Top Crypto Hacks of 2026: Biggest Web3 and DeFi Security Failures

Bablu Singh Nirwan
Bablu Singh Nirwan
Published:
Last Updated:
Top Crypto Hacks in 2026 KelpDAO, Ostium, THORChain, Verus, and DxSale overview

Top Crypto Hacks: How $100M+ Vanished in Blockchain Attacks

Crypto security has had a genuinely rough stretch this year. Trackers following DeFi exploits put total losses well into the More than $100 million was lost across 20+ top crypto hacks, and the pattern behind them has shifted in an interesting way. Fewer attackers are digging through smart contract code looking for bugs. More of them are going after the people and infrastructure sitting around that code instead: compromised keys, manipulated price feeds, forged bridge messages, and old contracts nobody thought to check on anymore.

defillama data regarding to recent hack

Source: defillama.com data

Here's a closer look at five of the largest incidents from this stretch, broken down by what actually happened, how much was lost, what the team behind each project said afterward, and whether anything was ever recovered in top crypto hacks

graphical representation

The KelpDAO Bridge Exploit

What happened: On April 18, attackers found a way into the infrastructure behind KelpDAO's cross-chain bridge. The bridge runs on a messaging system that lets tokens move between blockchains, and this system relies on a small set of verifier nodes to confirm that a transfer is genuine. KelpDAO's setup used just one verifier instead of several checking each other, so once attackers got into that single verifier's backend servers, they could push through fake confirmations that looked completely legitimate onchain.

How much was lost: Roughly 116,500 rsETH, worth about $292 million. That makes it the single largest loss on this entire list and one of the biggest DeFi hacks of the year overall.

What the team said: KelpDAO's emergency multisig froze the protocol's core contracts within about 46 minutes of the drain, fast enough to block two follow-up withdrawal attempts. In the weeks afterward, KelpDAO and the company behind the bridge infrastructure publicly disagreed over who was responsible for the risky single-verifier setup. The infrastructure provider eventually admitted it had allowed a configuration that wasn't appropriate for an asset holding this much value.

Was it recovered: No. As of the most recent reporting, the stolen funds have simply sat untouched rather than being moved, laundered, or returned. KelpDAO has since switched its bridge over to a different cross-chain messaging provider.

official source of kelpdao

Source for verification: KelpDAO official X post

The Ostium Oracle Exploit

What happened: On July 15, someone got hold of a signer key tied to Ostium's price-feed system. Ostium runs perpetual futures on real-world assets like stocks and forex, and it needs live price data pushed onchain constantly to know whether trades are winning or losing. Using that compromised key, the attacker submitted fake, future-dated price reports that made losing trades look profitable, then simply cashed out the fabricated gains. The whole thing reportedly took about five minutes.

How much was lost: Estimates range between $18 million and nearly $24 million, depending on which security firm's tracing you go by.

What the team said: Ostium noticed the unusual activity almost right away and paused all trading within about an hour of the attack starting. Its founder confirmed the exact timing publicly and said the team was working alongside outside security firms and, separately, with law enforcement to dig into what happened.

Was it recovered? No, that's not been publicly confirmed. No reimbursement plan or fund recovery has been announced as of the latest updates.

official source of ostium hack

Source for verification: Ostium exploit

The Verus Bridge Exploit

What happened: On May 17, an attacker found a missing validation check on the Verus-Ethereum bridge and used it to drain a mix of wrapped Bitcoin, ETH, and USDC straight out of the bridge's reserves.

How much was lost: About $11.58 million total.

What the team said: Verus moved fast, shutting down its block-producing nodes to stop any further transfers and pushing out an emergency patch to close the gap. Then it did something a bit unusual: instead of only threatening legal action, the team publicly offered the attacker a deal. Return 75% of the stolen funds within 24 hours, and the remaining 25% would be treated as an accepted bounty rather than pursued as theft.

