Security
What 2026's onchain losses reveal for finance teams
CertiK reported a 46.8% drop in losses, but once the Bybit outlier is removed, H1 2026 ran roughly 28% higher, with rising incident frequency and a larger median loss

CertiK's Hack3d report for the first half of 2026 counts $1.31 billion lost across 344 security incidents. On its own, that is a 46.8% drop from the $2.47 billion recorded in H1 2025, but that drop is misleading.
H1 2025 was biased by a single event: the February 2025 Bybit wallet compromise. The $1.45 billion theft accounted for 58.7% of all losses recorded during the period.
Excluding Bybit, H1 2025 losses fall to about $1.03 billion. On that basis, H1 2026 losses were roughly 28% higher. CertiK’s conclusion is direct: “The underlying security environment has not improved; in several meaningful respects, it has deteriorated.”
The incident data supports that conclusion. The total number of incidents was almost unchanged YoY, moving from 345 to 344. The quarterly trend, however, worsened. Q2 2026 recorded 194 incidents, up 34% from 145 in Q2 2025, while total losses remained nearly flat. Median loss per incident also rose sharply, increasing 54.5% year over year in Q1 and 60.6% in Q2. The average loss was $3.82 million, around 28 times the median of $138,703, because a small number of catastrophic events pushed the average far above the cost of a typical incident.
For any company holding digital assets or moving stablecoins, the takeaway is clear: losses remain a routine part of operating onchain. The market recorded 344 incidents in six months, or roughly one every 12 hours.
Finance teams should focus on which failure modes can reach their own workflows, which controls can contain them and how quickly the company can respond when they occur.

Where the losses actually sit
A large share of the losses in CertiK’s data falls outside the control of a company’s finance team. Separating those incidents from the ones a company can influence is essential to understanding where controls and budget should go.
Here is the H1 2026 breakdown by attack vector, from CertiK's executive summary:

Two incidents drove nearly half of everything. The Kelp DAO loss on April 18 ($291.3 million) resulted from a compromised set of RPC endpoints: attackers took over two of the project's designated verifier RPCs, forced a failover onto poisoned nodes, and had fabricated withdrawals confirmed.
The Drift Protocol loss on April 1 ($285.3 million) resulted from a multi-stage admin and multisig key compromise that enabled the attacker to fabricate collateral and borrow against it.
Together, those two events account for about 44% of all H1 losses. Both originated in protocol infrastructure and key management. Transaction controls used by an operating company would not have prevented either event. The same applies to the 204 code-vulnerability incidents, which require stronger contract audits, security testing and re-audits after code changes.
This distinction matters because it determines where finance teams should focus. More than half of the total losses came from categories that pre-execution treasury controls cannot address. The relevant question is what remains once those losses are separated out.
Which losses finance teams can influence
Look at phishing. The headline is $366 million across 63 incidents, but the shape underneath is sharper than the total suggests. Just four social-engineering incidents produced $310 million, about 85% of all phishing losses, and the single largest was one victim losing $284.8 million across multiple chains in January.
By comparison, 27 wallet-drainer incidents caused about $11.4 million in combined losses. In this dataset, the greatest exposure came from a small number of targeted attacks designed to convince someone to authorize a high-value transfer to an address they believed was legitimate.
That failure mode sits directly inside a company’s treasury workflow. The authorized person may have followed the signing process correctly while relying on false information about the recipient. The relevant controls therefore need to operate at the point of transfer, before the transaction is approved and broadcast.
Range addresses that layer. It cannot prevent a protocol from losing its administrative keys or deploying vulnerable code. It can help prevent a company from sending funds to a fraudulent or compromised destination, allowing an unscreened transfer to proceed or discovering anomalous activity only during month-end reconciliation.
Three controls are especially important:
- Counterparty and sanctions screening checks every inbound and outbound transfer against sanctions lists, risk signals and the company’s matched-counterparty records. A recipient that appears as a wallet, bank account and exchange deposit address is treated as one entity, giving finance and compliance teams a consolidated view of exposure.
- Pre-execution enforcement applies those checks before a transaction is signed and broadcast. Depending on the company’s policy, Range can allow the transaction, block it or send it for additional review. This turns a written policy into an enforceable control inside the payment workflow.
- Continuous reconciliation and monitoring surface unexpected transfers and changes in near real time. That speed matters because laundering begins quickly. CertiK found that 80 of 88 Tornado Cash laundering flows started within one week of the original exploit.
The recovery data shows that early detection has financial value. CertiK reported that $115.3 million was frozen or returned during H1, accounting for the difference between the $1.31 billion in gross losses and the approximately $1.2 billion adjusted total. The opportunity to freeze or recover funds is measured in hours and days, rather than the time between monthly closes.
None of this replaces the compliance stack a team already runs. Range integrates with your existing sanctions and monitoring providers, while adding treasury context that those systems often lack: unified counterparties across rails, Travel Rule workflows and enforcement before the transaction executes.
Same coverage, less manual work and a control that fires before the money moves rather than a report that explains where it went.
The fastest-growing vector is not technical
Hack3d counts remote compromise. A second CertiK report, published July 23, counts the other direction, and its trend line is the steepest in either dataset: 52 verified wrench attacks in H1 2026, where physical threats or violence are used to force someone to transfer assets or surrender access to keys.
CertiK recorded 52 verified wrench attacks in H1 2026, with $124.1 million in known exposure. H1 2025 recorded $10.5 million, meaning reported exposure increased 11.8 times year over year. Home invasions rose from one incident to 20, while France accounted for 33 of the 52 verified attacks.
The way attackers select victims makes this an institutional risk as well as a personal-safety issue. CertiK found that targets can be identified through leaked databases, public wallet activity, tax and compliance records, compromised exchange data and insiders at organizations with access to sensitive information.
The consequences can extend beyond the individual. A founder or executive may also control treasury wallets, administrative keys, multisig shares, deployment permissions or exchange accounts. Under coercion, that access can turn a personal attack into a company-wide financial and operational incident.
The strongest controls reduce what any single person can authorize. Material transfers should require multiple approvers, with roles separated across initiation, review and signing. Withdrawal delays and pre-execution screening add further checkpoints that remain in place even when the person initiating the transaction is under pressure or acting on manipulated information.
Benchmark your own exposure against the H1 data
The value of CertiK’s report is its usefulness as a benchmark. Finance and compliance teams can use the findings to test whether their existing controls address the threats that most often arise and cause the largest losses.

CertiK’s H2 outlook points to more deliberate attacks on institutional infrastructure and the people who operate it. North Korean-affiliated groups are increasingly using social-engineering pipelines, infrastructure compromise and rapid cross-chain laundering. CertiK notes that the Drift incident shares characteristics with those patterns, although it has not been formally attributed.
Finance teams should prepare for online and offline attacks. The controls review should therefore extend beyond wallet architecture and smart-contract security to include recipient verification, approval separation and transaction enforcement.
Turn the H1 findings into a controls review
Finance teams should use the H1 data to answer three immediate questions: who can authorize a material transfer, how the recipient is verified and how quickly the company would detect a fraudulent payment.
The controls that answer it are the ones you can put in place before the next incident, not after. If you want to see counterparty screening and pre-execution enforcement running against your own treasury, get in touch, and we will walk through it against your actual transfer flow.
Protect your time and money
Get your unified treasury dashboard in 30 minutes.


