2025 vs. 2026: Statistical Comparison
Published 7/17/2026, 12:13:18 PM
The data from 2025 and the first half of 2026 indicates that fewer, larger attacks are not replacing volume-driven exploits. Instead, the market is experiencing a bifurcation: sophisticated nation-state actors are concentrating on high-value infrastructure targets, while the overall frequency of attacks has reached record highs due to AI-powered automation targeting retail users and smaller protocols.
2025 vs. 2026: Statistical Comparison
While 2025 was defined by extreme concentration (a "Mega-Hack" year), 2026 has seen a massive surge in the total number of incidents, even as the total value stolen has decreased.
| Metric | 2025 (Full Year) | 2026 (H1) | Trend |
|---|---|---|---|
| Total Stolen | ~$3.4B | ~$972M | -57% (H1 vs H1) |
| Incident Count | ~150 | 207 | +149% (Record frequency) |
| Largest Hack | Bybit ($1.5B) | KelpDAO ($292M) | Shift to Infrastructure |
| Concentration | Top 3 = 69% of losses | Top 2 = 44% of losses | More distributed risk |
The "Fewer but Larger" Trend (Nation-State Strategy)
The narrative of high-concentration attacks is driven almost entirely by sophisticated groups like North Korea’s Lazarus Group. In 2026, this group accounted for 76% of all stolen value despite executing only two known attacks [Source: https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks].
- Infrastructure Targeting: Attackers have moved away from smart contract logic bugs toward compromising key management and RPC nodes.
- KelpDAO ($292M): An infrastructure exploit involving poisoned RPC nodes [Source: https://www.chainalysis.com/blog/kelpdao-bridge-exploit-april-2026/].
- Drift Protocol ($285M): A credential theft involving fake token collateral [Source: https://www.chainalysis.com/blog/lessons-from-the-drift-hack/].
The "Volume-Driven" Resurgence (AI & Retail)
Contrary to the idea that volume attacks are disappearing, Q2 2026 set a record with 70 exploits—double the previous quarterly high. This is driven by two factors:
- AI Multipliers: Attackers use AI to generate high-fidelity phishing campaigns and clone websites, enabling high-frequency "volume attacks" on individual wallets.
- DeFi Hardening: While the number of DeFi exploits remains high (60% of incidents), the median loss per exploit has fallen 75% (from $6M to $1.5M) as bug bounties and audits limit the damage of logic-based attacks.
Key Vector Evolution: From Code to Credentials
The most significant shift across both years is the transition from protocol-level exploits to infrastructure compromises. Private key and credential theft now account for 72% of all losses in 2026. Attackers are increasingly targeting the "supply chain" of crypto—signing interfaces, operator workflows, and bridge nodes—rather than the underlying smart contract code.
Conclusion
The "replacement" narrative is inaccurate. The crypto ecosystem is currently facing a two-pronged threat: protocol-level risk is consolidating into fewer, massive infrastructure hits (often by nation-states), while user-level risk is expanding into a higher volume of automated, AI-driven social engineering attacks. 2025 was an anomaly of extreme concentration due to the Bybit hack; 2026 represents a more frequent, albeit less "top-heavy," threat environment.