Was it recovered? Mostly, yes. The attacker took the deal and returned 4,052.4 ETH, worth roughly $8.5 million, a few days later, keeping about $2.8 million as the agreed bounty. This is easily the cleanest recovery story on this list. Verus did note publicly that accepting the deal didn't rule out further legal action down the line.

official source of verus hack

official source of recover

Source for verification: Verus recovery

The THORChain Vault Exploit

What happened: On May 15, someone who had joined THORChain's network as a node operator just two days earlier exploited a weakness in the process nodes use to jointly sign off on transactions. That let them reconstruct enough key material to move funds out of one of THORChain's six vaults without proper authorization.

Source: Yt THORChain

How much was lost: About $10.7 million from that single vault.

What the team said: THORChain's automated monitoring caught the imbalance within minutes and triggered a network-wide halt on trading and signing, even while the underlying blockchain kept running normally. The network then stayed paused for roughly five weeks while the team investigated and coordinated a response with node operators.

Was it recovered? Not directly, but the protocol chose not to pass the cost onto RUNE holders either. Rather than creating new tokens to cover the gap, which would have diluted everyone's holdings, THORChain absorbed the loss using its own protocol-owned reserves. It's also worth knowing this wasn't a one-off for THORChain; the network has dealt with repeated security incidents over the years, including an earlier personal wallet compromise tied to its founder.

official source of thorchain

Source for verification: THORChain exploit

The DxSale Legacy Locker Exploit

What happened: The real story here starts about 269 days before the actual theft. Ownership of an old DxSale liquidity-locking contract on BNB Chain quietly changed hands to a new wallet, with no announcement made to any of the projects or users whose funds were still sitting locked inside it. On May 29, the new owner used a newer BNB Chain transaction feature to drain the contract in one coordinated sequence, hitting roughly 1,400 separate locked positions, some dating back to 2021.

How much was lost: Around $7.3 million.

What the team said: DxSale's public statement pinned the blame mainly on that newer BNB Chain feature, without really addressing the earlier, undisclosed ownership change that actually gave the attacker control in the first place. The team did clarify that its newer locker contracts, which have been through third-party audits, were untouched and remain safe to use.

Was it recovered? No public compensation plan for the affected liquidity providers has been confirmed as of the latest coverage.

official source of DxSale

Source for verification: DxSale exploit

Conclusion

Line these five up together, and a pattern jumps out fast. The biggest loss on this list didn't come from a flaw in any smart contract; it came from infrastructure sitting just outside it, a bridge's verification system that only had one point of failure. Ostium's attack worked the same basic way, going after a price-feed signer key rather than the trading contracts themselves. Even the smaller losses fit the theme. THORChain's came down to a compromised signing process, and DxSale's traced back to an old, forgotten contract that changed hands quietly without anyone noticing.

The aftermath looked pretty different from project to project, too. Verus talked its way into recovering most of what was stolen within days. THORChain ate the loss itself instead of passing it on to token holders. KelpDAO and Ostium, the two biggest top crypto hacks here, are both still working through investigations with nothing recovered yet. DxSale's response drew some criticism for what it left out of its own explanation. Not one of these five required an attacker to actually break smart contract logic, and that says a lot about where crypto's weakest points really are right now.

Disclaimer

This article is for educational and informational purposes only and should not be considered financial or investment advice. Figures cited reflect estimates reported by blockchain security firms and news outlets at the time of writing and may be revised as investigations continue. Always verify details through official project channels and do your own research before making any financial decisions.

Bablu Singh Nirwan

About the Author Bablu Singh Nirwan

English Blog Writer at coingabbar.com

Bablu Singh Nirwan is a Content Writer with 6 months of experience covering blockchain, cryptocurrency, Web3, and digital finance. He specializes in researching emerging trends, simplifying complex topics, and creating SEO-optimized content. His work focuses on clarity, accuracy, and engaging insights that keep readers informed about the evolving crypto industry.

