assets on chain.
What changed in the first half of 2026?
Reporting published on 6 July 2026 said crypto losses in the first half of the year fell by 46.8% to $1.32 billion, with second-quarter losses rising to $807.5 million after two large breaches attributed to North Korean-linked actors reported by TradingView from Cointelegraph coverage and Secureshift’s republication. Cointelegraph’s original report, also mirrored by other outlets, framed the headline decline as misleading because it was heavily influenced by the absence of a single mega-hack on the scale of prior incidents.
The operational takeaway is that aggregate loss figures can fall even when the underlying attack surface stays dangerous. For risk teams, that means a lower dollar total should not be treated as evidence that custody, key management, or payout controls are now safe enough to relax.
Why does the attack mix matter more than the headline total?
The shift from phishing-heavy incidents in the first quarter to wallet compromises in the second quarter is the more important signal. Wallet compromise usually points to failures in private key handling, approval controls, or multisignature governance, which are harder to spot than a simple phishing email and often more expensive to unwind once funds move.
That matters most for businesses that routinely send or receive crypto at scale. Payment processors, exchanges, OTC desks, and treasury operators face a practical question: how are outbound transfers approved, logged, and recovered if a signer, device, or policy layer is compromised? The answer is usually less about one tool and more about layered controls, segregation of duties, and limits on who can move funds alone.
What should operators do now?
Operators should review where a single compromised credential could still authorize a transfer, then tighten those paths first. That includes checking signer distribution, access revocation, device hygiene, and whether payout workflows require enough human and technical separation to stop a fast drain.
For teams that handle recurring disbursements, a controlled payout process can reduce operational risk by making approvals, destination checks, and reconciliation more consistent. In Radom’s case, the relevant product area is mass payouts, but the broader principle is the same for any provider: the safer workflow is the one that makes unauthorized movement harder and easier to detect.
What is the limitation of this data?
This is a snapshot from early July 2026, not a full-year verdict. The data is useful because it shows how attackers adapted, but it does not prove the ecosystem is safer overall. If anything, it suggests the industry should pay less attention to the size of the loss chart and more attention to which control failed, how quickly funds moved, and whether treasury and payout systems can contain the blast radius.
For readers, the practical lesson is straightforward. Treat lower reported losses as a warning against complacency, not as evidence that crypto security has turned a corner.
Sources
- cointelegraph.com
- Crypto hacks fell 47% in H1 but ecosystem is no safer: CertiK
- Crypto hacks fell 47% in H1 but ecosystem is no safer: CertiK
- Crypto Hacks Fell 47% in H1 2026, But CertiK Says the
- Crypto hacks fell 47% in H1 but ecosystem is no safer: CertiK
- CertiK exposes hidden truth behind crypto's 50% loss drop
- Certik: Crypto-related losses in the first half of 2026 fall to ...
Want more analysis like this?
