Go to app

2025 vs. 2026: Statistical Comparison

Published 7/17/2026, 12:13:18 PM

The data from 2025 and the first half of 2026 indicates that fewer, larger attacks are not replacing volume-driven exploits. Instead, the market is experiencing a bifurcation: sophisticated nation-state actors are concentrating on high-value infrastructure targets, while the overall frequency of attacks has reached record highs due to AI-powered automation targeting retail users and smaller protocols.

2025 vs. 2026: Statistical Comparison

While 2025 was defined by extreme concentration (a "Mega-Hack" year), 2026 has seen a massive surge in the total number of incidents, even as the total value stolen has decreased.

Metric2025 (Full Year)2026 (H1)Trend
Total Stolen~$3.4B~$972M-57% (H1 vs H1)
Incident Count~150207+149% (Record frequency)
Largest HackBybit ($1.5B)KelpDAO ($292M)Shift to Infrastructure
ConcentrationTop 3 = 69% of lossesTop 2 = 44% of lossesMore distributed risk

The "Fewer but Larger" Trend (Nation-State Strategy)

The narrative of high-concentration attacks is driven almost entirely by sophisticated groups like North Korea’s Lazarus Group. In 2026, this group accounted for 76% of all stolen value despite executing only two known attacks [Source: https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks].

The "Volume-Driven" Resurgence (AI & Retail)

Contrary to the idea that volume attacks are disappearing, Q2 2026 set a record with 70 exploits—double the previous quarterly high. This is driven by two factors:

  1. AI Multipliers: Attackers use AI to generate high-fidelity phishing campaigns and clone websites, enabling high-frequency "volume attacks" on individual wallets.
  2. DeFi Hardening: While the number of DeFi exploits remains high (60% of incidents), the median loss per exploit has fallen 75% (from $6M to $1.5M) as bug bounties and audits limit the damage of logic-based attacks.

Key Vector Evolution: From Code to Credentials

The most significant shift across both years is the transition from protocol-level exploits to infrastructure compromises. Private key and credential theft now account for 72% of all losses in 2026. Attackers are increasingly targeting the "supply chain" of crypto—signing interfaces, operator workflows, and bridge nodes—rather than the underlying smart contract code.

Conclusion

The "replacement" narrative is inaccurate. The crypto ecosystem is currently facing a two-pronged threat: protocol-level risk is consolidating into fewer, massive infrastructure hits (often by nation-states), while user-level risk is expanding into a higher volume of automated, AI-driven social engineering attacks. 2025 was an anomaly of extreme concentration due to the Bybit hack; 2026 represents a more frequent, albeit less "top-heavy," threat environment.