Leave a comment

3 weeks ago

HOW DO I RECOVER MY LOST CRYPTO FROM A SCAMMER? CONTACT // GEO COORDINATES RECOVERY HACKER There is an expert hacker that can help you in recovering all the money lost to scammers online. GEO COORDINATES RECOVERY HACKER It recently worked for me and I now have peace of mind after the huge recovery of all my lost funds. I’m truly grateful for their service and I recommend their service to everyone who needs to recover their stolen crypto funds. I will advise you to contact them with the details below. Email: geovcoordinateshacker@gmail.com Website; https://geovcoordinateshac.wixsite.com/geo-coordinates-hackError Telegram @Geocoordinateshacker

Profile of Alexa Jason
Alexa Jason

1 month ago

How to Hire a Hacker to Recover Stolen Bitcoin ; META TECH RECOVERY PRO Top Crypto Recovery Expert in USA Meta Tech Recovery Pro was founded to help victims of crypto theft, cryptocurrency scams, and wallet loss recover their digital assets. We recognize that being defrauded is often accompanied by stress, uncertainty, and long-term disruption, and we approach each case with seriousness, discretion, and measurable progress. Our team combines experienced crypto recovery professionals with blockchain forensics specialists. Using systematic analysis of transaction histories, blockchain patterns, and relevant on-chain and off-chain activity, we trace where stolen funds moved, how wallet access was compromised, and what technical pathways may support restoration. This may include tracing suspicious transfers, mapping associated addresses, evaluating links to exchanges or custodial services, and determining recovery options based on the incident’s specific facts. Reach out to them via the following: - Support (@) metatechrecoverypro (.) com - https://wa.link/5ay4fv - - https://metatechrecoverypro (.) com We emphasize legitimacy, transparency, and responsible practice. Effective recovery requires both technical capability and ethical standards; therefore, we use structured procedures rather than unverifiable promises. We provide victims with clarity on what can be pursued and realistic outcomes, guided by evidence rather than marketing claims. Our services cover: - Lost access to a Bitcoin wallet (forgotten credentials, missing seed phrases, compromised devices, inaccessible keys). - Fraud from romance scams, where attackers manipulate victims into sending cryptocurrency while sustaining deceptive trust. - Defrauding via counterfeit or fake investment platforms, including impersonation of legitimate projects, promises of high returns, and deceptive withdrawal of funds. Timely action is critical, as crypto transactions are often irreversible and stolen funds may be quickly dispersed or converted. We encourage victims to document wallet addresses, transaction IDs, dates, communications, and any platform or contact information as early as possible to enable efficient forensic assessment. Our approach is comprehensive, considering how fraud operates, including tactics used to obscure fund flows, exploit wallet vulnerabilities, or socially engineer victims into approving transfers. By evaluating both behavioral and technical dimensions, we improve the likelihood of locating actionable leads and selecting the most appropriate recovery strategy. Recovery also requires accountability, confidentiality, and a patient, methodical mindset. Whether assets were taken through hacking, misdirection, manipulation, or wallet access loss, our team investigates thoroughly and guides you through the recovery process with professionalism. Meta Tech Recovery Pro is committed to helping victims reclaim what was taken, restore control where possible, and provide informed support throughout a challenging experience.

Profile of miguelrenata362
miguelrenata362

1 month ago

How to Hire a Hacker to Recover Stolen Bitcoin ; META TECH RECOVERY PRO Top Crypto Recovery Expert in USA Meta Tech Recovery Pro was founded to help victims of crypto theft, cryptocurrency scams, and wallet loss recover their digital assets. We recognize that being defrauded is often accompanied by stress, uncertainty, and long-term disruption, and we approach each case with seriousness, discretion, and measurable progress. Our team combines experienced crypto recovery professionals with blockchain forensics specialists. Using systematic analysis of transaction histories, blockchain patterns, and relevant on-chain and off-chain activity, we trace where stolen funds moved, how wallet access was compromised, and what technical pathways may support restoration. This may include tracing suspicious transfers, mapping associated addresses, evaluating links to exchanges or custodial services, and determining recovery options based on the incident’s specific facts. Reach out to them via the following: - Support (@) metatechrecoverypro (.) com - https://wa.link/5ay4fv - - https://metatechrecoverypro (.) com We emphasize legitimacy, transparency, and responsible practice. Effective recovery requires both technical capability and ethical standards; therefore, we use structured procedures rather than unverifiable promises. We provide victims with clarity on what can be pursued and realistic outcomes, guided by evidence rather than marketing claims. Our services cover: - Lost access to a Bitcoin wallet (forgotten credentials, missing seed phrases, compromised devices, inaccessible keys). - Fraud from romance scams, where attackers manipulate victims into sending cryptocurrency while sustaining deceptive trust. - Defrauding via counterfeit or fake investment platforms, including impersonation of legitimate projects, promises of high returns, and deceptive withdrawal of funds. Timely action is critical, as crypto transactions are often irreversible and stolen funds may be quickly dispersed or converted. We encourage victims to document wallet addresses, transaction IDs, dates, communications, and any platform or contact information as early as possible to enable efficient forensic assessment. Our approach is comprehensive, considering how fraud operates, including tactics used to obscure fund flows, exploit wallet vulnerabilities, or socially engineer victims into approving transfers. By evaluating both behavioral and technical dimensions, we improve the likelihood of locating actionable leads and selecting the most appropriate recovery strategy. Recovery also requires accountability, confidentiality, and a patient, methodical mindset. Whether assets were taken through hacking, misdirection, manipulation, or wallet access loss, our team investigates thoroughly and guides you through the recovery process with professionalism. Meta Tech Recovery Pro is committed to helping victims reclaim what was taken, restore control where possible, and provide informed support throughout a challenging experience.

Profile of miguelrenata362
miguelrenata362

1 month ago

I recommend Marie when it comes to recovering lost/stolen ust/bitcoin or any kind of cryptocurrencies' from fake investment platforms because they're well specialized in that area and you'll get your money back in full. I can boldly say this right now based on my prior deal i had with them; she was the only one who was able to recover my lost money $52,760 dollars back to my account, Only * (Alpharecovery11@gmail.com and WhatsApp +1 7127594675 successful in recovering my money. They are the only one who can fully restore your lost funds to your account without any deductions, I really value their work and am recommending her to you today. THANK ME LATER

Profile of Liam Hemsworth
Liam Hemsworth

1 month ago

In today's digital world, cyber threats are becoming increasingly sophisticated, placing businesses and individuals at greater risk than ever before. At MUYERN TRUST HACKER, we are dedicated to helping our clients protect what matters most through professional cybersecurity services, advanced digital investigations, and security consulting tailored to modern challenges. Established in 1998, MUYERN TRUST HACKER has built a reputation for delivering reliable cybersecurity solutions with discretion, professionalism, and technical expertise. Our team works with organizations and private clients worldwide, providing strategic guidance and practical solutions designed to strengthen digital security and reduce cyber risk. Our expertise covers a broad range of cybersecurity services, including digital forensics, cloud security consulting, cyber incident response, security assessments, cyber awareness guidance, and digital asset recovery support for legitimate cases involving online fraud or unauthorized transactions. Every engagement begins with understanding the client's unique situation. We believe there is no one-size-fits-all approach to cybersecurity, which is why every solution we provide is carefully planned to meet individual business or personal security requirements. Confidentiality, integrity, and transparency remain at the core of everything we do. As technology continues to evolve, so do cyber threats. MUYERN TRUST HACKER remains committed to staying ahead of emerging risks by applying proven methodologies, continuous research, and industry best practices to deliver dependable security services for clients around the globe. Whether you require proactive cybersecurity planning, assistance following a cyber incident, or professional digital investigations, our team is ready to help you move forward with confidence. Our Professional Services Cybersecurity Consulting Phone/Email Hacks School grade Upgrade Cloud Security Solutions Digital Asset Recovery Serving Clients Worldwide Website: (http://www.muyerntrust.com) Email: muyerntrusted(@)mail-me(.)com Whats App:* +1 2.0.2. 7.0.3 2.2.3.9 *Established 1998*

Profile of Shaya Suriita
Shaya Suriita

Frequently Asked Questions (FAQ)

Faq Got any doubts? Get In Touch With Us